Contract architecture
BNBrokers is a set of immutable, non-proxy modules with explicit reserve, routing and administrative boundaries.
Published addresses
$BNBROKERS
0x0000000000000000000000000000000000000000Core ownership
| Contract | Responsibility |
|---|---|
BrokerToken | Fixed-supply BNBROKERS with Permit and Burnable |
BNBrokersNFT | Mint, ERC-721 ownership, ERC-2981 royalty and account creation |
BrokerAccountRegistry | ERC-6551 account deployment and address derivation |
BrokerAccount | Owner-controlled token-bound execution account |
OpeningPositionDistributor | Pre-funded bStock selection and mint-time delivery |
BrokerRenderer | Unrevealed and revealed on-chain token metadata |
The NFT contract is the ownership root. Broker Accounts resolve authority from the current ERC-721 owner rather than maintaining a separate controller.
Economics and liquidity
| Contract | Responsibility |
|---|---|
ProtocolReserve | Market, Credit and treasury BNBROKERS bucket accounting |
BrokerMarket | FIFO inventory, specific selection and fixed-price trading |
BrokerLicense | License costs, burns, weights and historical checkpoints |
MarginDesk | Fixed-principal loans, repayment and liquidation |
PancakeV3TwapOracle | Fast/slow TWAP, bounds, spike checks and configured fallback |
ProtocolReserve exposes module-specific methods rather than a generic withdrawal surface. Market and Margin Desk permissions are wired during deployment and frozen with the rest of the protocol economics.
bStocks and distributions
| Contract | Responsibility |
|---|---|
BStockRegistry | Authorized assets, paths, output floors and enabled state |
PancakeV3BStockRouter | Native wrapping and authorized Pancake V3 swaps |
DistributionEngine | Snapshot, purchase, paginated allocation and accounting |
MarketHours | Market-funded DistributionEngine deployment |
AfterHours | Royalty-funded DistributionEngine deployment |
The router and registry are immutable references inside each engine. The engine may select only registered assets, and the router may be called only by explicitly authorized modules.
Administration
There are no upgradeable proxies.
Roles are separated:
DEFAULT_ADMIN_ROLEcontrols final administration and irreversible freezes;CONFIG_ROLEsets pre-freeze operational and economic configuration;KEEPER_ROLEstarts and services distribution operations;PAUSER_ROLEpauses new risk-creating actions.
Administrative control uses OpenZeppelin's delayed default-admin transfer and supports assignment to a multisig and timelock.
Pauses are deliberately asymmetric: new minting, market actions, licenses, rounds and loans can stop, while loan repayment and native-credit withdrawal remain available.