Warning! Contract bytecode has been changed and doesn't match the verified one. Therefore, interaction with this smart contract may be risky.
- Contract name:
- Shadow
- Optimization enabled
- true
- Compiler version
- v0.8.33+commit.64118f21
- Optimization runs
- 200
- EVM Version
- shanghai
- Verified at
- 2026-03-07T07:15:52.994787Z
Constructor Arguments
0x00000000000000000000000091aa12ba1a1c5ad3d7215ad0ac075c0b86e1c75b0000000000000000000000006dc226aa43e86fe77735443fb50a0a90e5666aa4000000000000000000000000e36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb0000000000000000000000000000000000000000000000006f05b59d3b200000
Arg [0] (address) : 0x91aa12ba1a1c5ad3d7215ad0ac075c0b86e1c75b
Arg [1] (address) : 0x6dc226aa43e86fe77735443fb50a0a90e5666aa4
Arg [2] (address) : 0xe36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb
Arg [3] (uint256) : 8000000000000000000
src/impl/Shadow.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
import {IEthMinter} from "../iface/IEthMinter.sol";
import {IShadow} from "../iface/IShadow.sol";
import {IShadowCompatibleToken} from "../iface/IShadowCompatibleToken.sol";
import {IShadowVerifier} from "../iface/IShadowVerifier.sol";
import {ShadowLayout} from "./Shadow_Layout.sol";
import {OwnableUpgradeable} from "../lib/OwnableUpgradeable.sol";
import {PausableUpgradeable} from "@openzeppelin/contracts-upgradeable/security/PausableUpgradeable.sol";
import {ReentrancyGuardUpgradeable} from "@openzeppelin/contracts-upgradeable/security/ReentrancyGuardUpgradeable.sol";
/// @custom:security-contact security@taiko.xyz
contract Shadow is IShadow, ShadowLayout, OwnableUpgradeable, PausableUpgradeable, ReentrancyGuardUpgradeable {
/// @custom:oz-upgrades-unsafe-allow state-variable-immutable
IShadowVerifier public immutable verifier;
/// @custom:oz-upgrades-unsafe-allow state-variable-immutable
IEthMinter public immutable etherMinter;
/// @notice Address that receives the claim fee (0.1%).
/// @dev Immutable at implementation-deploy time.
/// @custom:oz-upgrades-unsafe-allow state-variable-immutable
address public immutable feeRecipient;
/// @notice Maximum ETH amount (in wei) that can be claimed in a single proof.
/// @dev Mirrors the ZK circuit's MAX_TOTAL_WEI (8 ETH). Acts as an on-chain
/// guardrail if the verifier is ever misconfigured during an upgrade.
/// @custom:oz-upgrades-unsafe-allow state-variable-immutable
uint256 public immutable maxClaimAmount;
/// @dev Consumed nullifiers to prevent replayed claims.
mapping(bytes32 _nullifier => bool _consumed) private _consumed;
/// @dev Reserved storage gap for future upgrades.
uint256[49] private __gap;
uint256 internal constant _FEE_DIVISOR = 1000; // 0.1%
/// @custom:oz-upgrades-unsafe-allow constructor
constructor(address _verifier, address _etherMinter, address _feeRecipient, uint256 _maxClaimAmount) {
require(_verifier != address(0), ZeroAddress());
require(_etherMinter != address(0), ZeroAddress());
require(_feeRecipient != address(0), ZeroAddress());
verifier = IShadowVerifier(_verifier);
etherMinter = IEthMinter(_etherMinter);
feeRecipient = _feeRecipient;
maxClaimAmount = _maxClaimAmount;
}
/// @notice Initializes the proxy and transfers ownership to the Taiko DAO.
/// @dev The owner (proxy admin) MUST be the Taiko DAO governance contract
/// (timelock/multisig). UUPS upgrades replace all immutable dependencies
/// (verifier, etherMinter, feeRecipient, maxClaimAmount) atomically;
/// all upgrade proposals must go through DAO governance.
function initialize(address _owner) external initializer {
__OwnableUpgradeable_init(_owner);
__Pausable_init();
__ReentrancyGuard_init();
}
/// @notice Returns whether the nullifier has been consumed.
function isConsumed(bytes32 _nullifier) external view returns (bool _isConsumed_) {
_isConsumed_ = _consumed[_nullifier];
}
/// @notice Pauses the contract, disabling new claims.
/// @dev Only callable by the contract owner. Use in emergencies to halt ETH minting.
function pause() external onlyOwner {
_pause();
}
/// @notice Unpauses the contract, re-enabling claims.
/// @dev Only callable by the contract owner.
function unpause() external onlyOwner {
_unpause();
}
/// @notice Submits a proof and public inputs to mint ETH via the configured minter hook.
/// @dev Applies a 0.1% claim fee (`amount / 1000`) to feeRecipient.
/// @dev Protected by `whenNotPaused`: the owner can halt all new claims in an emergency
/// (e.g., if a critical vulnerability is discovered in the verifier or minter).
///
/// @dev **Deposit cap rationale:**
/// The ZK circuit enforces a maximum total of 8 ETH per deposit. This bounds the
/// extractable value from any hypothetical birthday collision attack on the 160-bit
/// target address space (~2^80 hash operations), ensuring such an attack remains
/// economically infeasible.
function claim(bytes calldata _proof, PublicInput calldata _input) external whenNotPaused nonReentrant {
require(_input.chainId == block.chainid, ChainIdMismatch(_input.chainId, uint64(block.chainid)));
require(_input.amount > 0, InvalidAmount(_input.amount));
require(_input.recipient != address(0), InvalidRecipient(_input.recipient));
if (_consumed[_input.nullifier]) {
revert NullifierAlreadyConsumed(_input.nullifier);
}
verifier.verifyProof(_proof, _input);
_consumed[_input.nullifier] = true;
uint256 fee = _input.amount / _FEE_DIVISOR;
uint256 netAmount = _input.amount - fee;
if (_input.token == address(0)) {
// ETH path
require(_input.amount <= maxClaimAmount, AmountExceedsMax(_input.amount, maxClaimAmount));
etherMinter.mintEth(_input.recipient, netAmount);
if (fee > 0) {
etherMinter.mintEth(feeRecipient, fee);
}
} else {
// ERC20 path
IShadowCompatibleToken token_ = IShadowCompatibleToken(_input.token);
require(
_input.amount <= token_.maxShadowMintAmount(),
AmountExceedsMax(_input.amount, token_.maxShadowMintAmount())
);
token_.shadowMint(_input.recipient, netAmount);
if (fee > 0) {
token_.shadowMint(feeRecipient, fee);
}
}
emit Claimed(_input.nullifier, _input.recipient, _input.amount, _input.token);
}
}
node_modules/@openzeppelin/contracts-upgradeable/interfaces/draft-IERC1822Upgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.5.0) (interfaces/draft-IERC1822.sol)
pragma solidity ^0.8.0;
/**
* @dev ERC1822: Universal Upgradeable Proxy Standard (UUPS) documents a method for upgradeability through a simplified
* proxy whose upgrades are fully controlled by the current implementation.
*/
interface IERC1822ProxiableUpgradeable {
/**
* @dev Returns the storage slot that the proxiable contract assumes is being used to store the implementation
* address.
*
* IMPORTANT: A proxy pointing at a proxiable contract should not be considered proxiable itself, because this risks
* bricking a proxy that upgrades to it, by delegating to itself until out of gas. Thus it is critical that this
* function revert if invoked through a proxy.
*/
function proxiableUUID() external view returns (bytes32);
}
node_modules/@openzeppelin/contracts-upgradeable/proxy/ERC1967/ERC1967UpgradeUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (proxy/ERC1967/ERC1967Upgrade.sol)
pragma solidity ^0.8.2;
import "../beacon/IBeaconUpgradeable.sol";
import "../../interfaces/IERC1967Upgradeable.sol";
import "../../interfaces/draft-IERC1822Upgradeable.sol";
import "../../utils/AddressUpgradeable.sol";
import "../../utils/StorageSlotUpgradeable.sol";
import {Initializable} from "../utils/Initializable.sol";
/**
* @dev This abstract contract provides getters and event emitting update functions for
* https://eips.ethereum.org/EIPS/eip-1967[EIP1967] slots.
*
* _Available since v4.1._
*/
abstract contract ERC1967UpgradeUpgradeable is Initializable, IERC1967Upgradeable {
// This is the keccak-256 hash of "eip1967.proxy.rollback" subtracted by 1
bytes32 private constant _ROLLBACK_SLOT = 0x4910fdfa16fed3260ed0e7147f7cc6da11a60208b5b9406d12a635614ffd9143;
/**
* @dev Storage slot with the address of the current implementation.
* This is the keccak-256 hash of "eip1967.proxy.implementation" subtracted by 1, and is
* validated in the constructor.
*/
bytes32 internal constant _IMPLEMENTATION_SLOT = 0x360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3ca505d382bbc;
function __ERC1967Upgrade_init() internal onlyInitializing {
}
function __ERC1967Upgrade_init_unchained() internal onlyInitializing {
}
/**
* @dev Returns the current implementation address.
*/
function _getImplementation() internal view returns (address) {
return StorageSlotUpgradeable.getAddressSlot(_IMPLEMENTATION_SLOT).value;
}
/**
* @dev Stores a new address in the EIP1967 implementation slot.
*/
function _setImplementation(address newImplementation) private {
require(AddressUpgradeable.isContract(newImplementation), "ERC1967: new implementation is not a contract");
StorageSlotUpgradeable.getAddressSlot(_IMPLEMENTATION_SLOT).value = newImplementation;
}
/**
* @dev Perform implementation upgrade
*
* Emits an {Upgraded} event.
*/
function _upgradeTo(address newImplementation) internal {
_setImplementation(newImplementation);
emit Upgraded(newImplementation);
}
/**
* @dev Perform implementation upgrade with additional setup call.
*
* Emits an {Upgraded} event.
*/
function _upgradeToAndCall(address newImplementation, bytes memory data, bool forceCall) internal {
_upgradeTo(newImplementation);
if (data.length > 0 || forceCall) {
AddressUpgradeable.functionDelegateCall(newImplementation, data);
}
}
/**
* @dev Perform implementation upgrade with security checks for UUPS proxies, and additional setup call.
*
* Emits an {Upgraded} event.
*/
function _upgradeToAndCallUUPS(address newImplementation, bytes memory data, bool forceCall) internal {
// Upgrades from old implementations will perform a rollback test. This test requires the new
// implementation to upgrade back to the old, non-ERC1822 compliant, implementation. Removing
// this special case will break upgrade paths from old UUPS implementation to new ones.
if (StorageSlotUpgradeable.getBooleanSlot(_ROLLBACK_SLOT).value) {
_setImplementation(newImplementation);
} else {
try IERC1822ProxiableUpgradeable(newImplementation).proxiableUUID() returns (bytes32 slot) {
require(slot == _IMPLEMENTATION_SLOT, "ERC1967Upgrade: unsupported proxiableUUID");
} catch {
revert("ERC1967Upgrade: new implementation is not UUPS");
}
_upgradeToAndCall(newImplementation, data, forceCall);
}
}
/**
* @dev Storage slot with the admin of the contract.
* This is the keccak-256 hash of "eip1967.proxy.admin" subtracted by 1, and is
* validated in the constructor.
*/
bytes32 internal constant _ADMIN_SLOT = 0xb53127684a568b3173ae13b9f8a6016e243e63b6e8ee1178d6a717850b5d6103;
/**
* @dev Returns the current admin.
*/
function _getAdmin() internal view returns (address) {
return StorageSlotUpgradeable.getAddressSlot(_ADMIN_SLOT).value;
}
/**
* @dev Stores a new address in the EIP1967 admin slot.
*/
function _setAdmin(address newAdmin) private {
require(newAdmin != address(0), "ERC1967: new admin is the zero address");
StorageSlotUpgradeable.getAddressSlot(_ADMIN_SLOT).value = newAdmin;
}
/**
* @dev Changes the admin of the proxy.
*
* Emits an {AdminChanged} event.
*/
function _changeAdmin(address newAdmin) internal {
emit AdminChanged(_getAdmin(), newAdmin);
_setAdmin(newAdmin);
}
/**
* @dev The storage slot of the UpgradeableBeacon contract which defines the implementation for this proxy.
* This is bytes32(uint256(keccak256('eip1967.proxy.beacon')) - 1)) and is validated in the constructor.
*/
bytes32 internal constant _BEACON_SLOT = 0xa3f0ad74e5423aebfd80d3ef4346578335a9a72aeaee59ff6cb3582b35133d50;
/**
* @dev Returns the current beacon.
*/
function _getBeacon() internal view returns (address) {
return StorageSlotUpgradeable.getAddressSlot(_BEACON_SLOT).value;
}
/**
* @dev Stores a new beacon in the EIP1967 beacon slot.
*/
function _setBeacon(address newBeacon) private {
require(AddressUpgradeable.isContract(newBeacon), "ERC1967: new beacon is not a contract");
require(
AddressUpgradeable.isContract(IBeaconUpgradeable(newBeacon).implementation()),
"ERC1967: beacon implementation is not a contract"
);
StorageSlotUpgradeable.getAddressSlot(_BEACON_SLOT).value = newBeacon;
}
/**
* @dev Perform beacon upgrade with additional setup call. Note: This upgrades the address of the beacon, it does
* not upgrade the implementation contained in the beacon (see {UpgradeableBeacon-_setImplementation} for that).
*
* Emits a {BeaconUpgraded} event.
*/
function _upgradeBeaconToAndCall(address newBeacon, bytes memory data, bool forceCall) internal {
_setBeacon(newBeacon);
emit BeaconUpgraded(newBeacon);
if (data.length > 0 || forceCall) {
AddressUpgradeable.functionDelegateCall(IBeaconUpgradeable(newBeacon).implementation(), data);
}
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[50] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/proxy/beacon/IBeaconUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts v4.4.1 (proxy/beacon/IBeacon.sol)
pragma solidity ^0.8.0;
/**
* @dev This is the interface that {BeaconProxy} expects of its beacon.
*/
interface IBeaconUpgradeable {
/**
* @dev Must return an address that can be used as a delegate call target.
*
* {BeaconProxy} will check that this address is a contract.
*/
function implementation() external view returns (address);
}
node_modules/@openzeppelin/contracts-upgradeable/proxy/utils/Initializable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (proxy/utils/Initializable.sol)
pragma solidity ^0.8.2;
import "../../utils/AddressUpgradeable.sol";
/**
* @dev This is a base contract to aid in writing upgradeable contracts, or any kind of contract that will be deployed
* behind a proxy. Since proxied contracts do not make use of a constructor, it's common to move constructor logic to an
* external initializer function, usually called `initialize`. It then becomes necessary to protect this initializer
* function so it can only be called once. The {initializer} modifier provided by this contract will have this effect.
*
* The initialization functions use a version number. Once a version number is used, it is consumed and cannot be
* reused. This mechanism prevents re-execution of each "step" but allows the creation of new initialization steps in
* case an upgrade adds a module that needs to be initialized.
*
* For example:
*
* [.hljs-theme-light.nopadding]
* ```solidity
* contract MyToken is ERC20Upgradeable {
* function initialize() initializer public {
* __ERC20_init("MyToken", "MTK");
* }
* }
*
* contract MyTokenV2 is MyToken, ERC20PermitUpgradeable {
* function initializeV2() reinitializer(2) public {
* __ERC20Permit_init("MyToken");
* }
* }
* ```
*
* TIP: To avoid leaving the proxy in an uninitialized state, the initializer function should be called as early as
* possible by providing the encoded function call as the `_data` argument to {ERC1967Proxy-constructor}.
*
* CAUTION: When used with inheritance, manual care must be taken to not invoke a parent initializer twice, or to ensure
* that all initializers are idempotent. This is not verified automatically as constructors are by Solidity.
*
* [CAUTION]
* ====
* Avoid leaving a contract uninitialized.
*
* An uninitialized contract can be taken over by an attacker. This applies to both a proxy and its implementation
* contract, which may impact the proxy. To prevent the implementation contract from being used, you should invoke
* the {_disableInitializers} function in the constructor to automatically lock it when it is deployed:
*
* [.hljs-theme-light.nopadding]
* ```
* /// @custom:oz-upgrades-unsafe-allow constructor
* constructor() {
* _disableInitializers();
* }
* ```
* ====
*/
abstract contract Initializable {
/**
* @dev Indicates that the contract has been initialized.
* @custom:oz-retyped-from bool
*/
uint8 private _initialized;
/**
* @dev Indicates that the contract is in the process of being initialized.
*/
bool private _initializing;
/**
* @dev Triggered when the contract has been initialized or reinitialized.
*/
event Initialized(uint8 version);
/**
* @dev A modifier that defines a protected initializer function that can be invoked at most once. In its scope,
* `onlyInitializing` functions can be used to initialize parent contracts.
*
* Similar to `reinitializer(1)`, except that functions marked with `initializer` can be nested in the context of a
* constructor.
*
* Emits an {Initialized} event.
*/
modifier initializer() {
bool isTopLevelCall = !_initializing;
require(
(isTopLevelCall && _initialized < 1) || (!AddressUpgradeable.isContract(address(this)) && _initialized == 1),
"Initializable: contract is already initialized"
);
_initialized = 1;
if (isTopLevelCall) {
_initializing = true;
}
_;
if (isTopLevelCall) {
_initializing = false;
emit Initialized(1);
}
}
/**
* @dev A modifier that defines a protected reinitializer function that can be invoked at most once, and only if the
* contract hasn't been initialized to a greater version before. In its scope, `onlyInitializing` functions can be
* used to initialize parent contracts.
*
* A reinitializer may be used after the original initialization step. This is essential to configure modules that
* are added through upgrades and that require initialization.
*
* When `version` is 1, this modifier is similar to `initializer`, except that functions marked with `reinitializer`
* cannot be nested. If one is invoked in the context of another, execution will revert.
*
* Note that versions can jump in increments greater than 1; this implies that if multiple reinitializers coexist in
* a contract, executing them in the right order is up to the developer or operator.
*
* WARNING: setting the version to 255 will prevent any future reinitialization.
*
* Emits an {Initialized} event.
*/
modifier reinitializer(uint8 version) {
require(!_initializing && _initialized < version, "Initializable: contract is already initialized");
_initialized = version;
_initializing = true;
_;
_initializing = false;
emit Initialized(version);
}
/**
* @dev Modifier to protect an initialization function so that it can only be invoked by functions with the
* {initializer} and {reinitializer} modifiers, directly or indirectly.
*/
modifier onlyInitializing() {
require(_initializing, "Initializable: contract is not initializing");
_;
}
/**
* @dev Locks the contract, preventing any future reinitialization. This cannot be part of an initializer call.
* Calling this in the constructor of a contract will prevent that contract from being initialized or reinitialized
* to any version. It is recommended to use this to lock implementation contracts that are designed to be called
* through proxies.
*
* Emits an {Initialized} event the first time it is successfully executed.
*/
function _disableInitializers() internal virtual {
require(!_initializing, "Initializable: contract is initializing");
if (_initialized != type(uint8).max) {
_initialized = type(uint8).max;
emit Initialized(type(uint8).max);
}
}
/**
* @dev Returns the highest version that has been initialized. See {reinitializer}.
*/
function _getInitializedVersion() internal view returns (uint8) {
return _initialized;
}
/**
* @dev Returns `true` if the contract is currently initializing. See {onlyInitializing}.
*/
function _isInitializing() internal view returns (bool) {
return _initializing;
}
}
node_modules/@openzeppelin/contracts-upgradeable/proxy/utils/UUPSUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (proxy/utils/UUPSUpgradeable.sol)
pragma solidity ^0.8.0;
import "../../interfaces/draft-IERC1822Upgradeable.sol";
import "../ERC1967/ERC1967UpgradeUpgradeable.sol";
import {Initializable} from "./Initializable.sol";
/**
* @dev An upgradeability mechanism designed for UUPS proxies. The functions included here can perform an upgrade of an
* {ERC1967Proxy}, when this contract is set as the implementation behind such a proxy.
*
* A security mechanism ensures that an upgrade does not turn off upgradeability accidentally, although this risk is
* reinstated if the upgrade retains upgradeability but removes the security mechanism, e.g. by replacing
* `UUPSUpgradeable` with a custom implementation of upgrades.
*
* The {_authorizeUpgrade} function must be overridden to include access restriction to the upgrade mechanism.
*
* _Available since v4.1._
*/
abstract contract UUPSUpgradeable is Initializable, IERC1822ProxiableUpgradeable, ERC1967UpgradeUpgradeable {
/// @custom:oz-upgrades-unsafe-allow state-variable-immutable state-variable-assignment
address private immutable __self = address(this);
/**
* @dev Check that the execution is being performed through a delegatecall call and that the execution context is
* a proxy contract with an implementation (as defined in ERC1967) pointing to self. This should only be the case
* for UUPS and transparent proxies that are using the current contract as their implementation. Execution of a
* function through ERC1167 minimal proxies (clones) would not normally pass this test, but is not guaranteed to
* fail.
*/
modifier onlyProxy() {
require(address(this) != __self, "Function must be called through delegatecall");
require(_getImplementation() == __self, "Function must be called through active proxy");
_;
}
/**
* @dev Check that the execution is not being performed through a delegate call. This allows a function to be
* callable on the implementing contract but not through proxies.
*/
modifier notDelegated() {
require(address(this) == __self, "UUPSUpgradeable: must not be called through delegatecall");
_;
}
function __UUPSUpgradeable_init() internal onlyInitializing {
}
function __UUPSUpgradeable_init_unchained() internal onlyInitializing {
}
/**
* @dev Implementation of the ERC1822 {proxiableUUID} function. This returns the storage slot used by the
* implementation. It is used to validate the implementation's compatibility when performing an upgrade.
*
* IMPORTANT: A proxy pointing at a proxiable contract should not be considered proxiable itself, because this risks
* bricking a proxy that upgrades to it, by delegating to itself until out of gas. Thus it is critical that this
* function revert if invoked through a proxy. This is guaranteed by the `notDelegated` modifier.
*/
function proxiableUUID() external view virtual override notDelegated returns (bytes32) {
return _IMPLEMENTATION_SLOT;
}
/**
* @dev Upgrade the implementation of the proxy to `newImplementation`.
*
* Calls {_authorizeUpgrade}.
*
* Emits an {Upgraded} event.
*
* @custom:oz-upgrades-unsafe-allow-reachable delegatecall
*/
function upgradeTo(address newImplementation) public virtual onlyProxy {
_authorizeUpgrade(newImplementation);
_upgradeToAndCallUUPS(newImplementation, new bytes(0), false);
}
/**
* @dev Upgrade the implementation of the proxy to `newImplementation`, and subsequently execute the function call
* encoded in `data`.
*
* Calls {_authorizeUpgrade}.
*
* Emits an {Upgraded} event.
*
* @custom:oz-upgrades-unsafe-allow-reachable delegatecall
*/
function upgradeToAndCall(address newImplementation, bytes memory data) public payable virtual onlyProxy {
_authorizeUpgrade(newImplementation);
_upgradeToAndCallUUPS(newImplementation, data, true);
}
/**
* @dev Function that should revert when `msg.sender` is not authorized to upgrade the contract. Called by
* {upgradeTo} and {upgradeToAndCall}.
*
* Normally, this function will use an xref:access.adoc[access control] modifier such as {Ownable-onlyOwner}.
*
* ```solidity
* function _authorizeUpgrade(address) internal override onlyOwner {}
* ```
*/
function _authorizeUpgrade(address newImplementation) internal virtual;
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[50] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/access/Ownable2StepUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (access/Ownable2Step.sol)
pragma solidity ^0.8.0;
import "./OwnableUpgradeable.sol";
import {Initializable} from "../proxy/utils/Initializable.sol";
/**
* @dev Contract module which provides access control mechanism, where
* there is an account (an owner) that can be granted exclusive access to
* specific functions.
*
* By default, the owner account will be the one that deploys the contract. This
* can later be changed with {transferOwnership} and {acceptOwnership}.
*
* This module is used through inheritance. It will make available all functions
* from parent (Ownable).
*/
abstract contract Ownable2StepUpgradeable is Initializable, OwnableUpgradeable {
address private _pendingOwner;
event OwnershipTransferStarted(address indexed previousOwner, address indexed newOwner);
function __Ownable2Step_init() internal onlyInitializing {
__Ownable_init_unchained();
}
function __Ownable2Step_init_unchained() internal onlyInitializing {
}
/**
* @dev Returns the address of the pending owner.
*/
function pendingOwner() public view virtual returns (address) {
return _pendingOwner;
}
/**
* @dev Starts the ownership transfer of the contract to a new account. Replaces the pending transfer if there is one.
* Can only be called by the current owner.
*/
function transferOwnership(address newOwner) public virtual override onlyOwner {
_pendingOwner = newOwner;
emit OwnershipTransferStarted(owner(), newOwner);
}
/**
* @dev Transfers ownership of the contract to a new account (`newOwner`) and deletes any pending owner.
* Internal function without access restriction.
*/
function _transferOwnership(address newOwner) internal virtual override {
delete _pendingOwner;
super._transferOwnership(newOwner);
}
/**
* @dev The new owner accepts the ownership transfer.
*/
function acceptOwnership() public virtual {
address sender = _msgSender();
require(pendingOwner() == sender, "Ownable2Step: caller is not the new owner");
_transferOwnership(sender);
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[49] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/access/OwnableUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (access/Ownable.sol)
pragma solidity ^0.8.0;
import "../utils/ContextUpgradeable.sol";
import {Initializable} from "../proxy/utils/Initializable.sol";
/**
* @dev Contract module which provides a basic access control mechanism, where
* there is an account (an owner) that can be granted exclusive access to
* specific functions.
*
* By default, the owner account will be the one that deploys the contract. This
* can later be changed with {transferOwnership}.
*
* This module is used through inheritance. It will make available the modifier
* `onlyOwner`, which can be applied to your functions to restrict their use to
* the owner.
*/
abstract contract OwnableUpgradeable is Initializable, ContextUpgradeable {
address private _owner;
event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);
/**
* @dev Initializes the contract setting the deployer as the initial owner.
*/
function __Ownable_init() internal onlyInitializing {
__Ownable_init_unchained();
}
function __Ownable_init_unchained() internal onlyInitializing {
_transferOwnership(_msgSender());
}
/**
* @dev Throws if called by any account other than the owner.
*/
modifier onlyOwner() {
_checkOwner();
_;
}
/**
* @dev Returns the address of the current owner.
*/
function owner() public view virtual returns (address) {
return _owner;
}
/**
* @dev Throws if the sender is not the owner.
*/
function _checkOwner() internal view virtual {
require(owner() == _msgSender(), "Ownable: caller is not the owner");
}
/**
* @dev Leaves the contract without owner. It will not be possible to call
* `onlyOwner` functions. Can only be called by the current owner.
*
* NOTE: Renouncing ownership will leave the contract without an owner,
* thereby disabling any functionality that is only available to the owner.
*/
function renounceOwnership() public virtual onlyOwner {
_transferOwnership(address(0));
}
/**
* @dev Transfers ownership of the contract to a new account (`newOwner`).
* Can only be called by the current owner.
*/
function transferOwnership(address newOwner) public virtual onlyOwner {
require(newOwner != address(0), "Ownable: new owner is the zero address");
_transferOwnership(newOwner);
}
/**
* @dev Transfers ownership of the contract to a new account (`newOwner`).
* Internal function without access restriction.
*/
function _transferOwnership(address newOwner) internal virtual {
address oldOwner = _owner;
_owner = newOwner;
emit OwnershipTransferred(oldOwner, newOwner);
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[49] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/interfaces/IERC1967Upgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (interfaces/IERC1967.sol)
pragma solidity ^0.8.0;
/**
* @dev ERC-1967: Proxy Storage Slots. This interface contains the events defined in the ERC.
*
* _Available since v4.8.3._
*/
interface IERC1967Upgradeable {
/**
* @dev Emitted when the implementation is upgraded.
*/
event Upgraded(address indexed implementation);
/**
* @dev Emitted when the admin account has changed.
*/
event AdminChanged(address previousAdmin, address newAdmin);
/**
* @dev Emitted when the beacon is changed.
*/
event BeaconUpgraded(address indexed beacon);
}
node_modules/@openzeppelin/contracts-upgradeable/security/PausableUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.7.0) (security/Pausable.sol)
pragma solidity ^0.8.0;
import "../utils/ContextUpgradeable.sol";
import {Initializable} from "../proxy/utils/Initializable.sol";
/**
* @dev Contract module which allows children to implement an emergency stop
* mechanism that can be triggered by an authorized account.
*
* This module is used through inheritance. It will make available the
* modifiers `whenNotPaused` and `whenPaused`, which can be applied to
* the functions of your contract. Note that they will not be pausable by
* simply including this module, only once the modifiers are put in place.
*/
abstract contract PausableUpgradeable is Initializable, ContextUpgradeable {
/**
* @dev Emitted when the pause is triggered by `account`.
*/
event Paused(address account);
/**
* @dev Emitted when the pause is lifted by `account`.
*/
event Unpaused(address account);
bool private _paused;
/**
* @dev Initializes the contract in unpaused state.
*/
function __Pausable_init() internal onlyInitializing {
__Pausable_init_unchained();
}
function __Pausable_init_unchained() internal onlyInitializing {
_paused = false;
}
/**
* @dev Modifier to make a function callable only when the contract is not paused.
*
* Requirements:
*
* - The contract must not be paused.
*/
modifier whenNotPaused() {
_requireNotPaused();
_;
}
/**
* @dev Modifier to make a function callable only when the contract is paused.
*
* Requirements:
*
* - The contract must be paused.
*/
modifier whenPaused() {
_requirePaused();
_;
}
/**
* @dev Returns true if the contract is paused, and false otherwise.
*/
function paused() public view virtual returns (bool) {
return _paused;
}
/**
* @dev Throws if the contract is paused.
*/
function _requireNotPaused() internal view virtual {
require(!paused(), "Pausable: paused");
}
/**
* @dev Throws if the contract is not paused.
*/
function _requirePaused() internal view virtual {
require(paused(), "Pausable: not paused");
}
/**
* @dev Triggers stopped state.
*
* Requirements:
*
* - The contract must not be paused.
*/
function _pause() internal virtual whenNotPaused {
_paused = true;
emit Paused(_msgSender());
}
/**
* @dev Returns to normal state.
*
* Requirements:
*
* - The contract must be paused.
*/
function _unpause() internal virtual whenPaused {
_paused = false;
emit Unpaused(_msgSender());
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[49] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/security/ReentrancyGuardUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (security/ReentrancyGuard.sol)
pragma solidity ^0.8.0;
import {Initializable} from "../proxy/utils/Initializable.sol";
/**
* @dev Contract module that helps prevent reentrant calls to a function.
*
* Inheriting from `ReentrancyGuard` will make the {nonReentrant} modifier
* available, which can be applied to functions to make sure there are no nested
* (reentrant) calls to them.
*
* Note that because there is a single `nonReentrant` guard, functions marked as
* `nonReentrant` may not call one another. This can be worked around by making
* those functions `private`, and then adding `external` `nonReentrant` entry
* points to them.
*
* TIP: If you would like to learn more about reentrancy and alternative ways
* to protect against it, check out our blog post
* https://blog.openzeppelin.com/reentrancy-after-istanbul/[Reentrancy After Istanbul].
*/
abstract contract ReentrancyGuardUpgradeable is Initializable {
// Booleans are more expensive than uint256 or any type that takes up a full
// word because each write operation emits an extra SLOAD to first read the
// slot's contents, replace the bits taken up by the boolean, and then write
// back. This is the compiler's defense against contract upgrades and
// pointer aliasing, and it cannot be disabled.
// The values being non-zero value makes deployment a bit more expensive,
// but in exchange the refund on every call to nonReentrant will be lower in
// amount. Since refunds are capped to a percentage of the total
// transaction's gas, it is best to keep them low in cases like this one, to
// increase the likelihood of the full refund coming into effect.
uint256 private constant _NOT_ENTERED = 1;
uint256 private constant _ENTERED = 2;
uint256 private _status;
function __ReentrancyGuard_init() internal onlyInitializing {
__ReentrancyGuard_init_unchained();
}
function __ReentrancyGuard_init_unchained() internal onlyInitializing {
_status = _NOT_ENTERED;
}
/**
* @dev Prevents a contract from calling itself, directly or indirectly.
* Calling a `nonReentrant` function from another `nonReentrant`
* function is not supported. It is possible to prevent this from happening
* by making the `nonReentrant` function external, and making it call a
* `private` function that does the actual work.
*/
modifier nonReentrant() {
_nonReentrantBefore();
_;
_nonReentrantAfter();
}
function _nonReentrantBefore() private {
// On the first call to nonReentrant, _status will be _NOT_ENTERED
require(_status != _ENTERED, "ReentrancyGuard: reentrant call");
// Any calls to nonReentrant after this point will fail
_status = _ENTERED;
}
function _nonReentrantAfter() private {
// By storing the original value once again, a refund is triggered (see
// https://eips.ethereum.org/EIPS/eip-2200)
_status = _NOT_ENTERED;
}
/**
* @dev Returns true if the reentrancy guard is currently set to "entered", which indicates there is a
* `nonReentrant` function in the call stack.
*/
function _reentrancyGuardEntered() internal view returns (bool) {
return _status == _ENTERED;
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[49] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/utils/AddressUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (utils/Address.sol)
pragma solidity ^0.8.1;
/**
* @dev Collection of functions related to the address type
*/
library AddressUpgradeable {
/**
* @dev Returns true if `account` is a contract.
*
* [IMPORTANT]
* ====
* It is unsafe to assume that an address for which this function returns
* false is an externally-owned account (EOA) and not a contract.
*
* Among others, `isContract` will return false for the following
* types of addresses:
*
* - an externally-owned account
* - a contract in construction
* - an address where a contract will be created
* - an address where a contract lived, but was destroyed
*
* Furthermore, `isContract` will also return true if the target contract within
* the same transaction is already scheduled for destruction by `SELFDESTRUCT`,
* which only has an effect at the end of a transaction.
* ====
*
* [IMPORTANT]
* ====
* You shouldn't rely on `isContract` to protect against flash loan attacks!
*
* Preventing calls from contracts is highly discouraged. It breaks composability, breaks support for smart wallets
* like Gnosis Safe, and does not provide security since it can be circumvented by calling from a contract
* constructor.
* ====
*/
function isContract(address account) internal view returns (bool) {
// This method relies on extcodesize/address.code.length, which returns 0
// for contracts in construction, since the code is only stored at the end
// of the constructor execution.
return account.code.length > 0;
}
/**
* @dev Replacement for Solidity's `transfer`: sends `amount` wei to
* `recipient`, forwarding all available gas and reverting on errors.
*
* https://eips.ethereum.org/EIPS/eip-1884[EIP1884] increases the gas cost
* of certain opcodes, possibly making contracts go over the 2300 gas limit
* imposed by `transfer`, making them unable to receive funds via
* `transfer`. {sendValue} removes this limitation.
*
* https://consensys.net/diligence/blog/2019/09/stop-using-soliditys-transfer-now/[Learn more].
*
* IMPORTANT: because control is transferred to `recipient`, care must be
* taken to not create reentrancy vulnerabilities. Consider using
* {ReentrancyGuard} or the
* https://solidity.readthedocs.io/en/v0.8.0/security-considerations.html#use-the-checks-effects-interactions-pattern[checks-effects-interactions pattern].
*/
function sendValue(address payable recipient, uint256 amount) internal {
require(address(this).balance >= amount, "Address: insufficient balance");
(bool success, ) = recipient.call{value: amount}("");
require(success, "Address: unable to send value, recipient may have reverted");
}
/**
* @dev Performs a Solidity function call using a low level `call`. A
* plain `call` is an unsafe replacement for a function call: use this
* function instead.
*
* If `target` reverts with a revert reason, it is bubbled up by this
* function (like regular Solidity function calls).
*
* Returns the raw returned data. To convert to the expected return value,
* use https://solidity.readthedocs.io/en/latest/units-and-global-variables.html?highlight=abi.decode#abi-encoding-and-decoding-functions[`abi.decode`].
*
* Requirements:
*
* - `target` must be a contract.
* - calling `target` with `data` must not revert.
*
* _Available since v3.1._
*/
function functionCall(address target, bytes memory data) internal returns (bytes memory) {
return functionCallWithValue(target, data, 0, "Address: low-level call failed");
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], but with
* `errorMessage` as a fallback revert reason when `target` reverts.
*
* _Available since v3.1._
*/
function functionCall(
address target,
bytes memory data,
string memory errorMessage
) internal returns (bytes memory) {
return functionCallWithValue(target, data, 0, errorMessage);
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],
* but also transferring `value` wei to `target`.
*
* Requirements:
*
* - the calling contract must have an ETH balance of at least `value`.
* - the called Solidity function must be `payable`.
*
* _Available since v3.1._
*/
function functionCallWithValue(address target, bytes memory data, uint256 value) internal returns (bytes memory) {
return functionCallWithValue(target, data, value, "Address: low-level call with value failed");
}
/**
* @dev Same as {xref-Address-functionCallWithValue-address-bytes-uint256-}[`functionCallWithValue`], but
* with `errorMessage` as a fallback revert reason when `target` reverts.
*
* _Available since v3.1._
*/
function functionCallWithValue(
address target,
bytes memory data,
uint256 value,
string memory errorMessage
) internal returns (bytes memory) {
require(address(this).balance >= value, "Address: insufficient balance for call");
(bool success, bytes memory returndata) = target.call{value: value}(data);
return verifyCallResultFromTarget(target, success, returndata, errorMessage);
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],
* but performing a static call.
*
* _Available since v3.3._
*/
function functionStaticCall(address target, bytes memory data) internal view returns (bytes memory) {
return functionStaticCall(target, data, "Address: low-level static call failed");
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-string-}[`functionCall`],
* but performing a static call.
*
* _Available since v3.3._
*/
function functionStaticCall(
address target,
bytes memory data,
string memory errorMessage
) internal view returns (bytes memory) {
(bool success, bytes memory returndata) = target.staticcall(data);
return verifyCallResultFromTarget(target, success, returndata, errorMessage);
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],
* but performing a delegate call.
*
* _Available since v3.4._
*/
function functionDelegateCall(address target, bytes memory data) internal returns (bytes memory) {
return functionDelegateCall(target, data, "Address: low-level delegate call failed");
}
/**
* @dev Same as {xref-Address-functionCall-address-bytes-string-}[`functionCall`],
* but performing a delegate call.
*
* _Available since v3.4._
*/
function functionDelegateCall(
address target,
bytes memory data,
string memory errorMessage
) internal returns (bytes memory) {
(bool success, bytes memory returndata) = target.delegatecall(data);
return verifyCallResultFromTarget(target, success, returndata, errorMessage);
}
/**
* @dev Tool to verify that a low level call to smart-contract was successful, and revert (either by bubbling
* the revert reason or using the provided one) in case of unsuccessful call or if target was not a contract.
*
* _Available since v4.8._
*/
function verifyCallResultFromTarget(
address target,
bool success,
bytes memory returndata,
string memory errorMessage
) internal view returns (bytes memory) {
if (success) {
if (returndata.length == 0) {
// only check isContract if the call was successful and the return data is empty
// otherwise we already know that it was a contract
require(isContract(target), "Address: call to non-contract");
}
return returndata;
} else {
_revert(returndata, errorMessage);
}
}
/**
* @dev Tool to verify that a low level call was successful, and revert if it wasn't, either by bubbling the
* revert reason or using the provided one.
*
* _Available since v4.3._
*/
function verifyCallResult(
bool success,
bytes memory returndata,
string memory errorMessage
) internal pure returns (bytes memory) {
if (success) {
return returndata;
} else {
_revert(returndata, errorMessage);
}
}
function _revert(bytes memory returndata, string memory errorMessage) private pure {
// Look for revert reason and bubble it up if present
if (returndata.length > 0) {
// The easiest way to bubble the revert reason is using memory via assembly
/// @solidity memory-safe-assembly
assembly {
let returndata_size := mload(returndata)
revert(add(32, returndata), returndata_size)
}
} else {
revert(errorMessage);
}
}
}
node_modules/@openzeppelin/contracts-upgradeable/utils/ContextUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.4) (utils/Context.sol)
pragma solidity ^0.8.0;
import {Initializable} from "../proxy/utils/Initializable.sol";
/**
* @dev Provides information about the current execution context, including the
* sender of the transaction and its data. While these are generally available
* via msg.sender and msg.data, they should not be accessed in such a direct
* manner, since when dealing with meta-transactions the account sending and
* paying for execution may not be the actual sender (as far as an application
* is concerned).
*
* This contract is only required for intermediate, library-like contracts.
*/
abstract contract ContextUpgradeable is Initializable {
function __Context_init() internal onlyInitializing {
}
function __Context_init_unchained() internal onlyInitializing {
}
function _msgSender() internal view virtual returns (address) {
return msg.sender;
}
function _msgData() internal view virtual returns (bytes calldata) {
return msg.data;
}
function _contextSuffixLength() internal view virtual returns (uint256) {
return 0;
}
/**
* @dev This empty reserved space is put in place to allow future versions to add new
* variables without shifting down storage in the inheritance chain.
* See https://docs.openzeppelin.com/contracts/4.x/upgradeable#storage_gaps
*/
uint256[50] private __gap;
}
node_modules/@openzeppelin/contracts-upgradeable/utils/StorageSlotUpgradeable.sol
// SPDX-License-Identifier: MIT
// OpenZeppelin Contracts (last updated v4.9.0) (utils/StorageSlot.sol)
// This file was procedurally generated from scripts/generate/templates/StorageSlot.js.
pragma solidity ^0.8.0;
/**
* @dev Library for reading and writing primitive types to specific storage slots.
*
* Storage slots are often used to avoid storage conflict when dealing with upgradeable contracts.
* This library helps with reading and writing to such slots without the need for inline assembly.
*
* The functions in this library return Slot structs that contain a `value` member that can be used to read or write.
*
* Example usage to set ERC1967 implementation slot:
* ```solidity
* contract ERC1967 {
* bytes32 internal constant _IMPLEMENTATION_SLOT = 0x360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3ca505d382bbc;
*
* function _getImplementation() internal view returns (address) {
* return StorageSlot.getAddressSlot(_IMPLEMENTATION_SLOT).value;
* }
*
* function _setImplementation(address newImplementation) internal {
* require(Address.isContract(newImplementation), "ERC1967: new implementation is not a contract");
* StorageSlot.getAddressSlot(_IMPLEMENTATION_SLOT).value = newImplementation;
* }
* }
* ```
*
* _Available since v4.1 for `address`, `bool`, `bytes32`, `uint256`._
* _Available since v4.9 for `string`, `bytes`._
*/
library StorageSlotUpgradeable {
struct AddressSlot {
address value;
}
struct BooleanSlot {
bool value;
}
struct Bytes32Slot {
bytes32 value;
}
struct Uint256Slot {
uint256 value;
}
struct StringSlot {
string value;
}
struct BytesSlot {
bytes value;
}
/**
* @dev Returns an `AddressSlot` with member `value` located at `slot`.
*/
function getAddressSlot(bytes32 slot) internal pure returns (AddressSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `BooleanSlot` with member `value` located at `slot`.
*/
function getBooleanSlot(bytes32 slot) internal pure returns (BooleanSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `Bytes32Slot` with member `value` located at `slot`.
*/
function getBytes32Slot(bytes32 slot) internal pure returns (Bytes32Slot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `Uint256Slot` with member `value` located at `slot`.
*/
function getUint256Slot(bytes32 slot) internal pure returns (Uint256Slot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `StringSlot` with member `value` located at `slot`.
*/
function getStringSlot(bytes32 slot) internal pure returns (StringSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `StringSlot` representation of the string storage pointer `store`.
*/
function getStringSlot(string storage store) internal pure returns (StringSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := store.slot
}
}
/**
* @dev Returns an `BytesSlot` with member `value` located at `slot`.
*/
function getBytesSlot(bytes32 slot) internal pure returns (BytesSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := slot
}
}
/**
* @dev Returns an `BytesSlot` representation of the bytes storage pointer `store`.
*/
function getBytesSlot(bytes storage store) internal pure returns (BytesSlot storage r) {
/// @solidity memory-safe-assembly
assembly {
r.slot := store.slot
}
}
}
src/iface/IEthMinter.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
/// @custom:security-contact security@taiko.xyz
interface IEthMinter {
/// @notice Mints ETH to the specified recipient.
function mintEth(address _recipient, uint256 _amount) external;
}
src/iface/IShadow.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
/// @custom:security-contact security@taiko.xyz
interface IShadow {
struct PublicInput {
uint64 blockNumber;
uint64 chainId;
uint256 amount;
address recipient;
bytes32 nullifier;
address token; // address(0) = ETH
}
/// @dev `amount` is the gross (pre-fee) value from the ZK proof. The recipient receives `amount - fee`.
event Claimed(bytes32 indexed nullifier, address indexed recipient, uint256 amount, address token);
error ChainIdMismatch(uint64 expected, uint64 actual);
error InvalidAmount(uint256 amount);
error InvalidRecipient(address recipient);
error NullifierAlreadyConsumed(bytes32 nullifier);
error AmountExceedsMax(uint256 amount, uint256 max);
/// @notice Submits a proof and public inputs to mint ETH via the configured minter hook.
/// @dev The Shadow implementation applies a 0.1% claim fee (`amount / 1000`) to an immutable feeRecipient.
function claim(bytes calldata _proof, PublicInput calldata _input) external;
}
src/iface/IShadowCompatibleToken.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
/// @custom:security-contact security@taiko.xyz
/// @title IShadowCompatibleToken
/// @notice Minimal interface for ERC20 tokens on Taiko that support Shadow privacy transfers.
///
/// DEPOSIT: Holder sends tokens to targetAddress via a plain ERC20 transfer.
/// No interaction with this interface is required at deposit time.
///
/// PROVE: ZK circuit proves _balances[targetAddress] >= total_note_amounts
/// using a two-level MPT proof anchored to a block hash.
/// The server fetches the storage key via balanceStorageSlot(targetAddress).
///
/// CLAIM: Shadow.sol calls shadowMint(recipient, amount).
/// New tokens are minted to recipient — no pre-minted reserve, no
/// transfer from targetAddress. Direct analogy to IEthMinter.mintEth.
///
/// GOVERNANCE: Because shadowMint calls _mint, ERC20Votes assigns voting units
/// only if recipient has an active delegate — standard _mint behaviour.
/// targetAddress never called delegate(), so its locked tokens carry
/// no active voting weight.
interface IShadowCompatibleToken {
/// @notice Caller is not the authorised Shadow contract.
error ShadowUnauthorised();
/// @notice Mint tokens to a Shadow claim recipient.
/// @dev MUST revert with ShadowUnauthorised if the caller is not authorised.
/// MUST mint `_amount` new tokens to `_to` via _mint or equivalent.
/// @param _to Claim recipient (from ZK proof journal).
/// @param _amount Token amount in raw smallest units.
function shadowMint(address _to, uint256 _amount) external;
/// @notice Returns the Ethereum storage key where `holder`'s token balance
/// is stored in this contract's storage trie.
/// @dev The Shadow server calls this with targetAddress before proving.
/// The key is passed directly to eth_getProof and to the ZK circuit.
/// MUST be pure — changing the derivation after deployment would cause
/// the prover to use wrong storage keys and fail.
/// @param _holder The address whose balance storage key is requested.
/// @return storageKey The bytes32 Ethereum storage key for holder's balance.
function balanceStorageSlot(address _holder) external pure returns (bytes32 storageKey);
/// @notice Returns the raw ERC20 _balances mapping storage slot index.
/// @dev The ZK circuit uses this slot together with the holder address to
/// recompute the expected storage key inside the proof, preventing
/// a malicious prover from substituting an arbitrary storage key.
/// @return The storage slot index (e.g. 0 for plain OZ ERC20).
function balanceSlot() external pure returns (uint256);
/// @notice Returns the maximum amount that may be minted in a single Shadow claim.
/// @dev Shadow.sol reads this value and rejects any claim where amount exceeds it.
/// The client also reads this value to constrain note amounts in deposit files.
/// @return The maximum raw token amount (smallest units) per single claim.
function maxShadowMintAmount() external view returns (uint256);
}
src/iface/IShadowVerifier.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
import {IShadow} from "./IShadow.sol";
/// @custom:security-contact security@taiko.xyz
interface IShadowVerifier {
error BlockHashNotFound(uint64 blockNumber);
error ProofVerificationFailed();
error ZeroAddress();
/// @notice Verifies a proof and its public inputs.
/// @dev Reverts on any failure (BlockHashNotFound, ProofVerificationFailed). Never returns false.
function verifyProof(bytes calldata _proof, IShadow.PublicInput calldata _input) external view;
}
src/impl/Shadow_Layout.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
/// @title ShadowLayout
/// @notice Storage layout documentation for Shadow.
/// @dev This file is auto-generated by script/gen-layouts.sh. DO NOT EDIT MANUALLY.
/// @custom:security-contact security@taiko.xyz
// solhint-disable max-line-length
// _initialized | uint8 | Slot: 0 | Offset: 0 | Bytes: 1
// _initializing | bool | Slot: 0 | Offset: 1 | Bytes: 1
// __gap | uint256[50] | Slot: 1 | Offset: 0 | Bytes: 1600
// _owner | address | Slot: 51 | Offset: 0 | Bytes: 20
// __gap | uint256[49] | Slot: 52 | Offset: 0 | Bytes: 1568
// _pendingOwner | address | Slot: 101 | Offset: 0 | Bytes: 20
// __gap | uint256[49] | Slot: 102 | Offset: 0 | Bytes: 1568
// __gap | uint256[50] | Slot: 151 | Offset: 0 | Bytes: 1600
// __gap | uint256[50] | Slot: 201 | Offset: 0 | Bytes: 1600
// _paused | bool | Slot: 251 | Offset: 0 | Bytes: 1
// __gap | uint256[49] | Slot: 252 | Offset: 0 | Bytes: 1568
// _status | uint256 | Slot: 301 | Offset: 0 | Bytes: 32
// __gap | uint256[49] | Slot: 302 | Offset: 0 | Bytes: 1568
// _consumed | mapping(bytes32 => bool) | Slot: 351 | Offset: 0 | Bytes: 32
// __gap | uint256[49] | Slot: 352 | Offset: 0 | Bytes: 1568
abstract contract ShadowLayout {}
src/lib/OwnableUpgradeable.sol
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.33;
import {Ownable2StepUpgradeable} from "@openzeppelin/contracts-upgradeable/access/Ownable2StepUpgradeable.sol";
import {UUPSUpgradeable} from "@openzeppelin/contracts-upgradeable/proxy/utils/UUPSUpgradeable.sol";
/// @custom:security-contact security@taiko.xyz
abstract contract OwnableUpgradeable is Ownable2StepUpgradeable, UUPSUpgradeable {
error ZeroAddress();
/// @custom:oz-upgrades-unsafe-allow constructor
constructor() {
_disableInitializers();
}
/// @notice Initializes the contract.
function __OwnableUpgradeable_init(address _owner) internal onlyInitializing {
__Ownable2Step_init();
__UUPSUpgradeable_init();
_transferOwnership(_owner);
}
/// @dev Authorizes an upgrade to a new implementation.
function _authorizeUpgrade(address) internal override onlyOwner {}
}
Compiler Settings
{"viaIR":true,"remappings":["forge-std/=node_modules/forge-std/src/","@openzeppelin/contracts/=node_modules/@openzeppelin/contracts/","@openzeppelin/contracts-upgradeable/=node_modules/@openzeppelin/contracts-upgradeable/","risc0-ethereum/=lib/risc0-ethereum/contracts/src/","openzeppelin/contracts/=node_modules/@openzeppelin/contracts/","erc4626-tests/=lib/risc0-ethereum/lib/openzeppelin-contracts/lib/erc4626-tests/","halmos-cheatcodes/=lib/risc0-ethereum/lib/openzeppelin-contracts/lib/halmos-cheatcodes/src/","openzeppelin-contracts/=lib/risc0-ethereum/lib/openzeppelin-contracts/"],"outputSelection":{"*":{"*":["*"],"":["*"]}},"optimizer":{"runs":200,"enabled":true},"metadata":{"useLiteralContent":false,"bytecodeHash":"ipfs","appendCBOR":true},"libraries":{},"evmVersion":"shanghai"}
Contract ABI
[{"type":"constructor","stateMutability":"nonpayable","inputs":[{"type":"address","name":"_verifier","internalType":"address"},{"type":"address","name":"_etherMinter","internalType":"address"},{"type":"address","name":"_feeRecipient","internalType":"address"},{"type":"uint256","name":"_maxClaimAmount","internalType":"uint256"}]},{"type":"error","name":"AmountExceedsMax","inputs":[{"type":"uint256","name":"amount","internalType":"uint256"},{"type":"uint256","name":"max","internalType":"uint256"}]},{"type":"error","name":"ChainIdMismatch","inputs":[{"type":"uint64","name":"expected","internalType":"uint64"},{"type":"uint64","name":"actual","internalType":"uint64"}]},{"type":"error","name":"InvalidAmount","inputs":[{"type":"uint256","name":"amount","internalType":"uint256"}]},{"type":"error","name":"InvalidRecipient","inputs":[{"type":"address","name":"recipient","internalType":"address"}]},{"type":"error","name":"NullifierAlreadyConsumed","inputs":[{"type":"bytes32","name":"nullifier","internalType":"bytes32"}]},{"type":"error","name":"ZeroAddress","inputs":[]},{"type":"event","name":"AdminChanged","inputs":[{"type":"address","name":"previousAdmin","internalType":"address","indexed":false},{"type":"address","name":"newAdmin","internalType":"address","indexed":false}],"anonymous":false},{"type":"event","name":"BeaconUpgraded","inputs":[{"type":"address","name":"beacon","internalType":"address","indexed":true}],"anonymous":false},{"type":"event","name":"Claimed","inputs":[{"type":"bytes32","name":"nullifier","internalType":"bytes32","indexed":true},{"type":"address","name":"recipient","internalType":"address","indexed":true},{"type":"uint256","name":"amount","internalType":"uint256","indexed":false},{"type":"address","name":"token","internalType":"address","indexed":false}],"anonymous":false},{"type":"event","name":"Initialized","inputs":[{"type":"uint8","name":"version","internalType":"uint8","indexed":false}],"anonymous":false},{"type":"event","name":"OwnershipTransferStarted","inputs":[{"type":"address","name":"previousOwner","internalType":"address","indexed":true},{"type":"address","name":"newOwner","internalType":"address","indexed":true}],"anonymous":false},{"type":"event","name":"OwnershipTransferred","inputs":[{"type":"address","name":"previousOwner","internalType":"address","indexed":true},{"type":"address","name":"newOwner","internalType":"address","indexed":true}],"anonymous":false},{"type":"event","name":"Paused","inputs":[{"type":"address","name":"account","internalType":"address","indexed":false}],"anonymous":false},{"type":"event","name":"Unpaused","inputs":[{"type":"address","name":"account","internalType":"address","indexed":false}],"anonymous":false},{"type":"event","name":"Upgraded","inputs":[{"type":"address","name":"implementation","internalType":"address","indexed":true}],"anonymous":false},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"acceptOwnership","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"claim","inputs":[{"type":"bytes","name":"_proof","internalType":"bytes"},{"type":"tuple","name":"_input","internalType":"struct IShadow.PublicInput","components":[{"type":"uint64","name":"blockNumber","internalType":"uint64"},{"type":"uint64","name":"chainId","internalType":"uint64"},{"type":"uint256","name":"amount","internalType":"uint256"},{"type":"address","name":"recipient","internalType":"address"},{"type":"bytes32","name":"nullifier","internalType":"bytes32"},{"type":"address","name":"token","internalType":"address"}]}]},{"type":"function","stateMutability":"view","outputs":[{"type":"address","name":"","internalType":"contract IEthMinter"}],"name":"etherMinter","inputs":[]},{"type":"function","stateMutability":"view","outputs":[{"type":"address","name":"","internalType":"address"}],"name":"feeRecipient","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"initialize","inputs":[{"type":"address","name":"_owner","internalType":"address"}]},{"type":"function","stateMutability":"view","outputs":[{"type":"bool","name":"_isConsumed_","internalType":"bool"}],"name":"isConsumed","inputs":[{"type":"bytes32","name":"_nullifier","internalType":"bytes32"}]},{"type":"function","stateMutability":"view","outputs":[{"type":"uint256","name":"","internalType":"uint256"}],"name":"maxClaimAmount","inputs":[]},{"type":"function","stateMutability":"view","outputs":[{"type":"address","name":"","internalType":"address"}],"name":"owner","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"pause","inputs":[]},{"type":"function","stateMutability":"view","outputs":[{"type":"bool","name":"","internalType":"bool"}],"name":"paused","inputs":[]},{"type":"function","stateMutability":"view","outputs":[{"type":"address","name":"","internalType":"address"}],"name":"pendingOwner","inputs":[]},{"type":"function","stateMutability":"view","outputs":[{"type":"bytes32","name":"","internalType":"bytes32"}],"name":"proxiableUUID","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"renounceOwnership","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"transferOwnership","inputs":[{"type":"address","name":"newOwner","internalType":"address"}]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"unpause","inputs":[]},{"type":"function","stateMutability":"nonpayable","outputs":[],"name":"upgradeTo","inputs":[{"type":"address","name":"newImplementation","internalType":"address"}]},{"type":"function","stateMutability":"payable","outputs":[],"name":"upgradeToAndCall","inputs":[{"type":"address","name":"newImplementation","internalType":"address"},{"type":"bytes","name":"data","internalType":"bytes"}]},{"type":"function","stateMutability":"view","outputs":[{"type":"address","name":"","internalType":"contract IShadowVerifier"}],"name":"verifier","inputs":[]}]
Contract Creation Code
0x610120346101cc57601f611a1338819003918201601f19168301916001600160401b038311848410176101d0578084926080946040528339810103126101cc57610048816101e4565b90610055602082016101e4565b6060610063604084016101e4565b92015192306080525f5460ff8160081c166101775760ff8082160361013d575b506001600160a01b031690811561012e576001600160a01b031690811561012e576001600160a01b0383161561012e5760a05260c05260e0526101005260405161181a90816101f98239608051818181610bfe01528181610d2401526110a4015260a0518181816105790152611351015260c05181818161032701526106e0015260e0518181816107cb015281816109440152610fc401526101005181818161036e01526106b50152f35b63d92e233d60e01b5f5260045ffd5b60ff90811916175f557f7f26b83ff96e1f2b6a682f133852f6798a09c465da95921460cefb3847402498602060405160ff8152a15f610083565b60405162461bcd60e51b815260206004820152602760248201527f496e697469616c697a61626c653a20636f6e747261637420697320696e697469604482015266616c697a696e6760c81b6064820152608490fd5b5f80fd5b634e487b7160e01b5f52604160045260245ffd5b51906001600160a01b03821682036101cc5756fe6080806040526004361015610012575f80fd5b5f905f3560e01c9081632b7ac3f31461133f575080633659cfe6146110865780633f4ba83a14610ff35780634690484014610faf5780634f1ef28614610cae57806352d1902d14610bec5780635c975abb14610bca5780636346e83214610b9a578063715018a614610b3557806377cfddfc1461049d57806379ba5097146104155780638456cb59146103ba5780638da5cb5b14610391578063aeef643914610356578063b655b1b714610311578063c4d66de81461017d578063e30c3978146101545763f2fde38b146100e4575f80fd5b34610151576020366003190112610151576100fd611380565b61010561150b565b606580546001600160a01b0319166001600160a01b039283169081179091556033549091167f38d16b8cac22d99fc7c124b9cd0de2d3fa1faef420bfe791d8c362d765e227008380a380f35b80fd5b50346101515780600319360112610151576065546040516001600160a01b039091168152602090f35b503461015157602036600319011261015157610197611380565b815460ff8160081c161591828093610304575b80156102ed575b156102915760ff198216600117845561020b9183610280575b506101ed60ff855460081c166101df816115fa565b6101e8816115fa565b6115fa565b6101f633611563565b61020660ff855460081c166115fa565b611563565b81549061023d60ff8360081c16610221816115fa565b61022a816115fa565b60ff1960fb541660fb556101e8816115fa565b600161012d5561024b575080f35b61ff00191681557f7f26b83ff96e1f2b6a682f133852f6798a09c465da95921460cefb3847402498602060405160018152a180f35b61ffff19166101011784555f6101ca565b60405162461bcd60e51b815260206004820152602e60248201527f496e697469616c697a61626c653a20636f6e747261637420697320616c72656160448201526d191e481a5b9a5d1a585b1a5e995960921b6064820152608490fd5b50303b1580156101b15750600160ff8316146101b1565b50600160ff8316106101aa565b50346101515780600319360112610151576040517f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03168152602090f35b503461015157806003193601126101515760206040517f00000000000000000000000000000000000000000000000000000000000000008152f35b50346101515780600319360112610151576033546040516001600160a01b039091168152602090f35b50346101515780600319360112610151576103d361150b565b6103db6115b6565b600160ff1960fb54161760fb557f62e78cea01bee320cd4e420270b5ea74000d11b0c9f74754ebdbfc544b05a2586020604051338152a180f35b5034610151578060031936011261015157606554336001600160a01b03909116036104465761044333611563565b80f35b60405162461bcd60e51b815260206004820152602960248201527f4f776e61626c6532537465703a2063616c6c6572206973206e6f7420746865206044820152683732bb9037bbb732b960b91b6064820152608490fd5b50346109f45760e03660031901126109f45760043567ffffffffffffffff81116109f457366023820112156109f457806004013567ffffffffffffffff81116109f45736602482840101116109f45760c03660231901126109f4576105006115b6565b600261012d5414610af057600261012d556105196114aa565b6105216114aa565b9067ffffffffffffffff46911603610ac55750606435918215610ab2576001600160a01b0361054e6114c1565b16156105586114c1565b90610a92575060a43591825f5261015f60205260ff60405f205416610a7f577f00000000000000000000000000000000000000000000000000000000000000006001600160a01b031690813b156109f45780602460405194631b27f98360e11b865260e060048701528260e4870152016101048501375f610104828501015260243567ffffffffffffffff81168091036109f457602484015260443567ffffffffffffffff81168091036109f4576044840152606483018590526084356001600160a01b038116908190036109f457608484015260a4830184905260c4356001600160a01b03811692908390036109f457836101048180945f9660c4830152601f801991011681010301915afa8015610a7457610a5f575b5080835261015f60205260408320805460ff191660011790556103e88204808303838111610a4b578491906001600160a01b036106ab6114d7565b16610866576106de7f000000000000000000000000000000000000000000000000000000000000000086818111156114ed565b7f00000000000000000000000000000000000000000000000000000000000000006001600160a01b0316906107116114c1565b823b1561086257604051634416e9e960e11b81526001600160a01b039190911660048201526024810191909152838160448183865af1908115610857578491610842575b5050816107b5575b5050505b7fba78a15e874441cf1871e3d2633ba91540bab663ae8664088ace7d60009ddd65604061078c6114c1565b6107946114d7565b82519586526001600160a01b0390811660208701521693a3600161012d5580f35b803b1561083357604051634416e9e960e11b81527f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03166004820152602481019290925282908290604490829084905af180156108375761081e575b8061075d565b8161082891611396565b61083357825f610818565b8280fd5b6040513d84823e3d90fd5b8161084c91611396565b61083357825f610755565b6040513d86823e3d90fd5b8480fd5b6001600160a01b036108766114d7565b169060405163194bd9ed60e11b8152602081600481865afa908115610a40578591610a0b575b5060405163194bd9ed60e11b8152602081600481875afa918215610a0057889187936109c1575b50906108d292918111156114ed565b6108da6114c1565b823b1561086257604051632ca6c9a560e21b81526001600160a01b039190911660048201526024810191909152838160448183865af19081156108575784916109ac575b50508161092e575b505050610761565b803b1561083357604051632ca6c9a560e21b81527f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03166004820152602481019290925282908290604490829084905af1801561083757610997575b80610926565b816109a191611396565b61083357825f610991565b816109b691611396565b61083357825f61091e565b92509550506020813d6020116109f8575b816109df60209383611396565b810103126109f45751879487906108d26108c3565b5f80fd5b3d91506109d2565b6040513d88823e3d90fd5b9450506020843d602011610a38575b81610a2760209383611396565b810103126109f4578693515f61089c565b3d9150610a1a565b6040513d87823e3d90fd5b634e487b7160e01b85526011600452602485fd5b610a6c9193505f90611396565b5f915f610670565b6040513d5f823e3d90fd5b8263350e9ad360e01b5f5260045260245ffd5b630bc2c5df60e11b5f9081526001600160a01b0391909116600452602490fd5b82633728b83d60e01b5f5260045260245ffd5b67ffffffffffffffff906304cce86960e51b5f521660045267ffffffffffffffff461660245260445ffd5b60405162461bcd60e51b815260206004820152601f60248201527f5265656e7472616e637947756172643a207265656e7472616e742063616c6c006044820152606490fd5b346109f4575f3660031901126109f457610b4d61150b565b606580546001600160a01b03199081169091556033805491821690555f906001600160a01b03167f8be0079c531659141344cd1fd0a4f28419497f9722a3daafe3b4186f6b6457e08280a3005b346109f45760203660031901126109f4576004355f5261015f602052602060ff60405f2054166040519015158152f35b346109f4575f3660031901126109f457602060ff60fb54166040519015158152f35b346109f4575f3660031901126109f4577f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03163003610c435760206040515f5160206117c55f395f51905f528152f35b60405162461bcd60e51b815260206004820152603860248201527f555550535570677261646561626c653a206d757374206e6f742062652063616c60448201527f6c6564207468726f7567682064656c656761746563616c6c00000000000000006064820152608490fd5b60403660031901126109f457610cc2611380565b6024359067ffffffffffffffff82116109f457366023830112156109f4578160040135610cee816113cc565b90610cfc6040519283611396565b808252602082019336602483830101116109f457815f92602460209301873783010152610d767f00000000000000000000000000000000000000000000000000000000000000006001600160a01b0316610d58308214156113e8565b5f5160206117c55f395f51905f52546001600160a01b031614611449565b610d7e61150b565b7f4910fdfa16fed3260ed0e7147f7cc6da11a60208b5b9406d12a635614ffd91435460ff1615610db55750610db3915061165a565b005b6040516352d1902d60e01b81529091906001600160a01b03821690602081600481855afa5f9181610f7b575b50610e425760405162461bcd60e51b815260206004820152602e60248201527f45524331393637557067726164653a206e657720696d706c656d656e7461746960448201526d6f6e206973206e6f74205555505360901b6064820152608490fd5b5f5160206117c55f395f51905f5203610f2457610e5e8261165a565b7fbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b5f80a2815115801590610f1c575b610e9357005b5f80610db39460405194610ea8606087611396565b602786527f416464726573733a206c6f772d6c6576656c2064656c65676174652063616c6c6020870152660819985a5b195960ca1b60408701525190845af43d15610f14573d91610ef8836113cc565b92610f066040519485611396565b83523d5f602085013e6116f6565b6060916116f6565b506001610e8d565b60405162461bcd60e51b815260206004820152602960248201527f45524331393637557067726164653a20756e737570706f727465642070726f786044820152681a58589b195555525160ba1b6064820152608490fd5b9091506020813d602011610fa7575b81610f9760209383611396565b810103126109f457519086610de1565b3d9150610f8a565b346109f4575f3660031901126109f4576040517f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03168152602090f35b346109f4575f3660031901126109f45761100b61150b565b60fb5460ff81161561104a5760ff191660fb557f5db9ee0a495bf2e6ff9c91a7834c1ba4fdd244a5e8aa4e537bd38aeae4b073aa6020604051338152a1005b60405162461bcd60e51b815260206004820152601460248201527314185d5cd8589b194e881b9bdd081c185d5cd95960621b6044820152606490fd5b346109f45760203660031901126109f45761109f611380565b6110d87f00000000000000000000000000000000000000000000000000000000000000006001600160a01b0316610d58308214156113e8565b6110e061150b565b6040519060206110f08184611396565b5f835280830192601f1982013685377f4910fdfa16fed3260ed0e7147f7cc6da11a60208b5b9406d12a635614ffd91435460ff1615611135575050610db3915061165a565b6040516352d1902d60e01b8152919290916001600160a01b038216908481600481855afa5f9181611310575b506111c25760405162461bcd60e51b815260048101869052602e60248201527f45524331393637557067726164653a206e657720696d706c656d656e7461746960448201526d6f6e206973206e6f74205555505360901b6064820152608490fd5b9293927fc9f76b5ec45e5cdef99837d7b6d2467235c1df8933c8ca56df5c35afa2c7d444016112b9576111f48261165a565b7fbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b5f80a28251158015906112b2575b61122957005b5f80610db3956040519561123e606088611396565b602787527f416464726573733a206c6f772d6c6576656c2064656c65676174652063616c6c86880152660819985a5b195960ca1b60408801525190845af4903d156112a9573d61128d816113cc565b9061129b6040519283611396565b81525f81943d92013e6116f6565b606092506116f6565b505f611223565b60405162461bcd60e51b815260048101849052602960248201527f45524331393637557067726164653a20756e737570706f727465642070726f786044820152681a58589b195555525160ba1b6064820152608490fd5b9091508581813d8311611338575b6113288183611396565b810103126109f457519087611161565b503d61131e565b346109f4575f3660031901126109f4577f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03168152602090f35b600435906001600160a01b03821682036109f457565b90601f8019910116810190811067ffffffffffffffff8211176113b857604052565b634e487b7160e01b5f52604160045260245ffd5b67ffffffffffffffff81116113b857601f01601f191660200190565b156113ef57565b60405162461bcd60e51b815260206004820152602c60248201527f46756e6374696f6e206d7573742062652063616c6c6564207468726f7567682060448201526b19195b1959d85d1958d85b1b60a21b6064820152608490fd5b1561145057565b60405162461bcd60e51b815260206004820152602c60248201527f46756e6374696f6e206d7573742062652063616c6c6564207468726f7567682060448201526b6163746976652070726f787960a01b6064820152608490fd5b60443567ffffffffffffffff811681036109f45790565b6084356001600160a01b03811681036109f45790565b60c4356001600160a01b03811681036109f45790565b156114f6575050565b632af9a0af60e21b5f5260045260245260445ffd5b6033546001600160a01b0316330361151f57565b606460405162461bcd60e51b815260206004820152602060248201527f4f776e61626c653a2063616c6c6572206973206e6f7420746865206f776e65726044820152fd5b606580546001600160a01b0319908116909155603380549182166001600160a01b0393841690811790915591167f8be0079c531659141344cd1fd0a4f28419497f9722a3daafe3b4186f6b6457e05f80a3565b60ff60fb54166115c257565b60405162461bcd60e51b815260206004820152601060248201526f14185d5cd8589b194e881c185d5cd95960821b6044820152606490fd5b1561160157565b60405162461bcd60e51b815260206004820152602b60248201527f496e697469616c697a61626c653a20636f6e7472616374206973206e6f74206960448201526a6e697469616c697a696e6760a81b6064820152608490fd5b803b1561169b5760018060a01b03166bffffffffffffffffffffffff60a01b5f5160206117c55f395f51905f525416175f5160206117c55f395f51905f5255565b60405162461bcd60e51b815260206004820152602d60248201527f455243313936373a206e657720696d706c656d656e746174696f6e206973206e60448201526c1bdd08184818dbdb9d1c9858dd609a1b6064820152608490fd5b91929015611758575081511561170a575090565b3b156117135790565b60405162461bcd60e51b815260206004820152601d60248201527f416464726573733a2063616c6c20746f206e6f6e2d636f6e74726163740000006044820152606490fd5b82519091501561176b5750805190602001fd5b6040519062461bcd60e51b825260206004830152818151918260248301525f5b8381106117ac575050815f6044809484010152601f80199101168101030190fd5b6020828201810151604487840101528593500161178b56fe360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3ca505d382bbca264697066735822122018e55136788877bf91d37f613d00be63e3a5ca3fb507122e84f1164a685c453b64736f6c6343000821003300000000000000000000000091aa12ba1a1c5ad3d7215ad0ac075c0b86e1c75b0000000000000000000000006dc226aa43e86fe77735443fb50a0a90e5666aa4000000000000000000000000e36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb0000000000000000000000000000000000000000000000006f05b59d3b200000
Deployed ByteCode
0x6080806040526004361015610012575f80fd5b5f905f3560e01c9081632b7ac3f31461133f575080633659cfe6146110865780633f4ba83a14610ff35780634690484014610faf5780634f1ef28614610cae57806352d1902d14610bec5780635c975abb14610bca5780636346e83214610b9a578063715018a614610b3557806377cfddfc1461049d57806379ba5097146104155780638456cb59146103ba5780638da5cb5b14610391578063aeef643914610356578063b655b1b714610311578063c4d66de81461017d578063e30c3978146101545763f2fde38b146100e4575f80fd5b34610151576020366003190112610151576100fd611380565b61010561150b565b606580546001600160a01b0319166001600160a01b039283169081179091556033549091167f38d16b8cac22d99fc7c124b9cd0de2d3fa1faef420bfe791d8c362d765e227008380a380f35b80fd5b50346101515780600319360112610151576065546040516001600160a01b039091168152602090f35b503461015157602036600319011261015157610197611380565b815460ff8160081c161591828093610304575b80156102ed575b156102915760ff198216600117845561020b9183610280575b506101ed60ff855460081c166101df816115fa565b6101e8816115fa565b6115fa565b6101f633611563565b61020660ff855460081c166115fa565b611563565b81549061023d60ff8360081c16610221816115fa565b61022a816115fa565b60ff1960fb541660fb556101e8816115fa565b600161012d5561024b575080f35b61ff00191681557f7f26b83ff96e1f2b6a682f133852f6798a09c465da95921460cefb3847402498602060405160018152a180f35b61ffff19166101011784555f6101ca565b60405162461bcd60e51b815260206004820152602e60248201527f496e697469616c697a61626c653a20636f6e747261637420697320616c72656160448201526d191e481a5b9a5d1a585b1a5e995960921b6064820152608490fd5b50303b1580156101b15750600160ff8316146101b1565b50600160ff8316106101aa565b50346101515780600319360112610151576040517f0000000000000000000000006dc226aa43e86fe77735443fb50a0a90e5666aa46001600160a01b03168152602090f35b503461015157806003193601126101515760206040517f0000000000000000000000000000000000000000000000006f05b59d3b2000008152f35b50346101515780600319360112610151576033546040516001600160a01b039091168152602090f35b50346101515780600319360112610151576103d361150b565b6103db6115b6565b600160ff1960fb54161760fb557f62e78cea01bee320cd4e420270b5ea74000d11b0c9f74754ebdbfc544b05a2586020604051338152a180f35b5034610151578060031936011261015157606554336001600160a01b03909116036104465761044333611563565b80f35b60405162461bcd60e51b815260206004820152602960248201527f4f776e61626c6532537465703a2063616c6c6572206973206e6f7420746865206044820152683732bb9037bbb732b960b91b6064820152608490fd5b50346109f45760e03660031901126109f45760043567ffffffffffffffff81116109f457366023820112156109f457806004013567ffffffffffffffff81116109f45736602482840101116109f45760c03660231901126109f4576105006115b6565b600261012d5414610af057600261012d556105196114aa565b6105216114aa565b9067ffffffffffffffff46911603610ac55750606435918215610ab2576001600160a01b0361054e6114c1565b16156105586114c1565b90610a92575060a43591825f5261015f60205260ff60405f205416610a7f577f00000000000000000000000091aa12ba1a1c5ad3d7215ad0ac075c0b86e1c75b6001600160a01b031690813b156109f45780602460405194631b27f98360e11b865260e060048701528260e4870152016101048501375f610104828501015260243567ffffffffffffffff81168091036109f457602484015260443567ffffffffffffffff81168091036109f4576044840152606483018590526084356001600160a01b038116908190036109f457608484015260a4830184905260c4356001600160a01b03811692908390036109f457836101048180945f9660c4830152601f801991011681010301915afa8015610a7457610a5f575b5080835261015f60205260408320805460ff191660011790556103e88204808303838111610a4b578491906001600160a01b036106ab6114d7565b16610866576106de7f0000000000000000000000000000000000000000000000006f05b59d3b20000086818111156114ed565b7f0000000000000000000000006dc226aa43e86fe77735443fb50a0a90e5666aa46001600160a01b0316906107116114c1565b823b1561086257604051634416e9e960e11b81526001600160a01b039190911660048201526024810191909152838160448183865af1908115610857578491610842575b5050816107b5575b5050505b7fba78a15e874441cf1871e3d2633ba91540bab663ae8664088ace7d60009ddd65604061078c6114c1565b6107946114d7565b82519586526001600160a01b0390811660208701521693a3600161012d5580f35b803b1561083357604051634416e9e960e11b81527f000000000000000000000000e36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb6001600160a01b03166004820152602481019290925282908290604490829084905af180156108375761081e575b8061075d565b8161082891611396565b61083357825f610818565b8280fd5b6040513d84823e3d90fd5b8161084c91611396565b61083357825f610755565b6040513d86823e3d90fd5b8480fd5b6001600160a01b036108766114d7565b169060405163194bd9ed60e11b8152602081600481865afa908115610a40578591610a0b575b5060405163194bd9ed60e11b8152602081600481875afa918215610a0057889187936109c1575b50906108d292918111156114ed565b6108da6114c1565b823b1561086257604051632ca6c9a560e21b81526001600160a01b039190911660048201526024810191909152838160448183865af19081156108575784916109ac575b50508161092e575b505050610761565b803b1561083357604051632ca6c9a560e21b81527f000000000000000000000000e36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb6001600160a01b03166004820152602481019290925282908290604490829084905af1801561083757610997575b80610926565b816109a191611396565b61083357825f610991565b816109b691611396565b61083357825f61091e565b92509550506020813d6020116109f8575b816109df60209383611396565b810103126109f45751879487906108d26108c3565b5f80fd5b3d91506109d2565b6040513d88823e3d90fd5b9450506020843d602011610a38575b81610a2760209383611396565b810103126109f4578693515f61089c565b3d9150610a1a565b6040513d87823e3d90fd5b634e487b7160e01b85526011600452602485fd5b610a6c9193505f90611396565b5f915f610670565b6040513d5f823e3d90fd5b8263350e9ad360e01b5f5260045260245ffd5b630bc2c5df60e11b5f9081526001600160a01b0391909116600452602490fd5b82633728b83d60e01b5f5260045260245ffd5b67ffffffffffffffff906304cce86960e51b5f521660045267ffffffffffffffff461660245260445ffd5b60405162461bcd60e51b815260206004820152601f60248201527f5265656e7472616e637947756172643a207265656e7472616e742063616c6c006044820152606490fd5b346109f4575f3660031901126109f457610b4d61150b565b606580546001600160a01b03199081169091556033805491821690555f906001600160a01b03167f8be0079c531659141344cd1fd0a4f28419497f9722a3daafe3b4186f6b6457e08280a3005b346109f45760203660031901126109f4576004355f5261015f602052602060ff60405f2054166040519015158152f35b346109f4575f3660031901126109f457602060ff60fb54166040519015158152f35b346109f4575f3660031901126109f4577f000000000000000000000000cb5a4069a869c7c5f5d01658e65c8ee0b949bca76001600160a01b03163003610c435760206040515f5160206117c55f395f51905f528152f35b60405162461bcd60e51b815260206004820152603860248201527f555550535570677261646561626c653a206d757374206e6f742062652063616c60448201527f6c6564207468726f7567682064656c656761746563616c6c00000000000000006064820152608490fd5b60403660031901126109f457610cc2611380565b6024359067ffffffffffffffff82116109f457366023830112156109f4578160040135610cee816113cc565b90610cfc6040519283611396565b808252602082019336602483830101116109f457815f92602460209301873783010152610d767f000000000000000000000000cb5a4069a869c7c5f5d01658e65c8ee0b949bca76001600160a01b0316610d58308214156113e8565b5f5160206117c55f395f51905f52546001600160a01b031614611449565b610d7e61150b565b7f4910fdfa16fed3260ed0e7147f7cc6da11a60208b5b9406d12a635614ffd91435460ff1615610db55750610db3915061165a565b005b6040516352d1902d60e01b81529091906001600160a01b03821690602081600481855afa5f9181610f7b575b50610e425760405162461bcd60e51b815260206004820152602e60248201527f45524331393637557067726164653a206e657720696d706c656d656e7461746960448201526d6f6e206973206e6f74205555505360901b6064820152608490fd5b5f5160206117c55f395f51905f5203610f2457610e5e8261165a565b7fbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b5f80a2815115801590610f1c575b610e9357005b5f80610db39460405194610ea8606087611396565b602786527f416464726573733a206c6f772d6c6576656c2064656c65676174652063616c6c6020870152660819985a5b195960ca1b60408701525190845af43d15610f14573d91610ef8836113cc565b92610f066040519485611396565b83523d5f602085013e6116f6565b6060916116f6565b506001610e8d565b60405162461bcd60e51b815260206004820152602960248201527f45524331393637557067726164653a20756e737570706f727465642070726f786044820152681a58589b195555525160ba1b6064820152608490fd5b9091506020813d602011610fa7575b81610f9760209383611396565b810103126109f457519086610de1565b3d9150610f8a565b346109f4575f3660031901126109f4576040517f000000000000000000000000e36c0f16d5fb473cc5181f5fb86b6eb3299ad9cb6001600160a01b03168152602090f35b346109f4575f3660031901126109f45761100b61150b565b60fb5460ff81161561104a5760ff191660fb557f5db9ee0a495bf2e6ff9c91a7834c1ba4fdd244a5e8aa4e537bd38aeae4b073aa6020604051338152a1005b60405162461bcd60e51b815260206004820152601460248201527314185d5cd8589b194e881b9bdd081c185d5cd95960621b6044820152606490fd5b346109f45760203660031901126109f45761109f611380565b6110d87f000000000000000000000000cb5a4069a869c7c5f5d01658e65c8ee0b949bca76001600160a01b0316610d58308214156113e8565b6110e061150b565b6040519060206110f08184611396565b5f835280830192601f1982013685377f4910fdfa16fed3260ed0e7147f7cc6da11a60208b5b9406d12a635614ffd91435460ff1615611135575050610db3915061165a565b6040516352d1902d60e01b8152919290916001600160a01b038216908481600481855afa5f9181611310575b506111c25760405162461bcd60e51b815260048101869052602e60248201527f45524331393637557067726164653a206e657720696d706c656d656e7461746960448201526d6f6e206973206e6f74205555505360901b6064820152608490fd5b9293927fc9f76b5ec45e5cdef99837d7b6d2467235c1df8933c8ca56df5c35afa2c7d444016112b9576111f48261165a565b7fbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b5f80a28251158015906112b2575b61122957005b5f80610db3956040519561123e606088611396565b602787527f416464726573733a206c6f772d6c6576656c2064656c65676174652063616c6c86880152660819985a5b195960ca1b60408801525190845af4903d156112a9573d61128d816113cc565b9061129b6040519283611396565b81525f81943d92013e6116f6565b606092506116f6565b505f611223565b60405162461bcd60e51b815260048101849052602960248201527f45524331393637557067726164653a20756e737570706f727465642070726f786044820152681a58589b195555525160ba1b6064820152608490fd5b9091508581813d8311611338575b6113288183611396565b810103126109f457519087611161565b503d61131e565b346109f4575f3660031901126109f4577f00000000000000000000000091aa12ba1a1c5ad3d7215ad0ac075c0b86e1c75b6001600160a01b03168152602090f35b600435906001600160a01b03821682036109f457565b90601f8019910116810190811067ffffffffffffffff8211176113b857604052565b634e487b7160e01b5f52604160045260245ffd5b67ffffffffffffffff81116113b857601f01601f191660200190565b156113ef57565b60405162461bcd60e51b815260206004820152602c60248201527f46756e6374696f6e206d7573742062652063616c6c6564207468726f7567682060448201526b19195b1959d85d1958d85b1b60a21b6064820152608490fd5b1561145057565b60405162461bcd60e51b815260206004820152602c60248201527f46756e6374696f6e206d7573742062652063616c6c6564207468726f7567682060448201526b6163746976652070726f787960a01b6064820152608490fd5b60443567ffffffffffffffff811681036109f45790565b6084356001600160a01b03811681036109f45790565b60c4356001600160a01b03811681036109f45790565b156114f6575050565b632af9a0af60e21b5f5260045260245260445ffd5b6033546001600160a01b0316330361151f57565b606460405162461bcd60e51b815260206004820152602060248201527f4f776e61626c653a2063616c6c6572206973206e6f7420746865206f776e65726044820152fd5b606580546001600160a01b0319908116909155603380549182166001600160a01b0393841690811790915591167f8be0079c531659141344cd1fd0a4f28419497f9722a3daafe3b4186f6b6457e05f80a3565b60ff60fb54166115c257565b60405162461bcd60e51b815260206004820152601060248201526f14185d5cd8589b194e881c185d5cd95960821b6044820152606490fd5b1561160157565b60405162461bcd60e51b815260206004820152602b60248201527f496e697469616c697a61626c653a20636f6e7472616374206973206e6f74206960448201526a6e697469616c697a696e6760a81b6064820152608490fd5b803b1561169b5760018060a01b03166bffffffffffffffffffffffff60a01b5f5160206117c55f395f51905f525416175f5160206117c55f395f51905f5255565b60405162461bcd60e51b815260206004820152602d60248201527f455243313936373a206e657720696d706c656d656e746174696f6e206973206e60448201526c1bdd08184818dbdb9d1c9858dd609a1b6064820152608490fd5b91929015611758575081511561170a575090565b3b156117135790565b60405162461bcd60e51b815260206004820152601d60248201527f416464726573733a2063616c6c20746f206e6f6e2d636f6e74726163740000006044820152606490fd5b82519091501561176b5750805190602001fd5b6040519062461bcd60e51b825260206004830152818151918260248301525f5b8381106117ac575050815f6044809484010152601f80199101168101030190fd5b6020828201810151604487840101528593500161178b56fe360894a13ba1a3210667c828492db98dca3e2076cc3735a920a3ca505d382bbca264697066735822122018e55136788877bf91d37f613d00be63e3a5ca3fb507122e84f1164a685c453b64736f6c63430008210033