Trust

Security & contracts

Everything we will and will not do, and where to verify it.

Official addresses

Until an address appears in this table, it does not exist. Anyone DMing you a "mint link" is scamming you.

Non-negotiables

  • No production debug controls
  • No seed phrase requests, ever
  • No approval transactions for the allowlist
  • No hidden supply; maximum supply cannot be raised
  • No unannounced team mint — reserves are published above
  • No fake gameplay screenshots
  • No guaranteed $BUNS allocation; Crumbs are non-transferable points
  • No passive-income or yield promises
  • No cross-chain bridge of the Genesis NFT during launch
  • No randomness from block variables
  • No core NFT upgrade controlled by a single wallet — multisig withdrawal, separate utility-authority signer

Contract design

  • Fixed-supply ERC-721 on audited OpenZeppelin 5.x components, non-upgradeable
  • Merkle-proof allowlist with configurable phases and per-wallet limits
  • ERC-2981 royalty signal (3.5%), ERC-4906 metadata-update events
  • Provenance hash committed before mint; base URI reveal
  • Off Shift / Clocked In state, department, First Shift timestamp, badge references
  • Clock-In accepts EIP-712 claims signed by the utility authority with nonce, expiry and chain id; replays rejected
  • Foundry unit, fuzz and invariant tests published with the source
  • Future utility ships as separate modular contracts

Allowlist data & terms

We store: wallet address, SIWE nonce/session, X id and handle, Discord id and membership, First Shift score and timestamp, referral source and qualified referral count, IP/device risk indicators, point total, tier, consent timestamp and review status. Duplicate devices are flagged for review — shared households are not auto-banned. Top referral accounts are manually reviewed. Data is used only for allowlist qualification and anti-sybil review.