Undelivered timeout — refund to the operator
A funded slot where delivery never happened. After the timelock the Operator's commitment is refundable.
Engineering assessment, not a legal opinion
What follows describes what the contract mechanically permits. Whether it satisfies a given regulator is for counsel. Residual questions are listed rather than resolved.
What happens
refundEscrow(escrowId) is permissionless after the timelock expires. It credits the allocation as refundable; the Operator collects with withdrawRefund(escrowId).
Crediting and collecting are separate on purpose — the same reason as the dispute refund path: a settlement step must not be able to fail on a transfer.
Non-custody evaluation
Holds. VF cannot prevent the refund (permissionless), cannot accelerate it (the timelock is on-chain), and cannot receive it (the destination is the Operator's own allocation).
This path is also where V5–V7 were weakest in appearance: VF's relayer swept expired refunds, which looked like VF moving money. It never was — the V5 refundEscrow moves no tokens at all, only unlocking them back to the campaign balance for the Operator to withdraw. V8 keeps that separation and makes it explicit.
No-service evaluation
Holds. Returning a commitment to the party who made it, on a condition they set, is not a transfer executed on anyone's behalf.
Residual questions for counsel
- If VF's relayer routinely triggers refunds, VF is again in the path without authorising anything. Same shape as the release-broadcast question, and it should get the same answer.
- An Operator who never calls
withdrawRefundleaves funds in the contract indefinitely. They remain the Operator's, and nobody else can take them, but counsel may want a view on abandoned balances.