MPGR HUB · MoneyPaiger ($MPGR)
Whitepaper v2.0
An onchain operating system for agents, payments, games and holder utility — built natively on Base.
Public product documentation · September 2026 · Informational only, not an offer of securities and not financial advice
1. Executive summary
MoneyPaiger ($MPGR) is a fixed-supply utility token on Base, Coinbase’s Ethereum Layer 2. MPGR HUB is the product built around it: a Base-native application where a person talks to an AI agent, researches and prepares onchain actions, plays MPGR Run, earns XP and season points, stakes and locks $MPGR, and claims rewards from a vault.
The thesis is public and simple: token → app → AI → payments → onchain activity. MPGR HUB is not a ticker with a landing page; it is a shipping application deployed from GitHub to Vercel, running on Base mainnet only (chain ID 8453).
What is live today
| Capability | Status |
|---|---|
| $MPGR token on Base | LIVE |
| Wallet connect — RainbowKit, Coinbase Wallet, Farcaster Mini App | LIVE |
| MPGR Agent — research, reason, prepare; user signs | LIVE |
| Coinbase CDP Trade API with a 0x fallback (BYO wallet) | LIVE |
| Coinbase B20 tokenized-stock research + Aerodrome Slipstream path | LIVE (prepare / confirm) |
| x402 payment proposals | LIVE (prepare / confirm) |
| MPGR Run, XP, seasons, leaderboard, check-in, referrals | LIVE |
| Staking, token lock and reward vault clients | LIVE on Base |
| SIWE sessions and a server-owned XP ledger | LIVE |
What is explicitly not claimed as finished
- An independent third-party smart-contract audit.
- Enabled competitive financial game payouts — operator-gated and fail-closed by default.
- Onchain DAO governance.
All three are tracked in the roadmap, not presented as current guarantees.
2. Vision & mission
Vision: build the leading AI-powered onchain operating system on Base — one place where a user can talk to an agent that understands wallet and market context, research tokenized stocks and Base markets, prepare a trade, transfer or payment, confirm it in their own wallet, and play, earn, stake and belong to a season — without leaving Base.
Mission: reward real users, builders and contributors. Prefer long-term utility over short-term hype. Keep the token supply fixed. Fund rewards from a community treasury, not from inflation.
Token
MoneyPaiger (MPGR)
Product
MPGR HUB
Tagline
Play. Trade. Earn. With AI.
Network
Base (8453)
3. Problem
Onchain products still ask ordinary people to be their own integration layer.
- Fragmentation. Staking, locking, claiming, playing and trading usually live in five unrelated interfaces with five unrelated mental models.
- High cost of intent. Turning “swap some USDC into a tokenized stock” into a safe, correct transaction means finding a route, understanding slippage, checking liquidity and reading raw calldata — or blindly trusting a button.
- AI without guardrails. Most AI assistants can describe an onchain action but cannot safely prepare one, and the moment an assistant can sign, the user has lost the only control that mattered.
- Rewards without trust. Points, streaks and leaderboards are easy to fake when the client reports the score and the server believes it.
- Engagement without utility. Gamified crypto products often emit tokens to buy attention, which dilutes holders and ends badly.
4. Solution
MPGR HUB answers with one product built on four commitments.
- One surface, four verbs. The Agent (Home) for research and preparation, Games for play, Rewards for progression, Staking and Token Lock for onchain commitment — all on Base, all with the same confirmation language.
- Prepare, never presume. The Agent converts intent into a structured, validated proposal with the exact effect shown before signing. Deterministic code decides what is allowed; the model only suggests.
- Server-owned truth. XP, ranking, referral attribution and game verification are computed server-side. The browser is a cache, never a witness.
- Fixed supply, treasury-funded rewards. 1,000,000,000 MPGR, permanently. Every reward is an existing token from the community treasury — never newly minted supply.
5. MPGR HUB architecture
MPGR HUB is a Next.js App Router application. Domain logic lives in typed modules; the client renders and signs; the server validates, prices, stores and verifies.
| Layer | Implementation |
|---|---|
| App | Next.js App Router, React, TypeScript (strict), Tailwind CSS |
| Wallets | Wagmi, Viem, RainbowKit, Farcaster Mini App connector |
| Chain | Base mainnet only — one typed registry for chain ID, addresses, decimals and ABIs |
| AI | Pluggable providers (Gemini default, NVIDIA NIM, OpenAI) with a deterministic fallback; Coinbase AgentKit prepare-only |
| Trade | Coinbase CDP Trade API, 0x Swap API fallback, Aerodrome Slipstream for B20 |
| Payments | x402 — exact scheme, USDC on Base, EIP-3009 TransferWithAuthorization |
| Data | Upstash Redis / Vercel KV for sessions, XP ledger, referrals, leaderboard and game allocation |
| Auth | SIWE nonce + signature, HMAC session cookie |
| Contracts | MPGR token, MPGRStaking, MPGRTokenLock V1, MPGRRewardVault on Base |
| CI | lint, typecheck, unit and security tests, high-severity audit script, Foundry contract tests, production build |
Three product surfaces
- Home — the Agent. There is no separate Agent tab. Home is an always-on command centre: status, suggested prompts, conversation, and shortcuts into research, trade and rewards.
- Rewards — play and progression. MPGR Run, XP, level, streak, season, Season Pass, leaderboard, achievements, on-chain claims.
- Profile — account control. Wallet, session, XP, holder tier, Premium, referrals, activity and sign-out.
Repository map: app/ pages and API routes, components/ UI, hooks/ client hooks, lib/ domain logic, contracts/ and test/ Solidity and Foundry tests.
6. The MPGR Agent
The Agent is the centre of MPGR HUB. It reads live context, retrieves facts through read-only tools, composes an answer, and — when the request is an action — produces a structured proposal for the user to confirm.
Capabilities today
- Research $MPGR, Base markets and Coinbase B20 tokenized stocks.
- Analyse portfolio and wallet context.
- Prepare Base transfers, including Basename recipients.
- Prepare swaps via Coinbase CDP with a 0x fallback.
- Prepare B20 tokenized-stock orders on Aerodrome Slipstream.
- Prepare x402 payments for agentic commerce.
- Route the user into Rewards, Run, staking and lock flows.
- Fall back to an on-device deterministic engine if no network model answers.
Hard limits
- The Agent cannot sign, broadcast, approve or pay.
- The Agent cannot choose a transaction destination; destinations are resolved from a typed registry.
- The Agent cannot claim success before deterministic code confirms it.
Operational detail: Docs → MPGR Agent.
7. Research → planning → confirmation → execution → verification
The enforced loop is understand → research → reason → plan → confirm → execute → verify. It is a structural property of the codebase, not a prompt convention.
| Stage | Guarantee |
|---|---|
| Understand | A closed intent list. Unmatched input becomes research or help — never an action. |
| Research | Read-only tools only. Facts carry their source and observation time; unavailable data is reported as unavailable. |
| Reason | Policy sits in the system channel; model and tool output are untrusted data and cannot override it. |
| Plan | Deterministic code builds the proposal and validates every field. There is no execute-mode tool in the registry. |
| Confirm | The user sees amount, asset, destination or route, provider, slippage and risk facts, and must confirm. |
| Execute | The connected wallet signs. Where an approval is required, its receipt is confirmed before the main transaction is sent. |
| Verify | The app waits for the receipt and checks its status. A revert is reported as a failure, never as success. |
See Docs → Agent workflow for the same loop described at implementation level.
8. Agent safety & permission model
The model may suggest. Deterministic code decides. The wallet signs.
- Allowlist, not denylist. AgentKit runs in prepare-only mode on Base; its signing, transfer and auto-payment actions are unreachable and are denied server-side even if a caller invents the action name.
- Tool contract. Every tool declares a name, purpose, input schema, output shape, timeout and risk level. Write-capable tools require confirmation.
- Risk levels. Read tools are low risk; prepare tools are medium (swap, B20 order, x402) or high (transfer) and always require an explicit confirmation step.
- Closed navigation. When a reply should navigate, it resolves an intent through a fixed whitelist. A model never produces a route string.
- Budgets and limits. Prompt and output caps, per-IP and per-wallet rate limits, a daily AI token budget, and bounded execution parameters (slippage 1–500 bps, 30-second quote freshness).
- Untrusted-data discipline. User text, memory, tool output and model output are all treated as untrusted; only validated tool arguments reach the execution layer.
FUTURE — configurable autonomy
User-set spend caps, per-action allowance limits and revocable delegated permissions are not implemented. They are tracked at Roadmap → autonomous agent permissions. Today the guarantee is absolute: one action, one confirmation.
9. Wallet & security model
MPGR HUB is non-custodial by construction. Reads are open; writes require a signed session and a wallet signature.
- Session over address. A nonce, a SIWE signature and an HMAC session cookie. Server handlers take the wallet from the session, never from request JSON.
- No secrets client-side. No private key, API secret or CDP credential is exposed under a
NEXT_PUBLIC_name. - Browser values are a cache. XP, scores, referrals, ranks and reward claims from the browser are never trusted for ranking or payouts.
- Bigint token math. Integer or bigint arithmetic only — never floating-point accounting.
- Validated boundaries. Shape, size, range, origin and authorization are checked at every API route. Provider, RPC, Redis and stack-trace errors are never returned raw.
- Fail-closed money paths. Financial game settlement requires both operator gates; if either is off, nothing is paid.
Full list: Docs → security model and Docs → approval boundaries.
10. Base ecosystem
MPGR HUB is Base-native by design. There is no multi-chain runtime today, no bridge and no cross-chain execution path.
| Layer | How MPGR HUB uses it |
|---|---|
| Base mainnet | Sole production chain (8453) — low fees, fast finality, Ethereum security assumptions |
| Coinbase Wallet / Base App | First-class connection path through RainbowKit |
| Coinbase CDP Trade API | Onchain swaps for ETH / WETH / USDC / MPGR and Base ERC-20, BYO wallet |
| Coinbase B20 tokenized stocks | Research plus Aerodrome Slipstream USDC pools; no retail mint API |
| USDC on Base | Settlement asset for swaps and x402 payments |
| Farcaster Mini App | Distribution and auto-connect on the Base / Farcaster graph |
| Basenames | Human-readable transfer recipients, resolved server-side |
| Vercel | Production host, GitHub-connected |
The Agent never custodially trades a brokerage account, and MPGR HUB is not an authorized participant or a broker-dealer. Naming Coinbase, Base, USDC, Farcaster, Aerodrome, 0x or Vercel describes public infrastructure — it is not a claim of partnership or endorsement.
11. Trading & execution architecture
MPGR HUB does not invent a DEX, a stock mint API or a custodial broker. It composes public Base infrastructure behind one confirmation boundary.
Regular tokens
- Quote and price via the Coinbase CDP Trade API on network
base. - 0x Swap API is used as a fallback when CDP will not route the pair.
- Quotes older than 30 seconds are refreshed; a worse minimum-output aborts. Slippage defaults to 1% and is clamped to 0.01%–5%.
- Where the provider requires it, an ERC-20 approval is submitted and its receipt confirmed before the swap transaction is sent. Permit2 signatures are appended for the CDP flow.
Tokenized stocks (B20)
- Holding and secondary-market trading of Coinbase B20 assets are permissionless; primary mint and redeem are Authorized Participant only.
- A buy or sell in-app is a single-hop Aerodrome Slipstream USDC pool swap — not CDP and not 0x.
- MPGR HUB implements no retail mint path of any kind.
Risk presentation
Before signing, the confirmation surface shows deterministic risk facts: unverified token, no liquidity, incomplete simulation, insufficient balance, irreversibility and network. These are computed from the quote and the catalog — never guessed.
See Docs → trading and Docs → tokenized stocks.
12. MPGR Run & the gaming ecosystem
MPGR Run is the flagship title: a one-tap endless runner using the official MPGR character art, with server-issued sessions, heartbeats and authoritative verification.
- Authoritative verification. The server replays the issued seed and the submitted input trace tick-for-tick, recomputes the score, and applies drift-tolerant timing checks alongside heartbeat, rate and idempotency gates.
- Progression. 8 XP per completed run, capped at 10 XP-earning runs per day. Verified runs also feed weekly stats and campaign scoring.
- Financial payouts are off by default. Competitive monetary rewards require two independent operator gates and the pipeline is fail-closed without both.
Anti-cheat status
In-process deterministic replay is implemented, but no independent anti-cheat audit has been performed. Anti-cheat hardening is listed as IN PROGRESS.
Additional titles (Clicker, Memory Challenge, Space Shooter, 2048 Daily, Pet Raising, Speed Run, Roguelike RPG, AI Battle Arena) exist in the game registry as coming soon and are never shown as playable. See Roadmap → gaming ecosystem.
13. Rewards & XP economy
The economy has one rule that matters: rewards are existing tokens from the treasury, never new supply.
XP and progression
- Fixed XP values: connect 50, daily check-in 20, profile 30, share 15, quest 40, referral 100, MPGR Run 8.
- XP drives levels and streaks; the authoritative total is a server-owned ledger, not the browser.
- Season points are derived from XP earned inside the current UTC month; the Season Pass adds a 20-level reward track over the same season.
Claiming
- Real MPGR claiming is on-chain via the deployed MPGRRewardVault (
claim/claimMultiple). A vault reward is allocated or claimed. - The Reward Hub groups rewards by category and only shows real numbers where a live provider exists behind that category.
- Local mock claim generation was removed — the hub does not invent claimable MPGR.
Gamification surfaces
- Achievements computed from the XP record and MPGR Run statistics.
- Global leaderboard sourced from the server ranking.
- Campaigns: config-driven events with their own points ledger and leaderboard, separate from global XP.
See Docs → rewards, Docs → XP and Docs → seasons.
14. Staking
Staking runs against the deployed MPGRStaking contract on Base.
Contract
0x1690C7b6d312284e30434d93498e56eE09fFa12c
Model
Single-sided MPGR staking; rewards paid in MPGR
Lock term
None — stake, claim or unstake at any time
Minimum stake
100 MPGR (contract constant)
Reward schedule
730 days (contract constant)
Reward pool
25,000,000 MPGR (contract constant)
APR bounds
1% – 100% (contract constants)
Actions
approve · stake · unstake · claimRewards · exit
Live APR, total staked, individual stakes and accrued rewards are read from the contract with short cache TTLs and background refresh. All actions are wallet-signed after an explicit confirmation.
Contract: view on BaseScan. Interface: /staking.
15. Token lock
Token lock runs against the deployed, immutable MPGRTokenLock V1 contract.
Contract
0x0cb910b19b9d0ab772375a0b2e49b84ccdd51550
Duration presets
30 · 90 · 180 · 365 days
Early unlock
Allowed any time with a fixed 10% on-chain penalty
Penalty split
90% returned to the locker, 10% to the penalty recipient
Drives
Premium tier and Holder Score
Actions
approve · createLock · withdraw · earlyUnlock
The penalty is a contract constant, not a UI decision: earlyUnlock() computes and executes the split on-chain. The app only previews it before you sign.
Contract: view on BaseScan. Interface: /app/token-lock.
16. $MPGR token utility
$MPGR is the unit of the MPGR HUB economy. It is a utility token, not a security, not an equity claim and not a promise of profit.
- Live utility. Staking yield; lock and holder commitment; vault claims; game and season incentives when the operator gates are on; referral and quest budgets; and the economic surface the Agent operates around (swaps, x402, portfolio).
- Reputation utility. Holder tier (badge, frame, governance voting weight, reputation bonus) and Premium multipliers (1.5× XP, 1.25× rewards) derived from on-chain positions.
- Future utility. Governance weight over treasury reallocation inside the 100,000,000 MPGR cap, emission rates, campaign budgets and the emergency reserve. Governance is PLANNED, not live.
No paid subscription
Premium is not sold. It is derived from MPGR you have locked on-chain, and it lapses automatically if you release enough of it.
17. Tokenomics
Name
MoneyPaiger
Symbol
MPGR
Network
Base (8453)
Maximum supply
1,000,000,000 MPGR
Decimals
18
Inflation
None
Future minting
None
Private sale
None
VC allocation
None
Locked team allocation
None
Token contract: 0xB2000000000000000000008d204203177a78AF01
Initial distribution
| Bucket | Amount | Share |
|---|---|---|
| Liquidity pool (Base DEX) | 900,000,000 | 90% |
| Community treasury | 100,000,000 | 10% |
The 90% liquidity allocation is already in market liquidity. The 10% treasury funds every MPGR HUB incentive; it is not a hidden team unlock.
Community treasury — 100,000,000 MPGR
Emission policy
Rewards are dynamic against user activity, remaining treasury, staking participation and seasons. No category emits forever, and rates can be slowed to protect the treasury. Unused category balances are not burned out of existence; future governance may reallocate undistributed treasury within the 100,000,000 cap. The maximum supply stays 1,000,000,000.
Full token page: /$MPGR → tokenomics
18. AI agent infrastructure
The Agent is designed so that no single model, vendor or prompt is a point of failure or a point of trust.
- Providers. A common interface with Gemini as the default, NVIDIA NIM and OpenAI implemented, and a deterministic on-device engine as the final fallback. Anthropic and Ollama are declared but unimplemented.
- Routing and resilience. Task classification picks a provider order; each network provider is wrapped in guardrails, a timeout, a circuit breaker and diagnostics.
- Prompt architecture. Trusted policy lives in the system channel; client and tool context is explicitly labelled untrusted so it cannot override it. Stable policy lives in code, not only in a prompt.
- Tool layer. Every tool declares schema, purpose, timeout and risk; prepares are separate from reads; no tool executes a wallet write.
- Cost control. Prompt and output caps, per-IP and per-wallet rate limits, and a daily AI token budget enforced atomically.
- Onchain layer. Coinbase AgentKit in prepare-only mode on Base with a read-action allowlist.
19. x402 & agentic payments
x402 is the payment path for agentic and machine-to-machine commerce. MPGR HUB implements it with the same confirmation discipline as trading.
- Discover. The resource is fetched and its 402 payment requirements parsed.
- Register. The server independently re-fetches the resource, applies SSRF and allowlist checks, and stores the server-observed terms. Client-supplied terms are not trusted.
- Confirm and sign. The user reviews amount, asset, recipient and resource, then signs an EIP-3009 TransferWithAuthorization.
- Submit. The payment is submitted against the stored registration, so the terms paid are exactly the terms approved.
Scope is deliberately narrow: Base mainnet only (eip155:8453), the exact scheme only, and a known-asset EIP-712 domain is required. There is no silent payment — AgentKit’s automatic payment actions are denied server-side.
See Docs → x402 and Roadmap → x402.
20. Provider & agent marketplace (future)
FUTURE — not shipped
None of the following exists in the product today. It describes direction only, and is tracked at Roadmap → AI & service marketplace and Roadmap → agent-to-agent economy.
The provider abstraction already in the codebase is what makes a marketplace plausible later: any model, tool or service that can satisfy the tool contract — schema, risk level, timeout, source attribution and confirmation behaviour — could be listed, priced and metered.
- Provider marketplace. Third-party models registering behind the same guardrail, timeout and budget stack.
- Service marketplace. Tools and agents listed with schemas and pricing, paid per call over x402.
- Agent-to-agent economy. Agents that discover, quote and pay each other inside budgets a human set, with receipts and an audit trail.
- Funding. The AI ecosystem line in the community treasury is the intended long-term incentive source. No allocation has been spent on this today.
21. Long-term ecosystem vision
The long-term goal is a Base-first onchain operating system: one identity, one agent, one rewards graph and one payment rail — where playing, trading, earning and delegating all share the same confirmation language and the same treasury.
- One agent surface. Research, execution, games, rewards and account control reachable from a single conversation.
- Bounded autonomy. Delegated, revocable permissions with onchain-enforceable budgets — always opt-in, always auditable.
- Open ecosystem. Public APIs, an SDK and partner integrations, so MPGR HUB modules can be used outside the app.
- Holder governance. Treasury, emissions and campaign budgets directed by the community within the fixed supply.
- Verifiable fun. Competitive play where the score, the ranking and the payout are all provably server-verified.
This section is directional. It is not a commitment, a timeline or an offer.
22. Roadmap
Status is tracked per area on the roadmap page, with four explicit labels: LIVE, IN PROGRESS, PLANNED and LONG-TERM VISION. No overall completion percentage is shown, because mixing shipped work with in-flight and directional items would be misleading.
Start here:
Full roadmap: /roadmap
23. Risks & limitations
| Risk | Honest status |
|---|---|
| Smart-contract risk | Contracts are deployed and covered by Foundry unit, fuzz and invariant tests in CI. An independent third-party audit has NOT been completed. |
| Game integrity | In-process deterministic replay, server sessions, heartbeats and timing/rate/idempotency gates are implemented. No independent anti-cheat certification has been performed, and an external verifier remains an additional operator gate. |
| Financial game rewards | Disabled by default. Two independent operator gates must both be enabled, and the pipeline is fail-closed otherwise. |
| Referral abuse | Self-referral is blocked and logged; re-attribution is rejected and logged; endpoints are authenticated and rate-limited. Sybil identity resistance is still being hardened. |
| Settlement durability | Settlement uses a lock and a reconciliation pass. Vault-level idempotency or a durable outbox is still in progress. |
| AI reliability | Model output can be wrong. It is treated as untrusted data, tool arguments are validated, and no write happens without confirmation — but a wrong answer can still be shown. |
| Market risk | Swaps, tokenized stocks and token prices are volatile. Slippage, liquidity and routing failures are possible; MPGR HUB does not guarantee execution at a quoted price. |
| Custody and key risk | You control your wallet. MPGR HUB cannot recover a lost seed phrase, reverse a confirmed transaction or refund a payment you approved. |
| Regulatory risk | Digital-asset regulation varies by jurisdiction and changes over time. Tokenized-stock access in particular may be restricted where you live. |
| Single-chain concentration | Base is the only supported chain. A Base outage, congestion or protocol failure affects the whole product. |
Track remediation at Roadmap → security.
24. Disclaimer
This whitepaper is informational. MPGR HUB provides technology services and does not provide financial, investment, legal or trading advice. $MPGR is a utility token on Base. Nothing here is an offer to sell or a solicitation to buy securities. Digital assets are volatile; do your own research; past performance is not indicative of future results.
MPGR HUB, MoneyPaiger and $MPGR are product and token names of the MPGR project. Base, Coinbase, Coinbase Wallet, Coinbase Developer Platform, USDC, Farcaster, Vercel, Aerodrome and 0x are trademarks of their respective owners. Mention does not imply partnership, endorsement or agency.
Reward vault contract: 0xbe4B0e8692670229129562a50A62f5173E30937C
This document may be updated. Version 2.0 reflects the product as of September 2026.