CIPHR docs, for developers
CiphrCollection is a buyer-paid ERC-721 on Robinhood Chain 4663. Its EIP-712 domain is Ciphr Collection, version 1, bound to the chain and deployed collection address. It inherits Ownable and Pausable. No relayer or hook mints pieces for buyers.
Constructor fields, in order: address owner, address signer, address token, address pool, uint256 minBuy. The first claimer can publish the fixed constructor payload through the canonical CREATE2 proxy. The owner, signer, token, selling pool and positive minimum are fixed by that payload. Only the owner can rotate the nonzero signer with setSigner. It emits SignerChanged(oldSigner,newSigner). Pending authorizations from the old signer then fail. Roll out the matching API SIGNER_KEY with the on-chain change.
MintAuthorization(address buyer,bytes32 buyRef,uint256 amountIn,uint256 deadline,bytes32 commitment,bytes32 ciphertextHash)
mintForBuy(address buyer, bytes32 buyRef, uint256 amountIn, uint256 deadline, bytes signature, bytes32 commitment, bytes ciphertext)The buyer obtains an enclave-signed sealed envelope directly from the enrolled CVM. The mint API verifies a buy and signs the commitment plus the hash of that entire envelope. The contract checks the buyer, buy reference, signer, deadline and one-claim rule, then checks the enrolled key signature, quote hash, token id, transfer cycle and nonce. The buyer pays network gas. The API proof and external attestation verifier are explicit trust boundaries.
Public and operator ABI entries: mintForBuy, authorizationHash, ownerOf, seedFor, seedOf, traitsForSeed, traitsOf, traitNamesOf, commitmentOf, ciphertextOf, cycleOf, reseal, reveal, revealed, revealedSecret, tokenURI, usedBuy, claimedBuyer, setSigner, pause, unpause. Inherited ERC-721 owner, approval, transfer and ERC-165 functions remain available. The contract emits SignerChanged(oldSigner,newSigner), Ciphered, Sealed, Revealed, Transfer as applicable. renounceOwnership reverts to preserve signer rotation.
Public helmet shape, edge, palette and sealed state come from the packed seed and the site table. The visor secret is encrypted inside the enrolled Phala CVM. A new holder requests a new seal after transfer. Only the current holder can request the CVM to sign a permanent public reveal. The contract preserves the existing five trait groups, SVG backgrounds and visor colors.
imageForTraits(uint8[4], bool, bytes32) draws the stepped graphite helmet. The sealed visor has noise squares and a keyhole; the revealed visor has two rows drawn from all four visor colors using the first two secret bytes. The public glass trait changes the visor fill, and the holder's private preview uses the same secret bytes and glass trait. tokenURI embeds this on-chain SVG. Ciphered(tokenId,buyer,buyRef,seed) records the original buyer, buy reference and public seedOf(tokenId). A reveal publishes the secret permanently; reseal protects the current holder before reveal.
The original option table disagreed with the helmet art. The corrected helmet table keeps character weights 500/300/150/50 and palette weights 500/250/150/100. The eight old edge weights are folded by index into mint/lime/graphite/frost at 460/240/180/120. All initial pieces are sealed. Public unlock is a permanent state change.
Successful holder reveal deletes the ciphertext and commitment. The revealed secret and public state persist. A nonholder or incorrect secret cannot clear either value.
The local pristine ethers 6.16.0 UMD bundle has SHA-256 9a85a5aa81305f85e6546452fd2093a8a68932bed3cec4f6491e4d031a90bc95. The shipped bundle has SHA-256 65772f76fae0bc74e7b923bc27aa928f48d7a9a72cc374f6393cf9378129d789. Byte comparison found one local license header and five address literal splits. The splits join the same address at runtime. The six exact edits are in contracts/vendor-patches/ethers.umd.min.patch.json. From the workspace root, run node .foreman/seven-cooks/privacy-tools/round5-vendor-proof.cjs to apply the edits to the pristine copy and compare every shipped byte.
The reported SigningKey.addPoints defect is not present in the local evidence: its implementation is byte identical in pristine and shipped ethers 6.16.0. Both compute the compressed point G + 2G as 3G. No addPoints correction can be attributed to this shipped bundle without another verified baseline.
Collection, token, pool, minimum, owner and signer addresses must be set to real launch values. The buyer must have native gas for the first CREATE2 publication and mint. No production collection address is claimed on this page.