A little ghost.
A clearer picture.
From early explorations to a working Cattle preview. Each pass records its question, what changed and what we kept. Generated concepts and browser captures are labeled separately.
The starting point
Familiar principles. Cattle’s own character.
The brief: build a framework-free landing page and app around a cutesy ghostly cow, using the imagegen design guide and the existing Eiko, Gyro, Odette and Meryl work as references.
Three hypotheses · generated concepts
Which first step makes sense?
These initial concepts used a tentative ThetaCow “price and date” brief while the product question was pending. The user then clarified Cattle’s long/short scope. Their visual ideas remain useful; their product framing is superseded.



User correction → source review → revised concept
Strategy, collateral and borrowing.
The user clarified that ThetaCow is specific to the short side, while ThetaCattle handles capital-efficient long and short exposure. Source review in thetaAaveCattle/ established the three parts that the interface must keep distinct.

| Observation | Decision | Reason |
|---|---|---|
| Long and short are option strategies | Adopt explicit names and behavior | Long call buys into strength. Covered short sells into strength. A covered short is not a bearish leveraged short. |
| Collateral has two assets | Show both underlying amounts | Both are supplied to Aave. A live starting mix must be quoted and validated. |
| Strike is quote per base | Show USDC per WETH | A dollar sign alone silently changes the product’s units. |
| Borrowing is optional | Separate it from creation | Debt adds interest, liquidation exposure and possible trade restrictions. |
| Short uses a pink down arrow | Reject the arrow shorthand | It suggests a price-down bet. The native UI uses the trading behavior instead. |
| Generated borrow buttons look live | Adapt into a labeled learning example | No live quote, reserve checks or transaction integration is available. |
| Several nested summaries repeat | Simplify in code | One receipt and one borrowing explanation are enough. |
Built-in imagegen · project assets
A companion with a job to do.
Two transparent raster illustrations give the landing, summary and empty state a consistent identity. Controls, units and diagrams remain native HTML/CSS. No incoming coin stream or safety shield implies a guaranteed result.

Used in the landing hero. Original generated artwork; not an Aave or CoW logo.

Used in the strategy summary and empty local-example view.
Generation method and full prompts
All four UI proposals and both final assets used the built-in imagegen tool. Prompts, exact source references, scope decisions and the illustration prompts are preserved in DESIGN-NOTES.md. The alpha channels are preserved in the project PNGs.
Native implementation · interactive preview
From a picture to a usable page.
The builder supports both strategies, validates both amounts and a future expiry, explains strike units, and reviews a frozen copy of the inputs. Examples can be saved and removed locally. The guide and borrowing lesson are optional native dialogs.
Landing · actual browser captures
Live /dev/cattle/ preview · 1440 × 1050 desktop and 390 × 844 phone viewports · full-page captures · no wallet · default Long call comparison.


Builder · first implementation → refined
Base WETH/USDC example · Long call · 0.25 WETH + 600 USDC · strike 2,400 USDC/WETH · expiry 28 September 2026, 00:00 UTC. CSS v2; the later JS v3 change adds focus cycling without changing the captured layout.


Review, save and understand borrowing



Behavior and understanding
Test what the page teaches.
Browser behavior can be checked now. Whether an unfamiliar user understands the product still needs user testing.
| Check | Result | Evidence scope |
|---|---|---|
| Input/model tests | 12 / 12 pass | Exact decimals, both deposit legs, invalid dates, malformed/denied storage, preserved past examples and independent borrowing anchors. |
| App interactions | Pass | Long/short switching, edits, frozen review, acknowledgement, save, reload and remove. |
| Negative amount / past date | Review remains closed | Field error appears and focus moves to the invalid input. |
| Borrowing lesson | Expected health values | No debt: no finite HF. Moderate debt: 2.00 → 1.90. Large hedge: 1.07 → 0.85, labeled blocked. |
| Keyboard dialogs | Pass after refinement | Tab/Shift+Tab cycle inside Guide; Escape returns focus to Guide. |
| Responsive geometry | No horizontal page overflow | App at 320, 390, 768, 1440 CSS px. Landing at 320, 390, 1440 CSS px. Main review button: 55px high. |
| Console and artwork | No observed app errors or broken app images | Live /dev/cattle/ checks. Generated PNG alpha preserved. |
| Live finance and comprehension | Not tested | No wallet/contract integration or newcomer study in this preview. |
Phone evidence uses measured viewport emulation. Window resizing alone did not change the viewport. A background-page capture stalled; checking resumed after selecting the target tab.
Questions for a newcomer
- Does “covered short” mean you profit whenever price falls?
- What goes into the position: an option premium or both collateral assets?
- Is borrowing automatic? What additional risk does it introduce?
- Why might a position’s next hedge be blocked while its current health factor is above one?
Record wrong turns and hesitation before changing the UI again. This journal does not claim measured comprehension or conversion gains.
Approved preview → external wallet and live positions
A real pasture, with room to explore.
The user approved the initial direction and requested wallet integration using Gyro, Eiko and Odette as references. Cattle may hold a large position, so the chosen pattern uses an external wallet. The app now opens on positions; the example builder remains one tab away.
| Need | Decision | Behavior |
|---|---|---|
| Connect a chosen wallet | Cattle-owned copy of Gyro’s bridge | Injected wallets, WalletConnect and Coinbase. No temporary wallet or private-key storage. |
| Explore without funds | Three explicit view choices | My wallet, sample data and live address preview. A fresh preview never reconnects a remembered wallet. |
| Debug the backend trial | One-click thetadeployer address | Shows the verified short D and long E positions, current collateral, debt, health and trade previews. |
| Prevent stale identity | Clear and reload on source/account changes | Superseded requests cannot publish data under another address. Disconnect removes listeners and reconnect preference. |
| Show account state accurately | Separate collateral, debt and health | Failed reads stay unavailable. Collateral less debt excludes exit fees. Post-transfer health excludes incoming proceeds. |


User observations · queued for the next visual/copy pass
More intent. A little moonlight.
The user noted that “long” and “covered short” do not explain why someone would choose either strategy. Long is generally bullish. Short commonly expresses range-bound or yield intent, with a delta-hedging spread intended to cover option premiums. That spread target does not apply to long. Neither is an exact replica of a conventional option payoff.
Latency → discovery index plus current chain reads
The index gets us started. Base fills the gap.
The user requested an indexer and clarified that cron always lags. Cattle now uses a dedicated Cloudflare D1 discovery index. The browser checks its block hash, reads every later block through the current snapshot, and reads balances and the lens directly at that snapshot.
| Condition | Result |
|---|---|
| Valid index | Reuse verified deployment history; scan from indexed block + 1 and refresh all account values directly. |
| Warming, stale, unavailable or mismatched index | Full chain discovery from the configured factory deployment. A failed read never means zero. |
| Lagging RPC or provider disagreement | Do not certify the interval. Each log provider must match the shared block hash before and after returning events. |
| Reorg or overlapping cron runs | Lease and atomic SQL fences protect the cursor. A reorg clears the prefix and rebuilds it. |
| Debugging | Use index=0 for direct discovery. Source and checkpoint details stay in the debug state and engineering notes. |
Live verification: the app used checkpoint 51,290,649, filled the next 23 blocks directly, and read both accounts at block 51,290,672. A separate indexed/full-scan comparison at 51,290,704 returned identical position data. One observed run took 7.6 seconds versus 8.5 seconds; no broad latency claim is inferred. Actual indexed phone capture ↗
Four independent wording reviews → one synthesis
Start with the view. Then explain the trade.
The user requested Claude Fable, Gemini via agy, Zai and a fresh Codex Astra. All four reviewed a frozen copy of the site. Their shared finding: the short’s intent was missing, while “replicate” and “stays available to borrow against” could promise too much.
The shared short description now explains the premium target and that no separate option premium is paid or received at entry. Mode banners follow the actual route. These model reviews do not establish measured newcomer comprehension.
Moonlit pasture → a working night theme
The same pasture, after sundown.
A smiling sun/moon toggle switches the landing, app and journal. Deep navy-green panels, lilac accents and quiet meadow silhouettes carry the original night concept into the actual interface. Numbers and controls keep clear contrast.

Regenerated hero artwork. Native CSS blends its opaque night backdrop into the page.

Used in summaries and empty states. img/assets/mark-night.png ↗
User correction → three generated order layouts
Short waits at limits. Long rebalances toward a target.
The user clarified that short should show a buy limit below and a sell limit above, while long uses a market rebalance after a sufficient target gap. Source review confirmed two short grid sides and one bounded market order for long. The option strike is not a fabricated long trigger.



Position identity + HF across prices + debt scenarios
What you hold. How its health can change.
Cards now lead with strategy notional, such as “1 × wstETH,” followed by the strategy, strike and expiry. Current supplied assets remain separate. The user chose a rebalancing-only HF estimate, with liquidation and the borrowing limit marked.


Independent review caught and verified a fix for two liquidation crossings hidden around a shallow U-shaped minimum. The implementation finds extrema before crossing searches. Current configuration has no separate Call/Put subtype; debt changes net exposure without changing the encoded strategy name.
Lifecycle study · roll integration queued
Funding is a start. Borrowing is another decision.
The guide now separates deploy/fund, review of the first rebalance, optional borrowing, and repayment or rolling. Borrowing is not bundled into creation. The HF planner gives the independent debt decision a place in the current read-only app.
Roll transaction controls remain queued. This study does not enable delegation, borrowing, repayment, rolling or activation sends. The initial pass had 75 passing tests; browser checks cover live charts, hypothetical borrowing and full repayment, 320/390px layouts, system theme changes, denied storage and the night wallet picker.
User correction → a continuous HF estimate
Buying can stop. Collateral still has value.
The user challenged the message “This target needs additional funding. No HF is plotted here.” With wstETH collateral and USDC debt, HF can keep rising as wstETH rises. Running out of quote assets limits further buying; it does not make the account’s health undefined.
The correction is checked against independently executed small trades for long and short in both price directions, including initially unaffordable targets. All 79 tests pass. Live charts were checked at Base block 51,294,774: the long’s +60% price point retains 0.97752 wstETH and zero USDC supplied, with HF 2.280 and debt unchanged. An independent unequal-LT cusp case also finds both liquidation and borrowing-limit crossings between ordinary plot samples. Astra verification ↗ · Repayment scenario capture ↗
User correction → both directions for long
Sell on a fall. Buy on a rise.
A single current order did not explain both responses. Long positions now have paired Sell market and Buy market tiles with estimated trigger prices. The current contract preview stays separate, with its actual minimum or maximum execution-price bound.
Independent reference: one base token of notional, 0.5 held, strike 3,100, 52% IV, seven days and a 30-quote minimum gives sell near 3,086.552, buy near 3,097.384, and a lower sell cutoff at 60. Review caught a tiny-CDF discontinuity at the minimum quote atom; the regression now prevents a false far-away trigger. Final-hour pause, missing inputs and fully held targets have explicit states.
Funding → optional borrowing in one tutorial
Keep the next decision in the same example.
The user asked to include borrowing in the example flow, then keep the example as tutorial mode for the live integration. Borrowing now follows the funding inputs inline. The separate borrowing lesson dialog is removed.
My Wallet → cached positions and the next action
Resume with context. Refresh before acting.
My Wallet can show its last saved positions immediately while refreshing Base data. Each fresh position links to its own Borrow, Repay and Roll review flow. The selected position, its assets and its debt carry into the review.


104 tests pass. Browser checks covered inline borrowing, saving and reload, actual long trigger levels, cache hydration, failed refresh, account/network changes and a refused already-funded roll destination. Independent cache and flow review ↗ · Repayment review capture ↗
15 September · user review of prices and spacing
Compare the same kind of price.
The user found that the long’s inventory-based triggers were far from the current order’s buy maximum. Short tiles showed execution limits, while long tiles showed activation thresholds. That comparison was misleading.


108 tests pass. Independent review verified price scaling, outward rounding, phase gates and retaining an exact candidate when the separate oracle read fails. Desktop and 390px phone checks found no horizontal overflow; the CoW history link opened the correct account.
User follow-up → contract pricing investigation
When to buy is different from the maximum to pay.
For long, the inventory-neutral price is where the target base amount equals the amount held. An oracle price sufficiently above it creates a buy gap; sufficiently below it creates a sell gap. The resulting market order is protected at the current oracle price plus or minus the slippage cap.
No arithmetic or direction bug was found in this witness. Exact inputs and RPC results ↗ · Assessment and scope ↗. No orders, signatures, backend settings or contracts were changed.
15 September · user wording refinement
Say what the strategy does.
The user proposed “buys” and “sells” in place of “targets more” and “targets less.” The shared descriptions now use those direct verbs, while keeping the bullish and range-bound intent labels.
Short: Buys more WETH as price falls and sells as it rises.
Applied to position cards, tutorial summaries, reviews, saved examples, the guide and landing-page direction labels. Live cards use their actual asset symbol. Execution conditions remain in the order details; this change describes the strategy’s direction.
User review → gaps before real funding
The interface is ready for the execution layer.
The user asked what remains before creating and funding real positions. Existing wallet reads, discovery, cache, scenarios and action reviews are in place. The next work is live configuration, transaction execution and recovery.
The current read/model tests do not establish live transaction readiness. Prove the full lifecycle on a Base fork, then a small explicitly authorized live run. No runtime capability was enabled by this assessment. Concrete gaps and implementation order ↗
15 September · sanity review before implementation
Keep the first live flow small.
A fresh agent read the requested sanity-check persona and critiqued the plan before coding. Its main finding was excess recovery machinery. The user asked for a minimum functioning version and confirmed the trial defaults.
Minimum live version · external wallet on Base
Create, fund, then choose what comes next.
New position creates a wstETH / USDC long call or covered short. Starting amounts are editable; a suggested mix helps explain strategy size. An unfunded option prepares a roll destination. Funding supplies assets to Aave and starts trading without creating debt.


120 frontend tests and two deployed-contract Base fork lifecycle tests pass. Browser checks use a wallet fixture with no key or send support. No agent wallet transaction was broadcast. Fable + Zai findings and decisions ↗ · Validation and limits ↗ · Open Cattle ↗
18 September · fee recipient clarification
The annual fee goes to the protocol.
The user clarified that the 1% annual fee belongs to the deployer/protocol. The earlier owner-recipient default and “paid to your wallet” wording were incorrect for new user positions.

121 tests pass. Independent evaluator review and browser checks passed. Validation ↗ · Open corrected app ↗
21 September · latest deployed contracts
A weekly cycle, with the same pasture.
The new Base deployment supports perpetual positions. Creation now offers weekly repetition or a dated expiry, with 53% trial IV. The calendar returns to the same strike each week; closing or rolling remains the owner’s choice.


130 frontend tests and five deployed-contract Base fork tests pass, including old-to-new debt roll and the one-hour-early weekly rollover. Both discovery indices are ready. Browser checks use real chain data and a wallet fixture without signing support. Deployment, review and validation ↗ · Open updated app ↗



