Current Status: ✅ All security fixes complete, ready for testnet deployment
Before deploying, ensure you have:
- Created
.env.localfile in project root - Obtained Alchemy API key
- Obtained WalletConnect Project ID
- Obtained BaseScan API key
- Generated secure webhook secret
- Have deployer wallet with private key
- Have test ETH on Base Sepolia (for testnet)
- Have real ETH on Base (for mainnet)
Create a file named .env.local in your project root:
# API Keys (get from respective services)
NEXT_PUBLIC_ALCHEMY_API_KEY=your_alchemy_key_here
NEXT_PUBLIC_TATUM_API_KEY=your_tatum_key_here
NEXT_PUBLIC_WALLET_CONNECT_PROJECT_ID=your_walletconnect_id_here
NEXT_PUBLIC_ONCHAINKIT_API_KEY=your_coinbase_cdp_key_here
BASESCAN_API_KEY=your_basescan_key_here
# Security
FARCASTER_WEBHOOK_SECRET=generate_random_string_here
# Deployment (NEVER share this!)
PRIVATE_KEY=your_deployer_wallet_private_keyGenerate Webhook Secret:
# PowerShell command to generate secure random string
-join ((65..90) + (97..122) + (48..57) | Get-Random -Count 32 | ForEach-Object {[char]$_})- Visit https://dashboard.alchemy.com/
- Sign up for free account
- Create new app, select "Base" network
- Copy API key to
.env.local
- Visit https://cloud.walletconnect.com/
- Create free account
- Create new project
- Copy Project ID to
.env.local
- Visit https://basescan.org/myapikey
- Sign up and create API key
- Copy to
.env.local
- Visit https://portal.cdp.coinbase.com/
- Create API key
- Copy to
.env.local
Visit Base Sepolia faucet:
- https://www.alchemy.com/faucets/base-sepolia
- Connect your wallet
- Request test ETH (free)
# Deploy contract
npx hardhat run scripts/deploy-sepolia.ts --network baseSepolia
# Note the deployed contract address# Replace CONTRACT_ADDRESS with your deployed address
npx hardhat verify --network baseSepolia CONTRACT_ADDRESSTest in this order:
- ✅ Mint an NFT
- ✅ List NFT for sale
- ✅ Buy NFT (from different wallet)
- ✅ Test pause/unpause (owner only)
- ✅ Withdraw funds
- ✅ Update price
- ✅ Cancel listing
- All Sepolia tests passed
- Have
0.01 ETH on Base mainnet ($30-50 for gas) - Double-checked
.env.localhas mainnet keys - Backed up deployer private key securely
# Deploy to Base mainnet
npx hardhat run scripts/deploy.ts --network base
# SAVE THIS ADDRESS! You'll need it for frontend# Replace CONTRACT_ADDRESS with deployed address
npx hardhat verify --network base CONTRACT_ADDRESSUpdate contract address in frontend:
// src/lib/contracts/marketplaceContract.ts
export const MARKETPLACE_ADDRESS = '0xYOUR_DEPLOYED_ADDRESS_HERE'In Vercel dashboard, add these environment variables:
NEXT_PUBLIC_ALCHEMY_API_KEYNEXT_PUBLIC_TATUM_API_KEYNEXT_PUBLIC_WALLET_CONNECT_PROJECT_IDNEXT_PUBLIC_ONCHAINKIT_API_KEYBASESCAN_API_KEYFARCASTER_WEBHOOK_SECRET
PRIVATE_KEY to Vercel!
# If not already deployed
npm i -g vercel
vercel
# If already deployed, redeploy
vercel --prod- Visit deployed site, connect wallet
- Mint a test NFT
- List NFT for sale
- Buy NFT from different wallet
- Test withdrawal
- Verify all transactions on BaseScan
- Test pause function works
- Test unpause function works
- Verify only owner can pause
- Check max price validation (try listing >1M ETH)
- Monitor contract for unexpected activity
- Set up BaseScan watch on contract address
- Enable email alerts for contract transactions
- Monitor error logs in Vercel
- Check wallet balances regularly
Solution: Add more ETH to deployer wallet
Solution: Check .env.local has correct keys without quotes
Solution: Make sure you're using same compiler version (0.8.22)
Solution: Check BaseScan for error message, likely validation issue
Solution: Verify contract address is correct in marketplaceContract.ts
-
PAUSE IMMEDIATELY
// Call pause() function from owner wallet await contract.pause()
-
Investigate Issue
- Check BaseScan for failed transactions
- Review error messages
- Check if exploit or just bug
-
If Funds at Risk
- Keep contract paused
- Contact users via social media
- Consider deploying fixed version
- Immediately rotate all keys
- Revoke old keys from service dashboards
- Update
.env.localand Vercel env vars - Monitor for unauthorized usage
- Contract deployment on Base: ~$30-50
- Domain name (optional): ~$10-15/year
- Professional audit (optional): $15K-$50K
- Alchemy API: FREE (up to 300M compute units)
- WalletConnect: FREE
- BaseScan API: FREE
- Vercel hosting: FREE (hobby plan)
- Total: $0/month 🎉
| Task | Duration |
|---|---|
| Get API keys | 30 min |
| Create .env.local | 5 min |
| Deploy to Sepolia | 10 min |
| Test on Sepolia | 1-2 hours |
| Deploy to mainnet | 15 min |
| Deploy frontend to Vercel | 10 min |
| Post-deployment testing | 30 min |
| TOTAL | 2.5-3.5 hours |
Your marketplace is ready when:
- ✅ Contract deployed and verified on BaseScan
- ✅ All test transactions successful
- ✅ Frontend connected to mainnet contract
- ✅ Pause/unpause tested and working
- ✅ No errors in Vercel logs
- ✅ Wallets can connect via RainbowKit
- ✅ NFTs mint, list, and sell successfully
- ✅ Withdrawals work correctly
- ✅ Royalties distributed properly
- Hardhat: https://hardhat.org/
- OpenZeppelin: https://docs.openzeppelin.com/
- Base Network: https://docs.base.org/
- RainbowKit: https://www.rainbowkit.com/
- Base Discord: https://discord.gg/buildonbase
- Farcaster: https://warpcast.com/~/developers
- Hardhat Discord: https://discord.gg/hardhat
Ready to deploy? Start with Step 1! 🚀