Quivra pairs collectible adventurers with funded NFT wallets, automatic trading strategies and NFT-supported $QVRA buybacks and burns.
THE GUILD'S FIELD GUIDE $QVRA
Current implementation
The public website and this field guide are live. The holder app and mint page are excluded from the public deployment. The collection, individual wallets, funded-slot controller, artwork catalog and proof-based reveal are implemented and tested locally. No production mint deployment is configured. PONS reward routing, OpenSea settlement, automatic trading services and buyback execution remain pending. The older reserve contracts are legacy prototypes, not the current system.
The approved model
At the default split while funding is enabled, each eligible 0.02 ETH in PONS creator rewards unlocks one mint slot: 0.01 ETH becomes deployer-claimable and 0.01 ETH stays reserved for that future NFT. No NFT is created yet. A buyer pays 0.015 ETH on Quivra's own mint page to create the NFT and activate its individual 0.01 ETH wallet grant in the same transaction.
Net primary-sale proceeds and resale royalties actually received default to an equal split: 50% buyback-and-burn budget, 50% deployer-claimable operations. Neither refills the NFT wallet. Holders can deposit, withdraw available assets while keeping the NFT, or authorize automatic trading within revocable limits.
This guide records the approved product design as of 22 September 2026. Product rules describe the intended implementation; prototype controls and historical simulations are explicitly identified. No production addresses or completed independent audit are published here. A design decision is not evidence of an implemented integration.
THE CHARACTERS
Three kindreds. One guild.
From ancient woods to ember-scarred kingdoms, three kindreds answer the call. Choose your companion, raise your banner, and write a tale worthy of the guild.
The FoxThe InuThe Chan
Appearance and rarity
Side-profile pixel foxes, inus and adult chans carry randomized eyes, capes, clothing, weapons, materials and finishes through forests, cities and burned landscapes. Foxes and inus have fur colors and styles; chans have hair colors and styles. Each character has 13 applicable traits. The completed first edition contains 5,555 designs built from 28 shared complete portraits and approved masked color variations. The fixed inventory determines actual trait frequencies; traits are not all independently distributed.
Appearance is assigned once through the mint randomness process; there is no holder customization or Trait Lab. Rarity is cosmetic and does not increase starting capital, permissions or trading performance. The first edition now contains 5,555 unique rendered designs, with a fixed inventory and locally tested asynchronous reveal. The landing portraits show finished edition designs. The content-addressed upload bundle is verified locally and prepared for storage handoff; pinning, retrieval verification, deployment and independent review are pending. No artwork is generated at mint time. Reveal assigns an existing design without replacement, with equal probability among the remaining designs in its edition.
Finish tier
Designs
Share (rounded)
Common
3,611
65.00%
Uncommon
1,111
20.00%
Rare
555
9.99%
Epic
222
4.00%
Legendary
56
1.01%
Kindred counts: 1,836 Foxes, 1,391 Inus and 2,328 Chans. Finish is a fixed cosmetic tier, not a performance rating or an overall rank.
What follows the NFT
The NFT carries agent access eligibility and control of its associated wallet for the current holder, under the published service terms. Resale transfers remaining wallet assets with the NFT, never a new grant. Private account data, credentials and funds in unrelated personal wallets do not transfer.
Withdrawing trading capital does not burn the NFT. An empty wallet retains the collectible and access eligibility, but cannot trade until funded. Ownership does not represent team equity, a share of protocol revenue or guaranteed returns.
Supply
The initial cap is 5,555 lifetime funded mint slots, including slots already minted. Unclaimed slots have no separate limit and remain fully backed by reserved grants. Funding a slot does not create an NFT. Burns, withdrawals and purchases never replenish the funded-slot allowance. The owner may raise the cap after it is reached; 5,555 is not an immutable maximum supply. The new catalog prevents duplicate DNA within and across editions and selects without replacement. Reopening requires enough already committed artwork; this implementation supports at most 32 editions of up to 6,000 designs each.
THE PROTOCOL / 01
Rewards kindle the forge.
Creator rewards unlock a slot. Your purchase creates the character.
Creator-reward flow
Verify receipt of fresh, eligible PONS creator rewards. Each receipt immediately credits the deployer share and the grant-funding share under the current split. Partial grant allocations accumulate until 0.01 ETH funds a slot.
At the default split, for each 0.02 ETH while funding is enabled, credit 0.01 ETH to the deployer and reserve 0.01 ETH for one additional mint slot. No NFT or NFT wallet is created at this point.
The buyer pays exactly 0.015 ETH on the Quivra mint page. The transaction consumes one available slot, creates the NFT directly for that buyer and assigns the reserved 0.01 ETH to its active wallet.
At the default split, the full direct mint payment splits into 0.0075 ETH operations and 0.0075 ETH buyback budget. No OpenSea primary listing or marketplace deduction is involved. Network gas is separate.
A failed mint rolls back the slot consumption, grant transfer and payment allocation. A transaction that reverts still costs network gas.
Initial cap and reopening
The initial cap counts 5,555 lifetime funded slots, including slots already minted. Funding the final slot immediately switches all excess and subsequent creator rewards to 100% deployer-claimable, including dust. This does not depend on buyers minting.
Already funded, unclaimed slots remain available with their full grants reserved. The controller cannot release their capital to the deployer. Buying a slot, transferring an NFT, withdrawing capital or burning an NFT never restores funding capacity.
Only the owner can resume funding, with an explicitly higher total cap after the current cap is reached. New rewards use the current creator split (50/50 by default). Existing claims, grants and unclaimed slots are not recycled.
At the default split, funding the first 5,555 slots requires 111.1 ETH: 55.55 ETH for the deployer and 55.55 ETH reserved for grants. With zero buyers, there are still zero NFTs and all 5,555 slots remain mintable.
Available mints and reserved capital
Available mints equal lifetime funded slots minus successful paid mints. Reserved capital equals available mints multiplied by 0.01 ETH. These counters are distinct from the number of NFTs minted.
For example at the default split, 0.24 ETH funds 12 slots and credits 0.12 ETH to the deployer. After five paid mints, five NFT wallets hold their initial 0.05 ETH and seven unclaimed slots retain 0.07 ETH in the controller. No unsold NFT inventory or primary listing queue exists.
Unclaimed slots have no expiry or separate cap. Their capital remains reserved until someone mints. Trait assignment follows the mint randomness request; no traits are assigned when a slot is funded.
Settlement requirements
The local controller implements receipt-time splits, slot reservation, paid mint settlement and separate claims. It now connects to the implemented ERC-721 collection and individual holder wallets in local tests. The 5,555-image edition, immutable catalog and drand proof adapter are implemented and locally tested. Storage pinning, independent review, production deployment and PONS routing remain outstanding.
The minter must create the requested token for the buyer, assign the full grant, reject unauthorized callers and activate the grant exactly once. The mint page verifies the configured network and contract code before requesting a transaction.
OpenSea is a separate secondary-market integration. Its orders, cancellation, listing locks and resale royalties still require validation. Neither primary proceeds nor royalty receipts ever count as fresh creator rewards.
THE PROTOCOL / 02
Follow the proceeds.
Sales fuel the forge. Creator rewards supply the starting capital.
The default 50/50 allocation
Destination
Share
Purpose
Buyback-and-burn budget
50%
Acquire $QVRA and verify the resulting burn.
Operations
50%
Deployer-claimable budget for the project.
NFT wallet top-up
0%
No sale-funded or royalty-funded grant.
The owner can adjust creator, primary and royalty splits independently for future receipts. The fixed grant stays 0.01 ETH; creator changes affect the funding rate. Existing claims, funded slots and holder balances remain intact. The displayed tables use default splits. The sale split applies to verified net primary-sale proceeds and to resale royalties actually received. The direct mint currently has no marketplace deduction: the full 0.015 ETH is split. No additional primary royalty is charged. There is no additional team cut. Round buybacks down in integer wei and assign the remainder to operations.
One primary purchase
Direct mint on Quivra: no OpenSea primary listing or marketplace fee. Network gas is paid separately and does not reduce the grant or the mint-price allocation.
Creator rewards required
0.02 ETH
Deployer creator-reward claim
0.01 ETH
One-time NFT starting capital
0.01 ETH
Gross primary price
0.015 ETH
Direct-mint marketplace fee
0 ETH
Net sale proceeds
0.015 ETH
Buyback budget
0.0075 ETH
Deployer operations claim
0.0075 ETH
Withdrawing the untouched 0.01 ETH grant after paying 0.015 ETH leaves 0.005 ETH acquisition cost before transaction costs. This removes the earlier automatic top-up extraction at the default price; it does not establish a resale floor, prevent all manipulation or guarantee that an NFT retains value. The controller requires the exact 0.015 ETH mint price.
Resale royalties
The seller keeps sale proceeds after marketplace fees and any royalties. Only the royalty received by the protocol is split. The royalty rate is not finalized and payment may depend on marketplace and transfer-enforcement support.
Example only: on a 0.02 ETH resale with a 5% royalty, the protocol receives 0.001 ETH and allocates 0.0005 ETH each to buybacks and operations. With a separate hypothetical 1% marketplace charge, the seller receives 0.0188 ETH before gas. The NFT wallet receives nothing from that royalty.
The implemented receiver forwards native ETH royalties into the controller. WETH and other ERC-20 royalty routing are not implemented. The collection owner can set the advertised royalty rate separately from the split of royalties received; neither setting alone proves marketplace enforcement. Production OpenSea settlement and enforcement remain unverified.
Buyback execution
The controller lets only the original deployer release allocated buyback ETH to that same wallet. Purchases and burns require separate deployer-signed transactions; released funds are under deployer control and their use is not enforced by the controller. A local mint-to-burn test passes; production venue integration remains pending. Allocated or released ETH is not an executed purchase or burn.
Track accrued budget, completed swaps and verified burns separately. An executor needs an approved token and venue, slippage/deadline limits, minimum economic batch size, receipt reconciliation and failed-swap retries that cannot spend a budget twice. Batch sizes and schedules remain implementation decisions.
Do not use holder trading capital for protocol buybacks. Trading profits stay in the NFT wallet unless the holder withdraws them. No agent performance fee or share of trading profits has been agreed. Burns do not guarantee market demand or price appreciation.
THE PROTOCOL / 03
Your companion. Your capital.
Each NFT has its own trading wallet. Its balance is real capital to trade or withdraw, not a fixed redemption promise.
Verified locally: the actual collection and wallet contracts create a separate wallet for each NFT and fund it with exactly 0.01 ETH in the paid-mint transaction. All 11 collection/wallet tests passed in the latest check on 22 September 2026, including withdrawals, transfer revocation and failed-mint rollback. These tests use disposable local blockchain state; they do not establish a live PONS-to-wallet flow on Robinhood Chain. Deployment, production reward routing and independent review remain pending.
Capital and activation
The one-time starting allocation is 0.01 ETH from creator rewards, reserved in the controller before a paid mint. The NFT and its funded wallet are created together; activation occurs exactly once. Resale, withdrawal, an empty balance or a service restart never generates a replacement grant.
After activation, the current holder can deposit and withdraw available wallet assets without burning the NFT. Holdings may include ETH and acquired tokens; a displayed ETH valuation is not a promise of immediately withdrawable ETH. Converting positions requires executable liquidity and incurs costs. Gains, losses, gas, deposits and withdrawals change the balance.
Holder control
The holder controls withdrawals and revocable trading authorizations. The deployer must not have an emergency withdrawal path into holder trading capital, including through token approvals or upgrade permissions. Treasury administration is separate.
An agent can execute authorized trades, not move funds to arbitrary recipients. In the implemented wallet, a successful withdrawal revokes trading permissions. Every NFT transfer also clears the old policy; the new holder must authorize trading again. The wallet address and remaining balances stay attached to that NFT. Insufficient capital or gas pauses trading; funded service and monitoring remain necessary.
Resale safeguards
Create a listing commitment identifying the NFT and the wallet assets included in the sale.
Pause automation and lock withdrawals or other asset-changing operations while that commitment is active. Settlement validates the committed assets; a balance display is not enforcement.
Cancel or invalidate the order onchain before releasing the lock. A marketplace UI delisting alone is insufficient. Multiple orders and unsolicited offers must not bypass the lock.
On settlement, transfer the NFT and remaining wallet assets together. Revoke old owner delegations, approvals and outstanding signatures using an ownership epoch or equivalent mechanism.
Keep trading paused until the buyer chooses and authorizes a strategy.
Unsolicited deposits must not grant control or unexpectedly release a commitment; handling of extra assets and unsupported tokens needs explicit settlement rules. Direct NFT transfers also revoke old control and pause automation. Private account data never travels with the token.
OpenSea/Seaport compatibility must be proven before activation, including offer acceptance and transfers outside the normal app. If the chosen integration cannot enforce these rules, disable funded-wallet sales through that route. Never imply a generic token-bound account solves listing safety on its own.
Retired redemption model
The earlier shared-reserve, burn-to-redeem and purchase-price-multiple ideas are retired. There is no fixed ETH claim, no sale top-up and no need to burn an NFT to withdraw its available assets. Existing local reserve contracts implement the old design; see legacy contract disclosure.
THE WORKSPACE / 01
Set your course. Keep command.
The holder sets the boundaries. The executor follows the strategy.
Automatic execution
The holder selects a strategy and explicitly authorizes bounded trading. Subsequent eligible orders execute automatically without a signature for each trade. Authorization is revocable and should expire; asset allowlists, approved venues, position and exposure ceilings, spend limits and slippage checks must be enforced outside the AI model.
The executor cannot authorize its own withdrawals or change the beneficiary. A running service, sufficient capital and execution gas are required. Failures, stale prices and ownership changes pause execution. Unsupervised operation still requires monitoring, alerts and a reliable stop mechanism; no limit guarantees a maximum loss. The local wallet enforces an executor, adapter, exact asset pair, expiry, per-trade limit, cumulative spend budget, minimum output rate and adapter code hash. Live quote validation, strategy signals, portfolio exposure controls and the running service still require implementation and review.
Strategy presets
Sentinel, Ranger and Seeker are current app configuration examples for patient, momentum-oriented and more active profiles. They are not implemented trading algorithms or validated profit claims. Symbols shown in the app are illustrative, not a supported-market list.
The separate PONS strategy study supports additional research directions: cautious large-cap trend investigation and cash/observation defaults for the sampled mid- and low-cap groups. Historical results do not justify autonomous market making or deployment. Read the evidence and limitations.
Holder and public views
My Guild groups owned characters; Agent Desk shows each wallet and strategy; presets configure limits. The performance explorer separates trading results from deposits, withdrawals and grants. The protocol dashboard separates reward receipts, deployer claims, wallet assignments, buyback budgets and verified burns.
The app currently uses browser-local settings and synthetic guild histories. Strategy Research separately loads archived historical simulations. Ownership checks, live balances, signed authorizations and execution are not connected. Cosmetic rarity never changes trading permissions or performance.
Agent costs
Trading venue fees, gas and slippage affect actual wallet returns. Direct mint and trading gas are separate from the full starting grant. Service pricing, gas sponsorship, supported venues and included usage are not finalized; no recurring or performance fee has been agreed. Publish these before activation and require explicit consent to any charges.
THE WORKSPACE / 02
Evidence before execution.
Archived PONS prices. Simulated orders. Results shown alongside their assumptions.
The first study
The pilot covers nine factory-verified PONS V1 tokens: DELTA, HMM and website in the millions; TYGR, WHEN and LOCK in the hundreds of thousands; Artcoin, RWOG and FORAI in the tens of thousands. Categories use reported market caps at collection, not historical entry-time capitalization. V2 bonding curves are outside this pilot.
The archived sample spans 22 August to 21 September 2026: 20 days for training and 10 later days for checking. It is a small current-survivor sample, not the full launch universe. Raw data and checksums remain preserved.
What the results support
The large-cap training winner lost 0.95% in the later period. Cash won the mid- and low-cap training comparisons. Large-cap trend following gained 4.28% later, but was not the training selection and depended heavily on one token. It is an exploratory lead, not a retrospectively substituted winner or a deployed strategy.
Model limits
Each token uses an independent $1,000 virtual cash sleeve, separate from the NFT's 0.01 ETH funding model. Modeled pool fees, slippage, gas and volume gates constrain fills; final positions that cannot clear the liquidity gate receive zero liquidation value. These assumptions do not reconstruct executable historical depth, all taxes or MEV.
No strategy is validated for live use. The next proposed forward simulation is not running or scheduled. Historical results are never presented as funded account returns.
Reproduce and inspect
The research workspace, archived inputs and reproduction tools remain local during prelaunch. Historical results do not represent live agent performance.
REFERENCE / 01
Know who holds the keys.
Protocol administration and holder trading capital have separate permissions.
Approved permission model
Action
Authority
Boundary
Claim creator rewards
Deployer
Current configured creator share (50% by default); 100% of excess and subsequent creator rewards at the funded-slot cap.
Claim operations
Deployer
Current configured operations shares (50% by default); primary and royalty settings are independent.
Change creator, primary-sale and royalty splits
Controller owner
Future receipts only; each share may be 0 to 100%. The grant remains 0.01 ETH and accrued claims are unchanged.
Set the advertised resale royalty rate
Collection owner
Separate from the royalty allocation split; the launch rate is not finalized.
Resume slot funding with a higher cap
Owner
Only after the current lifetime funded-slot cap is reached. Public cap-change event.
Official OpenSea account (secondary market)
Deployer
Planned account control; production marketplace integration remains pending.
Withdraw activated NFT wallet assets
Current holder
Available assets; no active listing lock. NFT retained.
Authorize or revoke trading
Current holder
Bounded strategy permissions; cleared on transfer.
Execute trades
Authorized executor
Approved policy; no arbitrary fund transfers.
Secondary listing
Current holder
Asset commitment, trading pause and withdrawal lock.
Emergency sweep of reserved grants or NFT wallet capital
None in the current controller/wallet contracts
No administrator withdrawal or sweep function. Broader recovery powers exist only in the superseded legacy prototypes disclosed below.
The deployer is designated to control the official OpenSea collection account; this does not control holders' marketplace accounts or secondary prices. Account setup and production settlement remain pending. Creator-income claims and operations claims are separately accounted even when paid to the same wallet. The controller supports bounded buyback releases to the immutable deployer wallet; it has no emergency recovery function. Any future treasury mechanism requires a separate implementation and review; it must not access reserved grants or holder wallets.
Protection requirements
No owner withdrawal path may reach holder NFT trading capital. Before minting, reserved grants must remain committed and cannot become deployer-withdrawable funds. Operator approvals, arbitrary calls, account upgrades and emergency mechanisms must not bypass these boundaries.
Publish deployed code, administrators, upgrade powers, emergency behavior and verified addresses before launch. Emergency pause policy must distinguish stopping automated trades from holder withdrawal rights; active marketplace locks require valid cancellation before unlocking.
Issuance controller
QuivraIssuanceController.sol is a new local component, independent of the legacy admin contracts. It has no emergency access to NFT grants. Its immutable deployer wallet can claim credited creator income and operations through separate claim functions; owner transfers do not change the beneficiary. Only the configured reward source can submit receipts. Production integration and independent review remain pending.
Legacy code disclosure
The legacy reserve contracts do not implement this model
The local QuivraReserveVault, QuivraAdmin and QuivraTreasury contracts are undeployed legacy prototypes. Their paused owner recovery can withdraw all vault ETH, including funds assigned to NFT holders. The old vault uses burn-to-redeem claims that can remain unpaid indefinitely after withdrawal. That authority is incompatible with the approved NFT-wallet design.
These files have not been silently changed or described as protecting holder funds. They must not be deployed as the new system. Replacement wallet custody, transfer invalidation and grant activation are now implemented locally and need independent review. Production settlement remains outstanding.
Legacy QuivraAdmin.sol
Legacy QuivraReserveVault.sol
Legacy QuivraTreasury.sol
Detailed legacy administration notes
REFERENCE / 02
The next chapter.
Delivery is measured in working behavior.
Live website and locally verified components
Live public landing page and docs: silent forest entrance, axe throw, matching forest loading images, mobile navigation, mist and finished collection portraits. Dashboard (Open Soon) is inactive; app and mint routes are not published.
Holder app preview, presets, synthetic performance explorer and protocol accounting examples.
Integer-wei calculator for the approved 0.02 / 0.01 / 0.015 ETH and 50/50 model.
Historical PONS strategy study with archived data and reproducible exports.
Local 5,555-cap issuance/reward controller with owner reopening and boundary tests; collection and individual wallets are implemented and tested locally; production deployment and reward routing remain pending.
5,555 final designs, fixed rarity counts, duplicate prevention, immutable metadata commitments and a verified local upload bundle; storage is not yet connected.
Actual collection and individual wallet contracts tested for atomic funding, holder withdrawals, transfer revocation, bounded trade permissions and native royalty allocation.
Legacy administration and reserve contracts retained for source transparency only.
Before funding and sales
Pin and verify the completed artwork release, independently review the proof-based reveal and collection contracts, and complete Robinhood Chain integrations before deploying the tested 5,555-cap issuance controller.
After the founder manually deploys the PONS token and supplies its address, verify the reward source and implement production routing into the tested controller. Configure the mint page against reviewed deployed contracts and verify the full flow on the target network.
Independently review the implemented holder wallets, transfer revocation and bounded trade permissions before deployment.
Verify direct paid mint settlement and separately validate safe secondary listings on the chosen OpenSea route, including stale orders and signatures.
Implement automatic strategy execution, monitoring, revocation, public accounting and verified burns.
Complete appropriate independent review and adversarial tests; publish verified addresses, permissions, costs and service terms.
Activation gate
Wallet connection, minting, the holder app, funded trading and marketplace automation are not publicly available. No launch date is committed. Validate strategies prospectively and enable only the specific integrations that have passed their funding, permissions and settlement checks.
REFERENCE / 03
A few things to know.
Can I withdraw and keep my NFT?
Yes. This is implemented and tested locally: after grant activation and outside a listing lock, the current holder can withdraw available assets and retain the NFT. A successful withdrawal revokes trading permission. Production deployment and the app withdrawal connection remain pending.
Does resale refill the wallet?
No. The grant occurs once. The buyer receives the remaining committed wallet assets and must authorize trading again. Both net primary proceeds and collected resale royalties default to 50/50 to buybacks and operations.
Is withdrawing the grant free profit?
At the approved 0.015 ETH primary price, withdrawing an untouched 0.01 ETH grant leaves 0.005 ETH acquisition cost plus transaction costs. This is not a guarantee against every extraction route or a promise of resale value.
Can the deployer withdraw holder trading capital?
The implemented controller and NFT wallets have no administrator function to withdraw reserved grants or holder trading capital. The existing legacy prototypes have broader powers and do not implement that protection; read the source disclosure.
Do unclaimed slots stop funding?
No NFT exists before a paid mint. Unclaimed funded slots do not stop further slot funding below the cap. At 5,555 lifetime funded slots, new creator rewards become 100% deployer-claimable; existing slots remain mintable. The owner may reopen funding at a higher cap.
Must I approve each trade?
The intended executor trades automatically within a holder's revocable authorization. Empty wallets, insufficient gas, listing commitments, ownership changes or invalid permissions pause execution. The preview has no running executor.
Are returns or burns guaranteed?
No. Capital can lose value and some assets may become illiquid. A buyback budget is not an executed burn; burns do not guarantee a rising price. Historical simulations are research, not funded agent performance.
Is the funded NFT wallet confirmed working?
Yes in local contract tests: simulated creator receipts fund slots, a 0.015 ETH paid mint creates an NFT and its own wallet, and that wallet receives the reserved 0.01 ETH. Live PONS routing and production deployment remain unverified. No real NFTs were minted in these checks.
Can I buy or mint here now?
The mint page and holder app are not publicly available. No production mint deployment is configured. Product language describes the approved design; check development status for delivery.