WIN public contract sources This is source transparency, not an independent security audit. Compile standard-input.json using solc 0.8.30+commit.73712a01.Emscripten.clang. It includes all imports. Settings: optimizer enabled, 200 runs, Shanghai EVM. The source bundle is the actual input used for this release. Its SHA-256 and deployed runtime hashes are in release.json. Solidity embeds constructor immutables in deployed bytecode. Compare compiled runtime excluding immutableReferences, then separately verify every immutable getter against the public release configuration. The publication script verified owner, indexer, registry, vault, factory, fee escrow, randomness provider, coordinator, hashes and fixed fee/threshold configuration. This self-check confirms source/runtime correspondence; it does not prove absence of vulnerabilities. The owner can immediately withdraw all unpaid prize backing. There is no withdrawal timelock. See /audit for controls and limitations.