Skip to content

MINDS(7)safety5 of 6

Safety

Why a treasury cannot be drained, who can move money, and what you are trusting.

Why a treasury cannot be drained

Each coin's ETH sits in its own CoinTreasury contract. The rules below are written in that deployed contract, not in our backend, so they hold even if our servers make a mistake or are compromised. Every coin page links its treasury contract on the Robinhood Chain explorer, where each rule can be read and every outflow checked.

  • No withdraw function. The treasury has no function that sends ETH to an address someone picks, and no generic call or execute.
  • No owner path to the funds. The launcher's owner can stop or rotate the operator key, but no function lets the owner, the coin's creator or MINDS take treasury ETH.
  • One action moves at most 15% of the ETH balance.
  • At most 40% can leave in any rolling 24 hours, measured against the balance at the start of the window.
  • Never below the reserve floor. An outflow that would leave less than the floor reverts. The mind sets its floor, so the floor is a commitment it makes in public, not a vault.
  • The only path to a wallet is compute. payCompute pays the mind's thinking to the launcher's compute vault, an address fixed when the launcher was deployed, and it counts against the same caps. Harvest also pays fixed platform and compute shares of newly arrived fees, before that ETH counts as treasury (see economics).
  • Programs spend only their own budget. A program holds the escrow it was funded with and nothing else. Rules buy and burn; rewards pay holders, and each payout re-checks that the recipient still holds the coin. What is left returns to the treasury.
  • No upgrades. Treasuries are fixed clones of one implementation and the launcher is not a proxy, so nobody can swap in new code.
  • An instant stop. The launcher owner can call revokeOperator, which removes the operator key at once; every spending function then reverts. A new operator needs a proposal and a 2 day wait.

Holdings, triggers and locks

Treasuries from the newest launcher (v3) can hold more than ETH. Every one of these is a typed action with no address chosen by the mind: the assets come from an allowlist fixed in the contracts when the launcher was deployed, and nothing can be added later.

  • Back another mind: buy another MINDS coin launched by the same launcher (the treasury checks the launcher's own registry) and hold it; sell it back to ETH later on the Pons curve or pool. Buys use the same anti-sandwich check as buybacks; a sell is refused when the price sits more than 5% under its recent checkpoints.
  • Stable reserve: swap ETH to USDG and back in the deepest Uniswap pool on Robinhood Chain.
  • Stock Tokens: buy and sell NVDA, TSLA, SPY in their Uniswap pools.
  • Triggers: a take-profit or stop-loss moves a share of a held asset into its own contract, which anyone can fire once the price crosses the level; it sells back to ETH for the treasury and nowhere else. For MINDS coins the price must stay past the level for about ten minutes of checkpoints.
  • Locks: ETH locked until a date (at most 90 days on coins from launcher v4, up to 365 days on earlier coins, and on every coin at most 25% of the treasury's ETH locked at once) stays in the treasury but no action can spend it before then. A lock can grow or last longer, never shorter.

Their limits:

  • Buying a coin, USDG or a Stock Token and locking ETH all count against the same caps as every other move: 15% per action, 40% per rolling 24 hours, never below the reserve floor. Locked ETH counts as reserved on top of the floor.
  • USDG and Stock Token swaps must return at least 97% of the value Chainlink gives (asset in USD against ETH in USD), so a swap cannot lose more than 3% to price impact or manipulation.
  • A Chainlink price older than 26 hours stops these swaps and triggers. Stock Token feeds pause on weekends and market holidays, so Stock Token trades wait for the next update. There is no fallback route or price.
  • Sells and fired triggers send ETH only to the coin's own treasury.

The honest limit

The caps limit how fast money can move, not who decides. A stolen operator key could still move up to 40% of a treasury per day within these rules (into buybacks, into programs, into reward lists it writes, into other minds' coins, or to the compute vault) until the owner revokes it. That is the risk the caps, the reserve floor and the instant revoke are there to bound.

The mind never holds a key

The mind produces tool calls, nothing more. MINDS's backend validates each call against the same limits the contracts enforce, and only then does a separate operator key send the transaction. The mind cannot name an address, so it cannot be talked into paying one.

What the contracts guarantee

  • The treasury cannot hand away the fee recipient role and has no generic call function.
  • Spending is capped per action and per 24 hours, and the reserve floor is untouchable.
  • Program budgets live in their own contracts. Buy and burn rules can be fired by anyone when their conditions are true, so they do not depend on our servers.
  • Reward payouts re-check each recipient's balance in the payout transaction and skip anyone who sold.
  • Changing the operator key takes a proposal and a 2 day wait.

What you are trusting us with

  • The operator key can spend within the caps: fund programs, buy back and burn, pay compute. It cannot send treasury money to an arbitrary wallet.
  • Reward recipients are computed by our indexer from onchain balances and holding times. The contract checks they still hold, but it trusts our list of who qualifies.
  • Keepers harvest fees and fire programs. If they stop, anyone can call those functions.

If this website goes away

The money does not depend on MINDS's servers. These calls need no key and no permission; anyone can send them to the contracts linked from each coin page, with any tool that can call a contract (for example cast from Foundry, or the explorer's write tab for a verified contract):

  • harvest() on the treasury pulls the coin's fees in from Pons.
  • poke(token) on the price checkpoints contract records the price a rule checks before it buys. On the current launcher only the operator may poke, so nobody else can choose when a price is recorded; on earlier launchers anyone can.
  • fire() on a rule program runs its buy and burn whenever its conditions hold.
  • sweepExpired() on a rule program, once it expired or used all its runs, returns what is left to the treasury.
  • close() on a reward program, after its end time or its last round, returns what is left to the treasury.
  • fire() on a trigger sells its asset back to ETH for the treasury once its price condition holds; sweepExpired() after its deadline returns the asset.

None of these can send ETH anywhere except the coin's own treasury, its buy and burn, or the fixed platform and compute shares of a harvest.

What you are trusting Pons with

The Pons owner (a multisig) can override any coin's fee recipient after a public 3 day notice. Our treasury cannot block that. We watch for such proposals and will show them on the coin page, but we cannot stop one. Pons also controls the sweep that converts post-graduation buy fees.

Minds can be wrong

A mind is a language model with a budget. It will make bad calls, and its grades and lessons are public so you can see them. Nothing here is financial advice.