Skip to content

Record: Base Sepolia EntryPoint v0.8 Deployment - #118

Merged
ManulParihar merged 9 commits into
mainfrom
record/base-sepolia-entrypoint-v8
Aug 18, 2026
Merged

ManulParihar merged 9 commits into
mainfrom
record/base-sepolia-entrypoint-v8

Conversation

@ManulParihar

Copy link
Copy Markdown
Member

What this deployment changes

This redeploys the full contract suite to Base Sepolia on EntryPoint v0.8, replacing the v0.7 deployment. Two things drove it: gas sponsorship needed a newer EntryPoint, and the old admin setup put every wallet one stolen key away from being drained.

Admin control no longer sits behind one key

The old deployment: one EOA owned the registry, both factories, and both wallet beacons. Whoever held that key could push an upgrade or change protocol settings instantly, with the transaction sitting in the public mempool for anyone to see coming.

The new deployment: ownership moves to a timelock contract (ProtocolAdmin).

  • Every admin action now waits two days before it can execute.
  • Proposing a change needs a 2-of-3 signature or a separate cold key, not one hot wallet.
  • A 3-of-3 guardian group can execute once the wait is over. It can also pause the protocol or cut off a compromised proposer immediately, but it cannot skip the two-day wait for anything else.

In practice: a stolen key can no longer touch user funds in a single transaction. The two-day window gives the team time to notice and react before any change takes effect.

Gas sponsorship now works

The wallets sit on EntryPoint v0.8. The paymaster that sponsors gas for users only supports v0.7 and v0.8, so this was required to keep gasless transactions running.

Because the EntryPoint address is baked into each wallet's bytecode, moving versions meant redeploying rather than upgrading in place. Every proxy, factory, and beacon here is new.

Testing and security work behind this deployment

This deployment sits on top of a hardening pass, not just a version bump.

  • 566 automated tests, unit, fuzz, and invariant, with 89.93% branch coverage across the suite.
  • Formal verification using Certora Prover on the admin timelock and the core wallet contracts. The timelock alone carries ten proven rules across 226 verified records, with zero assertion failures. A separate cross-contract proof covers the registry and both wallet types together.
  • Slither and Aderyn static analysis, both clean of high or medium findings.
  • Various bug Fixes
  • Sits on top of an earlier third-party audit (audits/2025-03-CDSecurity.pdf); this pass covers everything added or changed since.

Everything shipped with a paper trail

  • Full commit, deployer, constructor arguments, transaction hashes, and gas costs are recorded per contract.
  • Every address is verified on Basescan.
  • Dependency versions (compiler, OpenZeppelin, ERC-4337 libraries) are pinned and recorded, so this exact build can be reproduced later.

What stays the same

Device registration and the eSIM data purchase flow are unchanged in behavior. The v0.7 deployment stays live and untouched for anything still pointed at it.

ManulParihar and others added 9 commits August 18, 2026 16:12
address.json goes back to being a flat address lookup, one line per
contract, the same shape every other entry has. Everything else the
deploy captured lives in its own file next to it.
The full record for the Base Sepolia deployment on EntryPoint v0.8 is now
deployments/base-sepolia-84532-entrypoint-v8.json. The filename is the key the
scripts build from the chain id and EntryPoint version, so it cannot disagree
with the chain it describes and the scripts can find it without being told.
address.json is the address book, a flat name to address map per chain, and
that is all it holds. The build provenance, constructor arguments, role holders
and status that later scripts read move to deployments/<recordKey>.json, one
file per deployment.

The deploy now writes both, so the address book stays current without anyone
editing it by hand. Its already-deployed guard checks both files, since either
one alone is enough to make a redeploy overwrite something live.
The rehearsal now clears both its address book entry and its record file on
exit, and refuses to start when either exists. compute-initCode reads the
record file, since the address book no longer carries a contracts section.
Each contract address in the current deployment column now points at
its Basescan page, so the record can be checked without leaving the
README.
Updated README to include a link to the deployment commit.
@ManulParihar
ManulParihar merged commit 3d60588 into main Aug 18, 2026
@ManulParihar
ManulParihar deleted the record/base-sepolia-entrypoint-v8 branch August 18, 2026 11:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant