- messages.js: challenge/personal_sign/recover auth (vendored pinned
js-sha3 0.9.3 + noble-secp256k1 1.7.1, server-side only; self-tested
positive + tamper cases), 30d HttpOnly sessions, message store on the
volume, matrix-line permissions (your downline direct or broadcast, your
upline chain - nothing else, so spam is impossible by construction),
daily rate limits (30 direct / 3 broadcasts), 1500-char plain text
- chain.js: memberIdByAccount (wallet -> position for sign-in)
- API: msg-challenge/-verify/-me/-inbox/-send/-read public + msg-unread
(count only, no auth) + admin/messages (full visibility, disclosed to
members in the UI)
- Dashboard: Messages card with unread bell, one-tap wallet sign-in,
inbox with auto-read, compose with to-ID or whole-team broadcast
- Admin: Member Messages review table
- Chatbot canned answer + AI system prompt updated
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- GET /api/public/moonpay-url: returns a MoonPay checkout link for POL on
Polygon (pol_polygon). With partner keys in config (moonpayPublicKey/
moonpaySecretKey, now PATCHable), the URL is HMAC-signed and prefilled
with the member's own wallet address + shortfall amount; without keys it
falls back to MoonPay's generic buy page. MoonPay is merchant of record -
the site never touches funds.
- Join page: when the connected wallet can't cover the Premium entry, a
funding box appears with the exact shortfall, a buy button (new tab), and
a refresh-balance button.
- Training page: "buy POL with a card" callout after the funding video with
the three things to get right (POL, Polygon network, own address).
- Start page: one-line card-buy pointer under the sponsor card.
- Chatbot canned answer + AI system prompt updated (funding guidance).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Every coaching output now ends by teaching the recipient how to teach:
point them at the Coach Your Team panel on THEIR own dashboard and tell
them to run the same play for their two.
- Member dashboard dCoach footer: "you're not coaching two people - you're
teaching two coaches"; easy-win rows add "show them how you spotted it"
- Admin Coaching Radar: teach-forward rule footer
- AI chat system prompt: COACHING DOCTRINE section so chat answers frame
guidance teach-forward
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- chain.js getCoachingScan(rootId): classifies everyone below a root into
atRisk (POL forming they can't catch - corrected bought-level rule),
rollForward (qualified-at-Scintilla with entry rewards covering Ascensus),
and oneAway (1/2 directs)
- Admin: GET /api/admin/coaching?root= (name-decorated) + "Coaching Radar"
panel with tiered who/what-to-say/POL-at-stake rows, auto-loaded
- Member dashboards: memberPublic now returns .coach scoped to the member's
own leg; new "Coach your team" card shows the same triage so every member
coaches their own team - computed live, no snapshots or cron needed
- Chatbot canned answer + AI system prompt updated to describe the panel
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- chain.js getOrgShare now returns genCounts (breadth-first members per
generation below the root)
- Admin "Your Organization vs. the Network" panel renders a Gen 1..N bar list
with fill-vs-capacity (2^n slots)
- Member dashboard "Your team" card gains a Team Depth section computed from
the subtree client-side, labeling each generation with the level whose
upgrade pays that position (gen D pays at the level D+1 buy)
- AI chat system prompt updated to describe the new dashboard section
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Self-enroll pageviews now tracked as the "joinnow" event (track.js loaded
on the page; server whitelist + admin tiles/columns extended)
- A confirmed on-chain registration in the wallet-connect flow now auto-posts
to the submit-id API, so every self-enroll join records a submission with
source + clickid attribution and fires the purchase event and BeMob postback
with no manual ID entry
- Optional name/handle field on the join page feeds the submission and the
team Telegram alert
- Admin Traffic panel: Join-now views tile, Join-now -> Confirmed conversion,
and a per-source Confirmed column for campaign-level ROI reading
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New 4-min screen recording of the on-site wallet-connect join flow becomes
Video 4; the old dApp walkthrough is relabeled as the Video 5 backup method
and the payments explainer moves to Video 6. Chatbot canned answers and the
AI system prompt now describe the updated video lineup.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
/join-now now honors ?ref=<id> (resolves that member's moving-link joinTarget;
falls back to the global rotation sponsor). Repointed: /start 'Join With Current
Sponsor' -> /join-now; /my pitch buttons -> /join-now?ref=<id>; invite page
/join/<id> join button -> /join-now?ref=<id>; bare /join redirect -> /join-now.
'Get Started' learn CTAs still go to /start for onboarding. When the flag is off,
/join-now gracefully redirects to /start, so the wiring is safe either way.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
/join-now: public self-enroll page gated behind config.dappFallbackPublic
(default off -> redirects to /start, invisible until needed). Auto-assigns the
current rotation sponsor via /api/public/current-sponsor, registers the user's
own wallet, then redirects to /my/<newId> so new members land on their live
position instead of guessing their ID. HTML lives in private/, served only via
the flagged route. Reuses the proven contract engine. Admin /direct-join now
also shows a 'View position ->' link to /my/<newId> after a successful join.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contingency tool: if the official RM Circle dApp ever goes down, positions can
still be created/upgraded straight from the member's own wallet. Vanilla JS
talks only to window.ethereum (CSP-safe, no external libs), builds register()
[0x30de37e4, sponsorId+tier, value=base*1.05] and upgrade() [0xd55ec697,
value=next-level cost] calls decoded from live txs, reads prices via
getAllCosts() and position via getMember(address). Page lives outside public/
and is served only through a getSession-gated route, so it's admin-only. The
contract is public and immutable, so this cements a company-domain-independent
path to enroll.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds pyramid/Ponzi, 'if my 2 can't get their 2', affordability, 'not a
salesperson', and 'people quit' to both the chat.js canned KB and the
server.js AI system prompt (kept in sync). Answers distinguish this from a
pyramid (no pooled funds, same-tx peer-to-peer, verifiable on-chain), stay
honest (spillover fills the matrix but never qualifies; upgrades optional),
and never promise income. Keywords are apostrophe-free to match the punctuation-
stripped matcher.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The private 'upgrade #N soon' owner alert was firing to both email and the
Telegram feed; Marty wants it in his inbox only. Drop the sendTelegram call
(the email on the line above already covers every owner watcher). Payout and
recruiting Telegram feeds are unaffected.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
sendTelegram() takes an optional reply_markup; the recruiting posts carry an
inline URL button (🚀 Get Started — rmcircle.team) under every event, so the
busy new-members feed converts attention into clicks to the home page.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
sendTelegram() now takes an optional topicId; the same team events that post to
the internal team-build topic also fan out a recruiting-framed version (social
proof + CTA to rmcircle.team, no internal/contact detail) to the new-members
topic. Gated on config.telegramRecruitTopicId — dormant until set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds a synthesized next-step panel to /my: the level ladder (you-are-here →
upgrade-next), the single clearest action (qualify vs upgrade), and a funded
badge that checks the member's wallet against their next upgrade cost.
Privacy: the wallet balance is checked server-side (chain.balanceOf via
eth_getBalance) and ONLY a funded true/false is returned — the raw balance is
never exposed on the ID-addressable dashboard.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Fixes the spillover leak where a qualified member promoting their own link had
joins land back on themselves (bonus reward) instead of qualifying their team.
- /api/public/member now returns joinTarget: unqualified member -> self;
qualified -> next-to-qualify in their leg (reuses rotation-aligned nextInLine);
whole leg qualified -> global rotation sponsor; else -> spillover (prior behavior)
- /join page: the Join button, "join under" header, sponsor-ID copy, and the
submitted sponsorId all follow joinTarget; a note explains "invited by #X,
joining to help #Y qualify" so the new member knows their real sponsor
- Member's SHARE link is unchanged (/join/<id>); resolution happens when a
visitor opens it, so it self-corrects even for links already in the wild
Dry-run verified: /join/27 -> #34, /join/34 -> #34 (self), /join/21 -> #34.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Public promo is now RM-Circle-only; the Crypto Team Build Network is learned
after joining, not surfaced to prospects.
- nav brand "Crypto Team Build" -> "RM Circle" (subtitle "Premium Team Build")
- all <title>, og:site_name, twitter meta, footers, disclaimers, 404, chatbot
system prompt + canned answers, config siteName/supportLabel swept
- removed "a project of the Crypto Team Build Network" framing from prose
- banners regenerated: eyebrow now "The RM Circle · Polygon" (was Crypto Team Build)
- og-card.jpg regenerated (was "CRYPTO TEAM BUILD NETWORK PRESENTS")
- roadmap.webp already RM-Circle branded (no change needed)
- social posts/swipes: #CryptoTeamBuild -> #RMCircle, "crypto team build" -> "RM Circle team build"
Videos still reference old branding (VO + embedded site screenshot) — rebuilt next.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- 7-size banner kit (1200x630, 1080x1080, 1080x1920, 300x250, 728x90,
468x60, 125x125) rendered on-brand, exact dimensions, served from /banners
- Promo Tools page: 5 copy-paste social posts (X/Facebook), short + standard
+ long email swipes, banner grid (download / copy-URL), invite-link builder
- Branded Voice CTA (mybrandedvoice.com) for writing promos in your own voice
- Sync chatbot: chat.js canned answer + server.js AI system prompt updated
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Training: new "Video 5 · Why you're not getting paid yet" card with the
payments teaching video (+ poster). Promo Tools page at /tools (noindex,
unlinked from public nav — a team resource): share-ready video clips
with copy-link buttons, a personal invite-link builder, and three
compliant email/message swipes; banners noted as generate-on-request.
Chatbot gains a promo-tools answer. Old scroll-only clip is superseded
by the combined cut (retire it).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Domain migration go-forward: replaced every hardcoded rmcircle.saasy.top
across public/*.html (canonical, og:url, og:image, twitter tags),
chat.js (chatbot answer URLs + linkify self-link matcher), my.js, and
server.js (member-page OG injection, unsubUrl, chat system prompt) with
rmcircle.team. Old domain still serves everything; canonical now points
search engines + social previews at the new primary domain.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Feature (Marty): live payment proof + notifications now show the
generation for upgrade pass-ups (matrix hop distance payer→recipient),
removing the "why did they get it" question. chain.genBetween() adds a
`gen` field to payout events + /api/public/payouts; rendered as a gold
"Gen N" badge in the feed, "Gen N pass-up" in toasts, and "Gen N …" in
Telegram team alerts.
Domain: rmcircle.team is now live (added to Coolify alongside
rmcircle.saasy.top, SSL issued, both serve, no redirect). Switched the
auto-tweet CTA to https://rmcircle.team.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New chain.getOrgRouting(rootId, ownerIds) simulates the contract's
_payUpline routing for every member below the org root on their NEXT
upgrade, classifying where the POL lands: your positions, a teammate
in-org (healthy), an outsider above the org (true LEAK), or fees.
Surfaced on /api/admin/income and rendered as a panel in "My Positions
— Income": 4-stat summary + expandable list of payments escaping the
org. Distinguishes real leaks (money leaving the team) from teammates
earning — which the old upgrade-needs alert conflated.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New tweet.js posts a tweet to X via Blotato each time the indexer emits
a NEW team payout. Org-gated to the #21 organization; fires on all
payout types. Ships DISABLED (config.tweetEnabled default off / env
TWEET_ON_PAYOUT), so nothing posts until explicitly turned on.
Safety: dedupes by tx key (persisted to DATA_DIR/tweeted-payouts.json)
so restarts never re-post; a min-gap queue keeps bursts under Blotato's
30/min limit; API key read from env BLOTATO_API_KEY or DATA_DIR key
file, never committed or logged. Varied emoji/hashtag templates with a
CTA (+UTM) to the main page; deterministic template pick avoids X
duplicate-content rejection. Admin config allowlist gains tweetEnabled,
tweetCtaUrl, tweetHashtags, blotatoTwitterId.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The feed showed only the latest 12 of 136 recorded payouts. Now:
- chain.getPayoutsPublic(offset,limit) returns a page of the full
reversed history plus total/offset/limit/hasMore (limit capped 100).
- /api/public/payouts accepts ?offset & ?limit (defaults 0/40, so the
live poll + toast detection are unchanged).
- payouts.js keeps a deduped store keyed by payout key; the live poll
refreshes the recent page while "Show more" pulls older pages 12 at a
time (with slight overlap so a newly-arrived payout can't open a gap),
and "Show fewer" collapses back. Verified in-browser: 12 → 48 → 136
rows, button flips to "Show fewer", collapses to 12, 0 console errors.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Home page: new reassurance band between the live payment feed and the
final CTA — surfaces the three doubts (rules can't change, money never
sits in the contract, keeps running if creators vanish) and routes
skeptics to /contract.
CSP fix (the real find): style-src was 'self' with no 'unsafe-inline',
so the browser was silently dropping EVERY inline style="" attribute
site-wide — the attribute stayed in the DOM but never applied. This is
why the earlier margin fix only worked once moved to a class, and why
the new card rendered left-aligned with a teal eyebrow. Added
'unsafe-inline' to style-src only (script-src stays locked to 'self').
Verified via computed styles + full-page screenshots: home, /contract,
/how-pay-works now render as authored.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Answers the durability question: the contract is autonomous and
immutable (no admin heartbeat, no pause, no expiry), and the four
admin wallets are plain EOAs — read live from contract storage and
confirmed via eth_getCode — so a lost/abandoned admin wallet can
never reject or jam a member payment; at worst the project's own fee
sits uncollected. No stored balance means nothing can be stranded.
- contract.html: new section 6 card
- chat.js: matching canned answer (creators-disappear keywords)
- server.js: RESILIENCE fact added to the AI system prompt
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
chat.js: new canned answers for how-you-get-paid (two streams + depth-
matched levels), Premium vs Standard tier, and the member dashboard/
alerts. server.js AI system prompt: added PAY FLOW, TIERS, and MEMBER
DASHBOARD facts, and refreshed the site-pages list (/how-pay-works,
/my, /disclaimer, spillover article). Both chat modes now answer the
questions this session surfaced (skips, standard tier, dashboards).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Visual explainer of the two income streams: entry rewards you keep, and
the depth-matched upgrade ladder (each layer pays you once, at the one
level matching its depth) as an SVG flow diagram. Route + CSS added;
linked from training body and all footers. Educational, on-chain-factual
framing with disclaimer link.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
/my/:id and /join/:id are now served with server-injected, per-member
Open Graph + Twitter Card tags (social scrapers don't run JS, so the
per-ID meta must be in the static HTML). Strips any baked-in og/twitter
tags and injects a fresh ID-specific set — title/description reference
the member #, branded og-card.jpg image, canonical per-ID og:url. Bare
/my and /join paths unchanged.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Public /api/public/org-stats (from config.orgRootId, default 21) feeds a
prominent home-page band: share of the whole network, team size,
generations deep, and on-chain POL to the team — populated by bridge.js,
section hides itself if stats aren't ready. Paired with three mechanics
cards (spillover fills your matrix, depth pays as it climbs, the rotation
qualifies you) that make the "winning team" case honestly, plus the risk
caveat ("most participants may not profit") and a disclaimer link.
Live: 51.1% of members, 48 in the org, 10 generations, 25,423 POL.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New chain.getOrgShare(rootId) + /api/admin/org-share endpoint compute an
org's share of the whole contract by both member count and total POL
paid, from in-memory state. Admin card (default root 21, saved to
config.orgRootId, auto-loads) shows the two headline percentages, a bar,
and the member/POL breakdown. Verified: #21 org = 51.1% of members,
49.5% of POL.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A rotation joiner submits their ID after the rotation may have advanced
(esp. with auto-advance: the direct who completes a sponsor's 2/2 joined
under it, but the queue has already moved on). Keying "rotation" off the
currently-active sponsor mislabeled them "leg" (hit live: Harvey #92
under #36 after #36 qualified). Now: rotation if the on-chain referrer
is a queue sponsor that is active OR qualified (was/is worked); a
still-waiting or non-queue referrer stays a leg join, preserving the
original #49/#56-under-#46 fix. Auto-enqueue now parents the new
position to the actual on-chain referrer, not the current active.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reverses the earlier manual-Qualify design (Marty 2026-08-15): when the
auto-count brings a queue sponsor to 2/2 directs, the sponsor is now
auto-qualified and normalizeStatuses activates the next waiting position
— same as clicking Qualify, but automatic. Previously it stopped at 2/2
"active" and waited for a manual click, which left the rotation looking
stuck (hit live with #36 Mad Dog). #36 qualified manually to catch up;
rotation advanced to #34 Janie.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- /disclaimer: independent-resource, affiliate, earnings, risk, and
not-advice disclosures; linked from all footers.
- Self-service alerts: members opt in with their email on /my/:id to get
"you've been paid" + "upgrade needed" emails for their own position
(same watcher as the owner alerts, extended). Signed unsubscribe link
(/unsubscribe?id=&t=HMAC), on-chain-registration check, rate-limited,
masked-email status, confirmation email.
- Admin login: timing-safe compare + per-IP lockout (8 fails -> 15 min,
escalating). Previously unlimited/brute-forceable.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
New owner upgrade watcher: every 5 min it checks config.ownerIds against
the chain state and, when a leg member is ONE upgrade from paying a
position that isn't eligible yet (below the required level, or not
qualified), emails config.ownerAlertEmail + pings Telegram — "upgrade
#24 to Fabrica, #61 is one upgrade from paying you 2,486 POL." Deduped
per (position, level) in owner-alerts.json, re-fires if the situation
recurs. Same warning renders inline in the admin "My Positions" panel
(upgradeNeeds in the income endpoint). New ownerAlertEmail settings
field. Detection logic unit-tested.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Aggregates every on-chain payment received by a set of owned IDs
(defaults to 21,24,25, saved to config.ownerIds and prefilled/auto-loaded
next time). Shows grand total + per-position totals and a merged,
newest-first ledger (to / from / entry-or-upgrade level / amount) via a
focused chain.getIncome read and an admin-gated /api/admin/income
endpoint. Verified: 5,064.43 POL across 21/24/25, 11 payments.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Shareable page from the 2026-08-13 source review: code immutability
(no proxy/delegatecall/selfdestruct, Sourcify exact match), same-tx
distribution (no pooled funds), locked prices and fee constants, the
honest list of owner powers with the 50% entry-fee cap, where unmatched
pass-ups go, and verify-yourself links. Linked from all public footers,
the payment-proof note, and the chatbot (canned + AI prompt).
Also: passed-over lists now exclude structurally-skipped uplines — a
level-N payment never checks the first N-1 uplines, so listing them as
"not eligible" was misleading.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
When a queue member's MemberUpgraded event lands, their Level in the
rotation queue updates automatically (same op as the admin dropdown),
with a Telegram note. Current queue trued up against the chain: four
entries corrected (30, 35, 46 up to Ascensus; 56 down to Scintilla —
it had been set optimistically).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The chain-only BFS pick could promote structurally-next but inactive
positions (#21's dashboard said #38 — not in the queue, likely inactive —
while the team rotation was working #36). Next-in-line now prefers the
active rotation sponsor when they're in the member's leg and unqualified,
then the first chain-order queue participant, falling back to the pure
structural pick for legs outside the queue.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A verified rotation join (@chriskelly8, ID 73 under #36) still required
a manual "add to queue" step from the Telegram message and got missed.
Rotation-path submissions now insert themselves into the sponsor queue
as waiting positions (name from the submission, level from chain,
parent = active sponsor, dedupe-guarded), and the Telegram alert reports
the queue position instead of asking for action. #73 was added manually
to catch up.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Prospects who clicked a member's shared /my link landed on a bare stats
dashboard with no explanation of the program. New /join/<id> page carries the
full bridge-page story (video, strategy, matrix, live on-chain payout proof)
personalized to one sponsor: their live position stats as proof, their ID
pinned on the dApp join button, and the submit-your-ID form locked to them
(source invite-<id>). Dashboard share buttons + QR codes now hand out the
invite page; /my stays the member dashboard. Invalid/unregistered invite ids
fall back to the /start rotation. Tracked as new 'join' event with an admin
traffic column.
Also: the chain indexer now auto-increments a rotation sponsor's directs when
a registration names them as referrer (same op as the admin ⊕), announcing it
on Telegram. At 2/2 it alerts to Qualify instead of auto-rotating — moving
the team focus stays a human decision.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two leg-build members submitted the /start form thinking it was required,
polluting rotation bookkeeping. Rather than two forms, the server now
classifies every submission by on-chain truth: referrer == active
rotation sponsor -> "rotation" (Telegram says +1 direct, add to queue);
anyone else -> "leg" (correct sponsor credited, "no rotation action
needed"). The member dashboard gains its own "Just joined under this
position?" form so leg builders have a proper landing spot; /start
feedback explains each path to the submitter; admin submissions table
shows a rotation/leg chip. Verified against live data: ID 65 claiming
sponsor 36 correctly classified leg under #62.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Marty's final framing: the teachable rule stays "get your 2, retire
your link, help your 2" — but a late signup on a qualified link is
presented everywhere as a welcome bonus (full entry reward + depth via
spillover), never a rule violation. Applied consistently across the
strategy page, start callout, chatbot (canned + AI prompt), training
article, and both share-card notes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>