EVAL Engine

PlushFun: blind-box checkout, fair draws and talking plushies

PlushFun is our consumer hardware project: AI plush toys sold as blind boxes through plush.fun. This post covers the code behind it.

The storefront

plushfun is a Next.js app with a Postgres backend. A buyer picks a tier, pays, and receives a random draw of items from a collection. Tiers, prices, unit caps and eligibility rules (public, VIP, or promo code) live in a tier_inventory table rather than in code. The most recent infrastructure change moved the database from Supabase to Neon.

Checkout supports several methods side by side: card through Stripe, a fiat on-ramp through Transak, Crossmint, an x402 route per tier, and, since August 2026, Chromia Pay for paying in CHR. Referrals, promo codes, a sellback flow and shipping records complete the order lifecycle.

Making the CHR checkout safe to retry

Chromia Pay is the first method where the order is created server-side from a signed webhook instead of by the browser after payment. That removes a failure mode where a customer pays, closes the tab, and no order is created.

Webhooks retry, so the handler is idempotent. It claims the gateway's payment id in a table keyed on that id before doing any work. A unique index on the order's payment reference blocks a second order regardless. A failed attempt releases its claim so a transient error cannot lock a paying customer out. Prices, including promo discounts, are computed on the server and sent to the gateway in USD, and the gateway locks the CHR rate for the life of the payment.

Verifiable draws

Each draw uses a server seed whose SHA-256 hash is recorded before items are picked. Items are chosen with rarity weights (common through legendary, plus a 1% secret slot) from a deterministic function of the seed, with stock checked per item. An /api/orders/[orderId]/proof endpoint returns the seed, its hash and the drawn items so a buyer can reproduce the result. Anchoring the proof on Chromia is reserved in the response shape and marked as coming soon.

On-chain receipts

PlushFunNFT is an ERC-1155 contract with per-token supply caps, an allowlist of authorized minters, optional USDC collection on mint, and ownership renounce disabled. The repo includes Hardhat deploy scripts for Base and Base Sepolia.

The plush itself

The storefront has a Web Bluetooth page that provisions Wi-Fi on a plush over a small framed protocol with a header byte and checksum. plushfun-app is an Expo prototype of the same flow. plushfun-persona holds per-character audio: a Python script that renders system prompts such as "Wi-Fi connected" through a TTS API in each persona's voice, and a Bun CLI that converts video to 320x160 AVI and audio to 8 kHz MP3 for the device.

fluff-protocol is the beginning of a Go rewrite of the XiaoZhi server for PlushFun: Opus over WebSocket, ASR to LLM to TTS, with providers behind interfaces. So far it has the package layout, CI, and tested protocol message types.