Simulation only · no key loaded · never signs
This deployment carries no private key and cannot sign or broadcast anything. It builds the transaction, runs the safety guard, and does a read-only simulation, so you can audit exactly what the signing path would do before any key is ever involved.
The optional XP auto-racer
It enters free races. It cannot touch your assets.
The auto-racer's entire job is to sign one kind of transaction: a zero-value free-race entry. The racing contract only reads ownership, so a Gigling never moves and no approval is ever needed. This is proven on-chain in the methodology, and enforced in code by a guard that a signer-rejection test holds to account.
Enforced invariants
What it will and will not do
- ✳Signs exactly one function: joinRace, a free-race entry, and nothing else.
- ✳Never approve, setApprovalForAll, transfer, or permit. Your Giglings never move.
- ✳Never a nonzero value. Free races only; paid races are excluded and need a separate manual confirm.
- ✳Every transaction passes the safety guard before signing; the guard refuses everything outside the allowlist.
- ✳Per-transaction approval only. No batch pre-authorization, no session keys.
- ✳Kill switch and a daily race-count cap. Auto mode starts OFF.
The allowlist
Two contracts, one function
- Racing contract (the only signing target)
- 0x16e0b3d6394ce7597d34b73f5e5fb165fd74394e
- Giglings collection (read-only, never an approval target)
- 0xd320831c876190c7ef79376ffcc889756f038e04
- Allowed function
- joinRace(uint256, uint256, bytes) · selector 0x168491e9
Dry run
Build a real entry and watch the guard check it
Builds the joinRace transaction for a race and pet, runs every safety check, and simulates read-only. Nothing is signed.
The safety guard is enforced by a committed signer-rejection test that proves it refuses setApprovalForAll, approve, transfer, nonzero value, and any non-joinRace call. The full on-chain safety analysis and the re-runnable forensics harness are in SECURITY.md.