Stealth Buy on Uniswap v4
Buy any token on a Uniswap v4 pool straight into an ERC-5564 stealth address, with gas included and an announcement the receiver's wallet can find.
Stealth Buy is a small router for Uniswap v4. It swaps ETH for a token and delivers the token to a one-time stealth address instead of the buyer's wallet. It is the first piece of The Hook: the privacy layer for Uniswap v4.
What one call does
- Swaps ETH for the token on the pool you name (exact input). The pool's own hook and fees apply as they would for anyone.
- The PoolManager pays the tokens directly to the stealth address.
- Sends up to 0.01 ETH along to the same address, so the receiver can move the tokens later without funding that address from a known wallet.
- Announces the payment through the canonical ERC-5564 Announcer with the standard token metadata: view tag,
0xa9059cbb, token, amount (57 bytes). Any ERC-5564 wallet that scans, the ephemeral client included, finds it. - Refunds the ETH the pool did not use, and reverts if fewer tokens than your minimum arrive.
Interface
struct Stealth {
address stealthAddress; // generated from the receiver's stealth meta-address
bytes ephemeralPubKey; // 33-byte compressed key used to generate it
bytes1 viewTag; // lets the receiver skip 255 of 256 announcements
uint256 minOut; // slippage guard
uint256 gasTip; // ETH sent along for gas, at most 0.01 ETH
}
function buy(PoolKey calldata key, Stealth calldata s, bytes calldata hookData)
external payable returns (uint256 tokensOut);msg.value is the ETH to swap plus gasTip. The pool's currency0 must be native ETH.
What it hides and what it does not
| Hidden | Who receives the tokens. The stealth address cannot be linked to the receiver's meta-address or ENS name. |
| Hidden | That the receiver ever funded that address: the gas is already there. |
| Not hidden | Who bought. The buyer's address is the sender of the transaction. Buying for yourself from a known wallet links you to the stealth address. |
| Not hidden | The amount and the token. They are in the swap and the announcement. |
So Stealth Buy protects the receiver: paying someone in a token, gifts, payouts. For yourself it helps only when the ETH comes from a private source.
Design
- Stateless: no owner, no settings, holds no funds between calls.
- ETH accounting uses
msg.valueonly, never the contract's balance. - Works on any v4 pool with native ETH, with or without a hook.
- Tested against a pool with a fee-taking hook and a plain pool; an end-to-end test on a local chain buys into a stealth address, finds it with the ephemeral client scan, and withdraws the token and the leftover ETH to a fresh address.
Status
Built and tested. It goes to mainnet after an add-on security review; its address will be listed on Networks.