On this page

Contract Addresses

Find each Sepolia contract, what it does and which Fuyu deployment uses it.

How these addresses were checked#

We checked every contract in the two deployment tables on Ethereum Sepolia through an independent RPC on 2026-10-02. Each had runtime code, and its Keccak-256 hash matched the value in the corresponding API configuration or source deployment file. All reads used block 11828202, hash 0xb613d35efdf70ee1b2457cd67935556530a66f911a368b67d6d5481425302abe.

The hosted API and this source revision select different Pools. The first table shows the API response from the check; the second shows the active source profile at revision 4def6e17. Both sets exist onchain. To use either one, match it with the app build and deployment manifest, then check the route's current liquidity before submitting an action.

Keep each table's contracts together. Both use chain ID 11155111, but their Pool domains and constructor-bound settings differ. The public app's recovery URL for the new source bundle returned 404 during the check. The bundle is in the repository; you'll need a reachable copy on the host you use for recovery.

Hosted API deployment · Sepolia#

The public configuration returned the following deployment on 2026-10-02. The Pool was deployed at block 11797824. Its block hash matched 0x5773781d9f24271571b096deb33e2954f3f1b8cf9320ce8c4945de9e19402c89 when read through the independent RPC.

This Pool's domain is 4527036073603490995570783483612003915492427550420872067287949540190896173749. We checked the directory and account registry with pool() and poolDomain(), the router with pool(), and the Portal factory's binding getters. Their values all matched this Pool and domain.

ContractAddressResponsibility
ActionPool0x83CE32c83913c4637A635c997B161ecCA732c97BPrivate note state, proofs, nullifiers, reserves and queued settlement
Poseidon hash child0xb859BfC7f3DDed7Ad0F9575B9C8C0EeDD2D73333Hashes notes and tree entries for this Pool
FuyuGovernor0x50dba5871536179aa66932eF1D1e882df4B0B204Source-policy and asset/route governance
FuyuReceiveDirectory0xb49b9D0B908c64523Df47DeF5eDA005d361e68D4Authenticated public receiving descriptors
FuyuAccountRegistry0x5DC9241Ce36F17f241f3d13d8E97865cC5B89e6eVersioned encrypted account profile and controller registration
FuyuAccountRegistryFactory0xa53A81445F22a9F948A3DF0Bff42d1556967fEB1Creates the account registry associated with a Pool
FuyuUnregisteredEscrow0x7C110b6AEe5D76C69De148fBfd16eD8DE9B6F71DPublic payments to unregistered wallets
FuyuTransactionRouter0xBB14D2C1005CaA92Ef2d32b54771852180Bb46afAtomic queued settlement and bounded chained spends
Claim controller factory0xD08a887F76952160D4De9b35E8125cd38FaA3ed5Deploys recipient/refund-authorized claim controllers
Anonymous Portal factory0x0c01D28C34a348aE8B1645eF68B2c8FA25bA0616Creates immutable recipient-bound deposit Portals
Reviewed Aave ETH adapter0x92C7aB53cf70C8666022a2edccB8A8149D97f7bEETH supply to and redemption from the configured static WETH vault
USDC → ETH swap adapter0xF027452a6D4a803b59c320F63099670F7efE394fApproved exact-input Uniswap V3 route
ETH → USDC swap adapter0x837b7F0bAEaD17a758ee69ce94Ab66109d75F48BApproved reverse Uniswap V3 route

Checked-in deployment · Sepolia#

In the source, SEPOLIA_ACTIVE_PROFILE selects SEPOLIA_NATIVE_ETH_PROFILE and the separate deployment below. Its Pool was deployed at block 11812881. The independent RPC confirmed block hash 0x8855e6d17dd0dbf009a18a9f595b0e37afc11e29d62a2ed5eb74f6b63a854544.

This deployment uses domain 2123002541694988798946165044072273737634637675085476779155179838890530815293. Reads of its directory, registry, router and Portal factory matched the Pool. Use these addresses when working with this source release; at the time of the snapshot, the hosted API still returned the earlier set shown above.

Shared test assets and external venues#

Both releases use the same Aave test USDC, test WETH and static WETH share. The token runtime hashes matched their source and configuration values. We also found code at the configured Uniswap V3 venue. Before using a venue, check its route manifest and, for a proxy, the implementation and code hashes required by that manifest.

The route list contains aave-eth-supply, aave-eth-redeem, swap-usdc-eth and swap-eth-usdc. Each swap direction has its own adapter, with V3 fee 100, or 0.01%. Use only the assets and token pairs allowed by your selected deployment. Deploying an adapter doesn't enable every pair that venue can trade.

ItemSepolia addressMeaning
Aave test USDC0x94a9D9AC8a22534E3FaCa9F4e7F2E2cf85d5E4C86 decimals
Aave test WETH0xC558DBdd856501FCd9aaF1E62eae57A9F0629a3c18 decimals; configured wrapped-native asset
Static WETH share0x162B500569F42D9eCe937e6a61EDfef660A12E9818 decimals; underlying is Aave test WETH
Uniswap V3 USDC/WETH venue0xAd5fF0b22E32FC8aCA003816cF298143DaCC7FbDCheck the configured route and current liquidity before swapping

Governance and the public payee#

The hosted configuration names council Safe 0x26c3D140adAbDFbE1c8C606a07CA9914774437Fe and guardian Safe 0xDFFe775E0d1CF40e801E7D2C99fe940d03677112. Their runtime code matched the configured Safe proxy hash. The configuration lists Safe 1.4.1, a threshold of one and one development owner. Read the current Safe owner and threshold settings when checking who can authorize governance actions.

Both deployments name 0x03cAe8cb91623fa968b4B9c2Bc2b4b97f988B857 as the public relayer/payee. Proof fees go to that configured address. Use the app's funding destination for deposits; this payee address isn't a user Portal or a recovery key. The relay can submit from a separate hot wallet while keeping the proof's fee payment bound to the payee.

The configured governor delay is 604800 seconds, seven days. Whether genesis is still open can change while that delay stays fixed. Read the governor's current state before assessing a proposed action; a boolean saved in the deployment JSON can be out of date.

Verify a contract identity#

Check eth_chainId, the deployment block and its canonical hash, the full runtime code hash, the Pool domain and VK_HASH(). Check the directory, account registry, router, Portal factory and routes against that same Pool. Use your release manifest to decide which contracts to accept, even when an explorer displays verified source code.

Constructor values are part of a Pool's deployed runtime. Compare the correct hash: a creation-artifact SHA-256 and a deployed-runtime Keccak-256 describe different bytes. For a proxy, also check its implementation slot and implementation code against the venue manifest. The proxy's own bytecode can stay unchanged when its implementation changes.

Both Pools returned verification-key identifier 0x9be4fc098eacb83c4f84f0bca3a466803158f921960f8ac2981372aadd49352d. They share that verifier identifier, but keep their proofs and companion contracts tied to the correct deployment. The Pool domains and protocol-context behavior differ.

Historical and local contracts#

The source also includes older Sepolia profiles for Pools 0xF3cbf96f000C29F85693b667469828f328be6C03 and 0xf174039a78F094de36B89c441a70F669D01b434f. Use them to understand earlier releases. Choose the selected deployment's funding flow for new deposits. The current recovery registry has one entry, sepolia-8af98425; before using an older checked-in directory, check that the app and proof context still support it.

Each disposable fork bootstrap creates fresh Pool and companion addresses. Read its config.json and exported deployment.json to find them. There is no shared local Pool address you can reuse across runs. For another public network, obtain and check that network's manifest before adding its addresses to your integration.