pf-2026-0019
TVK Group EcosystemEnteleWALLET PR #277
First-Party Wallet Security + Release Assurance · Multi-chain · September 7, 2026
View project →This is an organizationally independent first-party Preflight Audit assurance engagement within TVK Labs & Technologies Ltd. It is not an independent third-party audit, external certification, accreditation, or physical-wallet validation. Technical assessment evidence is complete for the stated automated scope; release-controller GO acceptance is pending and production authorization must remain fail-closed until the exact-candidate Ed25519 signature verifies.
Executive Summary
Preflight Audit completed the technical first-party release-assurance review of EnteleWALLET PR #277 and then performed a controlled release-controller trust-root rotation after the previously pinned ephemeral controller private key was found to be unavailable for legitimate future signing. The current unsigned rotated candidate is afade3aae4890eb8ecc79941fa52b8accb03e66c. Formatting, lint, type checking, localization contracts, transaction-layer controls, testnet/production separation, browser validation, Android API 30/36 validation, and multiple database/security harnesses passed on the reviewed candidate lineage. Release authorization remains intentionally pending until a fresh Ed25519 GO is signed by the newly retained controller private key and all exact-head gates pass. The current canonical v1 bundle is 1168 files with SHA-256 a449ab3515f8b72de9b156f8aacf89415310b07d4e5cc2466982bf0eedad98e2; the capability-scoped v2 bundle is 1132 files with SHA-256 f080e4b15825f486f453de27831fd847474108901057ac52a09811775f1d8dbc.
Scope
- Exact repository candidate: tvk-group/entelewallet-app @ afade3aae4890eb8ecc79941fa52b8accb03e66c
- Canonical external-wallet Send source bundle v1: 1168 files / SHA-256 a449ab3515f8b72de9b156f8aacf89415310b07d4e5cc2466982bf0eedad98e2
- Capability-scoped external-wallet Send source bundle v2: 1132 files / SHA-256 f080e4b15825f486f453de27831fd847474108901057ac52a09811775f1d8dbc
- Active release-controller fingerprint: 52b49665e0e4b431d1fa579102dc2b15d333f4a29381d799201f240b6a00d4d7
- External-wallet Send transaction construction, fee/debit binding, threat screening, simulation, recipient risk, wallet/chain/account binding and duplicate-submission controls
- Release-governance signature boundary and pinned Ed25519 controller-key verification
- Browser, Android API 30/API 36 and PostgreSQL-backed production/referral/wallet-link/MEV validation evidence
Key Highlights
- Automated format, lint, typecheck and i18n gates passed for the reviewed candidate lineage
- EnteleWALLET 1.1 transaction-layer gate and external-wallet activation security checks passed
- Testnet Send mainnet-impossibility and testnet/production separation gates passed
- Playwright and Android API 30/API 36 validation passed in the reviewed candidate evidence
- Protected release controls correctly fail closed until a fresh signature from the rotated permanent controller verifies against the exact current source bundle
Findings Breakdown
Recommendations
- Generate the fresh acceptance only on the controller owner's machine using the permanent Ed25519 private key whose public fingerprint is 52b49665e0e4b431d1fa579102dc2b15d333f4a29381d799201f240b6a00d4d7; never commit, upload or transmit that private key
- The signed acceptance must bind candidate afade3aae4890eb8ecc79941fa52b8accb03e66c and canonical v1 digest a449ab3515f8b72de9b156f8aacf89415310b07d4e5cc2466982bf0eedad98e2
- Attach only the newly signed acceptance JSON to the EnteleWALLET candidate and rerun every protected release/market/SAST gate before merge
- Keep Swap, Staking, native self-custody and physical-device validation under their separate fail-closed gates
This page contains a public assessment summary only. Full reports are available to project teams upon request. Preflight Audit is part of TVK Labs & Technologies Ltd. — a TVK Group company. Ecosystem assessments are disclosed as affiliated projects.
Request full report