1–8 October 2026
Features built this week
What landed in NODO from Wednesday 1 October through Thursday 8 October. Position history is committed on the working branch and is not on main yet. Everything else below is on main.
| Product | Feature | Specifics |
|---|---|---|
| Site | Hostname 6 Oct · NOD-336 |
The public site is https://app.nodo.xyz. DNS
points at the API host directly, with a Let's Encrypt
certificate. Cloudflare does not sit in front of this name.
Port 80 redirects to HTTPS, except the ACME challenge path.
|
| Old hostname 6 Oct · NOD-336 |
nodo-rwa.grid3.xyz on ports 80 and 443 returns
308 to
https://app.nodo.xyz plus the original path and
query. A 308 keeps the HTTP method, so API POSTs follow the
redirect. MetaMask’s Blockaid scanner returns BLOCK for
grid3.xyz, which was flagging demo transactions
as malicious.
|
|
| Demo routes 6 Oct |
Demo JSON-RPC is
POST https://app.nodo.xyz/demo/rpc (any other
method is 405), proxied to the demo API’s method allowlist at
5 requests per second. The demo HTTP API is under
/demo/web/. Creating a session at
/demo/web/v1/demo/sessions is limited to 3
requests per minute. The production session cookie is scoped
to /web/v1 and is not sent to the demo API.
WEBSITE_ORIGIN for liquidation alert links is
https://app.nodo.xyz.
|
|
| Header 6 Oct |
Top navigation order is Loops, Simulation, Liquidations, My
Portfolio, Docs, in both the desktop and mobile menus. Try
demo is a header link to /liquidations/demo.
|
|
| Liquidations | Desk 1–3 Oct · NOD-320 |
The desk reads watched RWA borrow markets on Euler v2, Morpho
Blue, Aave v3, and Aave Horizon. The default read cycle is 30
seconds (LIQ_READ_CYCLE_SECONDS), and the page
shows that interval. A reading older than 120 seconds
(LIQ_STALE_AFTER_SECONDS) is not treated as safe
and blocks plan preparation. A cycle that read no market does
not refresh desk freshness.
|
| Plan 1 Oct · NOD-320 |
One plan covers a withdrawal of committed capital from the
fund’s chosen pool when the wallet is short (no fallback to
another pool), the liquidationCall, and the
expected collateral, bonus, and redemption. Size is capped at
the watchlist maximum and checked again at release. Manual
signing starts on Aave Horizon. The wallet signs each
transaction. Discount, bonus, redemption proceeds, and
settlement time are estimates. Settings changes require the
fund-owner wallet’s signature, and alert recipients are masked.
Viewers see the desk, history, and redemptions and cannot sign.
|
|
| Watchlist 3–5 Oct · NOD-328 | Each connected wallet has its own watchlist, alert channels, and inbox. Sign-in is one signed message per browser. Switching accounts never reuses another wallet’s session. Browser push follows the signed-in wallet. The same wallet sees that state in every browser where it signs in. Watching an asset records intent and does not reserve capital. | |
| Automatic liquidation 3–7 Oct · NOD-327 |
On Ethereum mainnet, for Morpho Blue, Aave v3, and Aave
Horizon. Any wallet deploys and manages only its own
liquidator. Committed capital sits idle in that contract and
can be withdrawn only back to the wallet. The keeper uses a
gas-only key and holds no fund assets. Only contracts the
wallet has accepted (keeperAccepted) are admitted.
The fund can revoke the keeper. Collateral is paid only to the
fund wallet. Open-race collateral is liquidated only when a
live exit quote, confirmed by a second source, clears the
fund’s minimum discount, and only by private submission.
Allowlisted collateral is judged against NAV and redeemed with
the issuer. Morpho repay is capped per liquidation, per
window, and by the contract balance. Email is sent after each
execution. On the site it is a strip on every liquidation tab;
Set up opens the sheet.
|
|
| Demo | NODO Demo Fork 5–7 Oct · NOD-334, NOD-336 | Try demo opens a mainnet fork. The banner reads: “Demo — NODO Demo Fork, a copy of Ethereum. Liquidations take this wallet’s dETH and GHO on the fork.” Start demo stages an underwater borrower and mines those transactions immediately so the call fits the proxy timeout. It seeds the borrow-market snapshot and collateral assets, and re-funds a wallet whose staged borrower is still open. Sessions are rate-limited. A fork guard, an RPC method allowlist, and a re-fork job keep the demo chain off production. |
| Loops | Gearbox v3 open 5 Oct · NOD-315, NOD-316, NOD-317 | Strategy planning runs inside the borrow runtime, and the credit-account position is reconciled from confirmed execution. A persisted market that omits quota rates is rejected. Older Gearbox snapshots from before quota rates are read as unpriced. Collateral approvals are reported during estimate. |
| Gearbox v3 full close 5 Oct · NOD-318 | The wallet funds the debt token. The selected credit account is repaid and its collateral returns to that wallet. A Morpho close ends the wallet’s market-scoped exposure. An Euler close ends the selected dedicated subaccount. A Gearbox close ends the selected credit account. | |
| Portfolio | Position history 8 Oct · this branch, not on main |
Open positions keep one sample every 300 seconds, the same
interval as monitor-positions. The first sample
in a slot is the one stored. Fields are health factor, LTV,
opening LTV, net APY, debt amount, debt value in USD,
collateral value in USD, equity in USD, and status
(active, externally-modified, or
needs-review). A missed slot is stored as a gap.
Closed positions and failed protocol reads are left out. The
position detail shows the equity series, a seven-day equity
change, and the snapshot table. Too little history is the
status insufficient-history, with no invented
series.
|
| Platform | Audit fixes 3–5 Oct · NOD-325 |
StrategyExecutorV2 blocks direct token calls by
selector, uses a two-day timelock for target and plan-signer
changes, two-step ownership, and balance baselines. An
execution is stored only after the transaction is confirmed on
chain. Organization membership requires the member wallet’s
signed attestation, and an execution stays in the organization
that created it. Workload signatures v2 cover the HTTP method,
path plus query, and body digest. The site enforces a content
security policy without unsafe-eval, and reports
violations to /web/v1/csp-reports. The wallet
dialog adds Ledger, Rabby, and Privy. API rate limits return
429.
|
| Alert routing 4–5 Oct · NOD-326 for Resend | Liquidation notices go through the wallet’s own channels, including email. Resend credentials stay in the worker environment. Slack is reserved for system errors. Source gaps and rejected targets stay in diagnostic logs. |