SKIP TO CONTENT

Demo build — mock protocol data. No chain, no ABIs yet.

  • SYNCING: ……

Docs · 01

MECHANISM

THE ONE RULE THAT CANNOT BE BROKEN

The liquid DN404 ERC20 balance never rebases. A global rebase that mutated holder balances would force NFT mint and burn sync across every wallet — impossible gas — invalidate every open OpenSea listing, and desync AMM reserves against the pool's own accounting.

Instead, emission accrues only inside the staking contract, as a per-user index. When a user's accrued amount crosses 1.0 whole token they call materialize() and pay their own gas to mint the new Seat. Lazy, pull-based, and non-negotiable.

THE TOKEN

Sourcesrc/K401.sol408 lines

  • ERC20 plus an ERC721 mirror, DN404 pattern, 18 decimals. 1e18 units = 1 Seat NFT.
  • 5% transfer fee, immutable, applied only on transfers to or from mapped AMM pairs. Wallet-to-wallet is zero. Whitelisted protocol contracts are zero.
  • mapPair() and setWhitelist() are add-only and owner-gated. There is no removal path, so a pair cannot be un-mapped to dodge the fee later.
  • Skip-NFT flag support, so AMM pairs and protocol contracts never mint Seats they cannot use.

SEATS AND THE TWO MODES

Sourcesrc/K401Staking.sol250 lines

A Seat is either ON THE CLOCK or VESTED. Never both. That choice is per Seat, not per wallet, so a single desk can run both strategies at once.

The two Seat modes compared
ON THE CLOCKVESTED
EarnsRebase emissionTokenized equities
Where it goesStaking index, then a new SeatThe Seat's own ERC-6551 account
Seat stateLocked in staking — not burnedFree and transferable
TransferableNo, while lockedYes
Keeps tier + TBAYesYes
Switching cost24h cooldown after clocking outNone to clock in

A locked Seat keeps its tier and its token bound account and still renders on marketplaces with status: ON_THE_CLOCK. It is escrowed, not destroyed.

MATERIALIZE

Sourcesrc/K401Staking.sol250 lines

pending(user) = balance * (index / userIndex) - balance
materialize() -> mints floor(pending) Seats, remainder carries forward

The global index grows each epoch using gons/index accounting. Your pending balance is derived, not stored per-Seat, so a rebase costs the same gas whether ten wallets or ten thousand are staked. Nothing is lost by waiting — the remainder always carries.

TIERS, UPGRADES AND FUSING

Sourcesrc/K401SeatRegistry.sol384 lines

Seat tiers, multipliers and upgrade costs
TierNameMultiplierCost to reach it
1INTERN1.00x
2ANALYST1.42x25,000 401K
3ASSOCIATE1.83x50,000 401K
4VP2.25x100,000 401K
5DIRECTOR2.67x200,000 401K
6MD3.08x400,000 401K
7PARTNER3.50x800,000 401K

Upgrade cost follows 25_000e18 · 2^(tier-1) and the 401K is burned. fuse() burns N Seats into one Seat at tier+1 — a deflation lever that strictly reduces Seat supply.

Tier persists through transfer

Tier is deliberately NOT reset on transfer. Resetting it — as 9to5 does — kills secondary volume, and secondary volume is protocol revenue through the 5% pair fee. Tier is resale value.

ERC-6551 TOKEN BOUND ACCOUNTS

Sourcesrc/K401Seat6551.sol195 lines

  • Every Seat has a token bound account, deployed lazily on the first stock delivery so ordinary transfers stay cheap.
  • Accrued equities live inside the TBA, which means they transfer with the NFT when it is sold. You are buying the account, not just the badge.
  • Withdrawing from a TBA costs 0 protocol fee. Ever. Only your own gas.

THE ORACLE

Sourcesrc/K401Oracle.sol148 lines

A Uniswap V2 style cumulative-price TWAP on the canonical 401K/USDG pair. checkpoint() is permissionless with a 30 minute minimum gap, and the valid read window is 30 minutes to 4 hours.

Fail-closed by design

Outside that window every consumer — Distributor, Bonds, Buyback, Stock Desk — reverts with StaleOracle() rather than acting on a price it cannot trust. A protocol that keeps trading on a stale oracle is a protocol being drained.