Testnet beta. Uzo Deploy is live on BOT Chain testnet (chain 968). Mainnet is not enabled yet. Everything here is free to try with test tokens from the faucet.
Uzo Labs is an independent project and is not affiliated with or endorsed by BOT Chain.
What Uzo can’t do
The factories and templates are immutable and have no admin keys. Once your contract is deployed, Uzo Labs:- can’t pause, upgrade or change it,
- can’t move your tokens, NFTs or funds,
- can’t take a fee from it.
What was checked
The details are incontracts/REVIEWS.md in the uzo-deploy repo. In short:
- Base code: OpenZeppelin Contracts v5.7.0, Solidity 0.8.28.
- Tests: 86 tests in Foundry, including fuzz tests at 10,000 runs, invariant tests and fork tests against testnet USDT.
- Coverage: 100% of lines, statements, branches and functions in the contract sources.
- Static analysis: Slither 0.11.6 reported 4 informational results. Each is explained in REVIEWS.md.
forge lintis clean.
Known limitations
- The tip jar accepts only the USDT set in its factory, plus BOT. Tokens with transfer fees or rebasing aren’t supported.
- NFT metadata hosting is the owner’s job. Freezing metadata stops changes to the base URI, not to whatever that URI serves. See NFT Collection.
Other people’s contracts
Anyone can deploy a contract with Uzo Deploy. Uzo Labs doesn’t review, endorse or promote contracts other people deploy. A token made with Uzo Deploy isn’t a sign that anyone trusts it. Uzo’s no-admin-key promise covers the template code, not what the deployer does with their own supply or their NFT owner rights.What you should do
- Start on testnet. Deploy and try everything there first.
- Check the factory address. Before you sign, compare the address your wallet shows with Contracts.
- Check the network. Make sure the app and your wallet are on the network you mean to use.
- Keep your keys safe. Uzo never asks for your seed phrase or private key. Anyone who does is trying to steal from you.
Report a vulnerability
Report security issues privately through GitHub. Don’t open a public issue.- Go to the uzo-deploy repo.
- Open the Security tab and select Report a vulnerability.
- Include the contract or page affected and the network, the steps to reproduce it or a proof of concept, and what an attacker could do with it.
contracts/src, the scripts in contracts/script and the web app at deploy.uzolabs.xyz. Out of scope: BOT Chain itself, BOTScan, wallets and third-party tokens such as USDT.