MINPENTAI $PENTA
protocol

Docs

Minpentai is a privacy protocol on Ethereum mainnet with a token that burns. Five contracts, one loop: fund → hide → speak → echo → knock. A sixth gives the echoes a body you can trade, and a small service lets a burned balance unlock a private chat with a model.

The name comes from Snowmoon, the novel Vitalik Buterin published in 32 chapters: Minpentai is a game-sport of walls, gliders and 32-player tournaments. The novel is GPL-3.0, we quote it, and we are not affiliated.

Contracts

ContractAddressWhat it does
$PENTA token 0x07DB…1c91 ↗ ERC-20, fixed supply 1,000,000,000, 18 decimals, no mint. 0.5 % tax on transfers → treasury. Public burn().
EchoBroadcaster 0xAAA8…61fF ↗ speak(amount, message) burns $PENTA and emits Burned(msgId, burner, amount, tier, message, timestamp). Minimum 1 PENTA. Message ≤ 280 bytes.
WhisperWall 0x62CD…3Aff ↗ Permanent inscriptions of tier 4+ echoes. Written by the keeper; anyone can read with totalInscribed() and wall(i).
PentaDoorstep 0x9DB0…3b58 ↗ knock(...) burns $PENTA at an address or ENS name and can forward an ETH gift in the same transaction.
WhisperNFT 0xF5bF…650d ↗ ERC-721 with on-chain SVG. mint(msgId) is permissionless for tier 4+ echoes; tokenId == msgId. totalMinted().
WhisperMarket 0x34d5…da88 ↗ On-chain listings: list(tokenId, price), buy(tokenId). 1 % fee on a sale → treasury.
StealthPay 0x5544…5120 ↗ Handles → ERC-5564 stealth meta-addresses (claim burns 100 $PENTA). payETH() pays a one-time address and announces it through the canonical ERC-5564 announcer in one transaction; 0.3 % → treasury.
Uniswap v4 pool PoolManager ↗ $PENTA/ETH, pool id 0xf029…f263, fee 1 %, tick spacing 200, no hooks. Seeded with 800,000,000 $PENTA + 1 ETH.

The loop

Tiers

TierBurned (whole $PENTA)What it earns
11 – 9logged once
210 – 99echoed for 24 h
3100 – 999relayed to the channels
41,000 – 9,999inscribed on the WhisperWall + mintable as a Whisper NFT
510,000 +WhisperWall + dedicated page

Tier is computed from whole tokens at burn time and stored in the record: tierFor(amount).

How to — step by step

Zip and unzip

  1. Open the dApp and unlock your pool account — one signature, no transaction. Your notes are derived from that signature and never leave the browser.
  2. Deposit a fixed denomination (min 0.01 ETH) or any of the eight pooled assets.
  3. Wait for approval — roughly 1–6 hours. The timer on the page counts it down. You can Ragequit at any moment and get the deposit back publicly.
  4. Withdraw to a fresh address, or send it as a Zip Pay bearer link — whoever opens the link claims it, and the two ends are never linked.

Speak

  1. Approve EchoBroadcaster for the amount, then call speak(amount, "your message").
  2. Minimum 1 $PENTA, message up to 280 bytes. The tokens are pulled in and burned in the same transaction.
  3. Check your tier from the emitted event. From tier 4 the keeper inscribes it and you can mint the NFT.

Speak without a trail — Unzip & Speak

  1. Zip a note first, then use Unzip & Speak in the dApp.
  2. The relayer withdraws to a fresh burner; the burner burns and speaks. Nothing on-chain connects your wallet to the message.

Knock

  1. Pick a door: an address or an ENS name, from the menu or any name you type.
  2. Burn $PENTA with a message. Optionally attach an ETH gift — it is forwarded to the recipient in the same transaction. Name-only doors cannot receive gifts.
  3. Every knock is stored under the door forever and shown on the door's page.

Private Swap

  1. You need an approved ETH note. Flow: Pool → deposit → wait for approval.
  2. Open Private Swap, choose the note and the token — USDC, USDT, DAI, wstETH, WBTC, USDS, USDe, $PENTA or any ERC-20 address.
  3. The relayer withdraws to a burner, the burner pays the 0.5 % Minpentai fee and swaps through an aggregator, then re-zips the output into its own pool (or leaves it on the burner if you uncheck Re-zip).
  4. The ETH that went in and the token that came out never share an address.

Private chat — burn to think

  1. Open Chat. The page makes a throwaway key that only your browser holds. No account, no login, no wallet connection.
  2. Get $PENTA onto that key — privately via Pool → Private Swap, or from any wallet you control.
  3. Burn 25 $PENTA to unlock 20 prompts. The chain sees a burn, never a question.
  4. Paste your own model key (OpenRouter, OpenAI or Groq). Prompts go straight from the page to the provider; nothing is proxied by us.

Fees

ActionCost
Transfer / swap $PENTA0.5 % tax → treasury
Whisper NFT sale1 % → treasury
Private Swap0.5 % of the swapped ETH → treasury, paid by the burner
Uniswap v4 pool1 % to liquidity providers
Private chat25 $PENTA burned per 20 prompts
Gifts at a door0 % — the protocol takes nothing

The protocol contracts and the deployer are tax-exempt so a burn never pays tax twice. See /tax.

The privacy model — what is public

PublicPrivate
  • That a deposit happened, and its size.
  • Every burn: the amount and the message.
  • Inscriptions, knocks, NFT sales, all transactions.
  • The burner address that pays for a private swap.
  • Which deposit a withdrawal came from.
  • Who wrote a message burned from a burner.
  • Your notes and their secrets — they never leave your browser.
  • What you type in the private chat.
Privacy pools protect against the chain, not against timing. A withdrawal minutes after a same-sized deposit is easy to pair — wait, or hide in a bigger crowd. The private chat is a burn-gated model call, not a messaging service: the provider still sees your prompt and your IP, so use Tor or a VPN if the IP matters to you.

Owner powers

Three, and they are all the contract can do:

There is no mint, no pause, no blacklist and no upgrade proxy. Ownership was not renounced and the liquidity NFT was not burned — deliberately, so the keeper can keep working; both are visible on-chain.

Integrate

Read the chain

// any router: pool id, tier thresholds, supply, echoes
const token = "0x07DB563340C60ba421B9802aa0369Dc5B70a1c91";
const broadcaster = "0xAAA877D4047cA38F54eD035AE980b20784C461fF";
const supply      = await provider.call({ to: token, data: "0x18160ddd" });        // totalSupply()
const echoes      = await provider.call({ to: broadcaster, data: "0x951166c0" });  // totalMessages()

Speak from a script

import { ethers } from "ethers";
const abi = ["function approve(address,uint256) returns (bool)", "function speak(uint256,string)"];
const token = new ethers.Contract(PENTA, abi, signer);
const bc    = new ethers.Contract(BROADCASTER, abi, signer);
await (await token.approve(BROADCASTER, ethers.parseEther("1500"))).wait();
await (await bc.speak(ethers.parseEther("1500"), "1500 PENTA, on the record.")).wait();
// tier: 1–9 → 1, 10–99 → 2, 100–999 → 3, 1000–9999 → 4, 10000+ → 5

Private chat API

A small read-and-spend service in front of the burn gate. It never sees a prompt — the model call is made by the browser.

GET  /health                         → price, minimum burn, token
GET  /pass?address=0x…               → { credits, burned, expires }
POST /session { address, txHash }    → verify an on-chain burn, credit prompts
POST /spend   { address, signature, nonce, ts } → spend one prompt (EIP-712)

// EIP-712 domain
{ name: "Minpentai Chat", version: "1", chainId: 1, verifyingContract: PENTA }
// type
Spend(address address, uint256 nonce, uint256 ts)

Endpoint host: minpentai-chat.stablepump-ops.workers.dev. 25 $PENTA = 20 prompts, 1.25 each; a burn of exactly 25 is the minimum.

Links