Skip to content

Protocol

Contracts, governance and upgrades.

Where EXIT's contracts are, who controls them, how they can change, and every change made so far. Addresses come from the deployment manifest; live values are read from the chain.

Deployment

Where it runs.

Chain
Ethereum (chain id 1)
Deployed
Oct 9, 2026, 6:45 PM UTC
Source commit
25ec0ede2a175eae5f9db58dc6db930509cc7697
Block explorer
eth.blockscout.com

Contracts

Proxies, implementations and versions.

EXIT, ExitRouter and ExitStaking are UUPS proxies: the proxy address never changes, and an upgrade points it at new code. Everything else is immutable.

EXIT

Proxy · UUPS

The EXIT token: 10,000,000,000 EXIT, minted once at genesis. It refuses any mint after genesis and any upgrade that changes the cap.

Version
1.0.0
Live check
Checking the chain…

ExitRouter

Proxy · UUPS

Verifies signed quotes, enforces the reward schedule and every limit, routes each asset to its adapter and pays EXIT from the RewardVault.

Version
1.0.1
Live check
Checking the chain…

ExitStaking

Proxy · UUPS

Fixed-term staking. Each position's reward is reserved in full when it opens, and claims can't be paused.

Version
1.0.0
Live check
Checking the chain…

RewardVault

Not upgradeable

Holds the 4.5B exit-reward allocation and pays exit rewards only within released tranches, released by the multisig or automatically by the TrancheKeeper.

TrancheKeeper

Not upgradeable

Releases the RewardVault's next tranche when the released balance runs low, at most once per interval, on a rule fixed in the contract. Pausers can stop it.

FounderVesting

Not upgradeable · no admin

Holds the founder's 1.5B and releases it on a schedule fixed in code that nobody can accelerate.

Staking rewards reserve

ExitTreasury

Holds the 1.5B staking-rewards allocation. Its only registered pool is ExitStaking.

ERC721ExitAdapter

Immutable · replaceable

Receives an ERC-721 NFT with its signed quote and burns it, or sends it to 0x…dEaD, verifying the result.

Live check
Checking ExitRouter…

ERC1155ExitAdapter

Immutable · replaceable

The same for ERC-1155 tokens, one token id per quote, with balances checked before and after.

Live check
Checking ExitRouter…

ERC20ExitAdapter

Immutable · replaceable

Takes exactly the quoted ERC-20 amount after your approval and disposes of it, refusing tokens that move any other amount.

Live check
Checking ExitRouter…

ExitTimelock

Governance

Holds the admin and upgrade roles. Every upgrade, and every change to limits, assets, signers or the launch, waits 48 hours in public before it can execute.

Each address links to its verified source on the block explorer. Adapters are replaced rather than upgraded: ExitRouter can register a new one, which shows in the event log below.

Governance

Who can change what.

The ops multisig proposes; the timelock enforces a public waiting period of 48 hours before any upgrade, or change to limits, assets, signers or the launch, can execute. Reward tranches are released by the multisig directly, or automatically when the released balance runs low. Pausing is instant and needs no delay.

Control
Multisig + timelock
Admin and upgrader
0x1C3e324E397920c62512831f4d27ea3678Be7c73DEFAULT_ADMIN_ROLE and UPGRADER_ROLE (the timelock)
Upgrade delay
48 hours
Ops multisig
0x2284CBA0867F6c330169A771a8415697E457d305Proposes and executes timelock calls; releases exit-reward tranches.
EXIT token upgrades
Checking…

Role holders as recorded at deployment. Role grants and revocations since then are listed under On-chain events below.

  • Upgrades (timelock)

    EXIT, ExitRouter and ExitStaking only, to fix security defects. The token refuses any new code that changes its 10B cap, and its upgrades can be sealed permanently.

  • Limits, assets, signers, launch (timelock)

    Caps, the asset allowlist, open eligibility and its limits, unblocking an asset, adapters, quote signers, the launch date, and unpausing.

  • Risk-reducing actions (pausers, instant)

    Pause exits or new stakes, block an asset, switch off open eligibility or an adapter, revoke a quote signer.

  • Treasury (multisig)

    Release exit-reward tranches from the RewardVault, and fund the staking pool from its reserve.

Scheduled changes

The public review window.

In production, every upgrade and governed change is scheduled on the timelock and can only execute once the delay has passed. Anything scheduled appears here first, with the exact call and when it becomes executable, so it can be reviewed before it takes effect.

Upgrades

Every upgrade, in public.

An upgrade is validated against the deployed storage layout, rehearsed on a testnet, proposed by the multisig, held by the timelock for the full delay, then executed and published here with its reason, code changes and security impact.

No upgrades since deployment: every proxy runs the implementation it was deployed with.

On-chain events

Upgrades, role changes, pauses, launch scheduling, asset and adapter changes and reward tranches, as indexed from the chain.

Reward schedule

1,000 EXIT per $1 in the Launch Month, then 100.

The Launch Month is the first 30 days from the official launch. ExitRouter decides the rate from chain time; every quote is signed at one rate, and a quote at the Launch Month rate is refused once the Launch Month ends. The launch can be rescheduled only before it starts, never into the past.

Eligibility and limits

What can exit, and how much.

ExitRouter enforces these limits on every exit, on-chain; the eligibility cutoff is applied when a quote is signed. An asset type can be open to any asset, not only allowlisted ones: those exits always go to 0x…dEaD, within a limit per asset. A pauser can switch open eligibility off at once; switching it on, or changing a limit, is a governed change.

Supply

10,000,000,000 EXIT. Fixed.

Minted once, at genesis, into six buckets. There is no mint function, minting is refused after genesis, and an upgrade that changes the cap is refused. Rewards come from these allocations, never from new tokens.
AllocationShareEXITHeld by
Exit rewards45%4,500,000,000RewardVault0xB4Bf182A4bA89C990468f105A7FC74EAceEa8a00
Staking rewards15%1,500,000,000Staking rewards reserve0x0F65C0dfE12350d8A88c75A3B88bb7a57dC63435
Founder (Anthony Anger)15%1,500,000,000FounderVesting0xbe5d07EfC8B89c9CeE1D3D89217Bbf6fDfaD8cB0
Liquidity10%1,000,000,000ExitTreasury0xFfb2F880EF80D3E1B6B586Cc12Ea19Dd52c6A045
Protocol treasury10%1,000,000,000ExitTreasury0xDb4F11265D353A2696Bd6A4aD900eCaB08Bb1DE3
Ecosystem + community5%500,000,000ExitTreasury0xa6D0DD299DbeCBDcC31E2F25294a04f35267fa27

Available at launch

About 1.5B EXIT (15% of supply) is planned to be operationally available at launch. On top of it, the founder's first unlock, 100,000,000 EXIT (1% of supply), is released to the founder's wallet at launch.

DEX / market liquidity · from liquidity600,000,000
Public / community launch · from protocol treasury400,000,000
Initial exit-reward tranche · from exit rewards300,000,000
Launch ecosystem incentives · from ecosystem + community200,000,000
Founder EXIT · first unlock, to the founder's wallet100,000,000

Founder vesting

Vesting starts at the official launch: 100,000,000 EXIT (1% of supply) at launch, then the same at the end of each of the next 14 months, 15 unlocks, fully vested 14 months after launch. The clock follows the launch scheduled on ExitRouter, so postponing the launch postpones every unlock; it never starts before the planned launch, and it latches permanently once the launch begins.

Circulating supply: how it is counted

Most EXIT sits in protocol contracts and multisigs for years, so six figures are kept apart, and no token is called circulating just because it is unlocked.

Allocated
Assigned to a bucket at genesis. Always the full 10B.
Protocol-held
Held by a protocol contract, a protocol multisig or the founder's wallet: the RewardVault, the staking reserve, ExitStaking's reward funds, FounderVesting, and the treasury, liquidity and ecosystem holders.
Vested
Founder EXIT whose unlock has passed: 1% of supply at launch, then 1% more at the end of each month.
Unlocked
No contract rule stops it moving: released founder EXIT, the RewardVault's released tranche, multisig balances.
Operationally available
Unlocked and set aside for a launch use: DEX liquidity, the public and community launch, the exit-reward tranche, ecosystem incentives. About 1.5B (15%) at launch.
Circulating
Held outside every protocol contract and multisig: by users (including EXIT they have staked), DEX pools and exchanges. Total supply minus protocol-held.
  1. Unlocked is not circulating. EXIT released in the RewardVault, or sitting in a treasury multisig, stays protocol-held until it is paid out or transferred to a third party.
  2. At launch 1% of supply in founder EXIT is vested and released to the founder's wallet, and the rest stays in FounderVesting. Founder EXIT only counts as circulating once it leaves the founder's wallet.
  3. EXIT added to a DEX pool counts as circulating, because anyone can buy it, and is reported separately so the pool depth is visible.
  4. Every figure is reproducible from chain data and the addresses on this page, and names the block it was computed at.

Circulating supply at launch is at most the operationally available amount, and starts lower: exit rewards only circulate once exits pay them out, and ecosystem incentives once they are distributed. Total supply: 10,000,000,000 EXIT.