1–8 October 2026

Features built this week

What landed in NODO from Wednesday 1 October through Thursday 8 October. Position history is committed on the working branch and is not on main yet. Everything else below is on main.

Product Feature Specifics
Site Hostname 6 Oct · NOD-336 The public site is https://app.nodo.xyz. DNS points at the API host directly, with a Let's Encrypt certificate. Cloudflare does not sit in front of this name. Port 80 redirects to HTTPS, except the ACME challenge path.
Old hostname 6 Oct · NOD-336 nodo-rwa.grid3.xyz on ports 80 and 443 returns 308 to https://app.nodo.xyz plus the original path and query. A 308 keeps the HTTP method, so API POSTs follow the redirect. MetaMask’s Blockaid scanner returns BLOCK for grid3.xyz, which was flagging demo transactions as malicious.
Demo routes 6 Oct Demo JSON-RPC is POST https://app.nodo.xyz/demo/rpc (any other method is 405), proxied to the demo API’s method allowlist at 5 requests per second. The demo HTTP API is under /demo/web/. Creating a session at /demo/web/v1/demo/sessions is limited to 3 requests per minute. The production session cookie is scoped to /web/v1 and is not sent to the demo API. WEBSITE_ORIGIN for liquidation alert links is https://app.nodo.xyz.
Header 6 Oct Top navigation order is Loops, Simulation, Liquidations, My Portfolio, Docs, in both the desktop and mobile menus. Try demo is a header link to /liquidations/demo.
Liquidations Desk 1–3 Oct · NOD-320 The desk reads watched RWA borrow markets on Euler v2, Morpho Blue, Aave v3, and Aave Horizon. The default read cycle is 30 seconds (LIQ_READ_CYCLE_SECONDS), and the page shows that interval. A reading older than 120 seconds (LIQ_STALE_AFTER_SECONDS) is not treated as safe and blocks plan preparation. A cycle that read no market does not refresh desk freshness.
Plan 1 Oct · NOD-320 One plan covers a withdrawal of committed capital from the fund’s chosen pool when the wallet is short (no fallback to another pool), the liquidationCall, and the expected collateral, bonus, and redemption. Size is capped at the watchlist maximum and checked again at release. Manual signing starts on Aave Horizon. The wallet signs each transaction. Discount, bonus, redemption proceeds, and settlement time are estimates. Settings changes require the fund-owner wallet’s signature, and alert recipients are masked. Viewers see the desk, history, and redemptions and cannot sign.
Watchlist 3–5 Oct · NOD-328 Each connected wallet has its own watchlist, alert channels, and inbox. Sign-in is one signed message per browser. Switching accounts never reuses another wallet’s session. Browser push follows the signed-in wallet. The same wallet sees that state in every browser where it signs in. Watching an asset records intent and does not reserve capital.
Automatic liquidation 3–7 Oct · NOD-327 On Ethereum mainnet, for Morpho Blue, Aave v3, and Aave Horizon. Any wallet deploys and manages only its own liquidator. Committed capital sits idle in that contract and can be withdrawn only back to the wallet. The keeper uses a gas-only key and holds no fund assets. Only contracts the wallet has accepted (keeperAccepted) are admitted. The fund can revoke the keeper. Collateral is paid only to the fund wallet. Open-race collateral is liquidated only when a live exit quote, confirmed by a second source, clears the fund’s minimum discount, and only by private submission. Allowlisted collateral is judged against NAV and redeemed with the issuer. Morpho repay is capped per liquidation, per window, and by the contract balance. Email is sent after each execution. On the site it is a strip on every liquidation tab; Set up opens the sheet.
Demo NODO Demo Fork 5–7 Oct · NOD-334, NOD-336 Try demo opens a mainnet fork. The banner reads: “Demo — NODO Demo Fork, a copy of Ethereum. Liquidations take this wallet’s dETH and GHO on the fork.” Start demo stages an underwater borrower and mines those transactions immediately so the call fits the proxy timeout. It seeds the borrow-market snapshot and collateral assets, and re-funds a wallet whose staged borrower is still open. Sessions are rate-limited. A fork guard, an RPC method allowlist, and a re-fork job keep the demo chain off production.
Loops Gearbox v3 open 5 Oct · NOD-315, NOD-316, NOD-317 Strategy planning runs inside the borrow runtime, and the credit-account position is reconciled from confirmed execution. A persisted market that omits quota rates is rejected. Older Gearbox snapshots from before quota rates are read as unpriced. Collateral approvals are reported during estimate.
Gearbox v3 full close 5 Oct · NOD-318 The wallet funds the debt token. The selected credit account is repaid and its collateral returns to that wallet. A Morpho close ends the wallet’s market-scoped exposure. An Euler close ends the selected dedicated subaccount. A Gearbox close ends the selected credit account.
Portfolio Position history 8 Oct · this branch, not on main Open positions keep one sample every 300 seconds, the same interval as monitor-positions. The first sample in a slot is the one stored. Fields are health factor, LTV, opening LTV, net APY, debt amount, debt value in USD, collateral value in USD, equity in USD, and status (active, externally-modified, or needs-review). A missed slot is stored as a gap. Closed positions and failed protocol reads are left out. The position detail shows the equity series, a seven-day equity change, and the snapshot table. Too little history is the status insufficient-history, with no invented series.
Platform Audit fixes 3–5 Oct · NOD-325 StrategyExecutorV2 blocks direct token calls by selector, uses a two-day timelock for target and plan-signer changes, two-step ownership, and balance baselines. An execution is stored only after the transaction is confirmed on chain. Organization membership requires the member wallet’s signed attestation, and an execution stays in the organization that created it. Workload signatures v2 cover the HTTP method, path plus query, and body digest. The site enforces a content security policy without unsafe-eval, and reports violations to /web/v1/csp-reports. The wallet dialog adds Ledger, Rabby, and Privy. API rate limits return 429.
Alert routing 4–5 Oct · NOD-326 for Resend Liquidation notices go through the wallet’s own channels, including email. Resend credentials stay in the worker environment. Slack is reserved for system errors. Source gaps and rejected targets stay in diagnostic logs.