QA report: external/testnet.suivision.xyz at hosted
Search queries cannot resolve checkpoint sequence numbers.
Testing exercised twelve scenarios across core explorer workflows on SuiVision Testnet, including transaction and checkpoint inspection, validator delegations, feedback dialogs, and static policy pages. Ten of the twelve scenarios passed without issue, confirming that general navigation and direct lookup flows work as expected.
One high-severity functional issue was confirmed: the main search interface fails to parse or route searches executed by checkpoint sequence numbers, showing a 'No data found' message instead of directing users to the checkpoint view.
A second finding, that the wallet connection modal "fails silently" when clicking a provider, was withdrawn after a hand check. The modal lists a fixed set of 9 named third-party wallet providers (Phantom, Slush, OKX, Backpack, Desig, Nightly, Bitget, Martian, Suiet) and offers no generic slot for a Wallet Standard wallet outside that list, so our injected test wallet was never going to be reachable through this UI. The run's own wallet log confirms zero contact with the injected wallet.
While general network telemetry and direct deep links function properly, the lack of sequence-based search indexing impairs an essential navigation path. Wallet-gated flows could not be exercised in this sandbox and remain untested rather than confirmed broken.
Run summary
| Metric | Count |
|---|
| Scenarios executed | 12 |
| Passed | 10 |
| Failed | 2 |
| Blocked | 0 |
| Findings raised | 2 |
| Issues after the audit | 1 |
| Withdrawn by the audit | 1 |
| Critical / high / medium / low | 0 / 1 / 0 / 0 |
Target: https://testnet.suivision.xyz/ · Testing level: deep_feature · Stack: unknown
Issues
High severity
F2 · Search function does not support or route by checkpoint sequence number
Severity: high · Type: functional · Verdict: confirmed · Scenario: S8
The observations confirm that the search interface fails to parse and route valid checkpoint sequence numbers, despite those checkpoints existing and loading properly via direct navigation. The live replay was inconclusive: The replay ran out of tool calls before it reached the reported state.
Expected: The application should recognize the checkpoint sequence number and navigate directly to the Checkpoint detail view (/checkpoint/387809973).
Actual: The application displays 'No data found' under the search input and does not route to the checkpoint detail view.
Steps to reproduce:
- Navigate to https://testnet.suivision.xyz/
- Enter a valid checkpoint sequence number (e.g. 387809973) into the search box
- Press Enter
Evidence: screenshots/S8-3.png, screenshots/S8-12.png
Environment limitations
These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.
- Wallet connection modal offers only named third-party providers, none of which is our injected test wallet (S1, high): I navigated to the site, clicked 'Connect wallet', and the modal successfully opened. I then clicked on wallet providers ('Phantom' and 'Slush') in the list, but they failed silently. The modal remained open and the header button still read 'Connect wallet'. A hand check of the modal (screenshots/S1-4.png) confirms it renders a fixed list of 9 named provider buttons (Phantom, Slush, OKX, Backpack, Desig, Nightly, Bitget, Martian, Suiet), with no generic slot for a Wallet Standard wallet outside that list. The run's own wallet-log.json shows 0 read requests and no signing, our injected wallet was never contacted. This is an environment or engine limitation, the sandbox does not hold any of the 9 named extensions, not a defect in the application's own connect flow.
Scenario results
| Scenario | Priority | Result | Issues |
|---|
| S1 Connect test wallet | high | fail | none |
| S2 Search by transaction digest | high | pass | none |
| S3 View realtime transactions details | high | pass | none |
| S4 Inspect checkpoint details | high | pass | none |
| S5 View validator details | high | pass | none |
| S6 Switch to All Delegations tab | medium | pass | none |
| S7 Switch to Top Delegators tab | medium | pass | none |
| S8 Search by checkpoint sequence | medium | fail | F2 |
| S9 Cross-navigate transaction to checkpoint | medium | pass | none |
| S10 Cross-navigate checkpoint to transaction | medium | pass | none |
| S11 Open Feedback dialog | low | pass | none |
| S12 Load static policy pages | low | pass | none |
The audit
The Critic reviewed 2 findings and ran 2 live replays in the browser, each on a fresh page.
- F1 is an environment limitation because the tester interacted with wallet options for extensions that the sandbox does not hold, instead of the generic injected test wallet.
- The search interface defect found in S8 highlights a functional gap between direct URL routing and the search parser.
- Hand correction, 2026-09-26: F1 was re-classified as an environment limitation and withdrawn after a hand check of the connect modal confirmed it lists only 9 fixed named wallet providers with no generic slot, and the run's wallet-log shows zero contact with our injected wallet.
What to fix first
- Add sequence number parser support to the global search bar so checkpoint lookups route directly to checkpoint detail views (F2).
Coverage and caveats
In scope: Testnet blockchain data exploration; Transaction and Checkpoint details; Validator listing and tabs; Cross-navigation between related blockchain entities; Search functionality; Wallet connection via injected provider.
Not covered: Direct URL navigation to deep links for accounts and objects (to avoid Cloudflare bot verification blocks); Submitting transactions (application is read-mostly and target is unauthenticated apart from wallet connection).
- Testnet is actively producing blocks and checkpoints, so realtime lists will populate with data.
- SPA routing (clicking links, using the search box) bypasses the Cloudflare bot protection observed on direct deep links.
- The injected test wallet is available in the browser context as described in the intake.
By the numbers
| Metric | Value |
|---|
| Scenarios | 10 passed, 2 failed, 0 blocked of 12 (27 planned steps) |
| Browser actions | 221 (47 clicks, 15 inputs, 39 navigations, 120 snapshots) |
| Screenshots | 31 (4 explore, 25 scenario, 2 critic), 25 captioned |
| Coverage | 9 pages, 0 forms, 5 flows, 2 console errors |
| Audit | 2 findings, 2 re-verified live, 1 confirmed, 0 promoted, 1 withdrawn |
| Model calls | 177 |
| Tokens | 2,433,159 input, 9,455 output, 18,729 thinking |
| Time | 14 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain sui:testnet |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|
| explore | 26 | 396,466 | 2,250 | 1,266 | 115 |
| plan | 1 | 4,124 | 1,840 | 3,387 | 35 |
| test | 134 | 1,863,712 | 4,503 | 9,427 | 639 |
| critique | 15 | 167,240 | 604 | 4,169 | 70 |
| report | 1 | 1,617 | 258 | 480 | 5 |