the checker/inside the enclave/the census

TEE Census

Every app on Flare that says it runs in a sealed chip has registered a fingerprint of its code. That record says which kind of chip. Most of them say "pretend".

Simulated mode is the supported way to develop, so this is expected on a testnet and is not a criticism of anyone. It is the reason the distinction has to be checkable: from the outside, an app on a simulator and an app on real confidential hardware behave identically. Both return signatures. Only this record tells them apart.

— of registrations run on real confidential hardware
Simulated (TEST_PLATFORM) Real hardware (AMD SEV, Intel TDX)
—public extensions
—with a code hash
—distinct code hashes
—extensions on real hardware

Loading the snapshot…

The ones on real hardware

— Every extension below has registered at least one code hash against AMD SEV or Intel TDX, which means an attestation from it can be checked against genuine confidential hardware. An extension registers a new hash each time its code changes, so several have more than one.

ExtensionPlatformHashesCode hash
Loading…

Why this page exists

A signature proves a key was used. It does not prove which machine used it, or what code that machine was running. Those facts live in the attestation certificate and in this registry, and comparing the two is the only way to tell a genuine enclave from a convincing imitation. That comparison is what the checker does for a single certificate; this page is the same question asked of the whole network.

Reads FlareTeeManager live from your browser. Takes under a minute.

Data read from FlareTeeManager at 0x1a9C4A0f9D76c0b1D91d22E24E573a9b377618aE on Coston2. Reproduce it yourself with node tools/registry-scan/scan.mjs. Open source, MIT.