Abstract
Alien Frozen Frogs is a colony-simulation game on Solana. Players run a frozen lunar base: unfreeze cryo-chambers into frog workers, manage their daily needs, develop buildings, send troopers on missions, and defend the outpost. Every worker is a living character with hunger, fatigue, hygiene, entertainment and social needs that directly affect performance.
The economy is built on one principle: verify, don't trust. Token supply is fixed at launch. The rewards treasury is a program-owned address with no private key. Pack drops and rarity upgrades use verifiable on-chain randomness with published odds and a guaranteed pity system. Reward emission is proportional to what the treasury actually holds, so the pool can never promise more than it has.
Why This Exists
Most play-to-earn games died the same death: rewards minted from thin air, hyperinflation, collapse. Most game tokens died another way: team allocations dumped on players, treasuries drained by insiders, "trust us" as the only guarantee. We designed against both failure modes from day one.
- No emission from thin air. Rewards are funded by real flows - player spending, trading fees, and revenue buybacks. Daily payout is a percentage of the treasury's actual balance. Mathematically, the pool cannot run dry.
- No insider faucet. The team holds a small, pre-announced, publicly streamed position. Project income comes from fees on live activity - the team earns only if the game lives.
- No invisible rules. Drop odds, upgrade chances, pity counters, payout limits and fee splits live in on-chain accounts and program code, changeable only through a multisig with a timelock - and visible to everyone at all times.
The Game
The Colony
Your base is a lunar compound of functional buildings. Each building is a gameplay loop:
| Building | Purpose |
|---|---|
| Cryo Lab | Unfreeze chambers into workers (with a supervisor assigned) |
| Workshop | Send workers to earn; repair and upgrade |
| Housing | Sleep and rest; fatigue management |
| Food Court | Feeding; hunger management |
| Gym | Workouts granting temporary performance bonuses |
| Club | Entertainment and socializing needs |
| Science Center | Cloning and research |
| Farm | Food production |
| Landing Field | Trooper arrivals and space missions |
| Beacon | Time-limited missions and events |
| Gates & Outpost | Tower-defense style base protection |
| Mines | Resource extraction |
Living Workers
Every frog tracks five needs - hunger, fatigue, hygiene, entertainment, friendship - decaying over real time. Neglected needs impose earning penalties; total exhaustion takes a worker out of action. Care actions are free, fast, and fully off-chain: the moment-to-moment game never asks you to sign a transaction or pay a fee.
Progression
- Account skills - 15+ purchasable skills (better diets, extra work slots, faster unfreezing, automation of care routines) unlocked by account level.
- Unit levels - individual worker development through play.
- Rarity - the on-chain layer: upgrades, fusion, and rare drops.
Progression is deliberately steep at the start: early earnings are modest and scale with investment of time and strategy. Spending accelerates progression but never replaces it - everything buyable is also reachable by play.
Units & NFTs
The Roster
19 unit templates across four classes - 8 workers, 3 supervisors, 5 troopers, 3 vehicles - each existing in 5 rarities: Common, Uncommon, Rare, Epic, Legendary. Rarity grants moderate, published stat bonuses (Legendary is roughly 2-3x Common - meaningful, never game-breaking).
True Ownership
Units are Metaplex Core assets in the player's wallet. Type, rarity and origin are on-chain attributes writable only by the game program - a player cannot forge a Legendary, and neither can we. Units are freely tradable on Solana marketplaces; a 5% royalty applies.
Packs & Verifiable Randomness
Units drop from packs. Drop tables (type x rarity weights) are stored in a public program account - the odds you see in the interface are read from the chain, not typed into a website. Pack opening uses on-chain verifiable randomness (VRF): neither the player nor the team can predict or influence the result, and every roll is provable.
Rarity Upgrades & Pity
Common through Epic can be upgraded via the Workshop: pay the attempt cost, VRF rolls against published odds. After 10 consecutive failed attempts, the next attempt is a guaranteed success. The pity counter lives on-chain in the player's account - check your own streak in the explorer.
Token & Launch
The token launches on pump.fun as a fair launch: fixed supply, mint authority revoked by the platform, no pre-mine, no private sale, no VC allocation.
The team's initial buy is 3% of supply, executed inside the launch transaction, announced in advance, and streamed linearly over 12 months with no cliff through a public Streamflow stream, governed by a published sell-policy.
The treasury starts empty - and fills by rule, not by promise
We do not pre-fund the reward pool. Instead, a one-time Fill Phase applies from launch: while the treasury's cumulative inflow is below 7% of supply, elevated shares of every flow are routed to it - 85% of in-game token spending (versus 70% later), 70% of SOL revenue via buyback (versus 50%), 80% of creator fees. The extra share comes out of the team's cut, never out of burn. In plain words: the team takes its full share only after the players' pool is funded.
| Flow | Fill Phase | Normal |
|---|---|---|
| In-game token spending | 85% treasury / 10% burn / 5% dev | 70 / 10 / 20 |
| Packs paid in token | 85 / 10 / 5 | 45 / 10 / 45 |
| SOL revenue | 70% buyback to treasury / 20% dev / 10% liquidity | 50 / 35 / 15 |
| Creator fees | 80% treasury / 20% dev | published normal split |
The phase ends at whichever comes first: cumulative inflow reaches 7% of supply, or the treasury sustainably funds $1,000 per day of rewards (balance x 1.5% x 7-day average price). The second condition is a price compensator: when the token is expensive, a smaller token balance buys the same daily reward power, so the phase does not drag on for months. Both the cumulative counter and the current mode are readable on-chain. A separate emergency rule re-applies the elevated shares automatically if the treasury ever falls below 1% of supply or under 30 days of payout budget, and releases at 2.5% - a safety valve, not a favor.
A public sell-policy governs the team's unlocked tokens (weekly cap, monthly reporting). A share of pump.fun creator fees is routed directly to the rewards treasury address - a permanent, verifiable inflow tied to trading volume. Token update authority is revoked after launch.
The Economic Loop
Three Forms of Value at Launch
- SOL/USDC - the permanent on-ramp; buy packs without owning the token.
- The game token - bought on the market or claimed from earnings; pays for everything, with a small price bonus over SOL.
- Earned balance - tokens you've earned but not yet withdrawn. Spending them in-game skips the claim fee entirely, and the tokens never leave the treasury - the strongest recycling loop in the economy.
Prices are identical in USD-anchored terms across all payment forms. Crystals, a prepaid premium currency with bundle bonuses, are planned as a Phase-2 addition: one-way conversion from the token, non-withdrawable, buying time and convenience - never status.
Proportional Emission
Daily reward budget = min(hard emission cap, 1-2% of current treasury balance). The treasury pays out a fraction of what it holds - it cannot be emptied, rewards breathe with activity instead of inflating against it, and the hard cap bounds damage even in a worst-case backend compromise. Per-wallet daily and weekly claim limits are enforced on-chain.
Unlike mining hardware, your "hashrate" grows not just from spending but from playing well: care, strategy and upgrades all raise your share. And unlike inflationary chains, total supply never grows - burn flows only shrink it. Rewards scale with the economy; supply scales with nothing.
Buyback (Year-One Rule)
A fixed percentage of SOL revenue purchases the token on the open market - sized as a share of revenue, executed as small orders over a rolling 7-14 day window (smoothing through pumps and dips, no discretion, sandwich-resistant). Purchased tokens flow to the treasury and to burn. The rule is fixed for the project's first year; any evolution after that will be announced, never silent. The buyback wallet is public.
Fairness & Security
The treasury has no private key
Reward funds sit in a Program Derived Address - an address deliberately generated off the ed25519 curve, meaning no matching private key exists at all. Not hidden, not held by a multisig, not burned: nonexistent. Only the program's own code can move those funds, and only through the paths written into it.
Every payout requires a valid backend signature over a single-use message, passes on-chain per-wallet limits, and fits within the global daily budget. A full compromise of our servers would be capped at roughly 1.5% of the treasury per day rather than the whole pool.
The rest of the stack
- Server-authoritative gameplay. All game formulas, timers and balances are computed server-side. The client sends intents, never values. Manipulating requests, devtools or multiple tabs yields nothing.
- Cryptographic identity. Sign-In With Solana: your wallet signature is your login. No passwords, no impersonation.
- Governed change. Program upgrade authority and economic configs are held by a multisig with a timelock: no rule changes overnight. A contract audit is planned prior to full economic launch; findings will be published.
- Append-only accounting. Every balance change is a ledger entry; any player's history is reconstructible and disputable with evidence.
Revenue Model
The project does not fund itself by selling a token allocation. Income streams:
| Stream | Split |
|---|---|
| In-game token spending (circulation) | 70% treasury / 10% burn / 20% development (dev share hard-capped at 25% in code) |
| Primary pack sales (SOL) | 50% buyback / 35% development / 15% liquidity & marketing |
| Primary pack sales (token) | 45% treasury / 10% burn / 45% development (hard-capped at 50%) |
| Secondary NFT royalties (5%) | 50% team / 50% buyback & burn |
| pump.fun creator fees | split between treasury and development (shares published) |
| Claim (withdrawal) fee, 2-5% | part burn / part development; zero fee when spending earned balance in-game |
| Limited boost-NFT series | ~50% of series revenue funds that series' own reward pool |
Every split is either enforced by program code or executed through published addresses. Current values live in a config account and can be adjusted only through the multisig with a timelock - publicly and in advance. The ceilings are compiled into the program itself and cannot be exceeded by any config change, so the share returning to players and burn has a floor no governance decision can breach.
Burn flows permanently reduce supply; a periodic burn report is published with transaction hashes.
Transparency Commitments
| Claim | How to verify |
|---|---|
| Supply is fixed | Mint authority = null (explorer) |
| Fill Phase state & cumulative inflow | On-chain counter in the treasury PDA + rules in program code |
| Team position (3%) & unlock schedule | Pre-launch announcement + public Streamflow stream |
| Fee splits & hard caps | Program code + config accounts |
| Creator fees flow to treasury | Fee-sharing configuration, treasury address |
| Drop odds, upgrade odds, pity | Public config accounts + per-player PDA counters |
| Emission <= min(cap, % of balance) | Program code + treasury balance history |
| Buyback rule execution | Public buyback wallet trail |
Roadmap
Milestone-gated, not date-promised. Each phase ships when its quality and security gates pass - sales never precede playable content.
Mobile app stores: under review, not committed
A build distributed through mobile app stores is an open question, not a promise. App store policies place strict conditions on games that touch digital assets - billing requirements, restrictions on rewarding users with cryptocurrency, and disclosure rules - and a careless approach there can put the whole project at risk rather than expand it.
We will therefore weigh this in a later phase, and only under a strict plan: any store build would carry the gameplay layer alone, with the token, NFTs and rewards remaining exclusively on the web. If the risk assessment does not come out clearly in our favour, we will simply not ship to stores - the web and progressive web app remain the primary route, and they require no platform's permission.
Legal & Structure
The project operates through a corporate entity; the token remains a public fair launch with no allocation sold privately. Our activities - issuing our own utility token, selling our own game NFTs, and paying rewards from a program-controlled treasury - do not constitute regulated crypto services (custody, exchange, order execution, brokerage, or operating a trading venue), which are what CASP/VASP licensing regimes target.
Several jurisdictions confirm this directly: the BVI Financial Services Commission has stated that primary token issuance alone is not a registrable VASP activity; the Cayman Islands treat issuance as lower-risk registration rather than full licensing; and MiCA excludes unique, non-fungible NFTs from its scope while exempting utility tokens that give access to an already-operating service.
Disclaimers
The token is a utility token for use within Alien Frozen Frogs. It is not an investment product, and nothing in this document is financial advice or an offer of securities. In-game rewards depend on gameplay, economic activity and treasury balance; they are not guaranteed, fixed or predictable. Digital assets are volatile and may lose value entirely. NFTs confer in-game utility and ownership of the digital asset only. Availability of the game and token may be restricted in certain jurisdictions; users are responsible for compliance with their local laws. This document describes intended design and may evolve; material changes will be announced publicly before taking effect.