R/C/ Raider Research · The Charter7 rules · public before the first trade

Hostile by design. Legitimate by mechanism.

Seven rules. They are published before the first trade and enforced in the software before they are enforced on-chain. Each one says what it means in practice, how the app enforces it today, and what would break it. Break one and the story ends.

Raider is a persona run by a model under human control: humans approve every post and sign every transaction.

Rule 1 of 7

Designed mechanisms only.

Votes, parameters, redemptions. Never a bug. Never social engineering. Never a dev-held key.

In practice

Raider only uses instructions a token’s own program offers to every holder: cast a vote, pass a proposal, change a holder-adjustable parameter, call a redemption. If the only way in is a bug, the target is off the board.

How the app enforces it

The scoring engine sets capturability to 0 and raises a never-touch hit whenever capture would need an exploit, so the verdict becomes NEVER and the simulator refuses the target even when forced. The codebase contains no exploit steps and nothing that touches a dev-held key.

What would break it

One capture that relies on a program bug, a pressured or phished developer, or a key someone else controls. Once is enough.

Rule 2 of 7

No dev-controlled treasuries.

Nothing to capture. It would just fund the dev’s exit.

In practice

If a developer’s wallet, or a launchpad operator’s signer, can move the treasury, buying the token buys a promise, not the treasury. Raider walks away and says why.

How the app enforces it

Dev and platform custody both carry a custody multiplier of 0, which zeroes capturability and makes the verdict NEVER. Multisig custody is discounted to 0.55, because a few signers can still move the money mid-raid.

What would break it

Raiding a dev- or operator-held treasury on the theory that nobody will move it.

Rule 3 of 7

No living communities.

A live, posting community of ~2,000+ real holders costs more to fight than the treasury is worth.

In practice

Raider targets abandoned treasuries: hype gone, dev silent, agent on autopilot. A project with people still building and posting is not a target, however good its numbers look.

How the app enforces it

A never-touch rule fires when the community is live and real holders reach about 2,000. Real holders are counted after clustering removes same-funder and bundled wallets, so bots cannot pad the count either way.

What would break it

Moving the line to fit a target, or treating an active project as abandoned because its chart is quiet.

Rule 4 of 7

Position limit.

Max 25% of the treasury in any one target. No leverage.

In practice

One failed raid cannot sink the vault. A raid that goes wrong is posted as an exit with its P&L, not hidden as a crisis.

How the app enforces it

The paper-raid simulator clamps any request above 25% of Raider’s treasury and reports the clamp in its output. There is no leverage parameter anywhere in the code.

What would break it

Borrowing to raid, or putting more than a quarter of the treasury into one target because this one looks certain.

Rule 5 of 7

Every decision posted.

With reasoning and a tx link. Fills are posted after the fact, never before.

In practice

The thesis goes out before the first buy. Fills are posted after they happen, so nobody can trade ahead of them. Every decision lands in the hash-chained decision ledger.

How the app enforces it

Each ledger entry carries the hash of the one before it; edit any entry and every later hash breaks, which anyone can check in the browser at /ledger. Simulated transactions start with SIM-. Post drafts pass a never-say lint and a human approval gate; nothing auto-posts.

What would break it

A trade with no post, a post with no tx, a fill announced before it happens, or a ledger entry that quietly disappears.

Rule 6 of 7

Value accrues by buy-and-burn only.

No dividend. No revenue share. No promise.

In practice

Captured value buys $RAIDER on the open market and burns it. Holders are not paid, and nothing here promises that a burn does anything to the price.

How the app enforces it

The simulator honours the tender premium first, pays back the stake the raid bought, then routes 70% of what is left (net captured value) to burn and 30% to the war chest. A raid that does not profit burns nothing. There is no holder-payout path in the code, and the never-say lint blocks dividend, revenue-share, return and price-target language.

What would break it

Any distribution to holders, or any copy that promises returns.

Rule 7 of 7

Holders hold the brake.

Holders vote only to blacklist targets and pause raids. The agent picks targets.

Target state No human key can withdraw the vault. True only after the program is deployed and audited. Until then Raider is paper-only.

In practice

Holders get a veto and a brake, not a steering wheel. The planned vault has no withdraw instruction at all, so the treasury can be traded, voted and burned, but not taken out.

How the app enforces it

Today nothing in this app can move money: no keys, no wallets, no signing. Operator tools run on localhost only. Until the vault program is deployed and audited, every raid is a paper raid labelled SIM.

What would break it

A human key that can withdraw from the vault, or holders choosing targets by vote.

NT/ Never touchHard rules · checked before any score

What Raider will never touch.

Any one of these makes the verdict NEVER, whatever the Raid Score says. The list is short on purpose.

  • Dev-controlled treasuriesNothing to capture. The money would go straight to the developer’s exit.
  • Launchpad-operated custodyWhen the platform’s signer holds the key, holders have no path to the treasury, so neither does Raider.
  • Living communities of ~2,000+ real holdersThe fight costs more than the treasury, and it is a fight with people, not a dead project.
  • Anything that needs a bugIf capture requires exploiting code rather than using a designed mechanism, that is a hack, not M&A. It ends the project.