Simulation only · no key loaded · never signs

This deployment carries no private key and cannot sign or broadcast anything. It builds the transaction, runs the safety guard, and does a read-only simulation, so you can audit exactly what the signing path would do before any key is ever involved.

The optional XP auto-racer

It enters free races. It cannot touch your assets.

The auto-racer's entire job is to sign one kind of transaction: a zero-value free-race entry. The racing contract only reads ownership, so a Gigling never moves and no approval is ever needed. This is proven on-chain in the methodology, and enforced in code by a guard that a signer-rejection test holds to account.

Enforced invariants

What it will and will not do

  • ✳Signs exactly one function: joinRace, a free-race entry, and nothing else.
  • ✳Never approve, setApprovalForAll, transfer, or permit. Your Giglings never move.
  • ✳Never a nonzero value. Free races only; paid races are excluded and need a separate manual confirm.
  • ✳Every transaction passes the safety guard before signing; the guard refuses everything outside the allowlist.
  • ✳Per-transaction approval only. No batch pre-authorization, no session keys.
  • ✳Kill switch and a daily race-count cap. Auto mode starts OFF.

The allowlist

Two contracts, one function

Racing contract (the only signing target)
0x16e0b3d6394ce7597d34b73f5e5fb165fd74394e
Giglings collection (read-only, never an approval target)
0xd320831c876190c7ef79376ffcc889756f038e04
Allowed function
joinRace(uint256, uint256, bytes) · selector 0x168491e9

Dry run

Build a real entry and watch the guard check it

Builds the joinRace transaction for a race and pet, runs every safety check, and simulates read-only. Nothing is signed.

The safety guard is enforced by a committed signer-rejection test that proves it refuses setApprovalForAll, approve, transfer, nonzero value, and any non-joinRace call. The full on-chain safety analysis and the re-runnable forensics harness are in SECURITY.md.