Skip to content
KIMP

Contracts overview

The seven KIMP core contracts on GIWA, their responsibilities, how they call each other, and who can change or pause them.

KIMP is seven Solidity contracts deployed on GIWA. They are written for Solidity ^0.8.24, are non-upgradeable, and share two access roles: the governance timelock, which sets parameters, and the guardian Safe, which can only pause.

Contracts#

ContractResponsibility
KimpIndexStores the finalized Kimp Index per asset and epoch. Computes the median, applies quorum, staleness and the circuit guard. Serves latest and twap. Holds the source switch setSource.
KimpReporterRegistryReporter bonds in $KIMP, report submission, automatic flagging, disputes and slashing. Forwards valid reports to KimpIndex.
KimpMarketKimp Contracts. open, increase, close, settle, redeem, liquidate. Margin, leverage, limits, fees and per-asset market state.
KimpPoolThe LP vault and counterparty. Escrows trader margin, holds liquidity, issues kLP, computes NAV, manages the withdrawal queue.
KimpVerifiedGateReads DojangScroll.isVerified for the Verified Lane. Stores the leaderboard opt-in flag.
KimpStaking$KIMP staking, the 30% fee share, reporter payments, unstake cooldown, voting weight.
KimpBuybackAccumulates 20% of fees, swaps to $KIMP with a TWAP guard, burns.

The $KIMP token, the governor, the timelock and the fair launch contract are deployed alongside them. See Mainnet deployment plan.

Call graph#

  1. 1Reporters call KimpReporterRegistry.submit once per epoch with signed reports for each asset.
  2. 2The registry checks bond status and signatures, then forwards reports to KimpIndex.
  3. 3KimpIndex finalizes each epoch: median of valid reports, quorum of 5, circuit guard above 300 bps.
  4. 4Traders call KimpMarket.open. For the Verified Lane, the market first calls KimpVerifiedGate.
  5. 5KimpMarket reads KimpIndex.latest for entry, checks caps against KimpPool.nav, and moves margin into pool escrow.
  6. 6Fees are split at collection: 50% to KimpPool, 30% to KimpStaking, 20% to KimpBuyback.
  7. 7At expiry, anyone calls KimpMarket.settle, which reads KimpIndex.twap over the final hour and books P&L against the pool.
  8. 8Keepers call KimpMarket.liquidate on under-margined positions and receive 10% of the penalty.

Access control#

RoleHolderPowers
onlyTimelockGovernance timelock, 48-hour delayEvery parameter setter, including setSource, caps, fees, limits
onlyGuardianSafe multisig, 4-of-7Pause and unpause markets. Nothing else.
onlyMarketKimpMarketPool escrow and payout, fee notifications
onlyRegistryKimpReporterRegistryReport forwarding into KimpIndex
PermissionlessAnyoneTrading, deposits, staking, settle, liquidate, execute, disputes

No role can transfer user funds out of the pool, change a position, or mint $KIMP.

Upgrade policy#

Core contracts are non-upgradeable. There are no proxies on custody logic. Contract references between core contracts are immutable where they carry custody, and timelocked where they do not. When a new version is needed, it is deployed side by side and governance votes to migrate. Existing positions settle on the contracts they were opened on. See Admin keys and timelock.

Units and conventions#

QuantityTypeUnit
Index valueint256Basis points, signed. Negative values are a reverse premium.
USD amountsuint25618 decimals
Timestampsuint64Unix seconds
Asset identifierbytes32Ticker, for example "BTC"
Epochuint64Unix minute, 60 seconds each

GIWA dependencies#

  • 1-second blocks and Flashblocks preconfirmations for fast feedback. See Flashblocks usage.
  • DojangScroll and the EAS predeploy for the Verified Lane. See Dojang integration.
  • An on-chain GIWA DEX for buyback execution.
  • The Upbit Oracle, once it ships on GIWA, as primary Upbit price source.

Full signatures are in Interfaces.