Promo kit
Ready-made posts, if you want to share this
Every card below pairs one verified, on-chain fact with the exact wording already used on our own channel — nothing here is written for you to spin or exaggerate. Download the image, copy the caption, post it as-is.

Yield here is simple interest, not compounded. It accrues on the recorded stake alone, every second, and stops the moment the plan's term ends — Starter at day 180, Elite at day 90. Claiming does not restart the clock and unclaimed yield does not compound while it waits.

The advertised minimum is 10 USDT. The real one is 11.37. The contract requires 10 USDT to remain AFTER the entry fee, and small deposits pay 12% — so 11.37 sent is the smallest amount that actually clears. Send exactly 10 and it reverts; you lose only gas, but you lose it for nothing.

Your plan is decided by what gets RECORDED, not what you send. Send 500 and 450 is recorded — below the Growth threshold, so you land on Starter. To actually reach Growth you need to send 555.56. The site's calculator works this out before you sign; read it before you pick a round number.

Claim fee is 10% of yield on Starter and Growth, half that — 5% — on Advanced and Elite. It is charged on yield only; principal is never touched by it. claimFeeBps() is a pure function in the contract, which means not even the owner can change it later.

If you joined through a referral link, part of your claim goes to the people above you — 8% of your yield for one Base-tier referrer, up to 35% for three Platinum uplines stacked. It comes out of YOUR claim, not paid by the protocol on top. No referrer, no deduction. Your dashboard shows your exact number once your wallet is connected.

Exit is open at all times, no approval needed. The penalty on principal declines every week: 50% in week 1, 40% in week 2, 30% in week 3, 20% in week 4, 10% from week 5 onward — and it never goes lower than 10%. Unclaimed yield is lost separately when you exit, so claim first if you're leaving.

There is no maturity function in this contract. After the full term, yield simply stops accruing — the only way out is still earlyExit(), still at the week-5+ rate. Hold a position to the very end and you still get 90% of principal back, not 100%. We'd rather you read that here than find out at withdrawal.

Exit works even if the contract is paused, and even if your address is blacklisted. Blacklisting blocks new stakes and claims — it does not freeze your principal. There is no state the owner can put the contract into that traps your exit.

Two independent ways to unlock a zero-penalty full withdrawal, and neither needs the owner's cooperation: the contract has been paused for 30 continuous days, or 3 votes from the partner body flip emergency mode and 12 hours pass. Either path, principal comes back whole.

There is a rescue function that can move the contract's full balance — and it needs 3 votes from the voting body plus a 48-hour delay before it's callable, and it can only ever send funds to a pre-set Gnosis Safe multisig, never an arbitrary address. We're telling you it exists because you should know, not because we expect to need it.

Referral tiers above Base require THREE conditions at once — your own stake, your direct volume, and your active referral count. All three, not any one. A tier priced in wallets alone gets gamed with throwaway accounts; a tier priced in real capital doesn't.

Referral tiers, three levels deep: Base pays 8/4/0%, Silver 12/6/2% (needs 500 staked, 2,500 direct volume, 3 referrals), Gold 15/8/4% (2,500 staked, 15,000 volume, 10 referrals), Platinum 20/10/5% (10,000 staked, 75,000 volume, 25 referrals). Every rate is paid at the UPLINE's own tier, never the tier below them.

A referral's volume counts toward your tier only while their position stays open. If they exit, your counted volume falls with them — it doesn't just stop rising, it actually decreases. That's deliberate: a tier earned once and kept forever regardless of whether the team is still there isn't measuring anything real.

Entry fee is a sliding scale, not one flat number: 12% under 500 USDT, 10% from 500, 7% from 2,500, 5% from 10,000. It comes off before your stake is even recorded — the deposit screen shows the exact split before you ever sign.

The free-stake window offers 100 places, each a 10 USDT position that costs the pool nothing until it's actually funded — a giveaway earns yield from day one but can't be claimed against until real capital backs it. That's what stops a hundred free positions from being a withdrawal on other people's deposits.

A free position isn't a dead end — top it up with real capital and it converts to an ordinary funded position on the spot, eligible for a plan upgrade like any other. The giveaway principal itself stays walled off forever, but everything else about the position becomes fully yours.

No proxy. No delegatecall. No upgradeable pattern anywhere in this contract. The code running today is the code that runs for as long as this contract exists — nobody, including us, can swap the logic underneath you later.

dailyRates is set once, at deployment, and is never assigned anywhere else in roughly 2,400 lines of contract code. We checked. There is no function — not for the owner, not for anyone — that raises or lowers it after the fact.

Three things this contract can genuinely do on Polymarket, unaided and permissionlessly: split collateral into a complete YES/NO set, merge a set back to collateral before resolution, and redeem winning tokens after a market settles. All three are real calls to Polymarket's own deployed contracts, and every event fires only once the call has actually succeeded.

What this contract cannot do: place an order on Polymarket's book. fillOrder, fillOrders and matchOrders are gated behind an onlyOperator permission that Polymarket's own admins control — not something we can code around, and not something granted to arbitrary third-party contracts. Until that changes, split-and-redeem alone nets to zero before gas; the profit in this kind of arbitrage only ever comes from the order book.

The honest math, per dollar deposited: Starter must pay back $2.59, Growth $3.09, Advanced $3.47, Elite $3.39 — against a strategy that has earned $0 so far. The gap is real and it's the same ratio at any size, because the rates are proportions, not fixed sums. Full table at arbhub.site/strategy.

An idle pool — no new deposits, everyone claiming as it accrues — drains before its own term ends on every single plan: Starter empties day 93 of 180, Growth day 62 of 150, Advanced day 44 of 120, Elite day 35 of 90. That's not a liquidity risk good management avoids; it's what a fixed rate above what the capital earns means, arithmetically.

What a real trading return could actually fund, after a 20% performance fee: 15%/year gets you 0.033%/day, 25%/year gets 0.055%/day, even 50%/year — better than almost any fund — only gets 0.11%/day. Starter's advertised 1.2%/day is still 11x that top scenario. The gap closes with a lower, honest rate, not a better guess at the strategy.

Source is verified on Sourcify with an EXACT match — both creation and runtime bytecode, not just a similar-looking recompile. That means the code you can read on Sourcify is byte-for-byte what's actually running at the deployed address. Nothing to take on trust there.

Your team doesn't have to be big to start — it has to start. Every person you bring in builds volume that counts toward your referral tier and your gold tier at once, three levels deep, the moment they claim. The compounding is real, it's just not automatic — that part's on you.

Nine gold tiers, from a single gram to a full kilo, now sit right on the homepage — not just in the menu. Your team volume across three levels is being tracked on-chain today, before the rounds even open. Build now, qualify later.

No lockup you can't leave. No maturity date holding your money hostage. Stake today, watch it build, and walk away whenever you decide to — the early-exit penalty drops every week and caps at 10%. Nothing here asks for your trust, only your address.

The referral programme pays real USDT the moment your team claims, and the gold tiers stack on top of that — same volume, two rewards. You don't need permission to start building; the contract doesn't ask who referred you first before it counts.

Read the code, not our word for it. Exact-match verified on Sourcify, no proxy, no upgradeable pattern, and the owner cannot touch a single dollar of staked principal. Confidence here isn't a marketing line — it's something you can check yourself in five minutes.

Yield doesn't wait for you to check the app. It builds every second, against the stake the contract already recorded, whether you're watching or not. Check in once a week or once an hour — the number keeps moving either way.

Every stake, every claim, every fee — it's all sitting on Polygon where anyone can look. Not a dashboard we control, not a number we could quietly change. The chain doesn't take our word for it either.

You don't need to arrive with a fortune. A modest, honest stake today is still a real position building real yield — the same contract, the same rates, the same rules as anyone depositing ten times more.

Claim today, claim next month, or let it build — the choice is entirely yours, and the contract has no opinion about it. There's no bonus for waiting and no penalty for claiming often. Take it on your own schedule.

Don't take a screenshot's word for a live number. Every figure on this channel and on the site traces back to the same contract call anyone can run themselves — read-only, no login, no permission needed. Check it, then decide.

Questions get real answers here, not a support ticket that disappears into a queue. If something about the contract, the rates, or the security model doesn't add up to you, ask — that's exactly what this channel is for.

This week alone: multi-provider RPC failover so no single outage can take a page down, a mobile display fix, a live market-news feed, and a homepage banner for the gold rewards. All of it shipped in the open, on the same branch anyone can read. A platform that's still building beats one that's finished pretending.

Every rate, fee, and threshold we publish was checked this session directly against the deployed contract — 41 separate reads, zero mismatches. You don't need to trust that we did it right: pull up 0x5589105c61154f93D11aa350a25c634d5B324bFB on Polygonscan and read dailyRates, claimFeeBps and planDurations yourself.

The voting body for anything requiring quorum — emergency mode, a rescue — is the owner plus every registered partner, and it takes 3 votes to move. One person alone, including the owner, can't trigger either path. The partner list is public and readable on-chain any time.

We have exactly one channel: @arbhub_site. No email address exists for this project — anything claiming to be one is forged. No DM, no "support agent," no second channel with our name and logo is us, no matter how convincing it looks.

A referral only counts toward your headcount once their recorded stake crosses a minimum floor. An empty or never-funded position doesn't count as a person on your team — which is what stops a tier from being priced in throwaway wallets that hold nothing.

The two development-fee wallets are barred from the free-stake window entirely, and everywhere else they're limited to one fixed-size position — no exceptions, enforced by the contract itself, not by policy. A wallet that collects protocol revenue getting a free claim on other depositors' capital would be exactly the kind of thing this project exists to not do.

Everything runs on Polygon mainnet, chain id 137. Collateral is USDT — check the token contract matches ours before you approve anything; a look-alike token on the wrong contract is a classic way people get separated from their money.

Before you sign a deposit: the screen shows what leaves your wallet, what the entry fee takes, and what actually gets recorded as your stake — three different numbers, all visible before you commit to anything. If a platform only shows you the amount you send, ask why.

Staking calls require tx.origin to equal msg.sender — a plain wallet, not a smart-contract intermediary. It's a participation rule, not a permission check: nothing here is authorized based on tx.origin, it can only narrow who's allowed to call in, so none of the classic tx.origin-phishing risk applies.

Owner fee withdrawals aren't limited by policy, they're limited by arithmetic — three checks, every time: can't exceed that budget's own uncollected balance, can't exceed the contract's actual liquid balance, and can't dip into what non-fee liabilities need. There's no path from here to a single dollar of staked principal.

Two read-only functions, dashboard() and userDepositBreakdown(), return the whole picture in one call each — gross deposits, fees collected, net stakes, pool balance, what's deployed to arbitrage; per-user gross, fee paid, net stake, active stake. No login, no dashboard we control, callable by anyone directly against the contract.

grantStake exists for the owner to seed a promotional or migrated position — but it isn't free money out of thin air: the same amount has to actually leave the owner's wallet and land in the contract, transferred and balance-checked exactly like a real user deposit. No mechanism here mints stake without matching collateral arriving.

A blacklist flag exists, but it can only block new stakes, top-ups, plan upgrades, and claiming — never earlyExit or emergencyWithdraw. Whatever a wallet is flagged for, its principal can never be permanently frozen by this switch. The owner can't even blacklist themselves; that path is closed off in the code.

Once the partner body votes emergency mode active, the owner cannot unpause the contract to undo it — that path is blocked while emergency mode is set. A vote that passes is a one-way wind-down decision; stakers exit through emergencyWithdraw, not a switch the owner can flip back.

Adding or removing a partner is blocked the moment emergency mode is active. The owner can't shrink the voting body mid-vote to cancel a rescue or an emergency exit already in flight — the people who can vote are locked in before the vote even starts moving.

Every swap into the arbitrage leg has a hard floor on acceptable slippage, and the contract checks it in code — a bound looser than that floor reverts, even when the owner is the one calling. It isn't a policy the owner promises to follow; it's a number the transaction can't get past.

When a strategy position unwinds, cost basis is retired first — so a loss simply retires less basis, it isn't absorbed elsewhere or written off the books. The performance fee only ever applies to a realized gain above that basis, never to returned principal, and never on a leg that lost money.

The recovery wallet — the only address a rescue can ever send funds to — can't be changed once a rescue vote is already pending. The owner can't quietly redirect the sweep target mid-vote; that address has to be set before anyone starts voting.

The performance fee on realized arbitrage profit starts at 10% and is owner-adjustable — but hard-capped in code at 20%. There's no path to raise it past that ceiling, whatever the reason. It only ever applies to realized gains, never to staked principal.

The moment emergency mode activates, the owner loses the ability to open new arbitrage positions or move any more pool collateral into the strategy — both paths are blocked in code. From that point on, the only things that happen are unwinding and stakers withdrawing their principal.

The free-stake programme has a hard cap in code — 100 slots, first-come, first-served. Once they're claimed, that specific door closes; it isn't a marketing number, it's a limit the contract itself enforces.

When a top-up pushes your stake into a higher plan, the rate doesn't wait on us to notice — you call upgradePlan yourself, permissionless, and it only ever moves your rate up to match what you actually have staked. No ticket, no approval, no owner in the loop.

Every claim is checked against a per-day ceiling — 200% of your staked amount, tracked per UTC day. Ordinary yield never comes close to that number; it exists purely as a backstop, so a miscalculation or an edge case can't drain a position in one call.

Automated security scanners flag things worth a second look — five spots in this contract got flagged. Every single one has a written note right next to it explaining why it isn't actually exploitable, not just a blanket suppression. Reviewed and documented, not silently muted.

The contract's own solvency figure explicitly subtracts platform fees that have been charged but not yet withdrawn. Fees sit in the same balance as pool capital until swept out — without that subtraction, revenue earmarked for us would quietly inflate what the pool looks backed by. This is the line that keeps the two from mixing.

The platform's own revenue cut is set once, at deployment, capped at 20% combined across both fee wallets — and there is no function anywhere in the contract to change it afterward. Not owner-adjustable like the performance fee; it's simply fixed for the life of the contract.

For the record: the free-stake giveaway was a 24-hour window from deployment, not a standing offer — and it closed weeks ago, checked in code against the block timestamp, not a policy anyone can extend. If you missed it, there's no owner switch to reopen it. The 100-slot cap we mentioned before was the second, independent limit on top of that clock.

A referrer only earns while their own position stays active — the moment they exit, their upline share stops too. Skin in the game is the whole basis for getting paid a cut of someone else's yield; it isn't a one-time signup bonus that keeps paying after they've left.

Pause the contract or trigger emergency mode, and only one direction of the arbitrage strategy freezes: opening new positions. Merging, redeeming, and swapping strategy tokens back to collateral all stay callable regardless — so money already committed can always come back to the pool, never get stuck mid-recovery.

The owner cannot add themselves as a partner — the contract checks the address and blocks it outright. There's no way to pad the emergency or rescue vote count with a second seat; the voting body's math only ever counts the owner once.

emergencyWithdraw only ever pays out the funded part of a position — a free-stake giveaway's principal is excluded by the same math every time. It never cost the pool anything going in, so it isn't something the pool pays back on the way out either.

The moment a position exits, its amount and rate are zeroed before anything else happens — deliberately, so no later claim call could ever compute a reward against a position that's already gone. It's the direct fix for a claim-after-exit drain bug that existed in an earlier version of this contract.

An emergency vote can be withdrawn right up until the 12-hour delay after activation elapses — after that, it's locked in and can no longer be revoked. Once the withdrawal escape hatch is live, no later change of heart among the voting body can pull it back out from under stakers.

The same 3-of-5 voting body (owner + up to 4 partners) that can trigger emergency withdrawals also gates a separate fund-rescue sweep — but rescue carries a deliberately longer 48-hour delay before it executes, versus 12 hours for emergency mode. More consequence, more time to react.

Voting to sweep funds to the recovery wallet is a separate act from voting for emergency mode — a partner who agrees to one hasn't thereby agreed to the other. And arming a rescue automatically opens stakers' own emergency withdrawal too, so a pending sweep never leaves anyone locked in with no way out.

A stolen owner key alone cannot drain this contract. Sweeping funds to the recovery wallet needs partner quorum first, then a 48-hour public countdown before it's callable — and any partner can revoke their vote at any time right up until execution, no lock-in window, unlike the separate emergency vote.

The blacklist function has one hardcoded exception: the owner's own address. There's no path — accidental or deliberate — to the owner blacklisting themselves and no path to blacklisting anyone else being some kind of loophole for self-privilege either. It's a plain address check, not a policy.

Before you ever sign a deposit transaction, a free read-only call tells you the exact fee split and net amount that will be staked — same math the contract itself uses. The fee is only honest if it's disclosed before you commit to it, not discovered after.

emergencyWithdraw is open to any staker, blacklisted or not. Blacklisting can stop someone from opening new stakes or claiming yield, but it was never built as a way to trap a position during an emergency — the escape hatch doesn't check that flag at all.

Every position, whatever route it comes in through — a first stake, a top-up, or an owner-granted stake — is capped at 25,000 USDT of funded principal. The same ceiling applies everywhere, so no single position can be built up past it by picking a different entry point.

A real fix carried over from an earlier version: referral rewards are subtracted from the referred user's own accrued yield, not credited on top of it from pooled capital. Fee, upline share, and user payout always sum back to exactly what accrued — a full referral chain can no longer quietly cost the pool more than the yield it actually earned.

A free giveaway position starts accruing yield the moment it's issued — but that yield stays locked until the holder deposits real collateral into it. A giveaway that's never funded pays nothing out, ever; the accrual clock running in the background costs the pool nothing on its own.

An earlier version gated referral tiers on headcount alone, which prices a tier in wallets rather than capital — a hundred throwaway accounts cost less to create than the top tier was worth. This version requires real staked volume too, and volume can't be faked cheaply. Headcount survives only as a floor, so one large referral can't carry a tier alone.

An earlier version's free promotional packages had no collateral behind them — the yield they drew came straight out of other depositors' principal, and the better the promotion worked, the bigger that hole got. The current grant mechanism instead requires the owner to fund it up front from marketing budget, so a promotion's cost sits with whoever ran it, never with other stakers.

When arbitrage capital swaps back to collateral, the contract retires its own tracked cost basis first — only what's left above that gets counted as profit. The performance fee is calculated on that leftover alone, so returned principal is mathematically never taxed, not just described that way.

Capital committed to each Polymarket market is tracked separately, keyed to that specific market's condition. When a position redeems, the contract knows exactly how much of that particular market's principal it's getting back — commitments across different open positions are never lumped together or guessed at.

A flat per-call percentage cap on arbitrage deployment isn't a cap at all — each call shrinks the balance the next one is measured against, so repeated calls converge on the entire pool. An earlier design was moved past 99% of collateral this way in 40 calls, leaving emergencyWithdraw unable to pay out. The cap here is cumulative against a fixed ceiling that doesn't shrink as it's consumed.

Every time pool collateral is approved for a swap, that approval is reset to zero again immediately after the call completes. The router never holds a standing claim on pool funds between transactions — only ever the exact amount of the swap in front of it, for as long as that swap takes.

The constructor refuses to deploy at all if the collateral token and the arbitrage strategy token are set to the same address. Letting that through would make every swap between them a silent no-op while the cost-basis counters kept moving anyway — a whole class of accounting bug closed off before the contract can even go live.

At deployment, only the strategy token gets a one-time unlimited approval to Polymarket's real Conditional Tokens contract — mirroring the exact pattern Polymarket's own official exchange contract uses. Pool collateral itself is never given a standing approval like that; it only gets approved for the exact amount of a swap, right before that swap happens.

The fixed-size staking restriction on the two development-fee wallets is checked live against whichever address currently holds that role — repointing the wallet moves the restriction with it, it can't be left behind on an old address. The two ordinary fee wallets that collect deposit and claim fees are deliberately NOT restricted this way; they stake on the same terms as anyone else.

Realized arbitrage profit that hasn't been redeployed yet adds directly onto the deployment ceiling, on top of the flat percentage-of-pool cap. A strategy that's actually making money earns room to run bigger; one that hasn't stays capped at the base percentage. Size follows results, not the other way around.

This contract implements the ERC-1155 receiver hooks Polymarket's own token contract calls back to on every split — not decoration, a hard requirement. Without them, the mint's acceptance check fails and every split reverts, in every market, permanently. Deliberately unrestricted to accept any token sent: refusing would risk blocking a legitimate mint for no real security gain.

Anyone can look up any address's own numbers in a single call: total gross deposited, platform fees paid, net amount actually staked, and current active stake. Same read-only, on-chain transparency as the pool-wide dashboard figures — just scoped down to one specific staker instead of the whole pool.

Opening a Polymarket position moves capital from the strategy-token balance into that specific market's committed amount — but the pool's overall arbitrage exposure figure isn't touched again here. That capital already left the pool at the earlier swap step; counting it a second time at the split would double-book the same money as deployed twice.

Merging a position back before a market resolves is treated as unwinding, not as realizing profit — so no performance fee applies there, whatever the outcome. The fee only ever gets charged once, at final redemption after a market actually settles, never on a mid-flight exit.

Three separate kinds of platform revenue — the deposit fee, the yield-claim fee, and the arbitrage performance fee — each go to their own distinct wallet address, tracked independently on-chain. Nothing is pooled together into one number; every revenue stream stays separately attributable to exactly where it came from.

Removing a partner automatically clears any emergency vote they'd already cast and drops the tally by one — the vote count can never silently drift out of sync with who's actually still in the voting body. This can only happen outside emergency mode in the first place, since the voting body itself is frozen once a vote is live.

The interface this contract uses to call Polymarket's real Conditional Tokens contract wasn't guessed or reconstructed from docs — the three function signatures (split, merge, redeem) were copied verbatim from Gnosis's actual open-source, deployed contract. Anyone can call those same three functions directly on Polymarket's contract too; no special role or permission is required for them.

This contract only compiles correctly with Solidity's viaIR pipeline enabled — without it, one of the read functions hits a genuine "stack too deep" compiler error, not a style choice. This was verified directly by compiling this exact file both ways: it fails under the legacy codegen and produces valid bytecode with viaIR on, which is exactly how the project's build config is set.

Every swap between pool collateral and the strategy currency has a hard minimum-return floor written into the contract, not left to whatever value is passed in off-chain. Both sides of that swap are dollar stablecoins, so anything worse than about 1% back would mean a sandwich attack or a depeg, not ordinary slippage — bounding it on-chain means even a mistyped or zeroed minimum can't hand the pool to a searcher.

Platform fees that have been charged but not yet withdrawn sit in the same token balance as pool capital — so the contract explicitly subtracts them before reporting total assets under management. Skipping that step would inflate every solvency figure and the arbitrage deployment ceiling, making the pool look backed by money that's actually earmarked for the fee wallets.

The deposit fee isn't a flat rate — it drops in bands as the deposit gets bigger, from 12% below $500 down to 5% above $10,000. A flat fee would make the smallest positions the cheapest thing to create, which is exactly backwards for resisting Sybil attacks. The bands are tested for monotonicity: a smaller deposit can never legally net more than a larger one just by crossing a fee tier.

Self-serve recovery of your own remaining principal is available through two completely independent unlock paths: 30 days of continuous pause with no owner action, or partner-vote quorum plus a 12-hour delay that doesn't depend on the owner at all. This works for ANY staker, including a blacklisted one, and no penalty applies either way.

Paying out collected platform fees to their wallet is bounded by three separate arithmetic checks, not policy: it can never exceed that budget's own uncollected balance, never exceed the contract's actual liquid balance, and never dip into what stakers are owed. There's no path from this function to staker principal — the ceiling is set only by fees already charged, at a rate the owner can never raise after deployment.

Referral volume counters use saturating subtraction rather than plain subtraction — if a rounding mismatch would ever push a running total negative, it clamps to zero instead of reverting. Volume is tracked across several code paths at once, so a tiny credited-volume discrepancy costs a member a sliver of tier progress; it can never brick every exit beneath them in the referral tree.

Blacklisting an address blocks new stakes, top-ups, plan upgrades, and claiming yield or referral rewards — but it cannot touch early exit or emergency withdrawal. A blacklisted user's principal can never be permanently frozen by this flag; the two paths back to your own money are carved out of the owner's reach entirely.

The fee charged on claiming yield isn't the same across all plans — Advanced and Elite stakers pay half what the entry-level tiers pay. Committing to a bigger, longer position doesn't just earn a higher rate; it also costs less to actually collect what you've earned.

Exiting a stake fully zeroes its amount and rate on-chain, not just marks it inactive — so no later claim call could ever compute a nonzero reward against a position that already paid out. This is a direct, documented fix for a real fund-drain bug found in an earlier version of the contract, where claiming after an early exit was still reachable.

Every downstream figure from a deposit — plan tier, min/max bounds, referral volume, the recorded stake itself — is derived from the NET amount after the platform fee, never the gross figure that left your wallet. That's what keeps the contract's booked liability equal to the capital it actually holds; it can never record a stake larger than what's really backing it.

Topping up is now open to free (giveaway) positions too — the only route by which a promotional stake can become a real, funded one. An earlier version locked this shut, leaving free-position holders with no path except claiming yield the pool was paying for nothing. The free portion still keeps its own separate accounting, so the giveaway itself never becomes withdrawable just because the position got topped up.

Capital currently out on the arbitrage strategy is tracked at cost — what was actually spent — deliberately never marked to market. That means the pool's total-assets figure needs no external price feed and can never report an unrealized gain as if it were spendable. The only profit that ever reaches the books is profit that has already come back as real collateral.

The yield-claim fee's combined rate is a hard constant at the code level — 10% total, split evenly between two wallets — and that's the one fee on the entire contract that not even the owner can raise after deployment. An earlier version split the same combined rate unevenly between wallets; what a user actually pays has always totalled the same number.

Free promotional positions are capped at 100 in this version, up from just 3 in an earlier one — safe to raise because the free liability is now conditional, not automatic. Claiming stays locked until the holder deposits real collateral, and neither exit path ever returns the free principal itself, so a free position that never converts into a real stake costs the pool nothing.

Blocking contract-mediated calls checks that the caller equals the transaction's origin — a pattern that's usually a red flag, since checking tx.origin for authorization is a classic phishing vector. Here it isn't: nothing gets authorized based on that identity, it only narrows who may participate at all (no smart-contract wallets). A restriction, not an access-control decision, which is precisely what keeps it safe.

The two deposit-fee rates are set once at deployment and are immutable — no governance vote, no key compromise, no later decision can ever raise what a depositor gets charged after they've read the rate. The contract goes further and refuses to even deploy if the combined fee would exceed 20%, so there was never a window where an honest number could balloon into something that isn't a platform fee anymore.

The owner cannot add a new partner to the voting body while an emergency vote is already live. Without that block, an owner facing a real vote could pack the body with friendly addresses to dilute it out mid-flight — blocking the addition during emergency mode closes that door entirely.

The moment an emergency vote reaches quorum, three things happen in the same transaction: the contract pauses immediately, new arbitrage deployments stop cold, and a fixed delay clock starts ticking toward the point where every staker can pull their own principal out through the emergency exit — no further action from the owner required, and none possible to stop it.

A partner can withdraw their emergency vote right up until the delay period fully elapses — after that moment it can no longer be revoked. That's deliberate: once stakers' withdrawal right has actually opened, nobody can vote it back closed out from under them. Revoking below quorum beforehand cancels emergency mode, but the contract stays paused until the owner deliberately unpauses it.

The owner can repoint where a rescue sweep would send funds — but not while any rescue vote is currently outstanding. Partners approve a sweep to a specific address; the owner can't quietly swap that address out from under an approval already in motion. To change the destination, the pending votes have to be revoked first.

The last-resort sweep of remaining collateral is deliberately not a unilateral owner action: it needs standing partner quorum, it's announced on-chain days in advance, and stakers' own emergency exit opens 36 hours before the sweep can even fire. A stolen owner private key alone cannot reach it — the owner calling the function is just the last of three independent conditions that all have to already be true.

The performance fee charged on realized arbitrage profit is owner-settable within limits, not arbitrary — the contract enforces a hard ceiling of 20% at the code level, and no owner action can ever push it past that regardless of what governance or a compromised key might attempt. It only ever applies to real, redeemed profit, never to principal.

Ownership doesn't move in one transaction. This contract uses OpenZeppelin's Ownable2Step, so transferring it takes a proposal from the current owner AND a separate acceptance from the new address — a mistyped or unreachable address during handoff can no longer brick ownership forever. The recommended setup routes it to a Gnosis Safe multisig or a timelock, not a single key.

The owner and all three fee-recipient addresses — two deposit/claim fee wallets and the arbitrage profit recipient — are constructor parameters read from environment variables at deploy time, not constants baked into the bytecode. Nothing about where platform revenue goes is fixed by us in advance; it's set once, openly, at deployment and verifiable in the constructor call itself.

The three Polymarket contract addresses this code references are hardcoded constants, not owner-settable — copied verbatim from Polymarket's own official deployment, so there's no admin function that could ever repoint them to a lookalike. Only one of the three, the Conditional Tokens contract, is actually called; the other two exchange addresses are kept in the code purely for reference and are never invoked.

An earlier version rolled its own reentrancy guard, its own pause flag, and string-based require() errors by hand. This version replaces all three with OpenZeppelin's audited ReentrancyGuard, Pausable, and custom errors, and routes every token transfer through SafeERC20 — so a non-standard ERC-20 that returns false instead of reverting can no longer cause a silent, unaccounted-for transfer failure.

Every deposit into this contract — a stake, a top-up, an owner-granted stake — is verified by comparing the contract's own token balance before and after the transfer, not by trusting the amount requested. A fee-on-transfer or otherwise non-standard token that delivers less than expected gets caught immediately; the position is never credited for collateral that didn't actually arrive.

Once an address exits a position — early or through the emergency escape hatch — that flag is permanent: the same address can never open a new stake in this contract again, ever. It's a deliberate one-way door, not a bug; a wallet that's already been paid out can't cycle back in.

An earlier version had functions called polymarketArbitrageTrade/polymarketArbitrageProfit that did nothing but transfer up to 20% of pool collateral straight to the owner, and pull it back only if the owner chose to — with zero on-chain evidence any trade ever happened. That's fund extraction mislabeled as arbitrage. Both functions are deleted entirely in this version; every Polymarket interaction now calls the real, official Conditional Tokens contract.

An earlier version had a function that let a small partner-appointed group vote to split 100% of the contract's balance among themselves. There's no way to make that safe with a more elaborate vote — so it's deleted entirely, not patched. What replaced it: emergencyWithdraw lets any individual staker pull out their own remaining principal alone, no one else's permission needed. No vote of any size can ever direct a single token to a partner or the owner.

The owner holds exactly one vote out of up to five in the emergency-mode governance body — the same as any partner. Three partners can trigger emergency mode over the owner's own objection, and the owner alone can neither force it through nor block it once it's moving. That's not a courtesy; it's the vote count.

The two development-fee wallets are locked to a single, exact position size — 1,000 USDT, no more, no less — and they pay the deposit fee on it exactly the same as any other depositor. No carve-out, no fee-free treatment for the wallets that collect the platform's own revenue.

This contract cannot hold POL (native Polygon currency) even by accident. Both receive() and fallback() revert unconditionally — there's no path for native currency to land in this contract at all, so there's nothing to get stuck and no withdrawal function needed for it. An entire class of bugs is closed off by simply refusing the deposit in the first place.

This contract doesn't override OpenZeppelin's standard renounceOwnership — the owner genuinely can give up ownership forever. Doing so would permanently disable every owner-only function (pause, blacklist, fee changes, rescue) with no way back, but it would never touch a staker's own stake, claim, or exit — those never required the owner's permission to begin with.

There's a public read-only isProtocolWallet(address) function whose only job is letting a front-end check, before a transaction is even signed, whether a wallet is one of the two development-fee wallets restricted to a fixed deposit size. It exists purely so a mismatched deposit fails gracefully in the UI instead of reverting on-chain after gas is already spent.

Referral earnings don't ride along with a regular yield claim — they pile up in their own pending balance and need their own separate call, claimRef(), to actually reach your wallet. Claiming your staking yield and claiming your referral income are two distinct actions on two distinct balances.

What you deposit and what actually trades on Polymarket are deliberately two separate tokens. Your stake is recorded in the pool's own collateral token; Polymarket's markets are denominated in a different token entirely, and the contract converts between the two only when it deploys capital into a position. Your deposit never has to match what Polymarket itself settles in.

The Uniswap router this contract swaps through is set once at deployment and marked immutable — there is no function anywhere that lets the owner repoint it to a different router later. A malicious or compromised owner key can adjust fees and wallets within limits, but can never redirect trades through a router of their own choosing.

How many distinct addresses have ever staked is its own running counter, incremented once per new depositor and never touched again after that — separate from total staked, total yield paid, and the pool's live balance. getGlobalStats() returns all four together, read-only, for anyone who wants the platform-wide picture in one call.

The contract's totalPaidOut counter only accumulates from yield actually claimed — it never increases when someone exits and gets principal back, early or through the emergency path. It's a running total of profit-like payouts specifically, not a catch-all figure for every dollar that has ever left the pool.

A referral who first stakes below the countable floor isn't locked out forever — if a later top-up pushes their position over that threshold, they start counting toward your headcount at that moment. The check isn't a one-time gate at the first deposit; it re-evaluates every time a referral adds to their stake.

Upgrading your plan doesn't just change your rate going forward — because unclaimed yield is calculated from your last claim using whatever rate is stored right now, upgrading applies the new, higher daily rate to your entire unclaimed period since your last claim, not only to time after the upgrade.

A rescue vote can be pulled back at any time right up until the sweep actually executes — even after the multi-day delay has fully elapsed. That's different from an emergency vote, which locks in and can no longer be revoked once the withdrawal window opens. A single partner changing their mind at the last second still stops the sweep, because the contract re-checks quorum at execution time, not just at the moment the vote first passed.

The function that credits externally-earned arbitrage profit back into the pool only moves value in — there's no matching function that lets the owner pull it back out to a wallet. Once profit is deposited this way, it becomes pool capital like any other, not a balance the owner can later reclaim for themselves.

When a Polymarket position is redeemed, the contract only retires that market's tracked commitment by whatever amount actually came back — never by zeroing it outright. An earlier design that zeroed the commitment on the first call would have let a second, partial redemption on the same market treat returned principal as pure gain. Tracking the real recovered amount closes that hole.

When pool collateral is swapped into the arbitrage currency, what the strategy owes back is recorded as the amount that LEFT the pool, not whatever the swap happened to return. Booking the output instead would let a single bad fill quietly write down the strategy's debt to stakers — the pool is owed back what it actually put in, regardless of execution quality on any one trade.

Referral shares for the three upline levels are paid out of a running remainder, not calculated independently and added up afterward. Each level's share is capped against whatever budget is left after the levels before it were paid, so three mismatched tier rates can never sum to more than the claim itself — it's impossible by construction, not just unlikely in practice.

If someone in your three-level upline chain is blacklisted, their share of your claim isn't rerouted to the next person up the chain — it simply stays in the pool. Blacklisting one link doesn't let the referrer above them collect an extra cut; that share is skipped entirely, not redirected.

Pass a referrer address that doesn't qualify — the zero address, yourself, someone with no active stake, or a blacklisted address — and your stake still goes through exactly the same. There's no revert for a bad referrer; the deposit just proceeds without a referral link attached, silently, rather than blocking you from staking at all.

Your referrer is recorded exactly once, the moment you first stake — there's no function anywhere in the contract that lets it be changed afterward, by you or by the owner. A top-up doesn't touch it, and it isn't reassignable. Whoever referred you at signup is who you're linked to for as long as that address stakes.

Anyone can call a public view function and get back every one of your direct referrals by address, along with each one's exact stake size and plan — not just the aggregate volume number. Your downline roster isn't a private dashboard figure; it's readable on-chain by anyone who knows your address.

An earlier version only ever exposed your direct referral level by name — the two levels above where your yield actually comes from were just a number with nobody attached. This version writes out full address lists for those levels too, so 'who's actually in my second and third level' has a real answer, not just a count.

The 200%-of-stake daily withdrawal cap is only checked starting from your second claim within the same UTC day — the very first claim of a fresh day always goes through unchecked, since there's nothing yet recorded against that day. The cap exists to stop rapid repeated claiming, not to limit the size of any single claim.

A public view function reads the contract's real ERC-1155 outcome-token balance straight from Polymarket's own Conditional Tokens ledger for any specific market position. Anyone can check what the contract actually holds against Polymarket's own records — not just trust the contract's internal accounting.

The contract advertises ERC-1155-receiver support through the standard supportsInterface check, but that isn't actually what lets it accept Polymarket's tokens — Polymarket's own contract only cares about the return value from the receiver hooks themselves. supportsInterface exists purely so wallets and block explorers can tell at a glance that this address can safely hold ERC-1155 tokens.

getGlobalStats() reports the contract's raw token balance — not the same figure dashboard() reports as pool assets. The raw balance includes fees not yet swept out and excludes whatever capital is currently deployed to Polymarket positions, so it isn't the number to read for the pool's real backing; totalAssets() is.

The moment an emergency vote reaches quorum, casting a NEW emergency vote becomes uncallable — the function itself is blocked once emergency mode is active. A partner who hadn't voted yet can't add their voice after the fact; only revoking an already-cast vote stays open, and only until the delay makes even that irrevocable.

Unlike an emergency vote, which stops being castable the instant quorum is reached, a rescue vote has no such lockout — a partner can still cast one even after emergency mode is already active. The two votes are deliberately independent: arming a fund rescue can keep gathering support through and after the point the withdrawal escape hatch has already opened.

Your gross deposited, platform fee paid, and net staked figures are permanent counters that never reset to zero — even after you exit for good and your active stake drops to nothing, those three numbers stay exactly as they were, forever readable by anyone who calls the contract with your address.

Topping up an existing position doesn't restart your early-exit penalty timer — the penalty schedule is measured from your stake's ORIGINAL start time, which a top-up never touches. Add funds to a position you opened weeks ago, and the whole thing — old and new capital alike — exits at whatever discount your original stake had already earned.

Higher plans pay more per day but run for fewer days — Starter earns for 180 days, Elite for only 90. Your cutoff date is your ORIGINAL stake's start time plus whatever plan you currently hold, so upgrading to a higher tier can pull that cutoff earlier, not later, even though your start date never changes.

The contract keeps a running internal counter of currently active stakers — incremented on every new stake, decremented on every exit — but never actually exposes it through any view function. What getGlobalStats() reports instead is a different number entirely: the lifetime count of every address that has ever staked, which only ever goes up.