← HOME

Smart Contracts Technical Reference

The ROBINDUDES smart contract suite is written in Solidity ^0.8.24 and built on OpenZeppelin v5.0 primitives. It establishes a trust-minimized boundary between high-frequency off-chain trading calculations and immutable on-chain state.

1. The Contract Suite

ContractTypeUpgradablePrimary Responsibility
GameNFT.solERC-721No (Immutable)Main collection, rarity traits, token minting, and ERC-6551 self-ownership cycle guards.
GameAccount.solERC-6551 ImplNo (Cloned)TBA "backpack" smart wallet per NFT, dynamic skill views, and CALL-only execution.
SkillRegistry.solUUPS ProxyYesSingle source of truth for skill levels per tokenId, anti-replay hashes, starter skills.
WeeklySettlement.solUUPS ProxyYesEpoch scheduler, trust-minimized results submission, and owner reward claims.
VirtualLedger.solUUPS ProxyYesVirtual USD balance tracking (non-transferable, non-ERC-20).
DudesToken.solERC-20No (Immutable)Fixed-supply utility token ($DUDES) with votes, permit, and burn capabilities. Zero admin.
PrizePool.solUUPS ProxyYesIsolated tier entry pots, pari-mutuel payouts, cancellations, and 100% refund claims.
SkillReroll.solUUPS ProxyYesTwo-step commit-reveal RNG, $DUDES burn sink, and 7-day cooldown management.

2. Canonical ERC-6551 Registry Singleton

ROBINDUDES does not deploy a proprietary registry. All Token Bound Accounts are created via the official, canonical ERC-6551 Registry Singleton:

0x000000006551c19487814612e58FE06813775758

This ensures full cross-marketplace and ecosystem compatibility with wallets and NFT platforms that recognize ERC-6551 token accounts.

3. Access Control & Role Matrix

All system roles are securely hashed and unified via libraries/GameRoles.sol:

RoleHeld ByScoped Permissions
DEFAULT_ADMIN_ROLEProtocol Multisig (Gnosis Safe)Grant/revoke roles, register skills, configure tier stakes, and set schedules.
MINTER_ROLEDedicated Minter ContractMints new NFTs within the hard-capped maxSupply. Kept separate from engine keys.
GAME_ENGINE_ROLEBackend Settlement KeeperSubmit weekly competition results, open new weeks, distribute prizes, and cancel empty tiers.
UPGRADER_ROLETimelockController (24-48h delay)Authorizes UUPS implementation contract upgrades across proxy contracts.
GUARDIAN_ROLEOps Emergency MultisigEmergency pause() and unpause() controls only. Cannot alter logic or balances.
REROLL_ROLESkillReroll.sol Address OnlyExclusive permission in SkillRegistry to execute paid skill rerolls.

4. Key Security Invariants & Audit Mitigations

1. Self-Ownership Cycle Protection (SOL-008)

Per EIP-6551 security considerations, transferring an NFT to its own Token Bound Account creates an unrecoverable ownership cycle where no valid signer can ever originate a transaction. In GameNFT._update, transfers dynamically check:

if (chainId == block.chainid && tokenContract == address(this) && boundTokenId == tokenId) {
    revert SelfOwnershipCycle(tokenId, to);
}

2. Checks-Effects-Interactions (CEI) & Anti-Reentrancy

All state-modifying functions across PrizePool, WeeklySettlement, SkillRegistry, and SkillReroll strictly execute state updates (marking records as consumed/distributed) before triggering external token or contract calls, backed by OpenZeppelin ReentrancyGuardUpgradeable.

3. Blast Radius Isolation (Separation of Funds from Logic)

WeeklySettlement never holds funds. Prize pool custody is completely isolated within PrizePool.sol. An issue or pause in token disbursements cannot block skill level progression or weekly competition finalizations.

5. Verified Sepolia Testnet Deployments

Contract NameSepolia AddressType
GameNFT0xe065493A3732c0DEE30aF36BfD93698a5189B1EdERC-721 Collection
SkillRegistry0x7cfe59907032d03fDCb0165628Ae20F6A0625F7AUUPS Proxy
VirtualLedger0x420a206A8C776E9cC585710062826d68ec2a27d1UUPS Proxy
WeeklySettlement0x3dE15Bd047464b56258FfEbBbBEe97c40231A4feUUPS Proxy
RobinDudesToken ($DUDES)0x0D741370A65B0771675ef7dA6b30Bb4Ad53C7dEdERC-20 Token
PrizePool0xD382026BbE154e0523944F090EDF520B085c28F4UUPS Proxy
SkillReroll0x9755322CA8A0B297D7d26c746c7240089Fa85A5DUUPS Proxy
GameAccount (Implementation)0xc55Eeedb19a15EA044c2C32C97cDAe37899aDAEBERC-6551 Account Impl
Next: Backend Architecture & Alpha EngineExplore the Alpha Engine vendor abstraction, simulation engines, and indexers.
VIEW ARCHITECTURE →