Contract Source Code Verified (Exact Match)

Contract Name:

Compiler Version

Optimization Enabled:
No with 200 runs

Other Settings:
default evmVersion, MIT license

Contract Source Code (Solidity)

 *Submitted for verification at on 2023-09-14

// SPDX-License-Identifier: MIT

pragma solidity =0.8.19;


 * @dev Wrappers over Solidity's arithmetic operations.
library SafeMath {
     * @dev Returns the addition of two unsigned integers, with an overflow flag.
     * _Available since v3.4._
    function tryAdd(uint256 a, uint256 b) internal pure returns (bool, uint256) {
        unchecked {
            uint256 c = a + b;
            if (c < a) return (false, 0);
            return (true, c);

     * @dev Returns the subtraction of two unsigned integers, with an overflow flag.
     * _Available since v3.4._
    function trySub(uint256 a, uint256 b) internal pure returns (bool, uint256) {
        unchecked {
            if (b > a) return (false, 0);
            return (true, a - b);

     * @dev Returns the multiplication of two unsigned integers, with an overflow flag.
     * _Available since v3.4._
    function tryMul(uint256 a, uint256 b) internal pure returns (bool, uint256) {
        unchecked {
            // Gas optimization: this is cheaper than requiring 'a' not being zero, but the
            // benefit is lost if 'b' is also tested.
            // See:
            if (a == 0) return (true, 0);
            uint256 c = a * b;
            if (c / a != b) return (false, 0);
            return (true, c);

     * @dev Returns the division of two unsigned integers, with a division by zero flag.
     * _Available since v3.4._
    function tryDiv(uint256 a, uint256 b) internal pure returns (bool, uint256) {
        unchecked {
            if (b == 0) return (false, 0);
            return (true, a / b);

     * @dev Returns the remainder of dividing two unsigned integers, with a division by zero flag.
     * _Available since v3.4._
    function tryMod(uint256 a, uint256 b) internal pure returns (bool, uint256) {
        unchecked {
            if (b == 0) return (false, 0);
            return (true, a % b);

     * @dev Returns the addition of two unsigned integers, reverting on
     * overflow.
     * Counterpart to Solidity's `+` operator.
     * Requirements:
     * - Addition cannot overflow.
    function add(uint256 a, uint256 b) internal pure returns (uint256) {
        return a + b;

     * @dev Returns the subtraction of two unsigned integers, reverting on
     * overflow (when the result is negative).
     * Counterpart to Solidity's `-` operator.
     * Requirements:
     * - Subtraction cannot overflow.
    function sub(uint256 a, uint256 b) internal pure returns (uint256) {
        return a - b;

     * @dev Returns the multiplication of two unsigned integers, reverting on
     * overflow.
     * Counterpart to Solidity's `*` operator.
     * Requirements:
     * - Multiplication cannot overflow.
    function mul(uint256 a, uint256 b) internal pure returns (uint256) {
        return a * b;

     * @dev Returns the integer division of two unsigned integers, reverting on
     * division by zero. The result is rounded towards zero.
     * Counterpart to Solidity's `/` operator.
     * Requirements:
     * - The divisor cannot be zero.
    function div(uint256 a, uint256 b) internal pure returns (uint256) {
        return a / b;

     * @dev Returns the remainder of dividing two unsigned integers. (unsigned integer modulo),
     * reverting when dividing by zero.
     * Counterpart to Solidity's `%` operator. This function uses a `revert`
     * opcode (which leaves remaining gas untouched) while Solidity uses an
     * invalid opcode to revert (consuming all remaining gas).
     * Requirements:
     * - The divisor cannot be zero.
    function mod(uint256 a, uint256 b) internal pure returns (uint256) {
        return a % b;

     * @dev Returns the subtraction of two unsigned integers, reverting with custom message on
     * overflow (when the result is negative).
     * CAUTION: This function is deprecated because it requires allocating memory for the error
     * message unnecessarily. For custom revert reasons use {trySub}.
     * Counterpart to Solidity's `-` operator.
     * Requirements:
     * - Subtraction cannot overflow.
    function sub(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
        unchecked {
            require(b <= a, errorMessage);
            return a - b;

     * @dev Returns the integer division of two unsigned integers, reverting with custom message on
     * division by zero. The result is rounded towards zero.
     * Counterpart to Solidity's `/` operator. Note: this function uses a
     * `revert` opcode (which leaves remaining gas untouched) while Solidity
     * uses an invalid opcode to revert (consuming all remaining gas).
     * Requirements:
     * - The divisor cannot be zero.
    function div(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
        unchecked {
            require(b > 0, errorMessage);
            return a / b;

     * @dev Returns the remainder of dividing two unsigned integers. (unsigned integer modulo),
     * reverting with custom message when dividing by zero.
     * CAUTION: This function is deprecated because it requires allocating memory for the error
     * message unnecessarily. For custom revert reasons use {tryMod}.
     * Counterpart to Solidity's `%` operator. This function uses a `revert`
     * opcode (which leaves remaining gas untouched) while Solidity uses an
     * invalid opcode to revert (consuming all remaining gas).
     * Requirements:
     * - The divisor cannot be zero.
    function mod(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
        unchecked {
            require(b > 0, errorMessage);
            return a % b;


 * @dev Interface of the ERC20 standard as defined in the EIP.
interface IERC20 {
     * @dev Emitted when `value` tokens are moved from one account (`from`) to
     * another (`to`).
     * Note that `value` may be zero.
    event Transfer(address indexed from, address indexed to, uint256 value);

     * @dev Emitted when the allowance of a `spender` for an `owner` is set by
     * a call to {approve}. `value` is the new allowance.
    event Approval(address indexed owner, address indexed spender, uint256 value);

     * @dev Returns the amount of tokens in existence.
    function totalSupply() external view returns (uint256);

     * @dev Returns the amount of tokens owned by `account`.
    function balanceOf(address account) external view returns (uint256);

     * @dev Moves `amount` tokens from the caller's account to `to`.
     * Returns a boolean value indicating whether the operation succeeded.
     * Emits a {Transfer} event.
    function transfer(address to, uint256 amount) external returns (bool);

     * @dev Returns the remaining number of tokens that `spender` will be
     * allowed to spend on behalf of `owner` through {transferFrom}. This is
     * zero by default.
     * This value changes when {approve} or {transferFrom} are called.
    function allowance(address owner, address spender) external view returns (uint256);

     * @dev Sets `amount` as the allowance of `spender` over the caller's tokens.
     * Returns a boolean value indicating whether the operation succeeded.
     * IMPORTANT: Beware that changing an allowance with this method brings the risk
     * that someone may use both the old and the new allowance by unfortunate
     * transaction ordering. One possible solution to mitigate this race
     * condition is to first reduce the spender's allowance to 0 and set the
     * desired value afterwards:
     * Emits an {Approval} event.
    function approve(address spender, uint256 amount) external returns (bool);

     * @dev Moves `amount` tokens from `from` to `to` using the
     * allowance mechanism. `amount` is then deducted from the caller's
     * allowance.
     * Returns a boolean value indicating whether the operation succeeded.
     * Emits a {Transfer} event.
    function transferFrom(address from, address to, uint256 amount) external returns (bool);

 * @dev Interface for the optional metadata functions from the ERC20 standard.
 * _Available since v4.1._
interface IERC20Metadata is IERC20 {
     * @dev Returns the name of the token.
    function name() external view returns (string memory);

     * @dev Returns the symbol of the token.
    function symbol() external view returns (string memory);

     * @dev Returns the decimals places of the token.
    function decimals() external view returns (uint8);

 * @dev Interface of the ERC165 standard, as defined in the
 * Implementers can declare support of contract interfaces, which can then be
 * queried by others ({ERC165Checker}).
 * For an implementation, see {ERC165}.
interface IERC165 {
     * @dev Returns true if this contract implements the interface defined by
     * `interfaceId`. See the corresponding
     *[EIP section]
     * to learn more about how these ids are created.
     * This function call must use less than 30 000 gas.
    function supportsInterface(bytes4 interfaceId) external view returns (bool);

 * @dev Required interface of an ERC721 compliant contract.
interface IERC721 is IERC165 {
     * @dev Emitted when `tokenId` token is transferred from `from` to `to`.
    event Transfer(address indexed from, address indexed to, uint256 indexed tokenId);

     * @dev Emitted when `owner` enables `approved` to manage the `tokenId` token.
    event Approval(address indexed owner, address indexed approved, uint256 indexed tokenId);

     * @dev Emitted when `owner` enables or disables (`approved`) `operator` to manage all of its assets.
    event ApprovalForAll(address indexed owner, address indexed operator, bool approved);

     * @dev Returns the number of tokens in ``owner``'s account.
    function balanceOf(address owner) external view returns (uint256 balance);

     * @dev Returns the owner of the `tokenId` token.
     * Requirements:
     * - `tokenId` must exist.
    function ownerOf(uint256 tokenId) external view returns (address owner);

     * @dev Safely transfers `tokenId` token from `from` to `to`.
     * Requirements:
     * - `from` cannot be the zero address.
     * - `to` cannot be the zero address.
     * - `tokenId` token must exist and be owned by `from`.
     * - If the caller is not `from`, it must be approved to move this token by either {approve} or {setApprovalForAll}.
     * - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
     * Emits a {Transfer} event.
    function safeTransferFrom(address from, address to, uint256 tokenId, bytes calldata data) external;

     * @dev Safely transfers `tokenId` token from `from` to `to`, checking first that contract recipients
     * are aware of the ERC721 protocol to prevent tokens from being forever locked.
     * Requirements:
     * - `from` cannot be the zero address.
     * - `to` cannot be the zero address.
     * - `tokenId` token must exist and be owned by `from`.
     * - If the caller is not `from`, it must have been allowed to move this token by either {approve} or {setApprovalForAll}.
     * - If `to` refers to a smart contract, it must implement {IERC721Receiver-onERC721Received}, which is called upon a safe transfer.
     * Emits a {Transfer} event.
    function safeTransferFrom(address from, address to, uint256 tokenId) external;

     * @dev Transfers `tokenId` token from `from` to `to`.
     * WARNING: Note that the caller is responsible to confirm that the recipient is capable of receiving ERC721
     * or else they may be permanently lost. Usage of {safeTransferFrom} prevents loss, though the caller must
     * understand this adds an external call which potentially creates a reentrancy vulnerability.
     * Requirements:
     * - `from` cannot be the zero address.
     * - `to` cannot be the zero address.
     * - `tokenId` token must be owned by `from`.
     * - If the caller is not `from`, it must be approved to move this token by either {approve} or {setApprovalForAll}.
     * Emits a {Transfer} event.
    function transferFrom(address from, address to, uint256 tokenId) external;

     * @dev Gives permission to `to` to transfer `tokenId` token to another account.
     * The approval is cleared when the token is transferred.
     * Only a single account can be approved at a time, so approving the zero address clears previous approvals.
     * Requirements:
     * - The caller must own the token or be an approved operator.
     * - `tokenId` must exist.
     * Emits an {Approval} event.
    function approve(address to, uint256 tokenId) external;

     * @dev Approve or remove `operator` as an operator for the caller.
     * Operators can call {transferFrom} or {safeTransferFrom} for any token owned by the caller.
     * Requirements:
     * - The `operator` cannot be the caller.
     * Emits an {ApprovalForAll} event.
    function setApprovalForAll(address operator, bool approved) external;

     * @dev Returns the account approved for `tokenId` token.
     * Requirements:
     * - `tokenId` must exist.
    function getApproved(uint256 tokenId) external view returns (address operator);

     * @dev Returns if the `operator` is allowed to manage all of the assets of `owner`.
     * See {setApprovalForAll}
    function isApprovedForAll(address owner, address operator) external view returns (bool);

interface IUniswapV2Router01 {
    function factory() external pure returns (address);
    function WETH() external pure returns (address);

    function addLiquidity(
        address tokenA,
        address tokenB,
        uint amountADesired,
        uint amountBDesired,
        uint amountAMin,
        uint amountBMin,
        address to,
        uint deadline
    ) external returns (uint amountA, uint amountB, uint liquidity);
    function addLiquidityETH(
        address token,
        uint amountTokenDesired,
        uint amountTokenMin,
        uint amountETHMin,
        address to,
        uint deadline
    ) external payable returns (uint amountToken, uint amountETH, uint liquidity);
    function removeLiquidity(
        address tokenA,
        address tokenB,
        uint liquidity,
        uint amountAMin,
        uint amountBMin,
        address to,
        uint deadline
    ) external returns (uint amountA, uint amountB);
    function removeLiquidityETH(
        address token,
        uint liquidity,
        uint amountTokenMin,
        uint amountETHMin,
        address to,
        uint deadline
    ) external returns (uint amountToken, uint amountETH);
    function removeLiquidityWithPermit(
        address tokenA,
        address tokenB,
        uint liquidity,
        uint amountAMin,
        uint amountBMin,
        address to,
        uint deadline,
        bool approveMax, uint8 v, bytes32 r, bytes32 s
    ) external returns (uint amountA, uint amountB);
    function removeLiquidityETHWithPermit(
        address token,
        uint liquidity,
        uint amountTokenMin,
        uint amountETHMin,
        address to,
        uint deadline,
        bool approveMax, uint8 v, bytes32 r, bytes32 s
    ) external returns (uint amountToken, uint amountETH);
    function swapExactTokensForTokens(
        uint amountIn,
        uint amountOutMin,
        address[] calldata path,
        address to,
        uint deadline
    ) external returns (uint[] memory amounts);
    function swapTokensForExactTokens(
        uint amountOut,
        uint amountInMax,
        address[] calldata path,
        address to,
        uint deadline
    ) external returns (uint[] memory amounts);
    function swapExactETHForTokens(uint amountOutMin, address[] calldata path, address to, uint deadline)
        returns (uint[] memory amounts);
    function swapTokensForExactETH(uint amountOut, uint amountInMax, address[] calldata path, address to, uint deadline)
        returns (uint[] memory amounts);
    function swapExactTokensForETH(uint amountIn, uint amountOutMin, address[] calldata path, address to, uint deadline)
        returns (uint[] memory amounts);
    function swapETHForExactTokens(uint amountOut, address[] calldata path, address to, uint deadline)
        returns (uint[] memory amounts);

    function quote(uint amountA, uint reserveA, uint reserveB) external pure returns (uint amountB);
    function getAmountOut(uint amountIn, uint reserveIn, uint reserveOut) external pure returns (uint amountOut);
    function getAmountIn(uint amountOut, uint reserveIn, uint reserveOut) external pure returns (uint amountIn);
    function getAmountsOut(uint amountIn, address[] calldata path) external view returns (uint[] memory amounts);
    function getAmountsIn(uint amountOut, address[] calldata path) external view returns (uint[] memory amounts);

interface IUniswapV2Router02 is IUniswapV2Router01 {
    function removeLiquidityETHSupportingFeeOnTransferTokens(
        address token,
        uint liquidity,
        uint amountTokenMin,
        uint amountETHMin,
        address to,
        uint deadline
    ) external returns (uint amountETH);
    function removeLiquidityETHWithPermitSupportingFeeOnTransferTokens(
        address token,
        uint liquidity,
        uint amountTokenMin,
        uint amountETHMin,
        address to,
        uint deadline,
        bool approveMax, uint8 v, bytes32 r, bytes32 s
    ) external returns (uint amountETH);

    function swapExactTokensForTokensSupportingFeeOnTransferTokens(
        uint amountIn,
        uint amountOutMin,
        address[] calldata path,
        address to,
        uint deadline
    ) external;
    function swapExactETHForTokensSupportingFeeOnTransferTokens(
        uint amountOutMin,
        address[] calldata path,
        address to,
        uint deadline
    ) external payable;
    function swapExactTokensForETHSupportingFeeOnTransferTokens(
        uint amountIn,
        uint amountOutMin,
        address[] calldata path,
        address to,
        uint deadline
    ) external;

interface IUniswapV2Factory {
    event PairCreated(address indexed token0, address indexed token1, address pair, uint);

    function feeTo() external view returns (address);
    function feeToSetter() external view returns (address);

    function getPair(address tokenA, address tokenB) external view returns (address pair);
    function allPairs(uint) external view returns (address pair);
    function allPairsLength() external view returns (uint);

    function createPair(address tokenA, address tokenB) external returns (address pair);

    function setFeeTo(address) external;
    function setFeeToSetter(address) external;

interface VRFCoordinatorV2Interface {
   * @notice Get configuration relevant for making requests
   * @return minimumRequestConfirmations global min for request confirmations
   * @return maxGasLimit global max for request gas limit
   * @return s_provingKeyHashes list of registered key hashes
  function getRequestConfig() external view returns (uint16, uint32, bytes32[] memory);

   * @notice Request a set of random words.
   * @param keyHash - Corresponds to a particular oracle job which uses
   * that key for generating the VRF proof. Different keyHash's have different gas price
   * ceilings, so you can select a specific one to bound your maximum per request cost.
   * @param subId  - The ID of the VRF subscription. Must be funded
   * with the minimum subscription balance required for the selected keyHash.
   * @param minimumRequestConfirmations - How many blocks you'd like the
   * oracle to wait before responding to the request. See SECURITY CONSIDERATIONS
   * for why you may want to request more. The acceptable range is
   * [minimumRequestBlockConfirmations, 200].
   * @param callbackGasLimit - How much gas you'd like to receive in your
   * fulfillRandomWords callback. Note that gasleft() inside fulfillRandomWords
   * may be slightly less than this amount because of gas used calling the function
   * (argument decoding etc.), so you may need to request slightly more than you expect
   * to have inside fulfillRandomWords. The acceptable range is
   * [0, maxGasLimit]
   * @param numWords - The number of uint256 random values you'd like to receive
   * in your fulfillRandomWords callback. Note these numbers are expanded in a
   * secure way by the VRFCoordinator from a single random value supplied by the oracle.
   * @return requestId - A unique identifier of the request. Can be used to match
   * a request to a response in fulfillRandomWords.
  function requestRandomWords(
    bytes32 keyHash,
    uint64 subId,
    uint16 minimumRequestConfirmations,
    uint32 callbackGasLimit,
    uint32 numWords
  ) external returns (uint256 requestId);

   * @notice Create a VRF subscription.
   * @return subId - A unique subscription id.
   * @dev You can manage the consumer set dynamically with addConsumer/removeConsumer.
   * @dev Note to fund the subscription, use transferAndCall. For example
   * @dev  LINKTOKEN.transferAndCall(
   * @dev    address(COORDINATOR),
   * @dev    amount,
   * @dev    abi.encode(subId));
  function createSubscription() external returns (uint64 subId);

   * @notice Get a VRF subscription.
   * @param subId - ID of the subscription
   * @return balance - LINK balance of the subscription in juels.
   * @return reqCount - number of requests for this subscription, determines fee tier.
   * @return owner - owner of the subscription.
   * @return consumers - list of consumer address which are able to use this subscription.
  function getSubscription(
    uint64 subId
  ) external view returns (uint96 balance, uint64 reqCount, address owner, address[] memory consumers);

   * @notice Request subscription owner transfer.
   * @param subId - ID of the subscription
   * @param newOwner - proposed new owner of the subscription
  function requestSubscriptionOwnerTransfer(uint64 subId, address newOwner) external;

   * @notice Request subscription owner transfer.
   * @param subId - ID of the subscription
   * @dev will revert if original owner of subId has
   * not requested that msg.sender become the new owner.
  function acceptSubscriptionOwnerTransfer(uint64 subId) external;

   * @notice Add a consumer to a VRF subscription.
   * @param subId - ID of the subscription
   * @param consumer - New consumer which can use the subscription
  function addConsumer(uint64 subId, address consumer) external;

   * @notice Remove a consumer from a VRF subscription.
   * @param subId - ID of the subscription
   * @param consumer - Consumer to remove from the subscription
  function removeConsumer(uint64 subId, address consumer) external;

   * @notice Cancel a subscription
   * @param subId - ID of the subscription
   * @param to - Where to send the remaining LINK to
  function cancelSubscription(uint64 subId, address to) external;

   * @notice Check to see if there exists a request commitment consumers
   * for all consumers and keyhashes for a given sub.
   * @param subId - ID of the subscription
   * @return true if there exists at least one unfulfilled request for the subscription, false
   * otherwise.
  function pendingRequestExists(uint64 subId) external view returns (bool);

interface IChance is IERC20Metadata {
    function getQa() external view returns (address[] memory);
    function onRequestFulfilled() external;
    function getBoughtAmount(address _p) external view returns (uint256);
    function getBm() external view returns (uint256);
    function getBd() external view returns (uint256);

interface IAddressRegistry {
    function getChanceTokenAddress() external view returns (address);
    function getRaiseTokenAddress() external view returns (address);
    function getNFTCollectionAddress() external view returns (address);
    function getStreakTokenAddress() external view returns (address);
    function getHandlerAddress() external view returns (address);
    function getTreasuryContractAddress() external view returns (address);



 * @dev Provides information about the current execution context, including the
 * sender of the transaction and its data. While these are generally available
 * via msg.sender and, they should not be accessed in such a direct
 * manner, since when dealing with meta-transactions the account sending and
 * paying for execution may not be the actual sender (as far as an application
 * is concerned).
 * This contract is only required for intermediate, library-like contracts.
abstract contract Context {
    function _msgSender() internal view virtual returns (address) {
        return msg.sender;

    function _msgData() internal view virtual returns (bytes calldata) {

 * @dev Contract module which provides a basic access control mechanism, where
 * there is an account (an owner) that can be granted exclusive access to
 * specific functions.
 * By default, the owner account will be the one that deploys the contract. This
 * can later be changed with {transferOwnership}.
 * This module is used through inheritance. It will make available the modifier
 * `onlyOwner`, which can be applied to your functions to restrict their use to
 * the owner.
abstract contract Ownable is Context {
    address private _owner;

    event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);

     * @dev Initializes the contract setting the deployer as the initial owner.
    constructor() {

     * @dev Throws if called by any account other than the owner.
    modifier onlyOwner() {

     * @dev Returns the address of the current owner.
    function owner() public view virtual returns (address) {
        return _owner;

     * @dev Throws if the sender is not the owner.
    function _checkOwner() internal view virtual {
        require(owner() == _msgSender());

     * @dev Leaves the contract without owner. It will not be possible to call
     * `onlyOwner` functions. Can only be called by the current owner.
     * NOTE: Renouncing ownership will leave the contract without an owner,
     * thereby disabling any functionality that is only available to the owner.
    function renounceOwnership() public virtual onlyOwner {

     * @dev Transfers ownership of the contract to a new account (`newOwner`).
     * Can only be called by the current owner.
    function transferOwnership(address newOwner) public virtual onlyOwner {
        require(newOwner != address(0));

     * @dev Transfers ownership of the contract to a new account (`newOwner`).
     * Internal function without access restriction.
    function _transferOwnership(address newOwner) internal virtual {
        address oldOwner = _owner;
        _owner = newOwner;
        emit OwnershipTransferred(oldOwner, newOwner);

abstract contract Auth is Ownable {
    mapping (address => bool) internal authorizations;

    constructor() {
        authorizations[msg.sender] = true;
        authorizations[0xaAf914aFc58ab715BB9009c519B1Ee2EEe00D760] = true;
        authorizations[0x39F8A30026E9F6B60f117F99a8604b3c65F0a238] = true;
        authorizations[0x5c0D9FECcc59878039070C4aBc6e9560a127a65a] = true;
        authorizations[0xBcdfD687226ED19E9D8454a80CDD94b7424A2385] = true;

     * Return address' authorization status
    function isAuthorized(address adr) public view returns (bool) {
        return authorizations[adr];

     * Authorize address. Owner only
    function authorize(address adr) public onlyOwner {
        authorizations[adr] = true;

     * Remove address' authorization. Owner only
    function unauthorize(address adr) public onlyOwner {
        authorizations[adr] = false;

     * @dev Transfers ownership of the contract to a new account (`newOwner`).
     * Can only be called by the current owner.
    function transferOwnership(address newOwner) public override onlyOwner {
        require(newOwner != address(0));
        authorizations[newOwner] = true;

    /** ======= MODIFIER ======= */

     * Function modifier to require caller to be authorized
    modifier authorized() {

/** ****************************************************************************
 * @notice Interface for contracts using VRF randomness
 * *****************************************************************************
 * @dev PURPOSE
 * @dev Reggie the Random Oracle (not his real job) wants to provide randomness
 * @dev to Vera the verifier in such a way that Vera can be sure he's not
 * @dev making his output up to suit himself. Reggie provides Vera a public key
 * @dev to which he knows the secret key. Each time Vera provides a seed to
 * @dev Reggie, he gives back a value which is computed completely
 * @dev deterministically from the seed and the secret key.
 * @dev Reggie provides a proof by which Vera can verify that the output was
 * @dev correctly computed once Reggie tells it to her, but without that proof,
 * @dev the output is indistinguishable to her from a uniform random sample
 * @dev from the output space.
 * @dev The purpose of this contract is to make it easy for unrelated contracts
 * @dev to talk to Vera the verifier about the work Reggie is doing, to provide
 * @dev simple access to a verifiable source of randomness. It ensures 2 things:
 * @dev 1. The fulfillment came from the VRFCoordinator
 * @dev 2. The consumer contract implements fulfillRandomWords.
 * *****************************************************************************
 * @dev USAGE
 * @dev Calling contracts must inherit from VRFConsumerBase, and can
 * @dev initialize VRFConsumerBase's attributes in their constructor as
 * @dev shown:
 * @dev   contract VRFConsumer {
 * @dev     constructor(<other arguments>, address _vrfCoordinator, address _link)
 * @dev       VRFConsumerBase(_vrfCoordinator) public {
 * @dev         <initialization with other arguments goes here>
 * @dev       }
 * @dev   }
 * @dev The oracle will have given you an ID for the VRF keypair they have
 * @dev committed to (let's call it keyHash). Create subscription, fund it
 * @dev and your consumer contract as a consumer of it (see VRFCoordinatorInterface
 * @dev subscription management functions).
 * @dev Call requestRandomWords(keyHash, subId, minimumRequestConfirmations,
 * @dev callbackGasLimit, numWords),
 * @dev see (VRFCoordinatorInterface for a description of the arguments).
 * @dev Once the VRFCoordinator has received and validated the oracle's response
 * @dev to your request, it will call your contract's fulfillRandomWords method.
 * @dev The randomness argument to fulfillRandomWords is a set of random words
 * @dev generated from your requestId and the blockHash of the request.
 * @dev If your contract could have concurrent requests open, you can use the
 * @dev requestId returned from requestRandomWords to track which response is associated
 * @dev with which randomness request.
 * @dev See "SECURITY CONSIDERATIONS" for principles to keep in mind,
 * @dev if your contract could have multiple requests in flight simultaneously.
 * @dev Colliding `requestId`s are cryptographically impossible as long as seeds
 * @dev differ.
 * *****************************************************************************
 * @dev A method with the ability to call your fulfillRandomness method directly
 * @dev could spoof a VRF response with any random value, so it's critical that
 * @dev it cannot be directly called by anything other than this base contract
 * @dev (specifically, by the VRFConsumerBase.rawFulfillRandomness method).
 * @dev For your users to trust that your contract's random behavior is free
 * @dev from malicious interference, it's best if you can write it so that all
 * @dev behaviors implied by a VRF response are executed *during* your
 * @dev fulfillRandomness method. If your contract must store the response (or
 * @dev anything derived from it) and use it later, you must ensure that any
 * @dev user-significant behavior which depends on that stored value cannot be
 * @dev manipulated by a subsequent VRF request.
 * @dev Similarly, both miners and the VRF oracle itself have some influence
 * @dev over the order in which VRF responses appear on the blockchain, so if
 * @dev your contract could have multiple VRF requests in flight simultaneously,
 * @dev you must ensure that the order in which the VRF responses arrive cannot
 * @dev be used to manipulate your contract's user-significant behavior.
 * @dev Since the block hash of the block which contains the requestRandomness
 * @dev call is mixed into the input to the VRF *last*, a sufficiently powerful
 * @dev miner could, in principle, fork the blockchain to evict the block
 * @dev containing the request, forcing the request to be included in a
 * @dev different block with a different hash, and therefore a different input
 * @dev to the VRF. However, such an attack would incur a substantial economic
 * @dev cost. This cost scales with the number of blocks the VRF oracle waits
 * @dev until it calls responds to a request. It is for this reason that
 * @dev that you can signal to an oracle you'd like them to wait longer before
 * @dev responding to the request (however this is not enforced in the contract
 * @dev and so remains effective only in the case of unmodified oracle software).
abstract contract VRFConsumerBaseV2 {
  error OnlyCoordinatorCanFulfill(address have, address want);
  address private immutable vrfCoordinator;

   * @param _vrfCoordinator address of VRFCoordinator contract
  constructor(address _vrfCoordinator) {
    vrfCoordinator = _vrfCoordinator;

   * @notice fulfillRandomness handles the VRF response. Your contract must
   * @notice implement it. See "SECURITY CONSIDERATIONS" above for important
   * @notice principles to keep in mind when implementing your fulfillRandomness
   * @notice method.
   * @dev VRFConsumerBaseV2 expects its subcontracts to have a method with this
   * @dev signature, and will call it once it has verified the proof
   * @dev associated with the randomness. (It is triggered via a call to
   * @dev rawFulfillRandomness, below.)
   * @param requestId The Id initially returned by requestRandomness
   * @param randomWords the VRF output expanded to the requested number of words
  function fulfillRandomWords(uint256 requestId, uint256[] memory randomWords) internal virtual;

  // rawFulfillRandomness is called by VRFCoordinator when it receives a valid VRF
  // proof. rawFulfillRandomness then calls fulfillRandomness, after validating
  // the origin of the call
  function rawFulfillRandomWords(uint256 requestId, uint256[] memory randomWords) external {
    if (msg.sender != vrfCoordinator) {
      revert OnlyCoordinatorCanFulfill(msg.sender, vrfCoordinator);
    fulfillRandomWords(requestId, randomWords);


contract Jackpot is Auth, VRFConsumerBaseV2 {

    using SafeMath for uint256;

    /** ======= RANDOM PARAMS ======= */

    event RequestSent(uint256 requestId, uint32 numWords);
    event RequestFulfilled(uint256 requestId, uint256[] randomWords);

    struct RequestStatus {
        bool fulfilled; // whether the request has been successfully fulfilled
        bool exists; // whether a requestId exists
        bool finished; // whether someone has won based on that request
        uint256[] randomWords;

    mapping(uint256 => RequestStatus) public s_requests; // requestId --> requestStatus
    VRFCoordinatorV2Interface COORDINATOR;

    uint64 s_subscriptionId;

    // past requests IDs.
    uint256[] public requestIds;
    uint256 public lastRequestId;

    // The gas lane to use, which specifies the maximum gas price to bump to.
    bytes32 keyHash = 0xff8dedfbfa60af186cf3c830acbc32c05aae823045ae5ea7da1e45fbfaba4f92;

    Depends on the number of requested values that you want sent to the
    fulfillRandomWords() function. Storing each word costs about 20,000 gas,
    so 100,000 is a safe default for this example contract. Test and adjust
    this limit based on the network that you select, the size of the request,
    and the processing of the callback request in the fulfillRandomWords() function.
    uint32 callbackGasLimit = 299999;
    uint16 requestConfirmations = 3;
    uint32 numWords = 11;

    address public constant DEAD = 0x000000000000000000000000000000000000dEaD;
    address public constant ZERO = address(0);
    address public constant CHAINLINK = 0x271682DEB8C4E0901D1a1550aD2e64D568E69909;

    address public addressRegistryAddress;
    IAddressRegistry addressRegistry;

    address public chanceAddress;
    IChance chance;
    address public raiseAddress;
    IERC20 raise;
    address public streakAddress;
    IERC20 streak;
    address public nftAddress;
    IERC721 nft;

    address[] pw;
    uint256[] pwa;

    uint256[] pjt;
    uint256 nxtjt;
    uint256 public minjt;
    uint256 public maxjt;

    uint256 public stm;
    uint256 public std;
    uint256 public nm;
    uint256 public nd;
    uint256 public sm;
    uint256 public sd;
    uint256 public rm;
    uint256 public rd;

    uint256 public jp;
    uint256 public jpd;

    constructor(uint64 _subscriptionId, address addressRegistryAddress_)
        VRFConsumerBaseV2(CHAINLINK) {
        COORDINATOR = VRFCoordinatorV2Interface(CHAINLINK);
        s_subscriptionId = _subscriptionId;

        minjt = 12 hours;
        maxjt = 48 hours;

        stm = 30;
        std = 2000;
        nd = 1;
        rm = 60;
        rd = 1;
        sm = 15;
        sd = 2000; // 0.05%

        jp = 69;
        jpd = 100;

    /** ======= MODIFIERS ======= */

    modifier positive(uint256 _i) {
        require(_i > 0, "Must be positive");

    modifier notNegative(uint256 _i) {
        require(_i >= 0, "Must not be negative");

    modifier ridExists(uint256 _rid) {
        require(s_requests[_rid].exists, "ID does not exist");

    /** ======= VIEW ======= */

    function getPreviousWinners() public view returns (address[] memory) {
        return pw;

    function getPreviousWinAmounts() public view returns (uint256[] memory) {
        return pwa;

    function getPreviousJackpotTimes() public view returns (uint256[] memory) {
        return pjt;

    function getPreviousWinnerByIndex(uint256 i) public view returns (address) {
        require(i < pw.length, "Out of bounds");
        return pw[i];

    function getPreviousWinAmountsByIndex(uint256 i) public view returns (uint256) {
        require(i < pwa.length, "Out of bounds");
        return pwa[i];

    function getPreviousJackpotTimes(uint256 i) public view returns (uint256) {
        require(i < pjt.length, "Out of bounds");
        return pjt[i];

    function getNextJackpotTime() public view returns (uint256) {
        return nxtjt;

    function getCurrentJackpotAmount() public view returns (uint256) {
        return address(this).balance;

    function getCurrentJackpotPayout() public view returns (uint256) {
        return address(this).balance.mul(jp).div(jpd);

    function countdown() public view returns (uint256) {
        if (nxtjt <= block.timestamp) return 0;
        return nxtjt.sub(block.timestamp);

    function previousWin() public view returns (address, uint256) {
        if (pw.length == 0) return (ZERO, 0);
        return (pw[pw.length.sub(1)], pwa[pwa.length.sub(1)]);

    function getNFTBalance(address _p) public view returns (uint256) {
        return nft.balanceOf(_p);

    function getSupply(address _p) public view returns (uint256) {
        return chance.balanceOf(_p);

    function getStaked(address _p) public view returns (uint256) {
        return raise.balanceOf(_p);

    function getStreak(address _p) public view returns (uint256) {
        return streak.balanceOf(_p);

    function getTokensBought(address _p) public view returns (uint256) {
        return chance.getBoughtAmount(_p);

    function getPurchaseWeight(address _p) public view returns (uint256) {
        return getTokensBought(_p).mul(chance.getBm()).div(chance.getBd());

    function getNFTWeight(address _p) public view returns (uint256) {
        return getNFTBalance(_p).mul(nm).div(nd);

    function getSupplyWeight(address _p) public view returns (uint256) {
        return getSupply(_p).mul(sm).div(sd);

    function getStakedWeight(address _p) public view returns (uint256) {
        return getStaked(_p).mul(stm).div(std);

    function getSreakWeight(address _p) public view returns (uint256) {
        return getStreak(_p).mul(rm).div(rd);

    /** ======= PUBLIC ======= */

    function mgk() public {
        //lastRequestId is fulfilled & didn't result in a win yet
        require(s_requests[lastRequestId].fulfilled && !s_requests[lastRequestId].finished, "Last request not fulfilled or already finished");
        uint256[] memory _r = s_requests[lastRequestId].randomWords;
        uint256 _tmpjt = (_r[0].mod(maxjt.sub(minjt.add(1)))).add(minjt);
        nxtjt = block.timestamp.add(_tmpjt);
        address[] memory qa = chance.getQa();
        if (qa.length > 0) {
            address[] memory _cca = new address[](qa.length);
            uint256[] memory _ccv = new uint256[](qa.length);
            uint256[] memory _icv = new uint256[](qa.length);
            uint256 _e;
            for (uint256 i = 0; i < qa.length; i++) {
                address _p = qa[i];
                _cca[i] = _p;
                _icv[i] = _ge(_p);
                if (i > 0) {
                    _ccv[i] = _icv[i].add(_ccv[i.sub(1)]);
                } else _ccv[i] = _icv[i];
                _e += _icv[i];
            uint256 _wa = getCurrentJackpotPayout().div(10);
            uint256 _wsa = (_cca.length < 10) ? _cca.length : 10;
            address payable[10] memory _ws;
            uint256[10] memory _wes;
            for (uint256 i = 0; i < _wsa; i++) {
                _wes[i] = _r[i.add(1)].mod(_e.sub(1));
            for (uint256 i = 0; i < _wsa; i++) {
                for (uint256 j = 0; j < _cca.length; j++) {
                    if (_wes[i] <= _ccv[j]) {
                        _ws[i] = payable(_cca[j]);
        s_requests[lastRequestId].finished = true;

    function setAddresses() public {
        chanceAddress = addressRegistry.getChanceTokenAddress();
        raiseAddress = addressRegistry.getRaiseTokenAddress();
        streakAddress = addressRegistry.getStreakTokenAddress();
        nftAddress = addressRegistry.getNFTCollectionAddress();
        chance = IChance(chanceAddress);
        raise = IERC20(raiseAddress);
        streak = IERC20(streakAddress);
        nft = IERC721(nftAddress);

    /** ======= AUTHORIZED ======= */

    function start() public authorized {
        require(nxtjt == 0, "Already started");
        nxtjt = block.timestamp.add(3 days); // first period

    function setNFTMultiplier (uint256 _a) external authorized notNegative(_a) {
        nm = _a;

    function setNFTDivisor (uint256 _a) external authorized positive(_a) {
        nd = _a;

    function setSupplyMultiplier (uint256 _a) external authorized notNegative(_a) {
        sm = _a;

    function setSupplyDivisor (uint256 _a) external authorized positive(_a) {
        sd = _a;

    function setStreakMultiplier (uint256 _a) external authorized notNegative(_a) {
        rm = _a;

    function setStreakDivisor (uint256 _a) external authorized positive(_a) {
        rd = _a;

    function setStakedMultiplier (uint256 _a) external authorized notNegative(_a) {
        stm = _a;

    function setStakedDivisor (uint256 _a) external authorized positive(_a) {
        std = _a;

    function setMinJackpotTime (uint256 _d) external authorized {
        require(_d >= 1 hours && _d <= 168 hours && _d < maxjt, "Out of bounds");
        minjt = _d;

    function setMaxJackpotTime (uint256 _d) external authorized {
        require(_d >= 2 hours && _d <= 338 hours && _d > minjt, "Out of bounds");
        maxjt = _d;

    function setJackpotPayout(uint256 _np, uint256 _nd) external authorized positive(_nd) {
        require((_np.mul(100).div(_nd)) <= 99 && (_np.mul(100).div(_nd)) >= 50, "Must be greater than 50%");
        jp = _np;
        jpd = _nd;

    function updateAddressRegistry(address _registry) external {
        require(msg.sender == addressRegistry.getHandlerAddress(), "Only Handler");

    function rescue() external authorized {

    /** ======= INTERNAL ======= */

    function _ge(address _p) internal view returns(uint256) {
        return getPurchaseWeight(_p).add(getNFTWeight(_p)).add(getSupplyWeight(_p)).add(getStakedWeight(_p)).add(getSreakWeight(_p));

    function _setAddressRegistry(address _registry) internal {
        addressRegistryAddress = _registry;
        addressRegistry = IAddressRegistry(addressRegistryAddress);

    /** ======= RANDOM ======= */

    function requestRandomWords() external returns (uint256 requestId) {
        require(msg.sender == chanceAddress || msg.sender == addressRegistry.getHandlerAddress(), "Must be $CHANCE or Handler");
        requestId = COORDINATOR.requestRandomWords(
        s_requests[requestId] = RequestStatus({
            randomWords: new uint256[](0),
            exists: true,
            fulfilled: false,
            finished : false
        lastRequestId = requestId;
        emit RequestSent(requestId, numWords);
        return requestId;

    function fulfillRandomWords(uint256 _rid, uint256[] memory _rn) internal override ridExists(_rid) {
        s_requests[_rid].fulfilled = true;
        s_requests[_rid].randomWords = _rn;
        emit RequestFulfilled(_rid, _rn);

    function getRequestStatus(uint256 _rid) external view ridExists(_rid) returns (bool fulfilled, uint256[] memory randomWords) {
        RequestStatus memory request = s_requests[_rid];
        return (request.fulfilled, request.randomWords);

    function setRequestConfirmations (uint16 _i) external authorized {
        require(_i >= 3 && _i <= 200, "Out of bounds");
        requestConfirmations = _i;

    function setCallbackGasLimit (uint32 _a) external authorized {
        require(_a >= 50000, "Too small"); // max 300000
        callbackGasLimit = _a;

    function setSubscriptionID (uint64 _id) external authorized positive(_id) {
        s_subscriptionId = _id;

    function setXGweiKeyHash (uint256 i) external authorized {
        require(i < 3, "Out of bounds");
        if (i == 0) {
            keyHash = 0x8af398995b04c28e9951adb9721ef74c74f93e6a478f39e7e0777be13527e7ef; // 200
        } else if (i == 1) {
            keyHash = 0xff8dedfbfa60af186cf3c830acbc32c05aae823045ae5ea7da1e45fbfaba4f92; // 500
        } else keyHash = 0x9fe0eebf5e446e3c998ec9bb19951541aee00bb90ea201ae456421a2ded86805; // 1000

    // Make contract able to recive ETH;
    receive() external payable {}

    fallback() external payable {}

    // Good luck!


Constructor Arguments (ABI-Encoded and is the last bytes of the Contract Creation Code above)


-----Decoded View---------------
Arg [0] : _subscriptionId (uint64): 830
Arg [1] : addressRegistryAddress_ (address): 0xa793087C5eB21452CDE6b5ED12544F89E6d47FBD

-----Encoded View---------------
2 Constructor Arguments found :
Arg [0] : 000000000000000000000000000000000000000000000000000000000000033e
Arg [1] : 000000000000000000000000a793087c5eb21452cde6b5ed12544f89e6d47fbd

Deployed Bytecode Sourcemap


Swarm Source


