MPGR HUB · MoneyPaiger ($MPGR)

Whitepaper v2.0

An onchain operating system for agents, payments, games and holder utility — built natively on Base.

Public product documentation · September 2026 · Informational only, not an offer of securities and not financial advice

1. Executive summary

MoneyPaiger ($MPGR) is a fixed-supply utility token on Base, Coinbase’s Ethereum Layer 2. MPGR HUB is the product built around it: a Base-native application where a person talks to an AI agent, researches and prepares onchain actions, plays MPGR Run, earns XP and season points, stakes and locks $MPGR, and claims rewards from a vault.

The thesis is public and simple: token → app → AI → payments → onchain activity. MPGR HUB is not a ticker with a landing page; it is a shipping application deployed from GitHub to Vercel, running on Base mainnet only (chain ID 8453).

What is live today

CapabilityStatus
$MPGR token on BaseLIVE
Wallet connect — RainbowKit, Coinbase Wallet, Farcaster Mini AppLIVE
MPGR Agent — research, reason, prepare; user signsLIVE
Coinbase CDP Trade API with a 0x fallback (BYO wallet)LIVE
Coinbase B20 tokenized-stock research + Aerodrome Slipstream pathLIVE (prepare / confirm)
x402 payment proposalsLIVE (prepare / confirm)
MPGR Run, XP, seasons, leaderboard, check-in, referralsLIVE
Staking, token lock and reward vault clientsLIVE on Base
SIWE sessions and a server-owned XP ledgerLIVE

What is explicitly not claimed as finished

  • An independent third-party smart-contract audit.
  • Enabled competitive financial game payouts — operator-gated and fail-closed by default.
  • Onchain DAO governance.

All three are tracked in the roadmap, not presented as current guarantees.

2. Vision & mission

Vision: build the leading AI-powered onchain operating system on Base — one place where a user can talk to an agent that understands wallet and market context, research tokenized stocks and Base markets, prepare a trade, transfer or payment, confirm it in their own wallet, and play, earn, stake and belong to a season — without leaving Base.

Mission: reward real users, builders and contributors. Prefer long-term utility over short-term hype. Keep the token supply fixed. Fund rewards from a community treasury, not from inflation.

Token

MoneyPaiger (MPGR)

Product

MPGR HUB

Tagline

Play. Trade. Earn. With AI.

Network

Base (8453)

See About → why MPGR HUB exists.

3. Problem

Onchain products still ask ordinary people to be their own integration layer.

  • Fragmentation. Staking, locking, claiming, playing and trading usually live in five unrelated interfaces with five unrelated mental models.
  • High cost of intent. Turning “swap some USDC into a tokenized stock” into a safe, correct transaction means finding a route, understanding slippage, checking liquidity and reading raw calldata — or blindly trusting a button.
  • AI without guardrails. Most AI assistants can describe an onchain action but cannot safely prepare one, and the moment an assistant can sign, the user has lost the only control that mattered.
  • Rewards without trust. Points, streaks and leaderboards are easy to fake when the client reports the score and the server believes it.
  • Engagement without utility. Gamified crypto products often emit tokens to buy attention, which dilutes holders and ends badly.

4. Solution

MPGR HUB answers with one product built on four commitments.

  • One surface, four verbs. The Agent (Home) for research and preparation, Games for play, Rewards for progression, Staking and Token Lock for onchain commitment — all on Base, all with the same confirmation language.
  • Prepare, never presume. The Agent converts intent into a structured, validated proposal with the exact effect shown before signing. Deterministic code decides what is allowed; the model only suggests.
  • Server-owned truth. XP, ranking, referral attribution and game verification are computed server-side. The browser is a cache, never a witness.
  • Fixed supply, treasury-funded rewards. 1,000,000,000 MPGR, permanently. Every reward is an existing token from the community treasury — never newly minted supply.

Architecture detail: section 5. Product behaviour: Docs.

5. MPGR HUB architecture

MPGR HUB is a Next.js App Router application. Domain logic lives in typed modules; the client renders and signs; the server validates, prices, stores and verifies.

LayerImplementation
AppNext.js App Router, React, TypeScript (strict), Tailwind CSS
WalletsWagmi, Viem, RainbowKit, Farcaster Mini App connector
ChainBase mainnet only — one typed registry for chain ID, addresses, decimals and ABIs
AIPluggable providers (Gemini default, NVIDIA NIM, OpenAI) with a deterministic fallback; Coinbase AgentKit prepare-only
TradeCoinbase CDP Trade API, 0x Swap API fallback, Aerodrome Slipstream for B20
Paymentsx402 — exact scheme, USDC on Base, EIP-3009 TransferWithAuthorization
DataUpstash Redis / Vercel KV for sessions, XP ledger, referrals, leaderboard and game allocation
AuthSIWE nonce + signature, HMAC session cookie
ContractsMPGR token, MPGRStaking, MPGRTokenLock V1, MPGRRewardVault on Base
CIlint, typecheck, unit and security tests, high-severity audit script, Foundry contract tests, production build

Three product surfaces

  • Home — the Agent. There is no separate Agent tab. Home is an always-on command centre: status, suggested prompts, conversation, and shortcuts into research, trade and rewards.
  • Rewards — play and progression. MPGR Run, XP, level, streak, season, Season Pass, leaderboard, achievements, on-chain claims.
  • Profile — account control. Wallet, session, XP, holder tier, Premium, referrals, activity and sign-out.

Repository map: app/ pages and API routes, components/ UI, hooks/ client hooks, lib/ domain logic, contracts/ and test/ Solidity and Foundry tests.

6. The MPGR Agent

The Agent is the centre of MPGR HUB. It reads live context, retrieves facts through read-only tools, composes an answer, and — when the request is an action — produces a structured proposal for the user to confirm.

Capabilities today

  • Research $MPGR, Base markets and Coinbase B20 tokenized stocks.
  • Analyse portfolio and wallet context.
  • Prepare Base transfers, including Basename recipients.
  • Prepare swaps via Coinbase CDP with a 0x fallback.
  • Prepare B20 tokenized-stock orders on Aerodrome Slipstream.
  • Prepare x402 payments for agentic commerce.
  • Route the user into Rewards, Run, staking and lock flows.
  • Fall back to an on-device deterministic engine if no network model answers.

Hard limits

  • The Agent cannot sign, broadcast, approve or pay.
  • The Agent cannot choose a transaction destination; destinations are resolved from a typed registry.
  • The Agent cannot claim success before deterministic code confirms it.

Operational detail: Docs → MPGR Agent.

7. Research → planning → confirmation → execution → verification

The enforced loop is understand → research → reason → plan → confirm → execute → verify. It is a structural property of the codebase, not a prompt convention.

StageGuarantee
UnderstandA closed intent list. Unmatched input becomes research or help — never an action.
ResearchRead-only tools only. Facts carry their source and observation time; unavailable data is reported as unavailable.
ReasonPolicy sits in the system channel; model and tool output are untrusted data and cannot override it.
PlanDeterministic code builds the proposal and validates every field. There is no execute-mode tool in the registry.
ConfirmThe user sees amount, asset, destination or route, provider, slippage and risk facts, and must confirm.
ExecuteThe connected wallet signs. Where an approval is required, its receipt is confirmed before the main transaction is sent.
VerifyThe app waits for the receipt and checks its status. A revert is reported as a failure, never as success.

See Docs → Agent workflow for the same loop described at implementation level.

8. Agent safety & permission model

The model may suggest. Deterministic code decides. The wallet signs.

  • Allowlist, not denylist. AgentKit runs in prepare-only mode on Base; its signing, transfer and auto-payment actions are unreachable and are denied server-side even if a caller invents the action name.
  • Tool contract. Every tool declares a name, purpose, input schema, output shape, timeout and risk level. Write-capable tools require confirmation.
  • Risk levels. Read tools are low risk; prepare tools are medium (swap, B20 order, x402) or high (transfer) and always require an explicit confirmation step.
  • Closed navigation. When a reply should navigate, it resolves an intent through a fixed whitelist. A model never produces a route string.
  • Budgets and limits. Prompt and output caps, per-IP and per-wallet rate limits, a daily AI token budget, and bounded execution parameters (slippage 1–500 bps, 30-second quote freshness).
  • Untrusted-data discipline. User text, memory, tool output and model output are all treated as untrusted; only validated tool arguments reach the execution layer.

FUTURE — configurable autonomy

User-set spend caps, per-action allowance limits and revocable delegated permissions are not implemented. They are tracked at Roadmap → autonomous agent permissions. Today the guarantee is absolute: one action, one confirmation.

9. Wallet & security model

MPGR HUB is non-custodial by construction. Reads are open; writes require a signed session and a wallet signature.

  • Session over address. A nonce, a SIWE signature and an HMAC session cookie. Server handlers take the wallet from the session, never from request JSON.
  • No secrets client-side. No private key, API secret or CDP credential is exposed under a NEXT_PUBLIC_ name.
  • Browser values are a cache. XP, scores, referrals, ranks and reward claims from the browser are never trusted for ranking or payouts.
  • Bigint token math. Integer or bigint arithmetic only — never floating-point accounting.
  • Validated boundaries. Shape, size, range, origin and authorization are checked at every API route. Provider, RPC, Redis and stack-trace errors are never returned raw.
  • Fail-closed money paths. Financial game settlement requires both operator gates; if either is off, nothing is paid.

Full list: Docs → security model and Docs → approval boundaries.

10. Base ecosystem

MPGR HUB is Base-native by design. There is no multi-chain runtime today, no bridge and no cross-chain execution path.

LayerHow MPGR HUB uses it
Base mainnetSole production chain (8453) — low fees, fast finality, Ethereum security assumptions
Coinbase Wallet / Base AppFirst-class connection path through RainbowKit
Coinbase CDP Trade APIOnchain swaps for ETH / WETH / USDC / MPGR and Base ERC-20, BYO wallet
Coinbase B20 tokenized stocksResearch plus Aerodrome Slipstream USDC pools; no retail mint API
USDC on BaseSettlement asset for swaps and x402 payments
Farcaster Mini AppDistribution and auto-connect on the Base / Farcaster graph
BasenamesHuman-readable transfer recipients, resolved server-side
VercelProduction host, GitHub-connected

The Agent never custodially trades a brokerage account, and MPGR HUB is not an authorized participant or a broker-dealer. Naming Coinbase, Base, USDC, Farcaster, Aerodrome, 0x or Vercel describes public infrastructure — it is not a claim of partnership or endorsement.

See Docs → Base ecosystem and Roadmap → Base expansion.

11. Trading & execution architecture

MPGR HUB does not invent a DEX, a stock mint API or a custodial broker. It composes public Base infrastructure behind one confirmation boundary.

Regular tokens

  • Quote and price via the Coinbase CDP Trade API on network base.
  • 0x Swap API is used as a fallback when CDP will not route the pair.
  • Quotes older than 30 seconds are refreshed; a worse minimum-output aborts. Slippage defaults to 1% and is clamped to 0.01%–5%.
  • Where the provider requires it, an ERC-20 approval is submitted and its receipt confirmed before the swap transaction is sent. Permit2 signatures are appended for the CDP flow.

Tokenized stocks (B20)

  • Holding and secondary-market trading of Coinbase B20 assets are permissionless; primary mint and redeem are Authorized Participant only.
  • A buy or sell in-app is a single-hop Aerodrome Slipstream USDC pool swap — not CDP and not 0x.
  • MPGR HUB implements no retail mint path of any kind.

Risk presentation

Before signing, the confirmation surface shows deterministic risk facts: unverified token, no liquidity, incomplete simulation, insufficient balance, irreversibility and network. These are computed from the quote and the catalog — never guessed.

See Docs → trading and Docs → tokenized stocks.

12. MPGR Run & the gaming ecosystem

MPGR Run is the flagship title: a one-tap endless runner using the official MPGR character art, with server-issued sessions, heartbeats and authoritative verification.

  • Authoritative verification. The server replays the issued seed and the submitted input trace tick-for-tick, recomputes the score, and applies drift-tolerant timing checks alongside heartbeat, rate and idempotency gates.
  • Progression. 8 XP per completed run, capped at 10 XP-earning runs per day. Verified runs also feed weekly stats and campaign scoring.
  • Financial payouts are off by default. Competitive monetary rewards require two independent operator gates and the pipeline is fail-closed without both.

Anti-cheat status

In-process deterministic replay is implemented, but no independent anti-cheat audit has been performed. Anti-cheat hardening is listed as IN PROGRESS.

Additional titles (Clicker, Memory Challenge, Space Shooter, 2048 Daily, Pet Raising, Speed Run, Roguelike RPG, AI Battle Arena) exist in the game registry as coming soon and are never shown as playable. See Roadmap → gaming ecosystem.

13. Rewards & XP economy

The economy has one rule that matters: rewards are existing tokens from the treasury, never new supply.

XP and progression

  • Fixed XP values: connect 50, daily check-in 20, profile 30, share 15, quest 40, referral 100, MPGR Run 8.
  • XP drives levels and streaks; the authoritative total is a server-owned ledger, not the browser.
  • Season points are derived from XP earned inside the current UTC month; the Season Pass adds a 20-level reward track over the same season.

Claiming

  • Real MPGR claiming is on-chain via the deployed MPGRRewardVault (claim / claimMultiple). A vault reward is allocated or claimed.
  • The Reward Hub groups rewards by category and only shows real numbers where a live provider exists behind that category.
  • Local mock claim generation was removed — the hub does not invent claimable MPGR.

Gamification surfaces

  • Achievements computed from the XP record and MPGR Run statistics.
  • Global leaderboard sourced from the server ranking.
  • Campaigns: config-driven events with their own points ledger and leaderboard, separate from global XP.

See Docs → rewards, Docs → XP and Docs → seasons.

14. Staking

Staking runs against the deployed MPGRStaking contract on Base.

Contract

0x1690C7b6d312284e30434d93498e56eE09fFa12c

Model

Single-sided MPGR staking; rewards paid in MPGR

Lock term

None — stake, claim or unstake at any time

Minimum stake

100 MPGR (contract constant)

Reward schedule

730 days (contract constant)

Reward pool

25,000,000 MPGR (contract constant)

APR bounds

1% – 100% (contract constants)

Actions

approve · stake · unstake · claimRewards · exit

Live APR, total staked, individual stakes and accrued rewards are read from the contract with short cache TTLs and background refresh. All actions are wallet-signed after an explicit confirmation.

Contract: view on BaseScan. Interface: /staking.

15. Token lock

Token lock runs against the deployed, immutable MPGRTokenLock V1 contract.

Contract

0x0cb910b19b9d0ab772375a0b2e49b84ccdd51550

Duration presets

30 · 90 · 180 · 365 days

Early unlock

Allowed any time with a fixed 10% on-chain penalty

Penalty split

90% returned to the locker, 10% to the penalty recipient

Drives

Premium tier and Holder Score

Actions

approve · createLock · withdraw · earlyUnlock

The penalty is a contract constant, not a UI decision: earlyUnlock() computes and executes the split on-chain. The app only previews it before you sign.

Contract: view on BaseScan. Interface: /app/token-lock.

16. $MPGR token utility

$MPGR is the unit of the MPGR HUB economy. It is a utility token, not a security, not an equity claim and not a promise of profit.

  • Live utility. Staking yield; lock and holder commitment; vault claims; game and season incentives when the operator gates are on; referral and quest budgets; and the economic surface the Agent operates around (swaps, x402, portfolio).
  • Reputation utility. Holder tier (badge, frame, governance voting weight, reputation bonus) and Premium multipliers (1.5× XP, 1.25× rewards) derived from on-chain positions.
  • Future utility. Governance weight over treasury reallocation inside the 100,000,000 MPGR cap, emission rates, campaign budgets and the emergency reserve. Governance is PLANNED, not live.

No paid subscription

Premium is not sold. It is derived from MPGR you have locked on-chain, and it lapses automatically if you release enough of it.

17. Tokenomics

Name

MoneyPaiger

Symbol

MPGR

Network

Base (8453)

Maximum supply

1,000,000,000 MPGR

Decimals

18

Inflation

None

Future minting

None

Private sale

None

VC allocation

None

Locked team allocation

None

Token contract: 0xB2000000000000000000008d204203177a78AF01

Initial distribution

BucketAmountShare
Liquidity pool (Base DEX)900,000,00090%
Community treasury100,000,00010%

The 90% liquidity allocation is already in market liquidity. The 10% treasury funds every MPGR HUB incentive; it is not a hidden team unlock.

Community treasury — 100,000,000 MPGR

Staking rewards30,000,000
Mini games15,000,000
Community quests12,000,000
Daily check-in10,000,000
Seasonal campaigns10,000,000
Referral program8,000,000
AI ecosystem rewards5,000,000
Community airdrops5,000,000
Ecosystem partnerships3,000,000
Emergency reserve2,000,000

Emission policy

Rewards are dynamic against user activity, remaining treasury, staking participation and seasons. No category emits forever, and rates can be slowed to protect the treasury. Unused category balances are not burned out of existence; future governance may reallocate undistributed treasury within the 100,000,000 cap. The maximum supply stays 1,000,000,000.

Full token page: /$MPGR → tokenomics

18. AI agent infrastructure

The Agent is designed so that no single model, vendor or prompt is a point of failure or a point of trust.

  • Providers. A common interface with Gemini as the default, NVIDIA NIM and OpenAI implemented, and a deterministic on-device engine as the final fallback. Anthropic and Ollama are declared but unimplemented.
  • Routing and resilience. Task classification picks a provider order; each network provider is wrapped in guardrails, a timeout, a circuit breaker and diagnostics.
  • Prompt architecture. Trusted policy lives in the system channel; client and tool context is explicitly labelled untrusted so it cannot override it. Stable policy lives in code, not only in a prompt.
  • Tool layer. Every tool declares schema, purpose, timeout and risk; prepares are separate from reads; no tool executes a wallet write.
  • Cost control. Prompt and output caps, per-IP and per-wallet rate limits, and a daily AI token budget enforced atomically.
  • Onchain layer. Coinbase AgentKit in prepare-only mode on Base with a read-action allowlist.

See Docs → AI architecture and Roadmap → AI provider layer.

19. x402 & agentic payments

x402 is the payment path for agentic and machine-to-machine commerce. MPGR HUB implements it with the same confirmation discipline as trading.

  • Discover. The resource is fetched and its 402 payment requirements parsed.
  • Register. The server independently re-fetches the resource, applies SSRF and allowlist checks, and stores the server-observed terms. Client-supplied terms are not trusted.
  • Confirm and sign. The user reviews amount, asset, recipient and resource, then signs an EIP-3009 TransferWithAuthorization.
  • Submit. The payment is submitted against the stored registration, so the terms paid are exactly the terms approved.

Scope is deliberately narrow: Base mainnet only (eip155:8453), the exact scheme only, and a known-asset EIP-712 domain is required. There is no silent payment — AgentKit’s automatic payment actions are denied server-side.

See Docs → x402 and Roadmap → x402.

20. Provider & agent marketplace (future)

FUTURE — not shipped

None of the following exists in the product today. It describes direction only, and is tracked at Roadmap → AI & service marketplace and Roadmap → agent-to-agent economy.

The provider abstraction already in the codebase is what makes a marketplace plausible later: any model, tool or service that can satisfy the tool contract — schema, risk level, timeout, source attribution and confirmation behaviour — could be listed, priced and metered.

  • Provider marketplace. Third-party models registering behind the same guardrail, timeout and budget stack.
  • Service marketplace. Tools and agents listed with schemas and pricing, paid per call over x402.
  • Agent-to-agent economy. Agents that discover, quote and pay each other inside budgets a human set, with receipts and an audit trail.
  • Funding. The AI ecosystem line in the community treasury is the intended long-term incentive source. No allocation has been spent on this today.

21. Long-term ecosystem vision

The long-term goal is a Base-first onchain operating system: one identity, one agent, one rewards graph and one payment rail — where playing, trading, earning and delegating all share the same confirmation language and the same treasury.

  • One agent surface. Research, execution, games, rewards and account control reachable from a single conversation.
  • Bounded autonomy. Delegated, revocable permissions with onchain-enforceable budgets — always opt-in, always auditable.
  • Open ecosystem. Public APIs, an SDK and partner integrations, so MPGR HUB modules can be used outside the app.
  • Holder governance. Treasury, emissions and campaign budgets directed by the community within the fixed supply.
  • Verifiable fun. Competitive play where the score, the ranking and the payout are all provably server-verified.

This section is directional. It is not a commitment, a timeline or an offer.

22. Roadmap

Status is tracked per area on the roadmap page, with four explicit labels: LIVE, IN PROGRESS, PLANNED and LONG-TERM VISION. No overall completion percentage is shown, because mixing shipped work with in-flight and directional items would be misleading.

Start here:

Full roadmap: /roadmap

23. Risks & limitations

RiskHonest status
Smart-contract riskContracts are deployed and covered by Foundry unit, fuzz and invariant tests in CI. An independent third-party audit has NOT been completed.
Game integrityIn-process deterministic replay, server sessions, heartbeats and timing/rate/idempotency gates are implemented. No independent anti-cheat certification has been performed, and an external verifier remains an additional operator gate.
Financial game rewardsDisabled by default. Two independent operator gates must both be enabled, and the pipeline is fail-closed otherwise.
Referral abuseSelf-referral is blocked and logged; re-attribution is rejected and logged; endpoints are authenticated and rate-limited. Sybil identity resistance is still being hardened.
Settlement durabilitySettlement uses a lock and a reconciliation pass. Vault-level idempotency or a durable outbox is still in progress.
AI reliabilityModel output can be wrong. It is treated as untrusted data, tool arguments are validated, and no write happens without confirmation — but a wrong answer can still be shown.
Market riskSwaps, tokenized stocks and token prices are volatile. Slippage, liquidity and routing failures are possible; MPGR HUB does not guarantee execution at a quoted price.
Custody and key riskYou control your wallet. MPGR HUB cannot recover a lost seed phrase, reverse a confirmed transaction or refund a payment you approved.
Regulatory riskDigital-asset regulation varies by jurisdiction and changes over time. Tokenized-stock access in particular may be restricted where you live.
Single-chain concentrationBase is the only supported chain. A Base outage, congestion or protocol failure affects the whole product.

Track remediation at Roadmap → security.

24. Disclaimer

This whitepaper is informational. MPGR HUB provides technology services and does not provide financial, investment, legal or trading advice. $MPGR is a utility token on Base. Nothing here is an offer to sell or a solicitation to buy securities. Digital assets are volatile; do your own research; past performance is not indicative of future results.

MPGR HUB, MoneyPaiger and $MPGR are product and token names of the MPGR project. Base, Coinbase, Coinbase Wallet, Coinbase Developer Platform, USDC, Farcaster, Vercel, Aerodrome and 0x are trademarks of their respective owners. Mention does not imply partnership, endorsement or agency.

Reward vault contract: 0xbe4B0e8692670229129562a50A62f5173E30937C

This document may be updated. Version 2.0 reflects the product as of September 2026.