Docs / Contracts

Contracts

The on-chain design in plain words. Live on BNB Chain mainnet. AI-assisted reviews only, no formal audit.

One vault per position

A factory contract creates one small vault contract for each position. Your USDT goes into that vault and nowhere else. One user's gap loss cannot touch another user's money. Your position id is the vault's address.

Deposits

You deposit USDT only, up to the launch caps: 1,000 USDT per position and 5,000 USDT in total across all users. The owner can change both caps at any time, with no redeploy; positions that already exist are not affected. You approve USDT to the factory, then create the position with an amount, a floor and a term. The app offers floors from 80% to 95% and terms from 30 days to 1 year. The contract accepts floors from 50% to 98% and terms from 7 to 400 days. There is no protocol fee in v1. You pay gas in BNB. The rule the vault follows is on How it works.

Price

The vault reads a 10-minute time-weighted average price (TWAP) from the PancakeSwap v3 pool, on-chain. The keeper supplies no price. Each asset has a trade cap, with QQQB the lowest, so a small pool cannot be pushed around cheaply.

Trading window

The vault trades only Monday to Friday, 15:30 to 19:30 UTC. A guardian sets a holiday table and can halt trading. There is no keeper flag for “market open”. We checked this window against the backtest: see the trading-window check.

Roles

  • Keeper. Calls rebalance, one swap per call, through allowlisted routers. The vault re-validates direction, size, router and minimum out. The keeper cannot withdraw or set prices. An EOA is the primary keeper. A Binance Agentic Wallet is an optional second keeper; it is not set up yet. See Agents.
  • Anyone. After the public delay (3,600 seconds of open-market time at launch, counted from that stock's last trade), anyone can call a public rebalance through the direct Pancake pool. It can be sandwiched within the 1% slippage bound.
  • Guardian. Can pause, halt trading, set holidays, remove a router, disable an asset and approve a new token implementation. It cannot move funds or add a router. A pause or halt stops rebalances and de-risking sells, never exits.
  • Owner (a single wallet; a multisig is not set up). Adds assets, adds routers (active after 24 hours), sets keepers and the guardian, sets defaults for new positions and the launch caps (at any time, with no redeploy; existing positions are unaffected). At launch the owner and the guardian are the same address, so the guardian adds no separation. Cannot touch any existing position or its funds. See Risks.
  • You. Only you can exit your position.

Exits

You can always leave. exitInKind is always allowed and sends you your USDT and any tokens that can still move, with no keeper, no factory and no market hours. It skips a token the issuer has paused. Or you can request a close, and the vault swaps everything to USDT and sends it to you. See Risks for issuer pause and blocklist cases.

Floor supports bStocks only in v1: NVDAB, SPCXB and QQQB, with SPYB optional. Next: Risks.