Appearance
Contract addresses
Every deployed Blazpay contract, with proxy and implementation addresses. All three vault families are UUPS-upgradeable.
BlazpayRelayer
Settlement for every EVM swap and bridge. 22 chains, all at v2. Signer and owner are 0x75a8b522FC3195e3a3570F11f111AC89c0D35975 on every chain. Fee inPercentFee = 10 (0.10%).
Source of truth: bz-backend/contract-deployment/scripts/blazpayRelayer.deployments.json.
| Chain | ID | Proxy | Implementation | Version |
|---|---|---|---|---|
| Optimism | 10 | 0xb8Bd470f3C2610F83025D049085A64f1C7b78F14 | 0x664d94391b5B68816E1Ec19966f516ebCe9b5091 | v2.1-raw |
| BSC | 56 | 0x5c23c9a42626Ade38ae1c9a3407096d4381EE6E6 | 0x29e4401fa66F200Cf778FFb40Baa01B8C91Bc5a0 | v2.1-raw |
| Unichain | 130 | 0xA01da2d3AbEFFbaa347B08C76EEC47169DdE72e9 | 0x9678B2095DF1D5975E51CA41EcC77547fdd144b8 | v2.1-raw |
| Polygon | 137 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Sonic | 146 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| opBNB | 204 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| World Chain | 480 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0x97BBe816cA1c7444695613096C16555e7e7c5f13 | v2 |
| HyperEVM | 999 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Sei | 1329 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Soneium | 1868 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Ronin | 2020 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Abstract | 2741 | 0xb8Bd470f3C2610F83025D049085A64f1C7b78F14 | — | v2.1-raw |
| Robinhood | 4663 | 0xb8Bd470f3C2610F83025D049085A64f1C7b78F14 | — | — |
| Base | 8453 | 0xb8Bd470f3C2610F83025D049085A64f1C7b78F14 | — | v2 |
| ApeChain | 33139 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | 0xAc8a7A702113a75E8B40715ac0b37D61933f29cf | v2.1-raw |
| Arbitrum | 42161 | 0x5c23c9a42626Ade38ae1c9a3407096d4381EE6E6 | — | v2.1-raw |
| Celo | 42220 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | — | v2 |
| Hemi | 43111 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | — | v2.1-raw |
| Avalanche | 43114 | 0xb8Bd470f3C2610F83025D049085A64f1C7b78F14 | — | v2.1-raw |
| Linea | 59144 | 0x5c23c9a42626Ade38ae1c9a3407096d4381EE6E6 | — | v2.1-raw |
| Berachain | 80094 | 0x7d98E59FabFBaDD5eCB61CC2cf876AA97f505531 | — | v2.1-raw |
| Scroll | 534352 | 0x5c23c9a42626Ade38ae1c9a3407096d4381EE6E6 | — | v2.1-raw |
Shared proxy addresses are not a mistake
Twelve chains share 0x7d98E5… because the proxy was deployed by the same TX_SIGNER EOA at the same nonce on each — deterministic CREATE produces the same address. Abstract differs because zkSync-stack CREATE uses a different derivation; Unichain differs because the deployer's nonce had drifted.
Not deployed, deliberately: Ethereum mainnet (1), Etherlink (42793).
World Chain's record carries "recovered": true, meaning the deployment record was reconstructed rather than written at deploy time.
DCA vault
CSIP. One chain.
| Item | Value |
|---|---|
| Contract | DCAInvestmentV2 |
| Chain | Arbitrum (42161) |
| Proxy | 0x998D4f9A36d196c762C6A646733E63d9eD1b980D |
| V2 implementation | 0xC804e3adA5d25FF4555f3B9f79fC035357f6bDF1 |
| V2.1 implementation (current) | 0x930a2b7F1B123B11d402bEfb6E1100f465082aD9 |
| Owner | 0x5935745431D1385ae1a9CE2644fb5f5d1f140459 (= executor) |
| Executor | Same |
feeAutoBuy | 0 |
autoClaimFeePerClaim | 0.00003 ETH |
Both implementations are verified on Arbiscan and Sourcify. Source is vendored at bz-backend/contract-deployment/contracts/dca/{BlazpayDcaV1,BlazpayDcaV2,Types}.sol — V1 was fetched from Arbiscan because it was never in the repo.
Owner and executor are the same EOA
So a compromised executor also holds UUPS upgrade authority over the DCA vault. setExecutor exists; separating them has not been done.
Autopilot vault
| Chain | ID | Proxy | Implementation |
|---|---|---|---|
| Arbitrum | 42161 | 0x689AaEc7E3012d84226e7c5F4DEeFdC01C86d23e | 0x7bF6f14c53BB18BC5D5cd34c9A81c8fb658bB168 |
| Robinhood | 4663 | 0x4dE7CD522f1715b2a48F3ad6612924841d450A0F | 0xa75A5bEE…16d7D |
| Arbitrum Sepolia | 421614 | 0x7cA5A09E59e8d84e678854184F67D8aF505EfF9f | — |
| Base | 8453 | not deployed | — |
| Item | Value |
|---|---|
| Contract | BlazpayAutopilotV1 |
| Owner / deployer | 0x2Ed05570214f6C0F7612B580aB37C163076e0162 (BACKEND_PRIVATE_KEY, EOA) |
| Executor | 0x5935745431D1385ae1a9CE2644fb5f5d1f140459 |
feeBps | 20 (0.20% of output) |
| Deploy cost | 0.0000659 ETH |
The Arbitrum deployment's original implementation was 0xdA2B20E9f6A7408B50Da8135E516bc767F536067; it was upgraded to the current one to add the router allow-list after the C-1 audit finding. Both proxy and implementation are Arbiscan-verified.
Two blockers on this contract
setRouters([...], true)must be called. The vault is fail-safe: with no allow-listed routers, no trade can ever execute. This is the current state on Robinhood Chain.- The owner EOA is not a multisig and holds upgrade authority.
Addresses are hardcoded as defaults in bz-backend/utils/constants.js (AUTOPILOT_ADDRESSES) and defi-dex/src/constants/index.ts, overridable by AUTOPILOT_ADDRESS_ARBITRUM, _BASE, _ROBINHOOD. The cron skips chains with an empty address.
Key addresses
| Address | Role |
|---|---|
0x75a8b522FC3195e3a3570F11f111AC89c0D35975 | TX_SIGNER — relayer signer and owner on all 22 chains |
0x5935745431D1385ae1a9CE2644fb5f5d1f140459 | PRIVATE_KEY_EXECUTOR — CSIP + Autopilot executor, DCA owner |
0x2Ed05570214f6C0F7612B580aB37C163076e0162 | BACKEND_PRIVATE_KEY — Autopilot owner and deployer |
0x5222…1D35 | 1inch referrer |
0x68b3…Fc45 | Uniswap SwapRouter02, used in the manual CSIP recovery |
Ecosystem contracts
Not tracked in a single deployment record. Sources are in bz-backend/contract-deployment/contracts/, duplicated per chain rather than parameterised.
| Contract | Purpose |
|---|---|
Blazpay_ProductsV2.sol | Shared on-chain product contract for games and commerce |
StakeRocketV3.sol | BlazRocket NFT staking |
RewardsHub.sol | Rewards aggregation |
NFTStaking.sol | Generic NFT staking |
MarketplaceNFT.sol | Legacy marketplace |
MockPointsToken.sol | Test helper |
modular/BaseCollection.sol | NFT base |
modular/BlazRocketNFT.sol | Rocket NFT |
modular/BlazBobNFT.sol | BlazBob NFT (11 tiers) |
modular/BzMarketplace.sol | Current marketplace |
modular/BzNFTStaking.sol | Current NFT staking |
poker/PokerManager.sol | On-chain poker |
Per-chain directories: arbitrum_sepolia/, avax/, hemi/, qubetics/, soneium/.
contracts/deprecated/ holds eight superseded contracts — BlazRocketNFT, Blazpay_ProductsV2, MarketplaceNFT, MarketplaceNFTv2, MockPointsToken, NFTStaking, NFTStakingV2, RewardsHub, StakeRocketV2. Some are still referenced by old records; do not delete without checking.
Legacy per-chain addresses
ChainContractAddress in swap-sdk/src/utils/constants.ts — pre-relayer product contract addresses, retained for compatibility:
| Chain | Address |
|---|---|
| Ethereum | 0xd3f64BAa732061F8B3626ee44bab354f854877AC |
| BSC | 0x880E0cE34F48c0cbC68BF3E745F17175BA8c650e |
| Polygon | 0x07d0ac7671D4242858D0cebcd34ec03907685947 |
| Avalanche | 0x1C7F7e0258c81CF41bcEa31ea4bB5191914Bf7D7 |
| Arbitrum | 0x1C7F7e0258c81CF41bcEa31ea4bB5191914Bf7D7 |
| Optimism | 0xad1D43efCF92133A9a0f33e5936F5ca10f2b012E |
| Base | 0x4F68248ecB782647D1E5981a181bBe1bfFee1040 |
| Fantom | 0xBE2A77399Cde40EfbBc4e89207332c4a4079c83D |
Native asset sentinels
Three addresses mean "the chain's native coin":
| Address | Used by |
|---|---|
0x0000000000000000000000000000000000000000 | Canonical — addressZero |
0xeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee | Several aggregators — addressE |
0x0000000000000000000000000000000000001010 | Polygon's MATIC pseudo-token |
Base.isNativeAddresss recognises all three. The triple s is in the source.
Verification
| Contract | Verified on |
|---|---|
| BlazpayRelayer v2 | Per-chain explorers |
| DCA V2 and V2.1 | Arbiscan + Sourcify |
| Autopilot proxy + implementation | Arbiscan |
finalContracts/deployed/metadata.json and creator-tx-hash.txt hold the original v1 relayer verification artefacts.