Whitepaper · a design overview
Brim
A floor that never dilutes. A yield that overflows.
The reserve funds the floor.
Nothing mints unpaid.
(3,3) with a redeem button.
This page is the full description of Brim's design, checked against the contracts, and the current statement of its launch settings. The yellow paper is the compact formal version, also in Chinese, Korean, and Japanese. The contracts are the final word on any mechanism; this page is not a yield card. The protocol is Brim and its token is BRIM. The only genuine BRIM is the token at the contract address published by @Brim_HQ. Nothing trading under these names before genesis is this protocol.
Numbers on this page are the launch configuration, dated September 2026. Section 18 lists every one with its bound and who enforces it; section 20 says who may change it, and on what delay.
The launch in nine numbers. Each is a dial with a bound; none is a promise.
The idea
What is this?
01What Brim is
A reserve. A reason to stay. A way to leave.
Why this exists
Tokenized stocks trade on Robinhood Chain now. Between trades, most of them do nothing. Nobody has put three things in one token: a basket of those assets that pays a yield, a yield paid only from money that has already arrived, and the basket itself handed back to anyone who asks.
The designs that came close took one of two shortcuts. Some paid a yield by printing it, and the token was worth a little less every time it was paid. Some promised a floor and kept it on a dashboard, so the day the premium died, the only exit was the market. We could not find a design that did all three, so we built one that refuses both shortcuts and lets anyone check the refusal in the mint itself.
The one-paragraph version
Brim is a protocol on Robinhood Chain that turns a basket of tokenized stocks into a yield-bearing token, BRIM. The basket is the reserve. The yield is what the protocol makes from it. The reserve fills to a line the protocol calls the brim: book value per token, what one BRIM's slice of the reserve is worth at accepted prices. New BRIM is only ever sold above that line, and whatever a buyer pays above it is surplus. A split the protocol calls the Waterfall divides the surplus among stronger backing, operating capital, overflow for stakers, and a small developer share. Stakers watch their balance grow in the token itself. New reward tokens are minted into the staked pool, and only against revenue that has already arrived: offering premiums, trading tolls, and profit the operating desk returns. A finite allocation set aside at genesis tops rewards up when those fall short of a target. Any holder can hand BRIM back to the protocol and take their pro-rata slice of the reserve, in kind, while the Tap is open. That is the redeem button.
The genesis plan backs the initial supply with tokenized Nvidia, the first asset in the reserve. After genesis, every registered mint path passes a backing check in the transaction that performs it: no sale, no reward, and no payout to anyone mints a token that was not paid for at the brim or above. Which contracts may mint is a governed list (15). There are no VCs, no insiders, and no pre-sale. The launch is open to anyone who wants to play. Top Juicers will be first in line.
The reserve is meant to be a basket of tokenized stocks. It opens with one, tokenized Nvidia, for two practical reasons: the genesis event takes in one asset, and the token's pool has to be quoted in one. After genesis the Policy Board admits more stocks behind its timelock, each with a live price (15), and every redemption pays a slice of whatever the reserve holds at the time. The sections below say "the reserve" for the whole basket.
Why it has not been built before
The parts are old. Olympus showed that a token sold above its backing can fund a staking flywheel, then minted its rewards on a schedule until the flywheel ran the other way. Terra showed that a backstop which pays is worth having, then made the backstop mint more of the thing that was falling. Reserve-style baskets showed honest onchain redemption, then let two-way minting and redemption pull the price to basket value, so a premium never lasts. Each kept a good idea and gave something up for it. Brim keeps the three good ideas and takes none of the shortcuts. The premium-issuance flywheel stays, with rewards minted only against revenue that has landed. The floor is a function anyone can call, with no mint on the way out. The basket can be taken in kind, with no pin holding the token to it. One inequality does the work, and the contract that mints checks it on every mint. The long form, with Ampleforth and NET beside them, is 16.
Why hold BRIM
Why hold BRIM rather than the basket itself? Any holder can hand BRIM back and take their slice of the reserve at the floor, 0.98× book value, and the market may price it above that. A holder who stakes also takes part in what later activity pays. Every later sale above book value, every trade in the token's own pool, and every profit the desk sweeps back sends most of its surplus to the staked pool as new tokens, backed before they are minted. That participation comes with the token however it was bought, and tokens from an offering can join the pool as they are released, from the cliff on.
An offering sells a stated allocation on a stated price path; the market sells whatever depth it has at the price it quotes. Which price is better on a given day is the buyer's call. Neither route buys extra backing, and nothing protects a premium: the market can take it away while book value stands still (02).
Buyers pay the surplus, traders pay the tolls, and leavers pay the fees that stay for those who remain. The Well, a fixed allocation set aside at genesis, is handed out over time rather than earned. The desk's profits come from investing outside those flows. At launch the staked pool's new tokens depend on offerings filling and on trading; the floor depends on no one buying anything. What remains when activity slows is walked through on the running example's own numbers in 14.
Four claims, four proofs
The four lines on the cover are the whole argument. The rest of this page proves them, one section at a time.
Start here if you are…
| Reader | Path |
|---|---|
| Curious, and want the shape of it | 01, 02, 06, 19 |
| A buyer or a staker | 01, 02, 04, 06, 07, then 08 and 10 for the yield and the end of the running example; 05 and 11 if you want the market and the Well; 19 before you decide. |
| A trader | 02, 05, 06, 19 |
| A Ripe juicer | 01, 13, 17, 19 |
| A researcher | 02, 09, 10, 16, 14, 19 |
| An auditor | 02, 03, 06, 09, 10, 15, 20, then the yellow paper and the contracts |
Yellow paper: abstract.
02Two numbers
Book value is the brim. The floor is the brim less the fee. No protocol action can lower the brim; markets can.
Book value, the brim
The protocol is organized around two quantities anyone can compute from chain state. The first is book value: the reserve's net asset value (NAV) at accepted prices, the prices the protocol's feeds currently accept, divided by the total supply of BRIM. That number is the brim: the fill line, what one BRIM is backed by. Every invariant in the protocol is checked against it.
book value = reserve NAV / total supply (2.1) the brim
The floor
The second is the floor: what the Tap pays, in reserve assets, to anyone who redeems while the Tap is open. It is book value less the redemption fee, 2% at launch. The fee stays in the reserve; it is what the holders who stay keep.
floor = book value × (1 − redemption fee) (2.2) fee = 2%
The law
At accepted prices, no protocol action can lower the brim. After genesis, every mint is checked against that rule in the transaction that performs it, by the contract that moves the money. This page calls that contract the door. The offering is one door and the reward engine is the other, and each refuses a mint that fails the check.
The reserve is tokenized stocks; their market prices move, and book value in dollar terms moves with them. What cannot happen, through any registered mint path, is dilution: no sale, no reward, and no payout to anyone mints a token that was not fully paid for. Markets may lower book value; protocol actions, at accepted prices, never will. The doors that exist today enforce the rule; governance can replace them, or change which contracts may mint, through the registry's timelock (15).
Protecting backing per token does not protect the premium someone pays for it. The market can take a premium away while the brim stands still; the brim is the part the protocol controls.
What moves the brim
The fastest way to learn the law is to list every action and ask what it does to the brim.
| Action | Effect on the brim | Why |
|---|---|---|
| An offering sale | Up | The buyer pays above the brim; the reserve keeps at least the backing for the tokens minted, and the reserve's share of the surplus lifts everyone. |
| A redemption | Up | All the BRIM handed in burns; the payout is computed on that amount less the fee, so the fee's share of the reserve stays behind. The fee is never zero (06). |
| A reward mint | Unchanged | Rewards are minted only against overflow moved into the reserve in the same transaction, at the brim, checked once when the overflow enters the reserve and again when the new tokens are minted, so a stale price cannot slip through. |
| A Well draw | Unchanged | Pre-minted supply moves from the Well into the staked pool. Neither supply nor reserves change. |
| A toll | Up | The reserve's share of the toll is banked; the rest becomes overflow, desk capital, and the developer share. |
| A desk sweep | Up | The reserve's share of a named sweep is banked. The desk never touches the reserve otherwise. |
| A rage quit | Up | Half the fee burns; the other half stays in the pool. |
| A reserve-asset price move | Either way | The dollar value of the reserve moves with its assets. This is the one row the protocol does not control. |
T2.1. What moves the brim. Every protocol action is up or unchanged; only the assets' own prices go both ways.
A mint that passes, a mint that fails
The law is one inequality, and the door runs it on every mint: the value paid, times the supply before the mint, must be at least the tokens minted, times the reserve's value before the mint. A sale above the brim passes. A mint below it is refused in the same transaction, whoever proposed it.
Every BRIM that exists was paid for.
Six words
The page uses six economic terms that are easy to run together. They are defined here and mean the same thing everywhere else.
| Word | Meaning |
|---|---|
| book value | reserve NAV divided by total supply, the formal quantity every invariant is checked against. |
| the brim | the same number, as the fill line: what one BRIM is backed by. |
| floor | what the Tap pays: book value less the redemption fee. |
| surplus | value that arrives above the brim, from a sale, a toll, or the desk. |
| Waterfall | the governance-set split of that surplus: overflow for stakers, capital for the desk, backing for the reserve, and a developer share. |
| overflow | the stakers' leg of the Waterfall, waiting for the Spillway's tick. |
T2.2. Six words.
One balance sheet is carried through this paper. A reserve worth $10,000 backs 10,000 BRIM, so the brim is $1.00 and the floor is $0.98. 5,000 BRIM are staked, 2,000 sit in the Well, and the developers' payee is set, so the split pays all four legs. Prices hold still and transfers are exact, so every number that follows is the protocol's own arithmetic. It continues in 04 (a purchase), 09 (the split), and 10 (the tick, then a redemption, and the four-state table).
Yellow paper: § 1.
03The parts, and how value moves
Small single-purpose contracts, two doors out, one lock, and receipts instead of promises.
The map
The protocol is a set of small, single-purpose contracts. Each has one job. Value moves through them in a fixed order, and the map follows it. The map shows every part as a box and every flow as an arrow. Two doors are marked: the only way backing leaves, and the only way overflow becomes rewards. Backing leaves the reserve only through the Tap, and overflow becomes staker rewards only through the Spillway. The desk sits beside the reserve, never inside it, behind a wall it does not cross.
The parts
| Plainly | The contract | Its one job |
|---|---|---|
| the offering | the Pour | Sells new tokens in governance-started offerings, always above the brim. |
| the reserve | the Reservoir | Holds the basket that backs every BRIM; value leaves through one door. |
| redemption | the Tap | That door. Burns BRIM, pays the pro-rata basket slice at the floor. |
| the split | the Waterfall | Routes every unit of surplus above the brim: overflow, desk capital, backing, a developer share. |
| the stakers' share | overflow | The stakers' leg of the Waterfall, counted unit by unit while it waits to become rewards. |
| the reward engine | the Spillway | Releases overflow into backed staker rewards, on a clock, under caps. |
| staking | the Basin | A share-based pool with three exits of differing speed and price. |
| the genesis allocation for rewards | the Well | Pre-minted BRIM that fills reward gaps in dry spells, gradually and never off a cliff. |
| the desk | the Mill | Swaps, yield strategies, liquidity, and credit on Ripe, through Brim Adapters. Runs on protocol-owned assets only. |
| vesting | the Decanter | Every offering allocation and every slow exit settles here before it is liquid. |
| the market toll | the Tollbooth | The hook on the token's own pool; every swap pays a toll into the split. |
| governance | the Boardroom | Two boards validate every dial; a registry decides which contracts exist and which may mint. |
T3.1. The parts. Plain words lead; the contract names are the ones you will see onchain.
One lock, and receipts
Every path that moves reserves or stake shares one settlement lock, which keeps a second such operation from starting before the first finishes. And every mint is sized from balances measured before and after, never from an amount someone promised. Governance is one box on this map; it gets its own section (15).
Yellow paper: § 2.
What you can do
How do I get in, get out, and stake?
04Buying in: the offering
New BRIM is sold in Dutch offerings that open at 5.00× book value and never close below 1.10×. The premium is the yield engine.
Two ways in
There are two ways to get BRIM. The market (05) quotes a price and fills what its depth allows. The offering sells a stated allocation on a stated price path, and pays a bonus for patience. The ladder in 02 shows both: the market trades between and above the brim, and the offering mints from 5.00× down to 1.10×.
An offering day
New BRIM is sold through offerings: events that governance starts and the Pour runs, each paid in one reserve asset, named when the offering is set up (tokenized Nvidia at launch), so the payment arrives in a reserve asset and is backing the moment it lands. Each offering is a Dutch auction on the price multiple over book value; the multiple counts the backing too, so 5.00× means paying 5.00 times book value, of which one part is backing and the rest is premium. The price opens at 5.00× book value and descends in a straight line over the window (one day at launch) to a 1.10× floor, the contract's own hard minimum. No sale below it is possible. Buy early and pay more for certainty; wait for a lower multiple, at the risk that the offering sells out. Every purchase is priced against the brim as it stands in that block, from a live price on every reserve asset; if any reserve asset cannot be priced, the offering refuses rather than guesses.
Anatomy of a sale
Because the buyer pays a premium over the brim but receives tokens backed only at the brim, every sale generates a surplus: real money above what backs the tokens actually minted, bonus included. The reserve keeps the backing first; only the surplus above it runs the Waterfall (09). That is the invariant, and the contract checks it in the transaction.
base = value paid / (premium × book value) (4.1) minted M = base + vesting bonus, never beyond value paid / (1.10 × book value) (4.2) invariant : the reserve keeps ≥ M × book value from every sale (4.3)
A buyer pays $100 at 2.0× the brim, takes no vesting bonus, and receives 50 BRIM, released over the vesting period. $50 goes straight into the reserve as the backing for those tokens. The other $50 is surplus and runs the Waterfall in the same transaction; 09 shows where it lands and what the reserve and the brim look like after the split. The tick, a redemption, and the four-state table are in 10.
At a 5.00× fill, about 80% of the payment is surplus; at the close, 9%. That is why the offering is the yield engine at launch, before external revenue scales.
The premium funds the yield.
Vesting
Every allocation vests through the Decanter, so freshly minted tokens are never liquid in the block they are born. Vesting runs 5 to 30 days at the buyer's choice, and longer vesting earns a bonus of up to 25% more tokens. The bonus can never push the effective price below the 1.10× minimum. Vesting begins when you buy. Nothing can be claimed until the cliff, which is the shortest vesting length, 5 days. At the cliff, everything accrued so far can be claimed at once, and the rest keeps releasing day by day until maturity. From the cliff on, a claim can go straight into the staked pool in the same transaction.
Bounds and budgets
Offerings are bounded by demand, by the 1.10× minimum, and by a budget the Policy Board sets per offering. They are never bounded by the reward budget that meters the Spillway (10): sales raise the brim, rewards hold it, and the two budgets are separate. An offering's terms cannot change while a window is live or scheduled; governance stops it first.
Yellow paper: § 3.
05The market and its toll
BRIM trades in its own pool. Every swap pays a toll in NVDA, never in BRIM, and the toll runs the same split as an offering's surplus.
The pool
BRIM trades in its own pool on Uniswap v4, against tokenized Nvidia (NVDA), the reserve's first asset and the pool's quote asset. The hook that runs the pool, the Tollbooth, binds that one pair; the pair is fixed at deployment, and no board can change it. The reserve can widen to other stocks while the pool stays quoted in NVDA. The pool quotes BRIM in NVDA, so a dollar price for BRIM moves with the stock as well as with the token; the dollar prices on the ladder in 02 are illustration only, and the pool never sees them. The pool charges no swap fee of its own: the toll is the only fee. Anyone can buy or sell there without touching the protocol's other doors, and for most people it is the first door they meet.
The toll
Every swap pays a toll in NVDA, never in BRIM: 5% to sell and 3% to buy at launch. The toll is the same share of what the trader pays or receives, however the order is written. Tolls accrue on the pool and settle outside the swap path: anyone can send what has accrued into the Spillway, where it enters the same Waterfall as offering surplus (09), as trading revenue. Because the toll is paid in a reserve asset, the reserve's leg of it is backing the moment it lands. Buys and sells both pay, so the pool funds yield in either direction.
The hook deploys with both tolls at zero; the launch values land through one Market Board timelock. A raise queued before a cut can never land after it: the cut cancels any raise still waiting in the queue.
Protocol-owned liquidity
The pool's liquidity is protocol-owned by construction. The hook admits liquidity from the desk's adapter and no one else, so a toll cannot be sidestepped by posting a position instead of a trade. Liquidity actions are queued by the Market Board behind a timelock and sized when they are queued, and execution must meet the price and minimum-output limits fixed when the action was queued.
The liveness rule
The swap callbacks read only the hook's own storage and touch only the pool manager. A failure in Brim's settlement or registries stays outside the swap: the market keeps trading, and the tolls keep accruing until someone routes them. The market still depends on what any pool depends on: the pool manager, the quote asset, the hook itself, and the chain.
Whether the pool or the Tap pays a seller more depends on depth, route, order type, gas, and what the seller wants to hold; it is a question for the trade, not for this page.
Yellow paper: § 6 (the Tollbooth row), § 10 (protocol-owned liquidity).
06Getting out: the floor
Hand BRIM to the Tap and take your slice of every asset in the reserve, in kind, less a 2% fee that stays for everyone else. No price oracle, no redemption queue, no buyer to find.
The basket, divided
Any holder can hand BRIM to the Tap and receive their pro-rata slice of the entire reserve basket, in kind, minus a fee (2% at launch) that stays in the reserve for everyone who remains. The tokens are burned before assets move. There is no queue and no buyer to find: the floor is a function anyone can call, with no market maker in between. The Tap pays 0.98× the brim, never the brim itself; the difference is what the holders who stay keep.
What redemption depends on
This is the trust layer the rest of the design leans on, and by design it is the least clever function in the protocol. Redemption needs no price oracle and no market liquidity; it hands over assets the reserve already holds. Market prices do not enter the calculation: the Tap divides what the reserve holds by the supply and pays the slice. A crashing market changes what the basket is worth. It does not change the arithmetic.
The reserve funds the floor.
The arithmetic is simple; what sits outside it is not. The Tap can be paused defensively, and the Policy Board can change the fee, never above 10% (a board bound, 15). And a reserve asset moves only if its issuer lets it (19): the Tap pays every asset in the basket or none, so one failed transfer reverts the whole redemption, burn included, until that asset moves again. Delisting does not unstick that. It only stops new deposits of the asset; what is already in the basket stays. Redemption from stake (07) goes through the same Tap and inherits the same preconditions.
Every exit lifts the brim
Every redemption raises book value for everyone left: all the BRIM handed in burns, and the payout is computed on that amount less the fee, so the fee's share of the reserve stays behind. The fee can never be set to zero. It is one of the two numbers behind the reward bound (10): no tick can pay in more than the instant exit charges, which is what makes sniping the tick a losing trade. A zero fee would switch rewards off, so the Policy Board refuses one.
The running example's redemption is in 10, beside the four-state table, once the sale's surplus has become rewards.
Yellow paper: § 4.
07Staking
Stake into a growing pool. Leave three ways, priced by urgency: wait for free, redeem at the floor, or rage quit and pay the patient.
A growing pool
Stakers deposit BRIM into the Basin and hold shares of a growing pool. You can deposit from a wallet, or claim a release from the Decanter and stake it in the same transaction, whether the release came from an offering or from an earlier withdrawal. Once it is staked, the three exits below are the only way out. Rewards arrive as tokens added to the pool, so the balance a share can claim grows. Your share count does not change; the pool behind it does. Brim is not a rebase. How rewards get into the pool, and how much can arrive per tick, is 10; this section is the pool and its doors.
(3,3) with a redeem button.
Three exits
Three exits, priced by urgency. Withdraw is a 7-day linear release of your BRIM through the Decanter with a 1-day cliff, and it charges no fee; a withdrawing position earns no further rewards while it releases. Redeem from stake is instant, straight through the Tap: you receive reserve assets, the basket slice for your BRIM less the 2% fee. Rage quit is instant, takes the full position, and pays out BRIM less a 50% fee. Every exit is signed with your own cap, the highest fee or the longest release you will accept, and a setting that changes after you sign cannot push past it.
| Exit | You receive | Speed | Price |
|---|---|---|---|
| Withdraw | all your BRIM, released over time | 7-day linear release through the Decanter, 1-day cliff | no fee |
| Redeem from stake | reserve assets: the basket slice for 0.98× your BRIM | instant, straight through the Tap | 2% fee |
| Rage quit | half your BRIM, liquid at once | instant, full position | 50% fee |
T7.1. Three exits. Two pay BRIM; one pays the basket.
The rage-quit split
Half of every rage-quit fee is burned; the other half stays in the pool for the stakers who remain. The last staker out burns the entire fee. When the pool empties, any residual burns for every holder. The impatient pay the patient.
Nothing stops a fast in-and-out
Capital that arrives just before a reward tick and leaves through the slow exit earns its share like anyone else. An address may take one protocol action per block, and past that nothing stops a fast in-and-out; the bounds in 10 only make instant extraction unprofitable. Mercenary liquidity is welcome, and the bounds keep it harmless. A paused Basin stops deposits and all three exits (15).
Yellow paper: § 5 (exits).
Where the yield comes from
Is the yield real, and how long does it last?
08Two ledgers
Yield lands in one of two places: your balance grows, or every token's backing grows. Every source in the protocol feeds one or both.
Two columns
Yield arrives in two ledgers. Either your balance grows, because tokens flow into the staked pool and each share represents more BRIM, or every token's backing grows, because value is banked or supply is burned and the brim rises for holders and stakers alike. Every source in the protocol lands in one of the two columns, and several land in both.
The sources
Six sources, and each has someone paying it. Three of them, offerings, tolls, and the desk's named sweeps, run the Waterfall (09): most of each becomes overflow for stakers and a slice stays in the reserve. An offering or a toll also pays a slice to the desk and a small slice to the developers, in the revenue asset; a sweep pays neither. The other three are the exits and the Well.
| Source | Who pays it | Your balance grows | The brim rises |
|---|---|---|---|
| Offerings | buyers, the surplus above the brim | the overflow leg | the reserve leg |
| Tolls | traders, on every swap | the overflow leg | the reserve leg |
| Desk sweeps | the desk's returns, from investment outside those flows | the overflow leg | the reserve leg |
| Rage quits | the impatient | half the fee stays in the pool | half the fee burns |
| Redemptions | leavers | the fee stays in the reserve | |
| The Well | a finite genesis allocation, handed out, never income | the gap below the target, and only the gap |
T8.1. Six sources, and who pays each.
Leavers pay the exit fees: a redemption fee stays in the reserve, and half a rage-quit fee stays in the pool while the other half burns. Either way those who remain are better off, and every exit through the Tap lifts the brim. The Well fills a remaining shortfall below the target after organic rewards (11); it is a finite, pre-minted allocation being handed out, and this page never counts it as income. At launch the overflow leg depends on offerings filling and on trading; the floor depends on no one buying anything (01).
The buyer in 04 paid $100 for 50 BRIM. When the tick in 10 mints 44.9910 BRIM against that sale's surplus, the buyer's tokens are still vesting, so the reward goes to the 5,000 BRIM already staked: tokens from an offering can be staked as they are released, from the cliff on, not at the sale. The claim and the stake can be one transaction. Once staked, the buyer's claim is their share of whatever later ticks mint, under the pool cap and the era budget: the same claim any staker has. The offering sold an allocation and a price path.
Activity is the yield
Offerings, trades, and exits are the yield; the Well is a bridge, and it runs out. Each of them lands in one of the two ledgers. All overflow passes through one split (09), one tick (10), and one bound; all burn-and-bank flows compound silently into the brim.
Yellow paper: § 6.
09The Waterfall
One split, every door. Whichever way surplus arrives, the same configured shares route it to stakers, the desk, the reserve, and the developers. A desk-sourced sweep skips the desk's leg and the developers'.
One split, every door
Every unit of surplus above the brim enters the Spillway through one of three routes: an offering's surplus, a settled toll, or a sweep the desk's governance has named. The same split runs, whichever route the surplus came through. It has four legs: overflow for stakers, capital for the desk's operating sleeve, backing for the reserve, and a share for the developers who build and maintain the protocol. Under the launch configuration (18), ordinary revenue routes 90% to overflow, 5% to the desk, 4% to the reserve, and 1% to the developers. The desk leg, the reserve leg, and the developer leg move at the door, in the revenue asset; the overflow leg waits for the tick.
The developer share is paid in the asset the revenue arrived in, never in newly minted BRIM, so it can never dilute; its ceiling is 10%, enforced at the door. Until a payee address is set, that share goes to the reserve and lifts the brim instead.
The $50 of surplus from the purchase in 04 runs the split, with the developers' payee set: $45.00 to overflow, $2.50 to the desk, $2.00 to the reserve, $0.50 to the developers. The desk, reserve, and developer legs move at the door; the $45.00 of overflow waits in the Spillway for the tick (10).
Two source states
The desk never pays itself, and a sweep pays no developer leg either. When the desk is the source of a deposit, both legs are suppressed and fold into the stakers' share, so a desk-sourced sweep routes 96% to overflow and 4% to the reserve under the same configuration. One split, two effective outcomes, depending on the door. The configured legs are listed in 18.
Overflow is accounting
Overflow is a running count, unit by unit and per asset, of what waits in the Spillway's own vault for the tick (10). The count is in units, not dollars. If units vanish from the vault (a transfer out that was not a tick), the credit is cut to what is actually there at the next tick and never grows back on its own; if their price falls, the same units back fewer reward tokens when the tick values them. Nothing enters the reserve unpriced: an asset that cannot be priced waits in the vault, whole, until it can.
What cannot mint
Donations and stray transfers can never authorize a mint. Supported, tracked assets that arrive without passing through a listed door are swept into the reserve as backing: they lift the brim and print nothing. Anything unsupported or unpriceable stays outside reward accounting altogether. Only revenue that entered through a listed door counts as overflow, and only overflow can become a reward.
Yellow paper: § 3 (surplus), § 5 (donations), § 6, § 11 (the Waterfall row).
10The reward tick
Rewards are released hourly, by anyone, from overflow that moves into the reserve in the same transaction, under a bound that makes sniping the tick a losing trade.
One tick, in order
Rewards are released by the Spillway on a permissionless tick: roughly hourly, metered in blocks, and cranked by anyone. One tick does five things in one transaction. It measures receipts, balances before and after, never amounts promised. It moves overflow into the reserve. It mints BRIM into the staked pool under the same backing inequality as a sale, checked again when the tokens are minted. It fills any remaining gap to the target from the Well, as a transfer. And it checks both legs against the bound. A dead price feed stops the tick rather than letting it guess. A tick inside the interval sweeps donations and mints nothing. A late tick collects one interval's allowance, never a backlog.
Nothing mints unpaid.
The bound
Each tick's total inflow to the pool is bounded by the stake and by the lesser of two dials: the pool cap and the redemption fee.
total pool inflow = minted + Well draw ≤ staked × min(pool cap, redemption fee) per tick (10.1)
The bound is not a tuning choice. It is what makes sniping the tick a losing trade: deposit just before a tick, and the most you can capture is less than the fee you pay to leave at once. At launch the pool cap, 1% of stake per tick, is the tighter of the two. The bound is a door check over two configured inputs; the door enforces it, the boards set the inputs.
Why sniping loses
Deposit just before the tick, take the most a tick can pay in, and leave through the instant exit. The exit fee is larger than the capture by construction.
The tick banks the $45.00 of overflow into the reserve and mints against it at the new brim of $1.000199: 44.9910 BRIM into the staked pool. It is not 45, because the sale already lifted the brim, and the mint is priced at the brim as it stands now. The 5,000-BRIM pool's per-tick cap is 50 BRIM, so it fits. The tick's target is 1.14 BRIM, so organic rewards carry it and the Well draws nothing. The reserve holds $10,097.00 against 10,094.9910 BRIM, and the brim is unchanged at $1.000199: a backed mint moves the brim by nothing.
Now another liquid holder, not the buyer whose allocation is still vesting, hands 100 BRIM to the Tap. All 100 BRIM burn; the payout is computed on 98 BRIM, a slice of every asset worth $98.0195 at the same accepted prices. The reserve is left with $9,998.9805 against 9,994.9910 BRIM, and the brim rises to $1.000399 for everyone who stayed.
| State | Reserve | BRIM supply | The brim |
|---|---|---|---|
| Before the purchase | $10,000 | 10,000 | $1.00 |
| After the purchase and the split (04, 09) | $10,052.00 | 10,050 | $1.000199 |
| After the tick | $10,097.00 | 10,094.9910 | $1.000199 |
| After another holder redeems 100 BRIM (06) | $9,998.9805 | 9,994.9910 | $1.000399 |
T10.1. The running example, four states, with the developers' payee set and the redeemer a different holder from the buyer. A sale lifts the brim, a backed mint leaves it where it is, a redemption lifts it again.
Two meters: the tick and the year
Minted rewards and Well draws are different things, even though they share the bound. Minted rewards come only from overflow that the tick moves into the reserve in the same transaction, and they are further metered by a yearly budget: reward mints in a reward era can never exceed 50% of the era's starting supply. That budget meters mints only; offerings and the Well never touch it, and burns never refill it. The Well draw mints nothing: it is a transfer of genesis-era supply (11), already counted in the brim, moving from the Well into the pool. Every tick reports three numbers separately: revenue-backed BRIM minted, Well BRIM transferred, and reserve value routed.
Yellow paper: § 5 (rewards).
11The Well
A finite, pre-minted allocation that pays only the gap organic rewards leave, so it pays most when the market is quietest. It pays toward a target, and it can never be emptied faster than its runway allows.
What the Well is, and is not
A reservoir needs a well for dry spells. At genesis, a fixed allocation of BRIM is placed in the Well. It is pre-minted, inside total supply from block one, and therefore already accounted for in the brim. Drawing on it later moves neither supply nor reserves: the brim is unchanged, to the wei, by every draw. Only the Spillway can draw from it, and no protocol path can mint it a refill; anyone may pay existing tokens in, and such a top-up is a gift to stakers.
The opposite of an emissions schedule
The usual emissions schedule pays a fixed stream, heaviest at launch, whether or not anything is happening, and it pays most into the hottest market, the one moment nobody needs it. The Well is built the other way round. It pays only the gap that organic rewards leave, so a hot week draws nothing and a dead week draws the target, within the glide. It is one allocation, sized once, and nothing prints it a refill: when it is spent it is spent, and by then the yield has either become organic or it has not. What it pays, and how fast, is arithmetic anyone can run.
The Well pays the gap, and nothing prints it a refill.
The Well's size is a genesis input (17), so the chart shows the rule for whatever balance the Well holds: how a draw tapers under the glide as the balance falls. The dry year in 14 runs the same arithmetic on the running example's sheet.
The draw recipe
Governance sets one target, an annual rate on the staked pool applied per tick. Each hourly tick starts with that target for total rewards. Organic rewards count toward it first. The Well can cover the remaining shortfall, subject to its glide and to the pool's inflow bound.
target = staked × target rate × (tick / year) (11.1) gap = min(max(target − minted this tick, 0), max(inflow bound − minted, 0)) (11.2) glide cap = Well balance × (tick / runway floor) (11.3) draw = min(gap, glide cap) paid if draw ≥ 0.01 BRIM, else zero (11.4)
The glide
Organic minting applies first; the Well fills only the gap. The glide is a speed limit: each tick may take at most one part in 30 × 24 of whatever is still in the Well (30 days at launch; governance can lengthen the runway behind the timelock). That is why a 30-day runway is not 30 days of full target: as the balance falls, the draws shrink, and they taper instead of stopping at a cliff. A growing pool raises the target and the inflow bound; it does not raise this drain. A draw below 0.01 BRIM is skipped.
Early is when it is deep
The target is a rate on the staked pool, and the pool is smallest at the start. So the earliest stakers are paid the full target for as long as the Well is deep against a small pool; as the crowd arrives the pool grows, the target grows with it, and the glide takes over. A higher target rate would drain the Well faster. How long the full target lasts depends on one ratio: the Well's depth against the stake it is paying. With no organic revenue at all, on the launch dials, the arithmetic says:
| The Well, as a share of the opening stake | The full target is paid, before the glide tapers it, for |
|---|---|
| 50% | about 46 days |
| 100% | about 98 days |
| 200% | about 172 days |
T11.1. Full-target days by depth, with no organic revenue, at the 30-day runway and hourly ticks, computed by the same rule as the explorer above. Organic revenue extends every row, because the Well pays only the gap. The Well's size is a genesis input (17); the rows show what the rule does at each depth.
Counter-cyclical by arithmetic
Hot weeks draw little or nothing. Quiet weeks draw the target while the Well is deep, and less as it shallows. The target is a ceiling for the Well's contribution, and organic rewards apply first; they may carry a tick above it on their own. The rate is quoted as an annual rate per tick; because ticks compound, the realized yield on a fully paid year is higher than the nominal number, and no tick is promised to fill. The chart to watch is organic overflow against Well draws. When organic rewards cover a tick's target, the Well contributes nothing to that tick. In the running example the tick's target was 1.14 BRIM and organic rewards minted 44.9910, so the Well drew nothing; in an hour with no overflow it would draw the gap, within its glide.
Brakes and raises
Security signers can lower the target instantly and only the timelock can raise it, so a queued raise can never undo a brake. Governance sets the target and the runway parameters; the counter-cyclicality is arithmetic. The Well reports its own bounds onchain: balance, target per tick, and the most a dry tick can draw. The target is not a promise; that limit is in 19.
Yellow paper: § 7.
12The desk
The desk runs a separate sleeve of protocol-owned assets. It can borrow and it can lose; it can never touch the reserve.
A separate sleeve
The Mill is the operating desk. It manages a separately capitalized sleeve of protocol-owned assets, never the reserve, through Brim Adapters: swaps, yield strategies, liquidity, and credit. If yield-bearing stablecoin positions are used at all, they live here as a desk strategy, not in the reserve. Its capital arrives through the Waterfall's desk leg. Every action settles on receipts measured on the desk itself, names the token it expects, and carries a minimum it must achieve. The reserve sits behind a wall the desk never crosses: it holds no debt, is never borrowed against, and pays out through the Tap alone.
The named sweep
The desk's flagship strategy is a credit line on Ripe (13): borrow against operating assets, and put the loan to work wherever it can earn more than the loan costs. Policy treats borrowed principal as a liability, never revenue, and permits only realized net profit to be swept: value remaining after principal repayment, accrued interest, execution costs, and realized losses. The contracts do not compute that profit; a timelocked governance action names the amount. The desk deploys, repays, and only then names a profit for the Waterfall, behind the timelock. A sweep takes no desk leg and no developer leg (09). Losses stay on the desk, and the reserve backing the floor never carries debt.
What is code, what is policy
| Code enforces | Policy decides |
|---|---|
| Only a contract listed in the Boardroom registry may drive the desk; the list holds only the boards, and governance changes it behind its timelock | which venues the desk uses |
| Every action settles on receipts, names the token it expects, and carries a minimum it must achieve | how much leverage, and what position size |
| An adapter must be listed and bound before the desk can use it | which adapters to propose |
| The reserve is unreachable from the desk | nothing; no board can reach it short of a registry change behind its own timelock |
| A sweep is a named amount into the split; losses stay on the sleeve | when to name a sweep, and how much |
T12.1. What is code, what is policy.
The Brim HQ team operates the desk through those boards, under each board's rules and delays, and those choices are theirs. Undecided: the sleeve's opening capital, which is a genesis input (17); after that it grows with the desk leg of every split.
Yellow paper: § 6 (the Mill row), § 8.
13The Ripe connection
Two doors connect Brim to Ripe; one wall keeps the reserve out of both.
Two doors
Brim is an independent protocol, but it launches with one deliberate ally: Ripe Protocol, an onchain lending protocol where people borrow against their tokenized stocks. The two are built around the same kind of asset, and the relationship runs through two doors.
The first is the desk's credit line on Ripe (12). The loan stays on the desk's own sleeve; only realized net profit, named by governance, comes back through the Waterfall. Ripe gains a protocol-scale borrower; Brim gains a yield engine on assets that would otherwise sit idle.
The second is genesis. On Ripe, people who stake RIPE or RIPE LP earn a juice score, and that score is what puts Ripe's most committed stakers, the Top Juicers, first in line for Brim's genesis event. The two communities are aligned from block one. Genesis itself is 17.
One wall
The two protocols share no balance sheet. Ripe never touches the reserve, the reserve is never borrowed against, the desk never borrows against BRIM, and the floor does not depend on Ripe: the loan is secured by the desk's own assets, never the reserve. If the credit line loses, the loss stays on the desk's sleeve; if Ripe stops, the desk has one fewer venue and the reserve has nothing to notice.
Ripe is a venue. The reserve does not know it exists.
Yellow paper: § 8.
14The loops
Three loops make the machine reinforce itself. One net catches it when demand is gone. Each loop is the mechanics of an earlier section, read as a cycle.
Three loops and a net
The premium loop. Demand brings buyers to an offering above the brim. The premium is surplus; the stakers' share of the surplus, after the split, is overflow; the overflow mints into the staked pool; a growing pool is more reason to show up at the next offering. The offering is 04; the split is 09.
The activity loop. Trades pay the toll in both directions, so trading in either direction funds yield: buys and sells both route into the same split, to overflow and to the brim. The toll is 05.
The patience loop. Rage quits and redemptions tax urgency: half of a rage-quit fee stays for the stakers who remain and half burns for every holder, and a redemption fee stays in the reserve. Those who remain keep the retained fee, the burn shrinks the supply under everyone, and both are one more reason to stay. The exits are priced in 06 and 07.
The net. The net is not a loop. When demand is gone, the Tap pays the basket, and there is no mint-on-redeem path to amplify a fall. The net holds when the Tap is open and every reserve asset transfers (06).
The contracts route the money. People decide whether to come back. Hot market or dead one, the same arithmetic holds; the table below sets the two side by side.
When demand is strong, the premium funds the yield. When demand is gone, the Tap pays the floor.
Take the sheet as 10 left it: a reserve of $9,998.9805 against 9,994.9910 BRIM, the brim at $1.000399, 5,044.9910 BRIM staked, 2,000 BRIM in the Well. For the walk, assume reserve prices hold, every hourly tick runs on fresh prices, no offering fills, no swap pays a toll, no sweep lands, nothing is deposited, withdrawn, redeemed, or paid into the Well, and no setting changes. Organic rewards are zero, so each tick asks the Well for the whole target, which grows with the pool.
- Day 0. The target is 1.15 BRIM per tick and the glide allows 2.78, so the Well pays the target in full.
- Day 33. The Well has shallowed until its glide cap falls below the target; from here the draws taper with the balance.
- Day 180. The draw falls under the dust line and stops, with 7.20 BRIM still in the Well.
- Day 365. The Well has paid 1,992.80 BRIM into the pool, which ends at 7,037.79 BRIM. Supply and reserve are unchanged, so the brim is $1.000399 at both ends, and the Tap still pays 0.98× that (06).
Drop the price assumption and the brim falls with the reserve's prices; nothing in the protocol stops that (19). Neither a premium anyone paid nor a dollar figure is protected. The redemption route and the arithmetic are.
Two states
| Strong demand | No demand | |
|---|---|---|
| What pays | the premium: offering surplus and tolls become overflow | the floor: the Tap pays the basket, in kind |
| The Well | draws little or nothing | draws the gap up to its glide cap, and tapers as it shallows |
| What it depends on | accepted prices for issuance; people who keep coming | the Tap open, every asset transferable |
T14.1. Two states. The same arithmetic, in a hot market and a dead one.
Yellow paper: § 6 (closing), § 9 (the synthesis paragraph).
What you are trusting
Who can change what, and how is this not Olympus?
15Who can change what
Brim is governed and upgradeable. Three control domains, two speeds: raises wait behind timelocks, brakes act at once, and contracts can be replaced through the registry behind its own timelock.
Three domains, two speeds
Three control domains. The Policy Board holds the economic dials, the Market Board holds the pool's, and the registry holds the set of contracts and their mint rights. The registry can replace any contract behind its timelock, switch minting on or off globally, and set the token contract's own permissions; the dial table in 18 names every dial by board. The protocol is upgradeable by design: a fix or a new version is a registry change, and the bounds on this page belong to the contracts registered today.
Two speeds. Raises and value-moving actions wait behind a timelock, are validated against ceilings when proposed and again when executed, and expire if they are not executed in time. Defensive reductions act at once: pausing a department, stopping a live offering, lowering the target, lowering the tolls, delisting an asset, locking a signer. Security signers can brake but never raise. Two of these cuts, the target's and the tolls', also cancel any raise of that dial still waiting in the queue, so a raise queued before the cut can never land after it.
What a pause stops
A signer can pause a department; only governance unpauses. A pause is not cosmetic: each one stops a specific set of actions and leaves the rest running, and some reach further than their name, since a paused Spillway or Decanter also stops offering purchases. T20.3 lists every pause department by department. The settlement lock and the ledger's records of stake and releases never pause, and the desk's risk-reducing actions stay live while the desk is paused.
Who may mint
Only two contracts hold mint rights: the offering and the reward engine, each checking the backing inequality at its own door on every mint. Mint rights are a governed setting: the registry can grant or revoke them behind its timelock, and a global mint switch sits above both. So "nothing mints unpaid" is a door check on every mint, and a list of contracts that governance maintains. The token contract also carries a pause, a blacklist, and the power to burn blacklisted balances; those powers sit in the registry's domain and are listed row by row in the authority matrix (20).
The launch trust model
At launch, governance is a multisig behind the timelocks described here, with a set of security signers who can only brake. The brim law binds what protocol actions may do; the boards' ceilings bind what a dial may be set to; the registry's timelock binds how the set of contracts may change. No single function is unstoppable, and governance can act. What waits, what acts at once, and who enforces each bound is stated above and tabulated in 20.
Yellow paper: § 2 (closing), § 11 (the floor has switches; the launch table's intro).
16Prior art
Brim borrows from five earlier designs, declines the part of each that gave way, and combines the rest under one constraint: new issuance preserves book value.
Borrowed, refused, changed
The short version is in 01; this is the long one. Brim sits at the intersection of several earlier monetary designs. Each solved a different problem, and each gave something up to do it. Brim combines selected parts of those designs under one constraint: new issuance must preserve current book value at the prices the protocol accepts.
Olympus (2021). Borrowed: premium issuance and the staking flywheel. Refused: staking rebases minted on a schedule, with no rule that each mint preserve backing per token, and a treasury "floor" that was a dashboard number with no redeem function; when the premium died, the only exit was the market. Changed: every mint must hold the brim, rewards are minted only against banked revenue, and the floor is a function anyone can call.
Terra / UST. The lesson from Terra was a backstop that pays. Refused: an endogenous backstop, where redeeming UST minted more LUNA and the exit amplified the crash it was meant to absorb. Changed: an exogenous basket and an exit in kind; there is no mint-on-redeem path.
Ampleforth. Ampleforth reached every holder by adjusting the unit: a proportional supply change, not a reward. Refused: rebasing unit balances with no reserve behind them, and nothing to redeem when demand left. Changed: shares of a growing pool, and real custody.
Reserve-style baskets. Borrowed: honest onchain redemption. Refused: the two-way mint-and-redeem arbitrage that pins price to basket NAV; holders own the basket and its yield, never a premium above it. Changed: the basket is a floor under the token, with nothing pinning the token to it.
NET (NetNet Capital Management). Borrowed: a real, onchain backing floor, with emissions capped by reserves. Refused: an exit that is a capacity-capped buyback bid just below NAV rather than a pro-rata take of the reserve, and staking yield that is still a rebase of minted supply, capped by reserves but not paid for by revenue. Changed: every mint is a paired inequality paid at the door, and the exit is the basket itself.
The wedge
The synthesis is the design. Take Olympus's premium-issuance flywheel, but mint new rewards only against banked revenue, with the finite Well carrying rewards while it lasts out of pre-minted, already-backed supply. Take Reserve's honest redemption, but remove the NAV pin. There is no price target to defend and no open-ended emission schedule to sustain. Against Olympus, Terra, Ampleforth, and NET, the difference is the same: you leave with a slice of the reserve, priced mechanically, not with a bid. Against Reserve, the difference is the missing pin.
Yellow paper: § 9.
Launch
What happens at block one, and what can go wrong?
17Genesis
One event, announced by @Brim_HQ, run in tokenized Nvidia, with Top Juicers first in line. Four things about how it ends are already fixed, and everything after it runs on the rules above.
What is already fixed
Genesis is the one moment that has to establish the backing every later mint is checked against, and the whole design leans on it ending in exactly one state. Four things are fixed now, whatever the event looks like.
- The reserve backs the entire initial supply, the Well included. Every token that exists when the event ends, the Well's allocation among them, is inside supply and inside the brim from the first block.
- The token's market is protocol-owned. The pool's hook admits liquidity from the protocol's own desk and no one else, so from the first swap every trade pays its toll into the split.
- The Tap is open. The redeem button works from the first block, at the floor, in kind.
- The genesis asset is tokenized Nvidia (NVDA), and only that. The event takes in tokenized Nvidia and nothing else, the reserve opens holding it and nothing else, and the token's pool is quoted in it. That is a launch fact, not the design: the reserve is meant to be a basket of tokenized stocks, and the board admits more after genesis (15). No stablecoin sits anywhere in the reserve.
Genesis is open to anyone who wants to play, with no pre-sale in front of it, and after it, the only way a new BRIM ever comes into existence is through a current mint door, fully paid, at or above the brim. The Well's size and the desk's opening capital are set here too (11, 12).
What is coming
The event itself is announced by @Brim_HQ, and the Ripe juice score (13) plays an important part in it: Ripe's most committed stakers, the Top Juicers, stand first in line. What it takes in is tokenized Nvidia; the rest of its mechanics are deliberately not on this page. What this page fixes is the state it ends in, and that state is what every later mint, every tick, and every redemption is checked against.
Yellow paper: § 10.
18Launch configuration
The mechanisms above are what the registered contracts enforce today. The numbers below are dials. Every one, dated, with its bound and who enforces it.
Mechanism, not dial
The mechanisms in this paper are enforced by the contracts registered today (15); the numbers below are dials. They are governed through the Policy Board and the Market Board within the ceilings shown: raises and value-moving actions wait behind timelocks, defensive reductions act at once. "The door" means the contract that moves the money refuses anything past the bound; "the board" means the current board's validation refuses it, and a board can be replaced through the registry's own timelock. This table is dated September 2026.
The dial table
| Dial | Launch | Bound | Enforced by | Board | Speed | Class |
|---|---|---|---|---|---|---|
| Redemption fee | 2% | above zero, never above 10% | the board | Policy | timelocked | board bound |
| Redemption open | yes | the open flag is a dial; a Tap pause is separate | the door | Policy; signers pause | the flag timelocked; a pause at once, and governance unpauses at once | configured |
| Reserve assets | tokenized Nvidia, the first of a basket | tokenized stocks; more admitted after genesis, each with a live price, never the protocol's own token | the door (admission); the board (the list) | Policy | add timelocked; delist at once | configured |
| The pool's pair | BRIM / NVDA | bound into the hook; the quote asset is a reserve asset, or tolls could never settle | the door | the registered set | ||
| Offering premium | 5.00× → 1.10× | 1.10× is the contract minimum | the door | Policy | timelocked | door bound |
| Offering window | one day | at most 90 days | the board | Policy | timelocked | configured |
| Vesting | 5 to 30 days, bonus up to 25% | bonus never above 25%; length never above 365 days | the door (bonus); the board (range) | Policy | timelocked | configured |
| Waterfall legs: stakers / desk / reserve / developers | 90 / 5 / 4 / 1 | desk leg never above 25%; developer leg never above 10% | the door | Policy | timelocked | door bound |
| Waterfall, desk-sourced sweep | 96 / 0 / 4 / 0 | the desk never pays itself; no developer leg on a sweep | the door | derived | ||
| Developer payee | set by the board | never a protocol contract; until set, the leg accretes to the reserve | the board | Policy | timelocked | configured |
| Well target | 200% nominal APR, prorated per tick | never above 200%; lowerable at once; not a guarantee | the board | Policy; signers lower | raise timelocked; cut at once | board bound; not promised as an outcome |
| Runway floor | 30 days | 30 to 365 days, at least 10 ticks | the board (range); the door (ten ticks) | Policy | timelocked | configured; a limit on the draw rate |
| Reward era budget | 50% of era-start supply per year | never above 1000% of era-start supply; meters mints only, and the Well never touches it | the door (metered); the board (ceiling) | Policy | timelocked | configured |
| Pool inflow cap | 1% of stake per tick | the lesser of its setting and the live redemption fee | the door | Policy | timelocked | door bound |
| Reward tick | hourly | never shorter than one hour | the board | Policy | timelocked | configured |
| Tolls | 5% sell / 3% buy | never above 10% per direction; the hook deploys at zero and the launch values land through one Market Board timelock | the door (the hook) | Market | raise timelocked; cut at once | door bound |
| Rage-quit fee | 50% | never above 90% | the door | Policy | timelocked | door bound |
| Withdraw release | 7 days, 1-day cliff | at most 60 days | the board | Policy | timelocked | configured |
| Price staleness | one day | five minutes to seven days | the board | Policy | timelocked | configured; depends on the feed |
| Mint rights | the offering, the reward engine | only registered contracts; a global switch above both | the token, via the registry | registry | grant timelocked; switch off at once | the registered set |
T18.1. The dial table, dated September 2026. The last column says what kind of claim each row is: a door bound is refused by the contract that moves the money, a board bound by the current board, and "configured" means a value governance can set within those. The full claim vocabulary is in 19 and 20.
Yellow paper: § 11 (the launch table).
19Honest limits
What the design does not claim, and for each claim it does make, what it depends on.
Eight limits
One more precondition sits under the brim law itself: the door checks hold on every mint through the current mint doors, and which contracts are mint doors is governed (15).
The claim matrix
Every claim on this page sits in at least one of four columns, and several sit in more than one.
| Claim | Enforced when callable | Availability governed | External preconditions | Not promised |
|---|---|---|---|---|
| No protocol action lowers the brim | the backing inequality at every current mint door | which contracts are mint doors; the mint switch | accepted prices from live feeds | a dollar value |
| Redemption in kind, pro rata | burn first, then the slice of every asset; no price read | the Tap open; the fee, above zero and never above 10% | every reserve asset transferable by its issuer; one failed transfer reverts the whole redemption | a dollar floor; liquidity for the assets received |
| The offering never mints below 1.10× | the door refuses | whether an offering is open at all | a strict price read of the reserve | an allocation at any price |
| Rewards per tick stay under the bound | the door check over the pool cap and the fee | the pool cap and the fee | a rate; an APY | |
| Rewards are backed | minted only against overflow moved into the reserve in the same transaction | the reward era budget; ticks require the Spillway unpaused | live feeds for the tick | a floor on rewards |
| The Well pays the gap | the draw recipe and the glide | the target (lowerable at once), the runway floor | live feeds for the tick; the draw is one of its steps and comes after the strict pricing | the target as an outcome; Well duration |
| Tolls fund yield | the hook charges on every swap; never above 10% | the toll levels; the liquidity adapter | the pool manager, the quote asset, the chain | trading volume |
| The desk never touches the reserve | the reserve's only outlet is the Tap; the desk's vault is separate | which contracts are registered | the venues the desk uses | desk profit |
| Genesis backs the initial supply | the genesis plan (17) | genesis mechanics, dates, allocation |
T19.1. The claim matrix.
Stress paths
That is the whole argument. The formulas are collected in 20, the contracts are the final word, and the only genuine BRIM is the token at the address published by @Brim_HQ.
Yellow paper: § 11.
20Reference
Everything an auditor, a translator, or a researcher needs, out of the narrative's way.
Glossary
- book value
- reserve NAV divided by total supply; the quantity every invariant is checked against.
- accepted prices
- the prices the protocol's configured feeds currently accept; a stale or dead feed is not accepted, and strict reads fail closed.
- the brim
- book value, as the fill line: what one BRIM is backed by.
- floor
- what the Tap pays: book value less the redemption fee. On this page the floor is always the redemption price; the offering has a minimum and the Well has a runway, which the dial table names the runway floor.
- surplus
- value that arrives above the brim, from a sale, a toll, or the desk.
- Waterfall
- the governance-set split of surplus into overflow for stakers, capital for the desk, backing for the reserve, and a developer share.
- overflow
- the stakers' leg of the Waterfall, waiting for the Spillway's tick.
- the offering (the Pour)
- the Dutch sale of new BRIM above the brim.
- the reserve (the Reservoir)
- the basket that backs every BRIM; exits only through the Tap.
- the Tap
- redemption: burn BRIM, receive the pro-rata basket at the floor.
- the Spillway
- the reward engine: the tick that turns overflow into backed rewards.
- the Basin
- the staked pool, share-based, with three exits.
- the Well
- the pre-minted genesis allocation that fills reward gaps under a glide.
- the Mill
- the operating desk: a separate sleeve of protocol-owned assets.
- the Decanter
- vesting: every allocation and every slow exit settles here before it is liquid.
- the Tollbooth
- the hook on the token's own pool; charges the toll and gates liquidity.
- Brim Adapters
- the desk's connectors to venues; each is registered and bound.
- the Boardroom
- governance: the Policy Board, the Market Board, and the registry of validating desks.
- the tick
- the permissionless, hourly reward checkpoint.
- the glide
- the rule that a tick may draw at most the Well's balance divided by the ticks in the runway floor.
- era
- a reward year; gross mints in an era are capped at a share of the era's starting supply.
- the quote asset
- the reserve asset the token's pool is priced in and the toll is paid in; tokenized Nvidia (NVDA) at launch.
- the door
- the contract that moves the money and refuses anything past its bound. The offering and the reward engine are the two mint doors; the Tap is the one door out of the reserve.
- (3,3)
- Olympus's shorthand for the outcome where everyone stakes and everyone does better for it. Brim's version adds the exit the original never had.
Questions
Formula book
| No. | Formula | Section |
|---|---|---|
| 2.1 | book value = reserve NAV / total supply | 02 |
| 2.2 | floor = book value × (1 − redemption fee) | 02 |
| 4.1 | base = value paid / (premium × book value) | 04 |
| 4.2 | minted M = base + vesting bonus, never beyond value paid / (1.10 × book value) | 04 |
| 4.3 | the reserve keeps ≥ M × book value from every sale | 04 |
| 10.1 | minted + Well draw ≤ staked × min(pool cap, redemption fee), per tick | 10 |
| 11.1 | target = staked × target rate × (tick / year) | 11 |
| 11.2 | gap = min(max(target − minted, 0), max(inflow bound − minted, 0)) | 11 |
| 11.3 | glide cap = Well balance × (tick / runway floor) | 11 |
| 11.4 | draw = min(gap, glide cap), paid if ≥ 0.01 BRIM | 11 |
| mint check | value paid × supply before ≥ minted × NAV before, at every mint door | 02, 10 |
T20.1. Formula book.
Authority matrix
| Action | Domain | Who | Delay | Ceiling | Ceiling enforced by | Touches |
|---|---|---|---|---|---|---|
| Set the redemption fee, open or close redemption | Policy Board | governance | timelocked | fee above zero, never above 10% | the board | the Tap |
| Set offering terms | Policy Board | governance | timelocked; not while a window is live | floor premium ≥ 1.10×; bonus ≤ 25% | the door | the offering |
| Set the offering budget | Policy Board | governance | timelocked | the ledger | ||
| Start an offering | Policy Board | governance | at once | not over a live window | the door | the offering |
| Stop an offering | Policy Board | governance, security signers | at once | the offering | ||
| Set staking terms | Policy Board | governance | timelocked | rage-quit fee ≤ 90%; release ≤ 60 days | the door (fee); the board (release) | the Basin |
| Set reward dials (tick, caps, target, runway floor) | Policy Board | governance | timelocked; a brake retires a queued change | target ≤ 200%; tick ≥ one hour; floor 30 to 365 days | the board; the door for the ten-tick rule | the Spillway |
| Lower the target | Policy Board | security signers, governance | at once | lower only | the board | the Spillway |
| Set the Waterfall's legs and the developer payee | Policy Board | governance | timelocked | desk leg ≤ 25%; developer leg ≤ 10%; the payee is never a protocol contract | the door (legs); the board (payee) | the Spillway |
| Add a reserve asset | Policy Board | governance | timelocked; needs a live price | never the protocol's own token | the door | the reserve |
| Delist a reserve asset | Policy Board | governance | at once | admission freeze only; tracked balances stay | the door | the reserve |
| Add or remove a revenue door | Policy Board | governance | add timelocked; remove at once | the Spillway | ||
| Add, remove, lock, unlock a security signer | Policy Board | governance | add and unlock timelocked; remove and lock at once | the boards | ||
| Pause a department | Policy Board | security signers, governance | at once | any department | ||
| Unpause a department | Policy Board | governance | at once | any department | ||
| Name a desk sweep | Policy Board | governance | timelocked; an explicit amount | the desk, the Spillway | ||
| Recover stray tokens from a department | Policy Board | governance | at once | never from the reserve, the Well, or any vault | the board | a department's own balance |
| Move desk funds to governance | Policy Board | governance | timelocked; an explicit amount | the desk's vault | ||
| Raise the tolls | Market Board | governance | timelocked; a cut retires a queued raise | never above 10% per direction | the door (the hook) | the pool |
| Lower the tolls | Market Board | security signers, governance | at once | lower only | the door | the pool |
| Replace the liquidity adapter | Market Board | governance | timelocked; bound to the hook (the hook checks); listed in the adapter registry (the board checks) | the door for the binding, the board for the listing | the pool | |
| Add or remove liquidity | Market Board | governance | timelocked; sized when queued | one loss policy | the board | the pool, the desk |
| Register, replace, or disable a contract | registry | governance | timelocked | the composition | ||
| Grant or revoke mint rights | registry | governance | timelocked | only registered contracts | the token | the token |
| Switch minting off or on | registry | governance | at once | the token | the token | |
| Pause the token | registry | governance | at once | the token | every transfer | |
| Blacklist an address | registry | a department granted the power | at once | the token | that address | |
| Burn a blacklisted balance | registry | governance | at once | only a blacklisted address | the token | that address |
| Set the price staleness window | Policy Board | governance | timelocked | five minutes to seven days | the board | pricing |
| Add a price feed | price registry | governance | timelocked; validated live | the registry | pricing |
T20.2. Authority matrix. Every governed action, who may take it, on what delay, under what ceiling, and who enforces the ceiling.
What a pause freezes
| Paused department | What stops | What keeps running |
|---|---|---|
| the Tap | redemption, including redemption from stake | everything else; the reserve is untouched. A frozen reserve asset has the same effect on redemption without a pause: one failed transfer reverts the whole basket exit |
| the Basin | deposits, from a wallet or straight from a Decanter claim, and all three exits | releases already in the Decanter keep accruing and claiming to a wallet |
| the Decanter | claims on releases in progress, and the creation of new releases, so offering purchases and staking withdrawals fail too | existing releases keep accruing; nothing is lost, only delayed |
| the offering | purchases; starting a window | the market |
| the Spillway | ticks: no mints, no Well draws; revenue deposits, so offering purchases fail too, since a sale must credit its surplus | tolls keep accruing on the pool until routed |
| the desk | new deployments, swaps, adding liquidity, and the named sweep to the split | withdrawing from a strategy and removing liquidity: risk-reducing actions stay live |
| the ledger | offering records, overflow credits, and reward checkpoints, so purchases and ticks fail with it | stake and release records, and the settlement lock, which never pauses |
| the token | every transfer (a governance-only pause) |
T20.3. What a pause freezes, checked row by row against each department's pause checks.
A change's life
Propose: a board records the change and validates it against its ceilings. Wait: the timelock runs; the change expires if not executed in time. Execute: the board validates again against the live state and applies it. Retire: a change whose nonce is stale, because a brake or another change landed first, is retired unexecuted. A queued change can execute only once.
Contract map
| Plainly | Contract | Holds or moves | Answers |
|---|---|---|---|
| the offering | Pour | mints allocations into the Decanter's vault; banks backing in the reserve; hands surplus to the Spillway | the offering window, the premium now, a purchase preview |
| the reserve | Reservoir | the basket; moves only by the Tap's instruction | NAV (strict and permissive), balances |
| redemption | Tap | burns BRIM; instructs the reserve to pay the basket | a redemption preview, the fee, open or paused |
| the reward engine | Spillway | runs the Waterfall at the door; ticks; draws the Well | the last tick, a tick preview, the Well's runway |
| its vault | SpillwayVault | overflow, waiting | |
| staking | Basin | shares; deposits and exits | staked balance, exit previews |
| its vault | BasinVault | the staked pool; rewards mint here | |
| the genesis allocation | Well | pre-minted BRIM; drawn only by the Spillway | its balance |
| the desk | Mill | the operating sleeve through adapters | positions |
| its vault | MillVault | operating assets | |
| vesting | Decanter | claims a release, optionally straight into the Basin | a release, what is claimable |
| its vault | DecanterVault | escrowed BRIM | |
| the market toll | Tollbooth | the hook; accrued tolls; the liquidity gate | the tolls, a toll preview, the canonical pool |
| the pool adapter | BrimPoolAdapter | the desk's one liquidity position | the pool's price |
| configuration | Charter | every dial and list | the dials |
| the ledger | Ledger | stake shares, releases, overflow credit, eras, the settlement lock | stake shares, releases, era meters |
| the economic board | PolicyBoard | validates and timelocks the dials | pending changes |
| the pool board | MarketBoard | validates and timelocks the tolls and liquidity | pending changes |
| the registry of boards | Boardroom | which desks may act | |
| the registry | Hq | which contracts exist; mint rights; the mint switch | mint rights, the switch |
| the adapter registry | Harbor | which adapters the desk may use | |
| pricing | PriceDesk, ChainlinkPrices | the price walk; strict and permissive reads | prices, staleness |
| the token | BrimToken | BRIM; mint gated by the registry; pause and blacklist | supply, balances |
T20.4. Contract map. Which contract holds what, and which one answers which number on this page.
Links and disclaimer
The yellow paper (also in Chinese, Korean, and Japanese) · @Brim_HQ · Ripe
Brim is an experimental onchain protocol. It holds no customer funds, offers no accounts, and is not a regulated financial institution of any kind. Nothing here is investment advice. The reserve is tokenized stocks whose value moves with markets. Participate at your own risk.