Docs
Minpentai is a privacy protocol on Ethereum mainnet with a token that burns. Five contracts, one loop: fund → hide → speak → echo → knock. A sixth gives the echoes a body you can trade, and a small service lets a burned balance unlock a private chat with a model.
The name comes from Snowmoon, the novel Vitalik Buterin published in 32 chapters: Minpentai is a game-sport of walls, gliders and 32-player tournaments. The novel is GPL-3.0, we quote it, and we are not affiliated.
Contracts
| Contract | Address | What it does |
|---|---|---|
| $PENTA token | 0x07DB…1c91 ↗ | ERC-20, fixed supply 1,000,000,000, 18 decimals, no mint. 0.5 % tax on transfers → treasury. Public burn(). |
| EchoBroadcaster | 0xAAA8…61fF ↗ | speak(amount, message) burns $PENTA and emits Burned(msgId, burner, amount, tier, message, timestamp). Minimum 1 PENTA. Message ≤ 280 bytes. |
| WhisperWall | 0x62CD…3Aff ↗ | Permanent inscriptions of tier 4+ echoes. Written by the keeper; anyone can read with totalInscribed() and wall(i). |
| PentaDoorstep | 0x9DB0…3b58 ↗ | knock(...) burns $PENTA at an address or ENS name and can forward an ETH gift in the same transaction. |
| WhisperNFT | 0xF5bF…650d ↗ | ERC-721 with on-chain SVG. mint(msgId) is permissionless for tier 4+ echoes; tokenId == msgId. totalMinted(). |
| WhisperMarket | 0x34d5…da88 ↗ | On-chain listings: list(tokenId, price), buy(tokenId). 1 % fee on a sale → treasury. |
| StealthPay | 0x5544…5120 ↗ | Handles → ERC-5564 stealth meta-addresses (claim burns 100 $PENTA). payETH() pays a one-time address and announces it through the canonical ERC-5564 announcer in one transaction; 0.3 % → treasury. |
| Uniswap v4 pool | PoolManager ↗ | $PENTA/ETH, pool id 0xf029…f263, fee 1 %, tick spacing 200, no hooks. Seeded with 800,000,000 $PENTA + 1 ETH. |
The loop
- Fund. ETH (or a stablecoin) goes into an audited 0xbow Privacy Pool as a note. The deposit is public; what happens next is not.
- Hide. The commitment joins a Merkle tree with everyone else's. The crowd is the privacy — the more deposits, the better it works.
- Speak. Burn $PENTA with a message. The burn and the message go on-chain together, permanently.
- Echo. Tier 4 and above are inscribed on the WhisperWall and can be minted as a Whisper NFT.
- Knock. Burn at someone's door. Attach ETH as a gift and it is forwarded in the same transaction.
Tiers
| Tier | Burned (whole $PENTA) | What it earns |
|---|---|---|
| 1 | 1 – 9 | logged once |
| 2 | 10 – 99 | echoed for 24 h |
| 3 | 100 – 999 | relayed to the channels |
| 4 | 1,000 – 9,999 | inscribed on the WhisperWall + mintable as a Whisper NFT |
| 5 | 10,000 + | WhisperWall + dedicated page |
Tier is computed from whole tokens at burn time and stored in the record: tierFor(amount).
How to — step by step
Zip and unzip
- Open the dApp and unlock your pool account — one signature, no transaction. Your notes are derived from that signature and never leave the browser.
- Deposit a fixed denomination (min 0.01 ETH) or any of the eight pooled assets.
- Wait for approval — roughly 1–6 hours. The timer on the page counts it down. You can Ragequit at any moment and get the deposit back publicly.
- Withdraw to a fresh address, or send it as a Zip Pay bearer link — whoever opens the link claims it, and the two ends are never linked.
Speak
- Approve
EchoBroadcasterfor the amount, then callspeak(amount, "your message"). - Minimum 1 $PENTA, message up to 280 bytes. The tokens are pulled in and burned in the same transaction.
- Check your tier from the emitted event. From tier 4 the keeper inscribes it and you can mint the NFT.
Speak without a trail — Unzip & Speak
- Zip a note first, then use Unzip & Speak in the dApp.
- The relayer withdraws to a fresh burner; the burner burns and speaks. Nothing on-chain connects your wallet to the message.
Knock
- Pick a door: an address or an ENS name, from the menu or any name you type.
- Burn $PENTA with a message. Optionally attach an ETH gift — it is forwarded to the recipient in the same transaction. Name-only doors cannot receive gifts.
- Every knock is stored under the door forever and shown on the door's page.
Private Swap
- You need an approved ETH note. Flow: Pool → deposit → wait for approval.
- Open Private Swap, choose the note and the token — USDC, USDT, DAI, wstETH, WBTC, USDS, USDe, $PENTA or any ERC-20 address.
- The relayer withdraws to a burner, the burner pays the 0.5 % Minpentai fee and swaps through an aggregator, then re-zips the output into its own pool (or leaves it on the burner if you uncheck Re-zip).
- The ETH that went in and the token that came out never share an address.
Private chat — burn to think
- Open Chat. The page makes a throwaway key that only your browser holds. No account, no login, no wallet connection.
- Get $PENTA onto that key — privately via Pool → Private Swap, or from any wallet you control.
- Burn 25 $PENTA to unlock 20 prompts. The chain sees a burn, never a question.
- Paste your own model key (OpenRouter, OpenAI or Groq). Prompts go straight from the page to the provider; nothing is proxied by us.
Fees
| Action | Cost |
|---|---|
| Transfer / swap $PENTA | 0.5 % tax → treasury |
| Whisper NFT sale | 1 % → treasury |
| Private Swap | 0.5 % of the swapped ETH → treasury, paid by the burner |
| Uniswap v4 pool | 1 % to liquidity providers |
| Private chat | 25 $PENTA burned per 20 prompts |
| Gifts at a door | 0 % — the protocol takes nothing |
The protocol contracts and the deployer are tax-exempt so a burn never pays tax twice. See /tax.
The privacy model — what is public
| Public | Private |
|---|---|
|
|
Owner powers
Three, and they are all the contract can do:
setTreasury(address)— move the treasury (today a plain wallet; the point of the power is to move it to a multisig).setTaxExempt(address, bool)— add or remove a tax-exempt account.inscribe(...)on the wall, plus the keeper's mint duty.
There is no mint, no pause, no blacklist and no upgrade proxy. Ownership was not renounced and the liquidity NFT was not burned — deliberately, so the keeper can keep working; both are visible on-chain.
Integrate
Read the chain
// any router: pool id, tier thresholds, supply, echoes
const token = "0x07DB563340C60ba421B9802aa0369Dc5B70a1c91";
const broadcaster = "0xAAA877D4047cA38F54eD035AE980b20784C461fF";
const supply = await provider.call({ to: token, data: "0x18160ddd" }); // totalSupply()
const echoes = await provider.call({ to: broadcaster, data: "0x951166c0" }); // totalMessages()
Speak from a script
import { ethers } from "ethers";
const abi = ["function approve(address,uint256) returns (bool)", "function speak(uint256,string)"];
const token = new ethers.Contract(PENTA, abi, signer);
const bc = new ethers.Contract(BROADCASTER, abi, signer);
await (await token.approve(BROADCASTER, ethers.parseEther("1500"))).wait();
await (await bc.speak(ethers.parseEther("1500"), "1500 PENTA, on the record.")).wait();
// tier: 1–9 → 1, 10–99 → 2, 100–999 → 3, 1000–9999 → 4, 10000+ → 5
Private chat API
A small read-and-spend service in front of the burn gate. It never sees a prompt — the model call is made by the browser.
GET /health → price, minimum burn, token
GET /pass?address=0x… → { credits, burned, expires }
POST /session { address, txHash } → verify an on-chain burn, credit prompts
POST /spend { address, signature, nonce, ts } → spend one prompt (EIP-712)
// EIP-712 domain
{ name: "Minpentai Chat", version: "1", chainId: 1, verifyingContract: PENTA }
// type
Spend(address address, uint256 nonce, uint256 ts)
Endpoint host: minpentai-chat.stablepump-ops.workers.dev. 25 $PENTA = 20 prompts, 1.25 each; a burn of exactly 25 is the minimum.
Links
- The dApp — Pool, Speak, Knock, Market, Private Swap, Wallet, Chat.
- Analytics — live supply, burns, treasury, pool.
- Tax — every fee and where it goes.
- Buy $PENTA on Uniswap ↗
- 0xbow Privacy Pools ↗ — the audited pools underneath Zip.
- Snowmoon ↗ — the novel the name comes from.