
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@indexcoop/flash-mint-sdk
Advanced tools
The Flash Mint SDK provides easy to use functions to integrate flash minting for Index's products.
To find out more about the contracts, go to Index's smart contracts repo.
This SDK currently supports the contracts listed here.
$ npm install @indexcoop/flash-mint-sdk
A limitation to be aware of (especially for getting quotes) is that the contracts can only mint or redeem an exact amount of Index token.
Additionally, make sure that the (Index/Set) tokens have been approved on the specific FlashMint contracts.
With v3, while you could still use other quote providers individually, we recommend
solely using the FlashMintQuoteProvider
which will do most of the guess work for you.
This provider will return the appropriate quotes for any Index token, automatically
selecting the correct FlashMint contract for you - as well as preparing the call data.
import { FlashMintQuoteProvider, QuoteToken } from '@indexcoop/flash-mint-sdk'
// Input/output token should be of type QuoteToken with the following properties
const inputToken: QuoteToken = {
symbol: 'ETH',
decimals: 18,
address: '0xEeeeeEeeeEeEeeEeEeEeeEEEeeeeEeeeeeeeEEeE',
}
const outputToken: QuoteToken = {
symbol: 'icETH',
decimals: 18,
address: '0xc4506022Fb8090774E8A628d5084EED61D9B99Ee',
}
// Add a RPC URL e.g. from Alchemy
const rpcUrl = ''
// Use the 0x v2 swap quote provider configured with your API key or provide your
// own adapter implementing the `SwapQuoteProviderV2` interface.
const zeroexV2SwapQuoteProvider = new ZeroExV2SwapQuoteProvider()
// As 0x v2 does not allow swap quotes by defining outputAmounts any longer we're
// now added a second swap quote provider for that - Li.Fi (provide API key).
const lifiSwapQuoteProvider = new LiFiSwapQuoteProvider(apiKey, integrator)
const quoteProvider = new FlashMintQuoteProvider(
rpcUrl,
zeroexV2SwapQuoteProvider,
lifiSwapQuoteProvider
)
// Option 1 - get a quote for a specified index token amount
const quote = await quoteProvider.getQuote({
chainId: 1,
isMinting: true,
inputToken,
outputToken,
indexTokenAmount: wei(1).toString(),
inputTokenAmount: wei(1).toString(),
slippage: 0.1,
})
// Option 2 - get a quote for a fixed input amount (am approx. indexTokenAmount
// should still be added to the request).
await quoteProvider.getFixedInputQuote({
chainId: 1,
isMinting: true,
inputToken,
outputToken,
indexTokenAmount: wei(1).toString(),
inputTokenAmount: wei(1).toString(),
slippage: 0.1,
})
The returned quote is an object including meta data but most importantly the inputOutputAmount
which is the quote for the given request* and a tx
object which is a tx object
basically ready to be send.
interface FlashMintQuote {
chainId: number
contractType: FlashMintContractType
contract: string
isMinting: boolean
inputToken: QuoteToken
outputToken: QuoteToken
inputAmount: BigNumber
outputAmount: BigNumber
indexTokenAmount: BigNumber
inputOutputAmount: BigNumber
slippage: number
tx: TransactionRequest
}
* for minting this will be the input amount, for redeeming the output amount
To execute the flash minting of an Index token for convenience use the tx
object
returned by the FlashMintQuoteProvider
.
...
const quoteProvider = new FlashMintQuoteProvider(
rpcUrl,
zeroexV2SwapQuoteProvider,
lifiSwapQuoteProvider
)
const quote = await quoteProvider.getQuote({...})
let tx = quote.tx
const gasEstimate = await provider.estimateGas(tx)
tx.gasLimit = gasEstimate
const res = await signer.sendTransaction(tx)
console.log(res.hash)
When adding new .env vars do not forget to update the publish.yml
function getContractType(token: string)
in src/quote/provider/utils.ts and add a test// run all tests
npm run test:hardhat src/tests/e2e/index.test.ts
// run tests for a specific chain
npm run test:hardhat src/tests/e2e/index.test.ts -- --grep "chain 1"
// run tests for a specific product exiting on first failure
npm run test:hardhat src/tests/e2e/index.test.ts -- --bail --grep "hyETH"
cast run --rpc-url http://127.0.0.1:8545/ 0x8ea51dd6cec3e1bea98b143715fe9a1375ca7e01c120f0065cb4ef6c0e0dd23a // mainnet
cast run --rpc-url http://127.0.0.1:8453/ 0x362c844b7a1ecd5feb14e389eccd68d34373281892e5a6d387131ed9bfef9b01 // base
cast run --rpc-url http://127.0.0.1:8548/ 0x5434cd90c4b06faed9d77d256e5d569b94c1ef88217d25e82bc6cf1b84153b69 // arbitrum
We will encourage contributing and open dialog how to improve the SDK. How though is still TBD. 🚧 In the meantime just open an issue.
Copyright © 2025 Index Coop.
FAQs
The FlashMintSDK of the Index Coop.
The npm package @indexcoop/flash-mint-sdk receives a total of 144 weekly downloads. As such, @indexcoop/flash-mint-sdk popularity was classified as not popular.
We found that @indexcoop/flash-mint-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.