01 / THE RULESSix lines, and nothing else
- Every six hours, one coin flips. Launch day ramps into it: four flips an hour apart, then four three hours apart, then every six hours forever — ten flips in the first day.
- Your last $FLIP trade puts you on a side: a buy is HEADS, a sell is TAILS — any amount, from any wallet, on Base or cross-chain.
- Your position stays until you trade again. You never re-confirm it.
- Your entire $FLIP balance at the snapshot is your stake.
- The winning side splits the pot pro-rata by stake.
- drand picks the side. Positions lock at the bell, before anyone can know the coin.
There are no tiers, no locks, no minimum hold, no dust floor, no streak bonuses, no referrals. Tokens someone else pays for do not change your side.
02 / SIDESWhat counts as your trade
Only trades through the $FLIP/WETH pool Clanker created set a side. Trades on any other pool do not, and the protocol's own fee conversions are not trades.
In such a transaction, every initiator is sided by its own balance change: more $FLIP is HEADS, less is TAILS. The initiators are the wallet that sent the transaction, any smart account whose own operation succeeded, and any Safe that executed in it — so a smart wallet is sided like any other. Contracts that did not initiate — pools, routers, bridges, settlement contracts — are never sided.
Wallets that did not initiate follow two rules instead. If $FLIP leaves one, it is TAILS: tokens cannot leave without its owner's signature or approval, so an intent sell, a permit sell or a cross-chain sell all count. If $FLIP arrives, see below.
Tokens that arrive without you sending the transaction
If $FLIP simply lands in your wallet, it counts as a buy only when it is your first trade ever, or when you paid for it yourself. "Paid for it yourself" means one of:
- A signed order on Base. The transaction filled an order you signed on CoW, UniswapX, 1inch or 0x Gasless that names you as the recipient, or the whole transaction was your own relayed call through a listed gasless wallet (Calibur, Turnkey, MetaMask's delegations, thirdweb and others).
- A cross-chain buy you paid for. Through Relay, Across, deBridge or Mayan, paid from the same address on another listed chain, or from a Solana wallet linked to yours by your own earlier Relay sell. The order has to name $FLIP and name you as where it goes.
Each of those facts is checked on the chain it happened on: the signature the protocol verified, the deposit that paid for the order, the payout that links a Solana wallet. One thing is not on-chain anywhere: a Relay order's recipient. Relay's own solvers send those fills, one order each, and Relay is trusted to deliver an order as it was placed.
Tokens added beyond what your order or payment names — a filler's gift, a relayer's extra transfer — do not count for a wallet that already has a side. For Across, deBridge and Mayan, what counts is the order's own destination field: Across's recipient, or the swap its deposit asked for — read only for the contract that carries it out, and only when that contract's own record says it went through — deBridge's receiver, Mayan's destination. An order written in a format that cannot be read counts for nobody, so an unfamiliar route leaves your side where it was.
03 / THE CLOCKThe bell, and what it freezes
The schedule is a formula, not a table. On launch day four flips are one hour apart, then four are three hours apart, then it settles to every six hours forever. Ten flips land in the first day. Anyone can compute flip #500's timestamp on launch day.
Anyone may ring the bell once its time has passed; whoever does is paid a small fixed bounty by the vault. Ringing it freezes four things at once:
- Positions, as of the end of the block before the bell.
- The pot, reserved for that flip alone.
- The drand round that will decide the coin — a round about five minutes in the future.
- The entropy: the hash of the block before the bell.
A flip is never cancelled. There is no void function. If the list is late or the drand round is late, the flip waits and resolves exactly as it would have on time, while later bells keep ringing on schedule with their own pots.
04 / THE LISTWho was on which side
After the bell, the list of wallets, sides and balances is folded from public chain data and published on-chain as a Merkle root, together with both sides' totals, the snapshot block, and a hash of the registry of addresses the fold used.
Publishing the list is the one job that is not permissionless: it belongs to a Safe, and the Safe's only power is publishing. It cannot move funds, change the clock, or touch a coin.
Because the inputs are public, anyone can rebuild the same list from chain data with the open-source verify tool and compare it to what was committed. A list that does not match its own totals cannot pay out more than that flip's own pot, so a wrong list can never reach another flip's COINc.
05 / THE COINDecided by a beacon, checked by the vault
The coin is keccak256(drand randomness ‖ entropy) % 2 — zero is HEADS, one is TAILS.
The randomness comes from drand quicknet, the public beacon run by the League of Entropy, which publishes a round every three seconds. The round that decides a flip is fixed when the bell rings — about five minutes before that round exists — and its value is the same for everyone in the world.
The vault verifies drand's threshold signature itself, on-chain, against a public key fixed at deploy. There is no oracle contract, no subscription and no vendor that can retire a version: the check is mathematics. Anyone may deliver the signature, and whoever does is paid a bounty.
Why two ingredients
A beacon alone is scheduled by clock time, and a contract's clock is the sequencer's: right after a Base outage, catch-up blocks can carry old timestamps, so a round "after the bell" could already be public. The block hash closes that gap, because it does not exist until the positions it freezes are sealed. The one exception is disclosed below.
06 / THE POTTrading fees, turned into COINc
Every trade through the pool pays a 3% fee. Clanker keeps a fifth of it; the rest goes to the vault, which has no withdraw function. The fee stream's recipient was locked at launch, so it cannot be redirected.
Fees arrive as WETH from Clanker's fee locker, and anyone may unwrap the vault's WETH into ETH. The pot itself is COINc, Coinbase's tokenized COIN, and anyone may convert between the two by calling the vault: you sell it COINc and it pays you its ETH, priced against Chainlink's COIN and ETH/USD feeds — not against COINc's own market.
- A descending auction. The discount the vault will accept grows from nothing to 2% over half an hour, and every conversion pushes that ramp back in proportion to its size, so fillers compete on price instead of gas.
- A volume limit. Conversions draw on an allowance that refills steadily, so dust calls use dust-sized allowance and cannot block real fills.
- Market hours. Conversion is refused from Saturday to Monday morning UTC, and whenever the COIN feed is more than 25 hours old or ETH/USD more than an hour old. Weekend fees convert on Monday.
- If the feeds die. After fourteen days without a fresh price, the vault runs its own oracle-free descending auction, stepping down 10% a cycle and never below a floor of one thirty-second of the last price it saw.
COINc is a token that tracks the price of COIN. It is not shares, and it is not ownership.
07 / PAYOUTSPro-rata, pushed, and never stranded
Each winner gets the flip's pot times their stake, divided by the winning side's total stake, rounded down. In other words, you receive the same fraction of the pot as your fraction of the winning side's stake: hold 1% of the stake on the winning side and you get 1% of the pot. What share that is of all $FLIP does not matter — only the share of the side that won.
- Claims are pushed for you: the bot pays every winner owed more than about 25 cents, in batches, shortly after the flip settles.
- Anyone can claim for anyone, with the flip's list, for 90 days.
- If COINc's issuer has paused the token or blocked a wallet, that claim is skipped and stays claimable; the rest are paid.
- Whatever is unclaimed after 90 days returns to the pot.
- If nobody is on the winning side, the coin still lands and the whole pot rolls into the next flip.
08 / WHAT NOBODY CAN CHANGEIncluding whoever built it
- The vault has no owner, no proxy, no upgrade path and no parameter setters. Every parameter is fixed at deploy.
- There is no withdraw function. COINc leaves the vault only through a claim against a published list.
- The clock is a formula. No one can move, add or cancel a flip.
- The fee stream is locked to the vault: nobody can redirect it or change what it is paid in.
- The coin is drand's signature verified on-chain. No key, no oracle account, no subscription to lapse.
- The Safe that publishes lists can rotate the hot key that does it, and nothing else.
Everything else — ringing the bell, revealing the coin, claiming for anyone, sweeping, converting fees, unwrapping — is permissionless. Three of those jobs pay a fixed bounty in ETH to whoever does them, once each per flip: ringing the bell, publishing the list, and revealing the coin. The bounty is skipped when the vault is short of ETH or the recipient refuses it, and nothing blocks when it is. That is how the protocol pays for its own upkeep.
09 / WHAT YOU TRUSTStated plainly
- The list is an assertion — reproducible by anyone from public data. A wrong or dishonest list can misdirect at most that flip's own pot.
- Whoever publishes the list sees the coin first, because the deciding round goes public about five minutes after the bell. They cannot change it; they could delay publishing, which leaves that flip's pot waiting, since there is no expiry.
- drand is honest-threshold. A large colluding group of League of Entropy members could predict rounds.
- During a Base outage that overlaps a bell, catch-up blocks can carry old timestamps, so whoever rings that bell might already see the deciding round. This is the one failure mode the rules accept, and it only happens while the chain itself is disrupted.
- Chainlink feeds price the fee conversion. A retired feed falls back to the vault's own auction after fourteen days; a live but wrong feed can mis-sell at most one allowance.
- COINc's issuer can pause the token or block addresses. Claims then wait, and stay claimable.
- Parking. Stakes are balances at the snapshot, so a holder can move tokens between their own wallets on different sides before a bell. It is visible on-chain and it costs gas.
- The bridges. Across's SpokePool and deBridge's destination contract are upgradeable by their teams, and Mayan rests on Circle attesting the burn; a compromised bridge could move a wallet's side. Relay's buys additionally rest on Relay's own records where the chains do not say it: which order a fill delivers, who an order paid out to, and who placed an order its relayer sent.
- Intent protocols and wallet code. A signed-order buy rests on the pinned contract that checked the signature — CoW, the UniswapX reactors, 1inch, and 0x's registry of its genuine Settlers — and, for gasless EIP-7702 wallets, on the listed wallet implementations. One of those has no published source and is listed on bytecode checks: evidence, not proof. A compromised protocol could move a wallet's side.
None of these can take COINc out of the vault: it leaves only through claims against a published list, and no list can pay more than its own flip's pot. What they could change is which side a wallet is on — and that changes who shares that pot.
10 / CHECK IT YOURSELFNothing here needs taking on faith
- The coin. Take the flip's drand round from its receipt, fetch it from drand's public API, and hash it with the entropy the bell froze. Anyone gets the same bit.
- The list. Run the open-source verify tool for that flip: it rebuilds the list from public logs and archive balances and prints whether the root matches what was committed on-chain.
- The money. Every bell, list and coin is a transaction, linked from its row in the receipts table on the front page, along with the drand round it used.
- The rules. The vault's parameters are immutable and readable on-chain; the schedule is a pure function you can call for any flip number.
11 / NUMBERS AND ADDRESSESThe constants, as deployed
| Flip interval | 6 hours |
|---|---|
| Launch ramp | 4 flips 1 hour apart, 4 flips 3 hours apart, then 6 hours |
| Pool fee | 3% of every trade |
| Claim window | 90 days, then back to the pot |
| Auto-paid above | about $0.25 of COINc |
| Conversion discount | 0 → 2% over 30 minutes |
| Feed age limits | COIN 25 hours · ETH/USD 1 hour |
| Fallback auction after | 14 days of dead feeds |
| Keeper bounty | fixed, at most 3 per flip |
Addresses
| Vault | — |
|---|---|
| $FLIP | — |
| Prize | COINc · 0xb200000000000000000000c85a31389D71F3ecfb |
| Registry | — |