Editorial standard
Methodology
The review separates direct evidence, bounded observations, threat-model assumptions, documented mechanics, and interpretation. Each analysis states both what the cited material establishes and what it does not.
Scope, boundaries, and threat model
What the public record establishes: The reviewed defaults concentrate several hosted and coordination roles at Lightspark; Operators receive substantial wallet and payment data; Operator code contains wallet-specific refusal controls; and none of twelve reviewed consumer-wallet surfaces exposed a complete in-app operatorless exit.
Critical boundary: The record does not show production use of the wallet gate, private compliance wiring, common control of Operator keys, retained historical keys, observed collusion, or a prepared user's inability to exit with complete current recovery material and external fee funds. Integrators can change default service configuration.
Threat-model assumption TM-1: Lightspark–Flashnet coordination is treated as a scenario to test, without assigning a probability, making the two roles one effective quorum under the published threshold. The scenario does not establish that coordination or key sharing has occurred.
Information hierarchy
The homepage presents ten principal claims. Topic pages divide those claims into evidence groups, and the 61 individual records preserve the complete technical and source trail. Direct Spark behavior, conditional attack analysis, consumer-product observations, and adjacent ecosystem context are labeled separately rather than treated as equivalent evidence.
Evidence rules
- Each factual statement identifies the sources that support it, with relevant code excerpts shown inline where available.
- Code links use pinned commits whenever available; short excerpts never replace the original.
- Threat-model assumptions are labeled and are not presented as observed events.
- Projections are not described as completed results.
- Closed-source findings are limited to published claims and observed interfaces.
- Absence findings name their reviewed scope and date and are documented in the wallet implementation review.
- Grid, Connect, Spark, Sparkcore, SSPs, Operators, and the Spark Entity are treated as distinct components.
- Exit mechanics and economics use Blink's cited public mainnet case study and a separately labeled, sanitized approximately 100,000-sat mainnet recovery record. The latter publishes rounded aggregate measurements but withholds provider provenance, transaction identifiers, addresses, raw transactions, timestamps, and secret material.
- Public code and released artifacts support independently checkable findings. Author-run wallet experiments publish sanitized aggregates; withheld recovery graphs prevent full independent reproduction of those measurements. They are labeled observations, not independently attested results.
- No assumption of operator good faith is needed: refusal, outage and malicious coordination are evaluated as scenarios. Capabilities do not establish intent, probability or observed abuse. Claims about motive require published supporting evidence.
Source types
Pinned source code, public schemas, official documentation, contracts, regulator records, public transaction data, product observations, public posts, and archived first-party material are labeled separately.
Corrections
Later contradictory evidence narrows or corrects a finding rather than being silently omitted.