One developer wallet A single developer wallet receives creator fees and signs payouts. Its balance is accounted in separate buckets: - Creator-fee funds: only newly verified creator-fee revenue enters the pool, measured from confirmed collection transactions. - Committed holder liabilities: entitlements not yet confirmed as paid. These are never available to new rounds. - Operating funds: deposits for network fees and rent. Never taken from the pool. - Other developer assets: anything else; never counted as pool funds. Project-controlled token holdings are excluded from cashback.
Isolated signer The key lives only in a separate signer service on a private network. It accepts two authenticated request types (a committed payout batch, or a creator-fee collection) and builds those transactions itself. It independently checks that every recipient holds committed, unpaid entitlement and refuses anything that would spend reserved funds. Optional per-transaction, per-round and per-day caps exist; the operator currently runs without practical caps. It never signs a transaction supplied by the website, the support assistant or any public API.
What the operator can do - Pause and resume rounds and payouts (the emergency pause). - Change parameters by publishing a new configuration version; each round records the version it used. - Disable the signer entirely. - Deploy new code.
The operator holds the developer wallet key and could move its funds outside this system. CASHBACK is not trustless, audited or unhackable; it is designed to make its behaviour verifiable on this site and on chain.