
Trust and safety
Architecture
The MTF contracts, what each one does, who can call what, and the admin powers with their timelocks.
How the contracts connect.
Text version
- Users call MTFRouter (ape, redeem) and IndexLocker (lock, claim, unlock).
- MTFRouter swaps through the Uniswap v4 PoolManager, which calls IndexHook on every MEME500 swap.
- IndexHook buys and sells the memes on V2 style pools, holds the vault and mints and burns IndexToken (MEME500).
- IndexHook checks MemeRegistry for approved tokens and sends fees to FeeSplitter.
- FeeSplitter apes the lockers' share into MEME500 for IndexLocker, sends the buyback share to the buyback wallet, and pays the treasury and creators.
- The MTF token and its pool are not deployed yet (TBA).
- IndexFactory creates new indexes and their pools (user-built indexes are switched off at launch).
Contracts#
| Contract | Role | Who calls it |
|---|---|---|
| IndexHook | Uniswap v4 hook for every index pool. Buys and sells the basket, holds the vault, mints and burns index tokens, enforces the 3% guard and the in-kind fallback. | Only the PoolManager calls the swap callbacks. Views are public. |
| MTFRouter | Entry point for ape and redeem. Never spends another user's approval. | Anyone |
| IndexFactory | Creates indexes and their pools, holds creator stakes, stores card metadata URIs. | Owner for official indexes; anyone for user-built indexes once switched on |
| MemeRegistry | The approved list and token tiers. | Owner proposes (48h timelock) and delists (instant) |
| IndexToken | The ERC-20 for each index, such as MEME500. | Only the IndexHook can mint and burn |
| FeeSplitter | Receives fees (ETH on apes, MEME500 shares on redeems) and splits them: lockers, creator, buyback wallet, treasury. | Keepers convert the locker share (rate limited, minimum output); the buyback share is sent to the buyback wallet |
| Buyback wallet | A public wallet that receives the buyback share. Once MTF launches, the team uses it to buy back and burn MTF manually, at its discretion. | Set at deploy; changing it requires a 48h timelock |
| IndexLocker | Locks, reward streaming in the index token, early exit penalties streamed over 7 days, and decay to 1× after maturity. | Anyone (their own locks); anyone can kick a matured lock |
| MTF token and pool | Planned platform token, fixed supply, 100% in a locked MTF/ETH pool at launch. | Not deployed yet: TBA |
Admin powers and their limits#
| Power | Who | Delay |
|---|---|---|
| List a meme or raise its tier | Registry owner | 48 hour timelock |
| Delist or downgrade a meme (blocks apes, never redeems) | Registry owner | Instant |
| Change MEME500 target weights | Owner | 48 hour timelock |
| Change fee splitter configuration or addresses used by the hook | Owner | 48 hour timelock |
| Change the buyback, backing or treasury wallet | Owner | 48 hour timelock |
| Buy back and burn MTF | Team, from the buyback wallet | Manual and discretionary; every burn is on-chain |
| Emergency pause of new apes | Owner (and a creator for their own index) | Instant; each can only clear its own pause; redeems stay open |
| Change the ape limits (min and max per ape, deposit cap) | Owner | Instant. Today: 0.01 ETH min, 5 ETH max per ape, no deposit cap |
| Appoint or remove keepers | Owner | Instant |
| Process locker rewards | Keeper | Rate limited, minimum output |
| Rebalance toward scheduled targets | Rebalance keeper appointed by the owner (none appointed yet) | Bounded size, minimum output, a few times per day at most |
| Switch user-built indexes on | Factory owner | 48 hour timelock; switching off is instant |



