Labels: bridge, compliance, priority:medium
Body:
Problem
Pi Network mainnet is still gradually opening (KYC gating, migrated vs. non-migrated wallets). Nothing states which Pi account states are eligible to originate a bridge deposit, so the relayer has no defined policy to enforce or reject against.
Proposed fix
Write an explicit eligibility policy (e.g., "only migrated, KYC'd Pi mainnet accounts may deposit") and have the relayer check and reject ineligible sources before ever calling mint_from_deposit.
Acceptance criteria
Labels: bridge, compliance, priority:medium
Body: