AURA SECURITY CENTER / REPORT AURA-SEC-2026-001

Contract security
assessment

Onchain contract details, active security controls and the internal review scope for AURA Collection V2.

ONCHAIN DEPLOYMENTMainnet deployment verified
INTERNAL REVIEWInternal security assessment complete
FUNCTION CHECKAuthorized mint flow verified
LIVE CONTRACT
AURA Collection V2
Network
Robinhood Mainnet · Chain ID 4663
Contract address
0x7632893B0624F7E35df9EEDF67ABec0C4c2c4D65
Deployment transaction
0xd90eecdfc6f7071109c6731b8b8fa744cbc3d39adad9ac287f9657f33290e41e
Deployment block
60,449,548
Deployment owner
0xD3894E8F239F5e24D8298C5Cd8e69804e1fDD56D
Authorized signer
0x9c624b7E2d78eF47c6276251d254cbFe80B46cb6
Runtime bytecode
10,013 bytes
Bytecode fingerprint
0x10a27d95d9442cb3ae9db2223481d4ce7d18f292cb9ccdfcca3fe0964844bbc3
Transaction status: successfulTotal supply at deployment: 0Mint price: 0 ETHPer-transaction limit: 50
02 / SECURITY CONTROLS

Active contract protections

V2 replaces unrestricted public minting with short-lived, single-use authorization bound to all transaction parameters.

EIP-712

Domain-separated signatures

Signatures bind AURA Collection and Robinhood Mainnet to reduce cross-contract and cross-network replay risk.

NONCE

Single-use authorization

Each payer has an independent nonce that increments immediately after minting.

PAUSABLE

Emergency pause

The owner may pause public minting during an incident and resume after review.

SUPPLY CAP

Fixed supply cap

Contract checks prevent cumulative supply from exceeding the configured cap.

EXACT VALUE

Exact payment

Transaction value must exactly match the onchain quoteMint result.

URI BINDING

Asset binding

The token URI list is hashed into the authorization to prevent post-signature substitution.

03 / REVIEW MATRIX

Internal code review results

Assessment based on AuraCollectionV2.sol, deployment parameters and observed mainnet state.

CheckStatusConclusion
Access controlPassed

Owner permissions cover pausing, signer rotation, price changes and contract revenue withdrawal.

Mint authorizationPassed

Every batch mint requires EIP-712 authorization issued by AURA's publishing service.

Replay protectionPassed

A per-payer nonce increments after minting so authorization cannot be reused.

Authorization expiryPassed

Authorization includes a deadline and expired signatures cannot execute.

Parameter bindingPassed

Payer, recipient, URI hash, quantity, value, nonce and deadline are signature-bound.

Supply and batch limitsPassed

Maximum supply is 1,000,000; each transaction may mint up to 50 tokens.

Reentrancy protectionPassed

Mint and withdrawal flows use ReentrancyGuard and failed transfers revert atomically.

04 / ASSURANCE BOUNDARY

Operational security priorities

This page documents AURA's internal technical assessment, deployed contract parameters and active onchain controls.

  1. Explorer source verificationCompiler version, optimizer settings and constructor arguments should remain available with the deployed source.
  2. Production key and permission governanceThe owner should migrate to a multisig wallet; the authorized signer should use an isolated production key with rotation and monitoring.
  3. Infrastructure and asset availabilityPinata/IPFS, RPC and publishing endpoints require rate limits, alerts, backups and recovery procedures.
VERIFY, THEN PUBLISH

Verify every step before signing.

Launch Studio →Read the whitepaper