Skip to content
Technology

Go where the liquidity, custody, and auditors already are.

Most token papers treat the chain section as a branding exercise. We treat it as an engineering decision with a paper trail. Chain selection follows liquidity and custody, not narrative , and we say out loud where they are not.

Hub and Spokes

One canonical asset. One canonical supply.

$NPKN is issued once, on Ethereum L1. Everything else is a spoke: a burn-and-mint representation whose supply nets to zero against the hub. No wrapped tokens, no lock-and-mint bridges holding honeypots, no ambiguity about where the real thing lives.

Structural steel and cranes at height. An immutable core with a modular periphery.
The Hub · Canonical issuance
Ethereum L1: ERC-3643

One canonical asset with one canonical supply, issued once. ERC-3643 (T-REX) is the consolidated institutional standard: $32B+ tokenized across 200+ deployments and 180+ jurisdictions, DTCC ComposerX integration, and native settlement on the BaFin-licensed 21X exchange. Every transfer runs through an on-chain eligibility check : enforced in the token itself, not promised in a PDF.

56%+ of tokenized RWA value lives here

Burn-and-mint spokes · supply nets to zero against the hub · no wrapped-token honeypots

Retail spoke

Base

Burn-and-mint via ERC-7802 hooks (the crosschain interface that ships in OpenZeppelin v5.5+) with Chainlink CCIP as the transport. Sub-cent fees, and the fastest-growing RWA TVL of any network over the past 18 months. The bridge vendor lives outside the token: CCIP is an authorized caller that can be replaced without touching $NPKN itself.

Honest note: Base's sequencer is centralized: acceptable for a distribution spoke, never for the hub.

Institutional spoke

XRPL mainnet

A native MPT issuance inside a Permissioned Domain, with RLUSD as the mint/redeem and settlement rail, plugging into ~$3.5B of XRPL RWA value, +$1.9B in 90-day inflows, BNY custody of RLUSD reserves, and an OCC-chartered trust bank.

Activation is gated on three published checks: XLS-66 native lending live, independent top-tier MPT custody, and Archax-scale secondary liquidity. Until then it is built, tested, and waiting. Not marketed.

Future RSX L1

Avalanche

A post-ACP-77 permissioned Avalanche L1 for the future RSX settlement layer: Napkin-appointed validators (Napkin entities, our auditor, a banking partner), Canadian-hosted for data residency, with eERC encrypted balances so even in-network participants see only their own flows.

The precedent path: Progmat migrated $2.8B of tokenized securities to a dedicated Avalanche L1; JPMorgan's Kinexys runs on a permissioned Evergreen subnet.

ChainRoleWhyEvidence
Ethereum L1Canonical hubDeepest custody, audit, and RWA gravity56%+ of RWA value; ERC-3643 $32B+; DTCC ComposerX
BaseRetail spokeSub-cent fees; ERC-7802 + CCIP burn-and-mintFastest-growing RWA TVL over 18 months
XRPL mainnetInstitutional spokeNative MPT + Permissioned Domains + RLUSD rail~$3.5B RWA; +$1.9B 90-day inflows; BNY, OCC charter
AvalancheFuture RSX L1Post-ACP-77 permissioned settlement, eERC privacyProgmat $2.8B; JPM Kinexys; Intain $5.5B
PlumeWatchlistRWA-native L2, too young for canonical issuance~$400M TVL; 190k+ RWA holders; BMA Class M
The paragraph most papers would omit
$25,741
XRPL EVM sidechain TVL
as of July 14, 2026. Not million. Thousand.

Zero DEX volume, ~168 active developers against Ethereum's ~8,448, flagship launch dApps at zero TVL. A roughly 24,000-to-1 miss against its own ecosystem projections. We do not deploy there, and we say so in print, because the reasoning generalizes: institutional demand found XRPL through its native primitives and skipped the EVM layer entirely. A chain decision made for narrative alignment rather than measured liquidity is how treasuries get stranded.

Contract Stack

Immutable core. Modular periphery.

The token contract itself is not upgradeable: holders should never have to trust that an admin key will not rewrite the asset they hold. Everything that legitimately needs to evolve lives in swappable modules behind interfaces: behind a Safe multisig and a 48-hour timelock, publicly visible for two days before it can execute.

Immutable core
The $NPKN token contract

ERC-3643 permissioned token, full ERC-20 interface preserved. OpenZeppelin Contracts v5, Solidity ^0.8.26, built and tested in Foundry. The asset you hold cannot be rewritten.

Compliance module

Jurisdiction rules change; the module swaps.

Engine module

Milestone steps activate; the constants do not move.

Oracle adapter

Feeds get upgraded; the token never does.

Module swaps: Safe multisig + 48h timelock · Emergency pause: security council, no timelock. An incident does not wait 48 hours

The Engine, as code

Three calls. No discretionary hand on the valve.

attestNAV()

The attestation lands

The oracle adapter receives an auditor-attested NAV and consolidated-FCF figure from the Chainlink feed. The Engine's share of attested FCF arrives at the current milestone percentage: 20/30/40, constants keyed to cumulative attested FCF, not admin-settable parameters.

buybackAndBurn()

The buyback leg

An independent execution agent triggers the pre-committed formula, enforced on-chain: TWAP-referenced pricing, daily volume caps, reverts inside blackout windows. Purchased tokens are burned in the same transaction. Every burn an event, every event traceable to a published wallet.

openTenderWindow()

The tender leg

Quarterly, a Dutch-auction tender opens, funded by the Engine's tender allocation and floored at the discount-bounded attested NAV. Holders tender; the auction clears; the contract settles.

Staleness is a first-class failure mode

The machine refuses to price anything against a number it cannot trust.

If the NAV feed goes stale or deviates outside configured tolerance, a circuit breaker freezes NAV-dependent actions, Engine buybacks, tender pricing, primary issuance, while leaving transfers untouched. Holders can always move their tokens. Combined with the 120-day audit covenant, staleness becomes expensive for exactly one party: us.

The Fork Question

What stops someone from forking us?

It deserves a real answer. SushiSwap forked Uniswap v2 in September 2020 and pulled roughly $810M (about 55% of Uniswap's liquidity) in a single day. It won, decisively, for about two weeks. Then it lost the decade: by 2025–26 its TVL sat 98.7% below peak while Uniswap collected roughly $985M in fees in ten months.

What forks copy

Code

A forker of the NPKN contracts would own a token pointing at nothing: no share of NewCo, no title to the machine or its free cash flow, no audited consolidation to attest, no acquisitions. The precedent is Figure on Provenance: anyone could fork the code; the $17–20B tokenized loan book never moved, because the moat is origination volume and legal ownership.
What forks cannot copy

The machine

Liquidity network effects, audit history, integrations, brand, teams, and in our case, the deal-sourcing engine itself: NapkinDeals.com, 22,369+ deals live across 50+ countries with 119,694+ deals analyzed. This is why $NPKN is not hidden behind a private chain: a walled garden would strangle distribution while protecting nothing that needed protecting.

Nobody can fork a portfolio of real operating companies, a EUR 500M bond program, and an audited consolidation. Forks copy code. Not machines.

Security & Launch Path

Priced for the destination we intend to reach.

Security spend is where token projects reveal whether they expect to exist in five years. Our budget assumes we do: $250–450K all-in for security, roughly 7–9 months from spec freeze to unrestricted mainnet.

Dual audits

Two firms, second on frozen code

Two full private audits from separate top-tier firms (OpenZeppelin and a Spearbit/Cantina team) with the second run on frozen post-remediation code, plus a public audit competition on the frozen commit. $150–300K budgeted across both engagements.
Formal verification

Invariants, proven

A Certora/Halmos suite proves the invariants that matter: cross-chain supply conservation, the Secure Mint bound, no transfer path bypassing compliance, ERC-4626 share-price monotonicity, pause completeness, and no upgrade path outside the timelock.
Bug bounty

Immunefi, live before the token

An Immunefi program at the institutional norm: 10% of funds at risk for critical findings, capped at $1M at launch and scaling toward $5–10M with TVL: published and funded before mainnet deployment, not after the first incident. We would rather pay a researcher than fund an attacker's exit.
Engineering discipline

Coverage, fuzzing, clean deploys

Foundry CI with >90% branch coverage, fuzz and invariant testing on supply and compliance choke points, Slither on every commit. Deterministic CREATE2 deployment, bytecode-verified on every chain, all roles transferred to Safes and timelock: deployer renounced before TGE.
The staged ratchet. Each stage gated on the previous one
PhaseScopeDurationExit gate
TestnetFull system on Sepolia + Base Sepolia, CCIP lanes, mock NAV feeds4–6 weeksComplete issue-fulfill-claim and pause-upgrade drills pass
Audit windowAudit 1, remediation, audit 2 on frozen code, public competition10–14 weeksAll criticals and highs resolved and re-reviewed
Guarded mainnetSupply cap, per-epoch issuance caps, per-address limits, allowlist-first4–8 weeksClean month of monitoring; post-deploy audit of live bytecode
Cap removalStaged raises of caps and CCIP rate limits4+ weeksEach raise follows a clean prior period

The bug bounty goes live before the token does. The caps come off after the audits: never before.

An engineering decision with a paper trail.

Section 7 documents every chain choice, every contract boundary, and every gate on the launch path, with the evidence attached.