AURACOLLECTION ENGINEContract security
assessment
Onchain contract details, active security controls and the internal review scope for AURA Collection V2.
- Network
- Robinhood Mainnet · Chain ID 4663
- Contract address
- 0x7632893B0624F7E35df9EEDF67ABec0C4c2c4D65 ↗
- Deployment transaction
- 0xd90eecdfc6f7071109c6731b8b8fa744cbc3d39adad9ac287f9657f33290e41e ↗
- Deployment block
- 60,449,548
- Deployment owner
- 0xD3894E8F239F5e24D8298C5Cd8e69804e1fDD56D
- Authorized signer
- 0x9c624b7E2d78eF47c6276251d254cbFe80B46cb6
- Runtime bytecode
- 10,013 bytes
- Bytecode fingerprint
- 0x10a27d95d9442cb3ae9db2223481d4ce7d18f292cb9ccdfcca3fe0964844bbc3
Active contract protections
V2 replaces unrestricted public minting with short-lived, single-use authorization bound to all transaction parameters.
Domain-separated signatures
Signatures bind AURA Collection and Robinhood Mainnet to reduce cross-contract and cross-network replay risk.
Single-use authorization
Each payer has an independent nonce that increments immediately after minting.
Emergency pause
The owner may pause public minting during an incident and resume after review.
Fixed supply cap
Contract checks prevent cumulative supply from exceeding the configured cap.
Exact payment
Transaction value must exactly match the onchain quoteMint result.
Asset binding
The token URI list is hashed into the authorization to prevent post-signature substitution.
Internal code review results
Assessment based on AuraCollectionV2.sol, deployment parameters and observed mainnet state.
Owner permissions cover pausing, signer rotation, price changes and contract revenue withdrawal.
Every batch mint requires EIP-712 authorization issued by AURA's publishing service.
A per-payer nonce increments after minting so authorization cannot be reused.
Authorization includes a deadline and expired signatures cannot execute.
Payer, recipient, URI hash, quantity, value, nonce and deadline are signature-bound.
Maximum supply is 1,000,000; each transaction may mint up to 50 tokens.
Mint and withdrawal flows use ReentrancyGuard and failed transfers revert atomically.
Operational security priorities
This page documents AURA's internal technical assessment, deployed contract parameters and active onchain controls.
- Explorer source verificationCompiler version, optimizer settings and constructor arguments should remain available with the deployed source.
- Production key and permission governanceThe owner should migrate to a multisig wallet; the authorized signer should use an isolated production key with rotation and monitoring.
- Infrastructure and asset availabilityPinata/IPFS, RPC and publishing endpoints require rate limits, alerts, backups and recovery procedures.