ENSv2 · checked inside every payment
The payment contract looks it up itself. If the name doesn’t point to this invoice’s vault, no money moves.
ENS, read live on Sepolia
resolving…
Pick a forgery and press Pay. Both go through the router's real check on Sepolia.
Real
Invoice #1048 · Acme Demo
$1,000.00
Pay to
Open invoice, signed by Acme's wallet.
Invoice #1042 · Acme Demo
$1,000.00
Pay to
The real forged order: claims acme-demo.eth, signed by 0xFdac…A39E.
Our server holds a key that can only file invoices. Try to misuse it.
Pick what the thief does.
Three things v1 can't do with stock contracts.
Scope a key to one branch
setApprovalForAll covers every name you own, root included. NameWrapper fuses only take rights away.
Cover invoices not issued yet
PublicResolver.approve works per name, one transaction each, and only after the name exists.
Resolve inside a payment
Wildcard resolvers may answer off-chain (OffchainLookup). A contract can't follow that.
v1 could approximate this only with a custom registrar contract. ENSv2 does it with stock contracts.
Every invoice below is an ENSv2 name on Sepolia. Click one to see its records.
Names on the current contracts, resolved from your browser through UniversalResolverV2.
The ENS app only shows standard records, so the two pdfiplus.* texts appear here, not there.
A third of every payment’s gas is the ENS check.
Remove ENSv2 and fake invoices get paid
Nothing to check the payee against.
…there is no safe hot key
Publishing would need the merchant's own key.
…there is no kill switch
Nothing to revoke when a key leaks.
Not cosmetic: each invoice costs two ENS writes to issue (register, then addr + two text records). A payment can’t settle without the address records matching, and the text records let anyone check the order and PDF are the ones issued.