Skip to content

Repository files navigation

Oak Network Smart Contracts

Audited by OpenZeppelin Audited by Immunefi Audited by PeckShield

Overview

Oak Network is programmable commerce and escrow infrastructure — an on-chain backbone for creating and managing conditional payment flows. Each flow is defined once on-chain and shared across platforms, while funds are held and settled by interchangeable treasury models.

Features

  • Cross-listable campaign creation
  • Multiple treasury models
  • Secure fund management
  • Customizable protocol parameters
  • Currency-based multi-token campaigns
  • Campaign-level Pledge NFTs (one ERC721 collection per campaign)
  • ERC-2771 meta-transactions for platform admin operations using multisig wallets
  • UUPS upgradeability for core protocol contracts

Prerequisites

Installation

  1. Clone the repository:
git clone https://github.com/oak-network/contracts.git
cd contracts
  1. Install dependencies:
forge install
  1. Copy environment template:
cp .env.example .env
  1. Configure your .env file following the template in .env.example

Documentation

Comprehensive documentation is available in the docs/ folder:

  • Technical specifications
  • Contract interfaces
  • Deployment guides
  • Development setup instructions

To view the documentation:

cd docs

Development

Compile Contracts

forge build

Run Tests

# Run all tests
forge test

# Run specific test
forge test --match-test testFunctionName

# Run tests with more verbose output
forge test -vvv

Deploy Contracts

Local Deployment

# Start local blockchain
anvil

# Deploy to local network
forge script script/DeployAll.s.sol:DeployAll --rpc-url http://localhost:8545 --private-key $PRIVATE_KEY --broadcast

Network Deployment

# Deploy to any configured network
forge script script/DeployAll.s.sol:DeployAll --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast

Deploy core + setup a specific treasury model

If you want a one-shot script that deploys the protocol (UUPS proxies), configures GlobalParams, and registers + approves a treasury implementation for a platform, you can run one of the DeployAllAndSetup*.s.sol scripts.

# Example: deploy and setup PaymentTreasury
forge script script/DeployAllAndSetupPaymentTreasury.s.sol:DeployAllAndSetupPaymentTreasury \
  --rpc-url $RPC_URL --private-key $PRIVATE_KEY --broadcast

These scripts read configuration from .env (e.g. PLATFORM_NAME, PROTOCOL_FEE_PERCENT, PLATFORM_FEE_PERCENT, CURRENCIES/TOKENS_PER_CURRENCY, and optional PLATFORM_ADAPTER_ADDRESS for meta-txs).

Contract Architecture

Core Contracts

  • GlobalParams: Protocol-wide parameter management
  • CampaignInfoFactory: Campaign creation and management
  • TreasuryFactory: Treasury contract deployment

Treasury Models

  • AllOrNothing: Funds refunded if campaign goal not met
  • KeepWhatsRaised: Flexible treasury that keeps funds regardless of goal achievement (tips, configurable fees, withdrawal gating)
  • PaymentTreasury: Payment-style treasury (off-chain payment creation + on-chain confirmation, line items, optional NFT mint)
  • TimeConstrainedPaymentTreasury: PaymentTreasury variant gated by launchTime → deadline + bufferTime

Notes on Mock Contracts

  • TestToken is a mock ERC20 token used only for testing and development purposes.
  • It is located in the mocks/ directory and should not be included in production deployments.

Deployment Workflow

At a high level:

  1. Deploy GlobalParams (UUPS proxy + implementation)
  2. Deploy TreasuryFactory (UUPS proxy + implementation)
  3. Deploy CampaignInfoFactory (UUPS proxy + implementation)
  4. Configure currencies/tokens + data registry keys + platforms (and optional platform adapters)
  5. Register and approve treasury implementations per platform, then deploy treasuries per campaign

For local testing or development, the TestToken mock token needs to be deployed before interacting with contracts requiring an ERC20 token.

Environment Variables

Key environment variables to configure in .env:

  • PRIVATE_KEY: Deployment wallet private key
  • RPC_URL: Network RPC endpoint (can be configured for any network)
  • SIMULATE: Toggle simulation mode
  • Contract address variables for reuse

For a complete list of variables, refer to .env.example.

Tip: script/ contains deployment, setup, and upgrade scripts for each treasury type (including UUPS upgrade scripts).

Security

Audits

The protocol has undergone multiple independent security reviews. Full reports live in the audits/ folder; see the audit index for per-finding status and remediation details.

Date Auditor Scope Report
Jun 17, 2026 OpenZeppelin Full protocol (commit 479241c) PDF
Dec 10, 2025 Immunefi (Neplox) PaymentTreasury PDF
Aug 5, 2025 Immunefi (Neplox) Creative Crowdfunding Protocol v1.0 PDF
May 20, 2025 PeckShield Creative Crowdfunding Protocol v1.0 PDF

Contributing

We welcome all contributions to the Oak Network. If you're interested in helping, here's how you can contribute:

  • Report bugs by opening issues
  • Suggest enhancements or new features
  • Submit pull requests to improve the codebase
  • Improve documentation to make the project more accessible

Before contributing, please read our detailed Contributing Guidelines for comprehensive information on:

  • Development workflow
  • Coding standards
  • Testing requirements
  • Pull request process
  • Smart contract security considerations

Community

Join our community on Discord for questions and discussions.

Read our Code of Conduct to keep our community approachable and respectful.

Contributors

Made with contrib.rocks.

License

This project is licensed under the MIT License.

About

Smart contract repository for Oak Network

Topics

Resources

Code of conduct

Contributing

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages