Result
A new repository containing an exact-output ETH → IMD contract, integration tests against an Ethereum fork, a minimal Next.js frontend, x402 integration, scripts, and documentation. Not deployed on mainnet. No real funds have been charged or transferred.
The contract is validated within the tested scope. Complete product acceptance with a real wallet and the live payment service remains pending; this is not certified production software.
Research
- Current IdentityMD documentation and responses: imd.fun/docs, capabilities, and OpenAPI. Prices and actions are dynamic; the same wallet signs both authorizations.
- POOL4: documentation, published configuration, and verified hook/token source on Blockscout, compared with deployed Ethereum bytecode.
- Evidence block 26125254; hash and timestamp in evidence/chain.json. The pool identifier was recomputed from its five fields rather than inferred.
- IMD contract
0xD34a99Bc0f67aE1bbd63C660e6d0b0dd03E263B7, Ethereum, 18 decimals. Native ETH, fee 10000, tickSpacing 60, hook0xc6C965Bd164c483e87d0B550671798e9A3602840. - PoolManager
0x000000000004444c5dc75cB358380D2e3dE08A90. Pool ID0x415829f72e9f54531c26eae76f107618540e898a45d6ae35959e143f5faca704. - Inspected SDK 2.27.0: Permit2 validity derives from the payment challenge; explicit IMD authorization is required in spending controls. No invented expiry rule.
Linked sources and detailed evidence: EXEC_PLAN.md, DEPENDENCIES.md, and evidence/chain.json.
Architecture and files
src/IMDUniversalPaymentRouter.sol: buyIMDWithETH, protected callback, and getters. src/libraries/MainnetConfig.sol: fixed market. src/interfaces/IPOOL4.sol: verified hook reads.
test/: adversarial unit tests, fuzzing, invariants, and real-market integration. script/Deploy.s.sol: simulation and later manual deployment. script/VerifyDeployment.s.sol: checks and simulation without broadcasting.
frontend/app/: screen and proxy routes. frontend/lib/: configuration, pricing/validation, queries, and signatures. frontend/tests/: payment safety and route restrictions. Exact dependencies and integrity hashes are in package-lock.json; Solidity libraries are pinned by commit.
The router calls Uniswap v4 directly, does not wrap ETH into WETH, and needs no ERC20 approvals. IMD goes directly to the recipient. Actual output is verified and only unused ETH from that purchase is refunded. There is no owner, upgrade mechanism, router fee, or arbitrary execution function.
Executed checks
Equivalent commands, executed using locally installed tool binaries:
forge fmt --check
forge build
forge test -vvv
forge test --match-contract RouterForkTest -vvv
forge test --match-contract RouterForkTest -vvv [without a pinned block: current state]
python -m slither . --json docs/evidence/slither-final.json
npm run test
npm run typecheck
npm run build
npm audit --json
Final contract result: 48 aggregate tests, 0 failed, 0 skipped: 35 unit tests, 3 fuzz tests, 1 campaign combining 2 invariants, and 9 fork tests. Foundry 1.8.4 counts the two invariants together. The campaign ran 128 sequences and 4096 calls without reverts. Each fuzz test ran 256 cases, including fuzzing against the real pool.
Coverage includes small purchases, 1 and 100 IMD purchases, different recipients, sequential users, insufficient limits with full rollback, refunds, zero amounts, deadlines, partial output, settlement mismatch, and callback/refund attacks. These amounts are tests, not action prices.
Frontend: 19 tests, all passed; type checking and build passed. Desktop/mobile browser checks covered current pricing, actions, controls, missing-wallet state, and disabled purchasing without deployment. No real browser signature was tested.
Corrected initial failures: redundant fixture inheritance, an incorrect assumption that a test address had zero initial balance, the SDK's explicit IMD permission requirement, and an additional settlement check. Windows tool isolation caused execution restrictions; successful final runs and logs are distinct from unsuccessful attempts.
Security
Initial Slither run: 66 findings. The unchecked settlement return was fixed. Final result: 65 findings (3 High, 22 Medium, 1 Low, 39 Informational), all retained and reviewed. Remaining High/Medium findings are explained as a caller-only bounded refund and upstream helper functions not executed by this router. No detectors were suppressed.
Adversarial review and reproductions: SECURITY_AUDIT.md. No confirmed unresolved Critical/High vulnerability was identified within the reviewed code, but self-review does not replace an independent audit. The POOL4 owner can withdraw liquidity; the bridge/token, IdentityMD service, and web infrastructure remain trust dependencies.
Gas
Block 26125254: 263,560 / 263,624 / 263,983 units for 0.000001 / 1 / 100 IMD. Measured around the call, with partially warm accesses following a quote; excludes base gas and does not guarantee real transaction cost. Logs and conditions are in README.
Integration and limitations
The frontend reads capabilities, calculates missing IMD, quotes exact output, requests confirmation, checks receipt, and prepares the normal payment. It includes bounded approval, Permit2/QuoteApproval signatures, retries using identical payload bytes, and status tracking. The wallet signs in the browser; the server holds no keys.
Acquisition through the public pool and construction of the documented payment flow require no changes to IMD. Live payment acceptance still needs testing with a human-controlled wallet and a deployed, verified router. Other actions use a minimal JSON form; contract wallets and delegated accounts are outside this version's scope. Public web deployment requires operational host controls and validation of the configured contract.
USDC, WETH, router fees, arbitrage, automatic operations, and mainnet deployment were not implemented.
V2
V2_DESIGN.md compares exact-output routes, bounded approvals, and risks of combining v3/v4. No optimal USDC route is claimed without checking current liquidity and testing it. A fully unified experience requires IdentityMD to support and authenticate that settlement model; sending tokens to payTo does not achieve it.
Reviewing the delivery
Start with README.md. Executed evidence is in docs/evidence; review of all 65 findings is in STATIC_ANALYSIS.md. The ZIP includes source, Solidity dependencies, and lockfiles; it excludes keys, installed Node dependencies, caches, and temporary build output.
Documentation is in English. Historical screenshots preserve the original Spanish frontend as tested; they are evidence, not translated mockups. Documentation edits do not represent a new execution of the earlier test suites.
Launch website iteration
The project now has an English launch website under the working name IMD Flow, with user and developer entry points, an illustrative preview, and a document reader. README and this report were translated into English; the other project documents were already English. The original Spanish purchase UI was moved into a component behind a separate server-side release gate at /checkout. The public landing page is /.
The frontend test suite was rerun with two additional release-gate tests: 21 passed, 0 failed. Type checking and production compilation passed. Contract source and settlement logic were unchanged, so the earlier 48 contract-test results remain historical evidence rather than a new run. Browser checks and design comparison are recorded in LAUNCH_QA.md. No public hosting deployment or mainnet transaction was performed.
Visual product and token presentation iteration
The next iteration replaces the simple orbit hero with original instrument artwork, adds a read-only demonstration using current official IMD requirements, links official use cases and resources, and explains the separate planned Stockereum project token. The user identified Stockereum as the intended venue; no launch settings, ticker, listing or holder rights were invented. Contract code, the existing checkout implementation, and settlement are unchanged.
Files added include frontend/components/LiveExperience.tsx, frontend/lib/live-demo.ts, frontend/app/visual.css, original image assets, live-demo tests, PROJECT_BRIEF.md, VISUAL_REDESIGN.md, and VISUAL_QA.md. The home page, shared navigation, document catalog, and architecture/security/integration documentation were updated. The new English project brief is available at /docs/brief.
Current frontend verification: 23 tests passed, including uncached read-only fetching, changed live amounts, and rejection of failed/incompatible responses. npm run test, npm run typecheck, and npm run build were executed. Browser checks and their limitations are recorded in VISUAL_QA.md. The existing 48 contract tests were not rerun because this iteration changes presentation/read-only data, not contracts. No token was created, no mainnet transaction was broadcast, and the website remains local.
Current job.open milestone
See JOB_OPEN_MILESTONE.md for the current architecture, API corrections and evidence, and LIVE_IMD_TEST.md for the exact human-controlled acceptance procedure. The refreshed contract suite passes 49 tests, including 10 dedicated real-fork tests. Slither reports the same 65 reviewed findings. The production client/state machine plus wallet adapter acquired the live-required amount from zero IMD on local Anvil and stopped at awaiting_payment_signature against the real unpaid IMD API. No mainnet deployment or real payment occurred. Earlier UI test counts and redirect descriptions above are historical.