Developers

Contract architecture

BNBrokers is a set of immutable, non-proxy modules with explicit reserve, routing and administrative boundaries.

Published addresses

$BNBROKERS

0x0000000000000000000000000000000000000000

Core ownership

ContractResponsibility
BrokerTokenFixed-supply BNBROKERS with Permit and Burnable
BNBrokersNFTMint, ERC-721 ownership, ERC-2981 royalty and account creation
BrokerAccountRegistryERC-6551 account deployment and address derivation
BrokerAccountOwner-controlled token-bound execution account
OpeningPositionDistributorPre-funded bStock selection and mint-time delivery
BrokerRendererUnrevealed and revealed on-chain token metadata

The NFT contract is the ownership root. Broker Accounts resolve authority from the current ERC-721 owner rather than maintaining a separate controller.

Economics and liquidity

ContractResponsibility
ProtocolReserveMarket, Credit and treasury BNBROKERS bucket accounting
BrokerMarketFIFO inventory, specific selection and fixed-price trading
BrokerLicenseLicense costs, burns, weights and historical checkpoints
MarginDeskFixed-principal loans, repayment and liquidation
PancakeV3TwapOracleFast/slow TWAP, bounds, spike checks and configured fallback

ProtocolReserve exposes module-specific methods rather than a generic withdrawal surface. Market and Margin Desk permissions are wired during deployment and frozen with the rest of the protocol economics.

bStocks and distributions

ContractResponsibility
BStockRegistryAuthorized assets, paths, output floors and enabled state
PancakeV3BStockRouterNative wrapping and authorized Pancake V3 swaps
DistributionEngineSnapshot, purchase, paginated allocation and accounting
MarketHoursMarket-funded DistributionEngine deployment
AfterHoursRoyalty-funded DistributionEngine deployment

The router and registry are immutable references inside each engine. The engine may select only registered assets, and the router may be called only by explicitly authorized modules.

Administration

There are no upgradeable proxies.

Roles are separated:

  • DEFAULT_ADMIN_ROLE controls final administration and irreversible freezes;
  • CONFIG_ROLE sets pre-freeze operational and economic configuration;
  • KEEPER_ROLE starts and services distribution operations;
  • PAUSER_ROLE pauses new risk-creating actions.

Administrative control uses OpenZeppelin's delayed default-admin transfer and supports assignment to a multisig and timelock.

Pauses are deliberately asymmetric: new minting, market actions, licenses, rounds and loans can stop, while loan repayment and native-credit withdrawal remain available.