Docs menu

CACHET docs, for developers

Contract

CachetCollection is a buyer-paid ERC-721 on Robinhood Chain 4663. Its EIP-712 domain is Cachet Collection, version 1, bound to the chain and deployed collection address. It inherits Ownable and Pausable. No relayer or hook mints pieces for buyers.

Status

Deployment

Constructor fields, in order: address owner, address signer, address token, address pool, uint256 minBuy, bytes32 seedCommitment, bytes32 ciphertextHash, bytes32 attestationHash, bytes32 sealManifestHash, uint64 drandRound, uint64 notBefore. The first claimer publishes fixed CREATE2 initcode, committing the four nonzero hashes on chain at that time. That can be later than offline seal creation. The manifest hash binds the other three hashes, round and time. Publication is blocked until independent Chutes attestation and output binding are implemented. Owner-only signer rotation remains.

Mint authorization

MintAuthorization(address buyer,bytes32 buyRef,uint256 amountIn,uint256 deadline)
mintForBuy(address buyer, bytes32 buyRef, uint256 amountIn, uint256 deadline, bytes signature)

The API checks a confirmed token Transfer from the selling pool to the final buyer and signs this typed message. The contract checks signer, deadline, minimum, transaction sender equal to buyer, unused buy reference and a lifetime one-claim rule for that buyer through claimedBuyer, regardless of current NFT balance. A repeated buyer reverts with BuyerAlreadyClaimed(). The contract does not inspect past token transfers itself. The buyer pays the network fee. A signer mistake can authorize an ineligible buy, so the API proof remains a trust boundary.

Functions and events

Public and operator ABI entries include mintForBuy, reserve, commitClaim, claimWithCode, revealSeed, seedOf, tokenURI, seedCommitment, ciphertextHash, attestationHash, sealManifestHash, drandRound, notBefore. The signer alone may reserve a settled code hash. A later-block commitment binds code, caller and recipient; a successful code claim consumes it once. The ZEC door is disabled pending live settlement proof. The contract emits SignerChanged, Minted, CodeReserved, ClaimCommitted, Transfer as applicable.

Cachet privacy mechanism

The site-owned preparation code derives the collection seed from a Chutes confidential model response plus a local nonce and encrypts it with tlock-js. Pinned drand identity and the ciphertext's embedded round are checked. Evidence and output binding are still unverified. A hash of evidence is not DCAP or NVIDIA verification. The producer may know the seed. The contract checks only seed hash and wall-clock gate; it does not verify beacon or TEE proofs.

Artwork and metadata

imageForTraits(uint8[5], bool, bytes32) draws the original on-chain line artwork with five groups, including five backgrounds. Before reveal, tokenURI shows sealed art and hides trait names; after reveal it derives traits from the disclosed seed. Minted emits zero as the seed before reveal. A public reveal discloses the seed and all traits.

Seal and reveal commands

Site-owned preparation: node scripts/prepare-cachet.cjs LAUNCH_ISO OUTPUT_JSON MODEL_ID CHUTE_ID. The resulting seal is marked UNVERIFIED and cannot become CREATE2 initcode until independent evidence and output binding are implemented. After the round, node scripts/reveal-cachet.cjs INPUT_JSON OUTPUT_JSON validates the seal, decrypts and writes calldata without sending a transaction. No plaintext seed is logged before reveal.

Ethers browser bundle provenance

The local pristine ethers 6.16.0 UMD bundle has SHA-256 9a85a5aa81305f85e6546452fd2093a8a68932bed3cec4f6491e4d031a90bc95. The shipped bundle has SHA-256 65772f76fae0bc74e7b923bc27aa928f48d7a9a72cc374f6393cf9378129d789. Byte comparison found one local license header and five address literal splits. The splits join the same address at runtime. The six exact edits are in contracts/vendor-patches/ethers.umd.min.patch.json. From the workspace root, run node .foreman/seven-cooks/privacy-tools/round5-vendor-proof.cjs to apply the edits to the pristine copy and compare every shipped byte.

The reported SigningKey.addPoints defect is not present in the local evidence: its implementation is byte identical in pristine and shipped ethers 6.16.0. Both compute the compressed point G + 2G as 3G. No addPoints correction can be attributed to this shipped bundle without another verified baseline.

Launch inputs

Collection, token, pool, minimum, owner and signer addresses must be set to real launch values. Prepare the seal against the pinned quicknet identity and publish the ciphertext, commitment, round, notBefore and matching CREATE2 constructor data. The test seal in evidence is not a production deployment. No production collection address is claimed on this page.