Skip to main content

Architecture

zk-pad is a set of Solidity contracts on BNB Smart Chain, a TypeScript SDK, three off-chain services (relayer, attestor, indexer) and a web app.

Components​

LayerComponentPathRole
Contracts (launch)ZkPadFactorycontracts/src/ZkPadFactory.solDeploys tokens, pools, locked liquidity, dev buy, MEV module
ZkPadTokencontracts/src/ZkPadToken.solFixed-supply ERC20
ZkPadHook (+ ZkPadHookBase)contracts/src/hooks/Infinity CL dynamic-fee hook: fee per direction, 25/75 split, locker-only liquidity
ZkPadLpLockercontracts/src/lockers/Owns liquidity forever; collects, converts and deposits LP fees
ZkPadMevDescendingFeescontracts/src/mev/Anti-sniper descending fee
ZkPadSwapRoutercontracts/src/periphery/Minimal exact-in / exact-out router for the UI
Contracts (vault)FeeVaultcontracts/src/vault/Opaque beneficiary accounts, EIP-712 owner actions, binds, fallback
RailgunShieldAdapter + ShieldSendercontracts/src/adapters/USDT-only shield into Railgun via per-beneficiary proxies
QuoteRegistry + route executorscontracts/src/consolidation/Quote allow-list (Tier 1 / Tier 2), USDT routes (Infinity CL, PancakeSwap V3), Chainlink bounds for creator-triggered consolidation
Off-chainSDK @zk-pad/sdkpackages/sdkIds, claim links, EIP-712, hints, launch math, Railgun data, service clients
Relayerservices/relayerValidates, simulates and submits signed vault actions (claims pay through relayerFee, other owner actions through a fee-only claim); fetch-everything account index
Attestorservices/attestorSalted commitments (paid handle lookups), OAuth, BindOwner signatures, hint index, event-sourced account index, veto watcher
Indexerservices/indexerPonder indexer: tokens, trades, candles, holders, activity, beneficiary dump
Web appapps/webNext.js dApp for traders, creators and beneficiaries

Contract relationships​

Main flows​

Launch​

See the sequence diagram in how it works. Key invariants:

  • only the hook, called by the factory, can initialize a zk-pad pool (beforeInitialize reverts for everyone else; Infinity skips the callback when the hook itself initializes);
  • the locker places the whole supply and SupplyNotPlaced reverts the launch otherwise;
  • the dev buy runs before the MEV module is armed.

The factory checks the quote allow-list (setQuoteToken, mirrored by the QuoteRegistry). The launch wizard lists every factory-enabled quote and overlays the registry's consolidation data; quotes the registry does not list can still be launched, without USDT consolidation.

Swap and fee collection​

Claim​

Design references​

  • docs/BUILD_SPEC.md: binding decisions.
  • contracts/PORTING.md: every deviation from Clanker v4.
  • docs/ARCHITECTURE.md and docs/THREAT_MODEL.md: the audit-facing versions of this section.
  • docs/research/*.md: evidence behind each decision.