Skip to content
Risk Factors

We publish what others hide.

A protocol that claims to have engineered away market beta, fraud, regulators, and its own founders is not a safer protocol. It is a less honest one.

Adversarial by Design

The red-team report on $NPKN.

It assumes a well-capitalized, patient, technically fluent adversary (a rival protocol, a short fund, a governance raider, a compromised insider, a bridge crew) who has read every section and is hunting for the seam. Every threat ends with an honest sentence about the risk we could not engineer away.

Assume adversaries

Every mechanism is specified against a hostile counterparty who knows the rules, not a cooperative one who follows the spirit. The published buyback wallet, the quarterly tender, and the audit lag are all targets. Built expecting attack on day one.

Prefer mechanisms over promises

Wherever a discretionary decision could become a hard-coded rule or a covenant with a penalty attached, it did, because the market's verdict is settled: accrual depending on a future decision is priced at zero.

Make honesty the cheapest strategy

Step-ups gate on attested cash flow because cash is expensive to fake. The disclosure penalty is inverted so our own silence costs us. The move throughout is to price dishonesty above honesty and let self-interest enforce the rest.
Sixteen threat classes, at a glance
Threat classPrimary vectorSeverityCore mitigation
Vampire / fork attackIncentivized liquidity migration to a copycatLowOff-chain moat: legal claim on audited companies
Buyback MEVSandwiching the published on-chain buybackMediumPrivate orderflow, batch auctions, randomized slices
Wash-down to tender snipeDepress market, then exit at the NAV floorMediumTWAP tender pricing, per-quarter caps, KYC holders
Buyback-tender reflexivityTwo legs draining one fixed cash flow in stressMediumPro-rata rationing, discount-bounding, no price promise
Single-company contagionOne fraudulent opco poisons the whole NAVHighComponent materiality, ring-fencing, no cross-guarantees
Bridge infinite-mintSupply-conservation break on Base or RSX gatewayHighBurn-and-mint, formal-verified conservation, rate caps
Oracle / signer compromiseForged attested NAV drives the EngineHighMulti-party signing, deviation bounds, staleness breaker
Attestation-lag arbitrageTrading real-time versus last-attested NAV gapMediumNotice periods, attested-date pricing, MAR insider lists
Counterparty concentrationFailure of a single venue, agent, or vendorMediumMulti-jurisdiction redundancy, swappable modules
Unlock / snapshot timingFront-running cliffs, farming the RSX snapshotLowMonthly linear vests, surprise snapshot, duration weight
Deal Scout gamingSelf-dealing or Sybil to farm sourcing bountiesLowKYC scouts, closed-deal-only pay, arm's-length attest
Milestone gamingShell deals to trigger Engine step-upsLowStep-ups gate on attested cash flow, not deal count
Governance captureBorrowed or bought votes seize parametersLowEngine non-votable; timelock, multisig, board veto
Insider dealing under MARTrading ahead of deals, attestations, step-upsMediumBlackout windows, insider lists, non-discretionary buyback
Conversion executionCourt order, dissent, bondholder consent, tax opinionsMediumGate G1: the token waits, automatically
Founder-sale opticsPhase 1 tender read as a hidden insider exitLowPre-capped Founder Liquidity Dial; blackout windows; on-chain disclosure

A RED-TEAM REPORT WITH NO RESIDUAL RISK IS NOT A RED-TEAM REPORT. IT IS MARKETING.

Key Attack Narratives

Named attacks, real precedents, honest residuals.

The attacks that end protocols cross domains: a technical bug becomes an economic event, one company's fraud becomes the whole system's freeze. Four of the sixteen, in full anatomy.

The wash-down to tender snipe

An adversary pushes the market price down (wash trades, spoofed depth, coordinated selling into a thin book) accumulates cheaply, then tenders back to the Engine at the NAV floor, extracting the spread from every other holder's cash flow.

Precedent
Saba Capital's 2023–24 campaigns forcing closed-end-fund tenders; Mango Markets, ~$110M drained by moving a thin price a mechanism read as truth.
Defense
The tender prices against last-attested NAV with a notice period (not spot) is capped per quarter, clears pro-rata via commit-reveal, and $NPKN is an ERC-3643 permissioned security: the wash legs cannot run through anonymous wallets.
Residual risk
Within the whitelisted holder set, coordinated selling into the pre-attestation window is still possible. The tender bounds a well-timed discount's profitability; it does not abolish it.

One failed company, the whole NAV

One acquired company with cooked books does not merely zero its own deal. It can force a restatement of the consolidated accounts, trip the attestation for the entire perimeter, freeze the Engine through the staleness breaker, and breach the bond's coverage test at once.

Precedent
Steinhoff lost roughly EUR 10B (about 96% of equity) when one fraud surfaced; NMC Health imploded on roughly $4B of hidden debt.
Defense
Component-materiality caps on any subsidiary's weight, ring-fencing with no cross-guarantees so one default cannot cross-default the rest, and audit scope over the AI-operated accounting stack.
Residual risk
A consolidated portfolio is a correlated instrument. For the first several years $NPKN carries real single-name concentration risk, and diversification dampens this only as the deal count grows.

The bridge infinite-mint

A supply-conservation break (a bug that mints $NPKN on a spoke without burning it on the hub) is an infinite-mint of a security, corrupting the per-token denominator every NAV, buyback, and tender calculation depends on.

Precedent
Bridges are where crypto loses the most: over $2.8B cumulatively. Ronin $625M, Wormhole ~$326M, and the BNB Bridge's forged proof minting ~$586M.
Defense
No lock-and-mint honeypot: burn-and-mint nets spoke supply to zero. ERC-7802 lives in the token with CCIP a swappable authorized caller, formal verification proves supply conservation as an invariant, and CCIP lanes are rate-capped through the guarded launch.
Residual risk
CCIP is itself a trusted network, the RSX gateway is a second bridge yet to be built, and bridges remain the industry's highest-loss category. We cut the blast radius; we cannot eliminate it.

Oracle-signer compromise and the attestation lag

Whoever signs the attested NAV is a point of trust. A compromised signer could push a false NAV the Engine executes against. And the live dashboard publishes faster data than the NAV that prices the tender, which is up to 45 days stale. That gap is tradeable.

Precedent
Synthetix 2019: one mispriced feed let a bot mint roughly $1B notional before it was unwound. The lag is the tokenized-asset version of the mutual-fund late-trading scandal.
Defense
Multi-party signing, rotatable keys, deviation bounds, and a staleness breaker that freezes NAV-dependent actions while transfers stay open. Tender pricing pinned to attested dates, with NAV-relevant data treated as MAR inside information.
Residual risk
Named-firm accountability is a legal deterrent, not a cryptographic guarantee, and the gap between live data and attested payouts can never be fully closed.
Residual Risks We Cannot Fully Eliminate

Four structural facts. Not attack-and-mitigation pairs.

These are structural facts about what $NPKN is, and pretending they are solved would be the reddest flag in this document.

Market beta

No mechanism outruns beta.

$NPKN trades in crypto markets and will fall when they fall. The Engine changes the per-token economics of a growing portfolio; it is not, cannot be, and is not designed to be price defense. Uniswap burned $596M of UNI and hit a cycle low of $2.90 two months later. Pump.fun spent over $350M on buybacks and sat 81% below its peak. Hyperliquid (the best-executed buyback in crypto history) drew down through the H1 2026 bear despite roughly $65M a month of buying.

Black-swan operator fraud

Expensive and detectable. Not impossible.

The verification stack is built to catch the RealT failure mode: tokens sold on assets never owned, dividends on empty properties, a $2.72M fraud across 39 homes. But a sufficiently sophisticated fraud inside an acquired company, or collusion reaching the attestation itself, is a tail we make expensive and detectable, not impossible. Named-firm auditor accountability is a deterrent backed by legal liability, not a guarantee no one ever lies successfully.

Regulatory reversal

Strategy reduces the risk. It does not abolish discretion.

A five-jurisdiction structure has five regulators, and securities regimes shift. We built prospectus-first because BaFin's Ethena action showed what launch-then-negotiate costs: a public-offer ban, frozen reserves, a EUR 600,000 fine, a supervised 42-day wind-down. But an adverse reinterpretation in a major market could still force geo-restriction of distribution, and we premise no plan on pending legislation.

Key-person risk

Cushioned by mechanism. Not neutralized.

The founder and a small leadership team drive strategy. The Engine and vesting are contractual and non-discretionary (they run whether or not any individual shows up) and governance sits behind a multisig, timelock, and independent board. But an AI-native serial acquirer is, at this stage, inseparable from the people who built it, and their loss would be a real shock the mechanisms cushion but do not neutralize.

Section 15

The risk-factor register, written to be read.

Each risk is real, each mitigation is specific, and none of the mitigations is a guarantee. Where a risk's attack mechanics are treated at length in the adversarial-design analysis, the one-line version is here and the full anatomy is in Section 14.

01NAV discount risk#1 structural risk
A token representing portfolio economics can trade persistently below attested net asset value. The killer of portfolio vehicles. Buybacks alone do not close a structural discount. Our answer is the arbitrage loop: quarterly Dutch-auction tender windows funded by the Engine, executed at the greater of market price or discount-bounded attested NAV, plus a hard covenant that no new NPKN is ever issued below attested NAV. A funded, recurring bid that scales with the discount is the only mechanism with a track record of closing one. It bounds the discount; it does not abolish it.
02Execution risk: 15 to 10,000
Constellation Software (TSX:CSU), the best serial acquirer in history, needed roughly three decades and 1,100+ deals to build a business worth tens of billions. Our 10,000-company ambition implies out-executing that benchmark by an order of magnitude. We therefore anchor nothing on 10,000: the valuation base case is the 100-deal intermediate milestone, we publish per-deal economics for every closed acquisition, and Engine step-ups are gated on cumulative attested FCF. A hard-currency number an auditor signs, not deal counts that shell purchases could game.
03Conversion execution risk
The token exists only if the Conversion completes: court approval of the Arrangement, dissent rights resolved, bondholder change-of-control consent on the EUR 500M program, and tax opinions supporting the rollover structure. Any one of these can fail or slip, and any failure delays the token. Gate G1 makes that delay automatic rather than negotiable: no court order and no consent means no TGE, with no management discretion to launch anyway. Delay, not improvisation, is the designed failure mode, and it is still a real cost to anyone waiting on the instrument.
04Market beta
NPKN will trade in crypto markets and will fall when they fall. Accrual is not price defense. The Engine changes per-token economics of a growing portfolio. It does not, cannot, and is not designed to defend a price.
05Regulatory risk
Securities regimes shift, and a five-jurisdiction structure has five regulators. Mitigation is the strategy itself: prospectus-first issuance and pre-filing engagement across the FMA, BCSC, and SEC pathways. Residual risk remains. An adverse reinterpretation in a major market could force geo-restriction of distribution. We do not premise any plan on pending legislation.
06Smart contract risk
Code fails. Mitigations: OpenZeppelin v5 base, immutable core token with modular periphery behind a 48-hour timelock, dual independent audits, a top-tier bug bounty exceeding $1M, and a guarded mainnet launch with caps. None of this reduces the risk to zero, and we will not pretend otherwise.
07Tokenized-equity liquidity risk
A tokenized share is a security token, and security tokens trade on fewer, thinner venues than crypto-native tokens; Canadian secondary infrastructure does not yet exist at scale. Mitigations: multiple venues rather than one (21X retail access in the EEA, the Securitize ATS in the US, further venues as lanes open) 40%+ genuine float, retainer-model market makers with published liquidity reports, and the quarterly tender floor as a funded, recurring exit channel priced against attested NAV. In the BC lane, buyers hold for four months and should expect thinner early markets.
08Key-person risk
The founder and a small leadership team drive strategy. The Engine and vesting are contractual and non-discretionary (they run whether or not any individual shows up to work) and the 20% founder cap with its published liquidity dial keeps leadership economics tied to the long game.
09Oracle and attestation risk
An oracle transmits; it does not verify. Our smart contracts execute only against auditor-attested values at ISAE 3000 examination level, with the signed attestation hashed on-chain and redemption pricing pinned to attested dates. The residual risk (auditor error or fraud in the underlying companies) is real and cannot be engineered away, only insured against by the audit stack's named-firm accountability.
10Bond-covenant interaction
Token distributions funded from portfolio cash flow are textbook restricted payments under a secured note program. All the more so now that the program's series carry first-ranking liens over operating assets. We publish the EUR 500M Vienna program's restricted-payments capacity analysis before TGE, and the Engine auto-suspends if bond coverage tests breach. If the analysis showed the Engine were impermissible, we would seek bondholder consent or restructure the waterfall before launch, not after. The token tranche is explicitly junior to the bond, and we say so in the terms.
11Cross-border tax and structure risk
A Canadian-resident founder with a Cayman foundation and Swiss-Liechtenstein issuers triggers some of the hardest rules in the Canadian tax code: deemed-resident-trust provisions, foreign accrual property income, departure tax. This is flagged, counsel-managed, and disclosed, but an adverse CRA characterization could impose material cost on the founder or require structural change. The structure was built with these rules in view, not in spite of them.
12Management's own published watch items

The FY2025 shareholder update names its own risk list, and we mirror it here deliberately: a risk section earns trust when token holders read the same watch items the company's shareholders do.

  • Financing and close risk on the combination target and the signed-LOI construction targets: run-rate stages beyond Stage 1 depend on deals that are not done until funded and closed.
  • Legacy liabilities under refinancing.
  • Customer concentration at the Day-1 construction platform: the anchor homebuilder relationship is both moat and concentration, and diversification is a stated post-close priority.
  • Integration capacity across operators as the platform scales.
  • Cross-border and geopolitical exposure, including the ADGM redomicile, Canadian exit-tax mechanics, and regional conflict.
  • Construction market cyclicality: rates, labor, and weather.

These are management's own published watch items, stated to shareholders before they were stated to token buyers.

The Feature

Integrity is not a disclaimer we bury on the last page. It is the feature.

The one mechanism every other mechanism depends on, and the only one we could not write in code, so we wrote it in incentives instead.

Read the risks before the pitch.

The white paper leads with mechanisms and ends with the adversary's view: both are written to be read, not skimmed.