Overview
Depositors wrap one to eight governance-approved canonical Binance bStocks in a dedicated account and escrow a BNB reserve. A draw allocates one active folio using inverse-reserve weight. The winner selects exactly one settlement outcome.
The compatibility register follows StockRip's current NVDA, TSLA, GME, AMZN, AAPL, PLTR, SPCX, and CASHCAT selector. Salt currently enables only the verified BSC mappings NVDAB, TSLAB, AMZNB, AAPLB, PLTRB, and SPCXB. GME has no verified GMEB mapping; CASHCAT is not a bStock.
Issuer metadata, market prices, halts, multipliers, and corporate actions help users understand a manifest. They never influence Salt draw pricing or selection.
Folio custody and onchain certificate
Each NFT controls a dedicated ERC-6551-compatible account. The manifest records balance deltas actually received, not requested amounts. New folios accept only canonical, active registry assets; redemption and recovery remain available after a halt, delisting, rebase, or corporate action.
The token URI, metadata, and SVG are generated completely onchain. The certificate prints every manifest symbol, exact raw token-unit balance, and full token contract address. Its deterministic treatment is Standard, Registered, Proof, Signed, or Archive, using 50% / 30% / 15% / 4% / 1% hash buckets. These print classes are decorative—not draw odds, value, or a promise of financial rarity.
The developer may correct the renderer before launch. Calling freezeRenderer() permanently fixes the verified renderer address for every current and future folio; this is an explicit deployment checklist item.
Inverse-reserve draws
For reserve rᵢ, weight is ⌊10³⁶ / rᵢ⌋. Unit base price is Σ(rᵢwᵢ) / Σwᵢ, the weighted harmonic reserve. Salt then adds the 5.5% surcharge and per-request randomness fee.
A Fenwick prefix tree provides logarithmic updates and selection. Pending requests freeze the active set; later deposits are staged. Price refunds apply when configured negative drift is breached or inventory empties, while the coordinator service fee remains non-refundable.
Hash-chain randomness
The keeper publishes a permanent reverse hash-chain commitment. Requests are FIFO. A valid preimage is mixed with the hash of the second future BSC block and the request number, then mapped into the recorded active weight root.
After 30 BSC blocks, anyone may skip a stalled head request. The keeper bond is slashed and the request is refunded. There is no alternate VRF provider switch.
Exclusive settlement
The winner may redeem the bStocks, keep the folio NFT, accept the standing BNB offer, route that offer into SALT, or escrow a fresh reserve and relist. State makes these outcomes mutually exclusive. After seven days, anyone may finalize redemption to the winner.
Flap launch and revenue rewards
Flap creates the canonical one-billion-supply SALT token, runs its bonding curve, and migrates it to PancakeSwap at 80% progress. Current Flap rules require every tax token—even TOKEN_TAXED_V3—to use V2_MIGRATOR.
The immutable Salt vault receives 100% of the allocated 3% buy and sell tax. Once the first public draw starts the program, anyone may process bounded BNB revenue through Flap. Actual SALT received is split 40% to time-weighted depositors by square-root reserve, 40% to settled purchasers, 10% to the irreversible burn address, and 10% to the immutable developer-wallet treasury. Rewards are purchased, never minted, and no APY is promised.
After migration, permissionless observation updates maintain a minimum 30-minute Pancake V2 cumulative-price TWAP. Processing stops safely when no fresh average exists.
Developer administration and pause safety
One configured developer wallet owns Salt’s administrative contracts and initially holds the pause role. It may pause only new deposits, repricing, draws, and token buys. It cannot block exits, credits, refunds, settlement, redemption, claims, stalled-request skipping, or slashing.
This single-admin model has immediate key-compromise and key-loss risk because it has no multisig approval or timelock delay. Salt’s revenue vault remains ownerless, non-upgradeable, and without arbitrary withdrawal or mutable recipients. Mainnet writes remain disabled until audits, testnet soak, issuer approval, legal review, and explicit dev-admin approval. See the risk notice.
Bounded parameters
| Network | BSC 56 / testnet 97 |
| Weight | ⌊10³⁶ / reserveWei⌋ |
| Minimum reserve | 0.10 BNB |
| Surcharge | 5.50% |
| Standing offer | 95% |
| Protocol acquisition cut | 1% |
| Protocol settlement cut | 1% |
| Master Seal tithe | 1% |
| Takeover threshold | 110% |
| Maximum batch | 25 |
| Default negative drift | 40% |
| Exclusive settlement | 24 hours |
| Public finalization | 7 days |
| Request expiry | 3,600 BSC blocks |
| Seed delay | 2 BSC blocks |
| Stalled reveal slash | 30 BSC blocks |
| SALT buy / sell tax | 3% / 3% |
| Flap migration | 80% / Pancake V2 |