No mainnet deployment was performed. No real wallet is needed for the checks below.
Local simulation
Install pinned dependencies, configure MAINNET_RPC_URL, run all tests, then:
forge script script/Deploy.s.sol:Deploy --rpc-url mainnet
Without --broadcast, Foundry simulates. This script intentionally follows Foundry's conventional startBroadcast/stopBroadcast structure for a future human operator. Automation must never append --broadcast. The simulated address is not a live deployment.
Constructor validates chain id 1, protocol code and the hook's PoolKey/id/manager. Output prints address, token, manager, hook and pool id. There are no owner transfers.
Future human deployment
Re-query official sources and current market; confirm chain, dependency/compiler hashes and audits. A human chooses wallet, gas, limits and the final deployment transaction. Keep keys in the wallet or secure signer; never commit them. Any new implementation requires a new address. Publish and verify source, compiler, optimizer and metadata settings.
Read-only verification of an existing deployment
Set ROUTER_ADDRESS to the independently confirmed deployment, then:
forge script script/VerifyDeployment.s.sol:VerifyDeployment --rpc-url mainnet
The script never calls startBroadcast. It reads code/configuration, funds a throwaway address in local simulation and dry-runs a small exact-output purchase. Test amount and generous simulated budget are verification parameters, never an action price or real transaction.
Also compare published verified source/runtime with the build artifact. Getter equality alone cannot prove authenticity: a malicious contract can mimic every getter. Confirm creation receipt and immutable settings, and run the full fork suite against the final code before setting NEXT_PUBLIC_ROUTER_ADDRESS. Rebuild Next.js after changing public environment configuration.
The frontend remains purchase-disabled with a blank router address. Configure the RPC only on the server; use HTTPS, a restrictive production CSP compatible with the selected wallet, host-level request limits and logs that omit authorization/payment headers. Test with a human-operated wallet before inviting users.
Toolchain
Foundry v1.8.4 downloaded from the official release; Windows archive SHA-256 7927f41b36fbe815f858ebb3e9fb7ca07a9b53fed67ccca6471acd7efd203aa1, matching published checksum. Solidity 0.8.26, Cancun, optimizer 200. Slither 0.11.3. Tool downloads are not bundled in the deliverable. Node package versions/integrities are fixed in frontend/package-lock.json.
Unsigned deployment package
Run forge build, then node script/prepare-deployment.cjs with MAINNET_RPC_URL set. The script performs read-only RPC calls and estimates contract creation gas. It saves deployment/unsigned-mainnet.json, containing compiled creation bytecode, its hash, chain ID, compiler version and a dated gas estimate. It never uses a private key or broadcasts.
The package is a review artifact, not a deployed address. It deliberately omits sender, nonce, gas price and gas limit: the human wallet must obtain and review fresh values. A contract creation transaction has no to address. Rebuild the package after any contract/compiler/dependency change. Deployment remains subject to explicit user authorization, source verification and the controlled live acceptance test.