Bringing the real maritime economy on-chain on BNB Smart Chain.
Version 1.0. Network stage: BNB Smart Chain testnet (chainId 97), with mainnet promotion (chainId 56) gated behind a single environment flip. All live figures in the application are read directly from the deployed contracts; nothing in this document should be read as a promise of rewards or of future value.
Utility disclaimer. $SHIPEX is a utility token used only to access the loyalty program and its benefits. It is not an investment, a security, e-money, or a financial product, and it is not an asset-referenced token or e-money token within the meaning of MiCA. It grants no ownership, no redemption right, and no claim on any vessel or on charter revenue. Nothing in this document is financial, legal, or tax advice. Program rewards are variable and are never guaranteed.
SHIPEX connects a compliant, permissioned utility token to the real maritime economy. Members complete identity verification once, participate with the $SHIPEX token in a fixed-term loyalty program, and receive program rewards whose design is anchored to an attested fleet of real vessels rather than to token emissions or market hype.
The system is built on four load-bearing ideas. First, real vessels are brought on-chain through a class-society attestation pipeline that anchors each vessel's attested value to its permanent IMO number in an on-chain VesselRegistry record. Second, a Proof of Reserve surface lets any member reconcile what the program references against the vessels it names. Third, participation runs through a non-custodial program contract, ShipexStakingV2, in which the tokens a member participates with are never moved out of reach and can be released back to the member at term end. Fourth, rewards are paid from a finite, on-chain reward reserve that charter activity from the fleet is designed to replenish, and the contract is engineered to revert a reward claim it cannot fully cover rather than to underpay, which keeps the program solvent by construction.
This whitepaper documents the market SHIPEX addresses, the on-chain architecture and attestation pipeline, the $SHIPEX utility design, the exact reward mechanism and its accrual mathematics with worked examples, the reserve sustainability model, the compliance framework built around the ERC-3643 permissioned token standard, the smart-contract security posture, the technology stack, the governance path, and a structured threat and risk model.
Shipping is the circulatory system of world trade. More than 80 percent of world commerce by volume moves by sea, carried by a global fleet whose commercial economics have historically been reachable only by shipowners, charterers, financiers, and a narrow band of specialist institutions. The maritime economy is measured in the tens of trillions of dollars, yet an ordinary participant has almost never had a transparent, low-friction way to connect to it.
SHIPEX exists to open that door on-chain, with compliance built in from the first step rather than retrofitted later. The project brings real vessels, an MR2 product oil tanker, a stainless-steel chemical carrier, and a membrane LNG carrier, on-chain, and runs a loyalty program in which verified members participate with the $SHIPEX utility token and receive program rewards paid from an on-chain reward reserve that charter activity from those vessels is designed to replenish. Every figure a member relies on, the reward rate on each tier, the amount participating, the rewards accrued, is read live from the deployed contracts on BNB Smart Chain, not from a marketing database.
This document is written for a technical and institutional reader. It is deliberately exhaustive: it states the real contract addresses, the real fleet, the real formulas, and the real safety properties, and it clearly labels every figure that is a design choice rather than an on-chain fact.
The maritime sector carries the overwhelming majority of goods that cross borders. The headline framing SHIPEX works from is straightforward and widely accepted: more than 80 percent of world trade moves by sea, and the broader maritime economy is measured on the order of tens of trillions of dollars. The application surfaces a 30T reference for the maritime economy as the size of the opportunity the project addresses.
Under that headline sits a cost-heavy, cyclical, and opaque industry. A vessel is a floating, depreciating, heavily regulated piece of infrastructure with a working life measured in decades, an operating cost base exposed to fuel and crew markets, and a charter-hire profile exposed to freight cycles. The result is an economy that is enormous, essential, and structurally hard for outsiders to reach.
Vessels are expensive, and the finance to build and hold them is concentrated. Representative newbuild and secondhand values for the major types illustrate the barrier:
| Vessel type | Representative value |
|---|---|
| Modern Panamax | 35 to 45 million USD |
| Medium-range (MR2) product tanker | around 28.5 million USD (SHIPEX fleet) |
| IMO Type II chemical tanker | around 19.2 million USD (SHIPEX fleet) |
| Membrane LNG carrier | 150 to 250 million USD range; SHIPEX newbuild attested at 54.0 million USD |
Mid-tier operators frequently struggle to access traditional ship finance at these levels, and individuals are effectively locked out entirely. The cost thresholds that make the sector important are the same thresholds that make it inaccessible. SHIPEX addresses accessibility by bringing vessels on-chain and letting verified members connect to the real maritime economy through a low-friction utility token, without operating ships themselves.
Maritime registry, flagging, and valuation records are fragmented across registries, class societies, insurers, and private valuers. That fragmentation creates room for fraud and friction. The International Maritime Organization's legal committee, at its LEG 113 session, introduced stricter verification rules aimed at fraudulent flag registrations, which raises compliance friction, especially for smaller operators.
An on-chain, class-attested record is a structural answer to this gap. When a vessel's attested value is anchored to its permanent IMO number in an immutable on-chain record, verification stops depending on a chain of private attestations and becomes something any member can check directly. SHIPEX treats verifiable, class-society-attested vessel records as the foundation of member trust.
The economics of shipping in this decade are being rewritten by carbon regulation, and the cost of that transition is a central pressure on operators. Three real regulatory frames drive this, and SHIPEX's market thesis is built on them explicitly:
The cost consequence is material. Transitioning to low-sulfur or alternative green fuels, including green methanol and ammonia, can raise voyage costs by up to 20 percent. A vessel's financial standing is increasingly a function of its environmental record alongside its cargo capacity, and the industry is reorienting from measuring success by tonnage toward measuring it by data quality and emission efficiency. On-chain infrastructure is well suited to this world: fuel saved and carbon reduced can be recorded immutably and made auditable, so compliance and performance become verifiable rather than self-reported.
The broader movement to bring real-world value on-chain has left the experimental stage. Market commentary through 2026 places the on-chain real-world value market in the tens of billions of dollars and growing quickly, with regulated frameworks such as the EU's MiCA and Dubai's VARA setting the terms of institutional entry. Sovereign debt, commodities such as gold, and economic rights connected to real estate and maritime vessels are the categories drawing the most attention.
SHIPEX positions maritime real-world value inside that movement, with a compliance-first design intended to meet institutional expectations from the outset rather than after the fact.
SHIPEX is best understood as two connected planes.
The value plane is the physical fleet and its attestation: real vessels, each with a class-society-attested value anchored on-chain to its IMO number in a VesselRegistry record, plus the Proof of Reserve surface that reconciles what the program references against the vessels it names.
The program plane is the on-chain machinery members interact with: the $SHIPEX token contract, the ShipexStakingV2 program contract, the reward reserve that funds program rewards, and the identity gating that restricts eligible participation to verified members.
The two planes meet in the reward reserve. Charter activity from the attested fleet is the designed source that replenishes the reserve, and the reserve is the only place program rewards are paid from. Members receive program rewards from the reserve; they do not receive a pro-rata share of charter revenue, and they hold no claim on the vessels or their earnings. What members can do is independently verify the fleet the program is built around.
A vessel does not appear on-chain by assertion. It moves through an onboarding pipeline whose stages are visible in the live fleet status:
The current fleet shows every stage of this pipeline at once. The MR2 tanker is trading and largely on-chain; the chemical carrier is mid-onboarding while a minor condition of class is cleared and its final certificate and valuation are anchored; the LNG carrier is a pre-delivery newbuild whose full attestation record anchors at delivery, before any tokens are minted against it. This staged honesty is deliberate: the program does not represent a vessel as fully on-chain before its attestation record exists.
Each vessel carries an attestation basis, not a marketing claim. The MR2 tanker's hull value is attested by an IACS member class society and an independent ship-valuation report, anchored on-chain to IMO 9456231. The chemical carrier's provisional valuation is lodged, with the final IACS class certificate and independent valuation to be anchored to IMO 9612874 before the vessel is marked active. The LNG carrier's yard installments and bareboat letter of intent are documented off-chain today, with the full attestation record anchoring to IMO 9789845 at delivery.
The class status of each vessel is carried through to the member: In class, Conditions, or Survey due. A condition of class is not hidden; it is surfaced and tracked to clearance. This is the difference between a record that is verifiable and a record that is merely asserted.
Two distinct reserves matter in SHIPEX, and they should not be confused.
The attested fleet value is the sum of the class-attested vessel valuations, currently about 101.7 million USD across three vessels. This is the real-world value the program is built around, and it is what the Proof of Reserve surface reconciles.
The reward reserve is an on-chain balance inside the program contract, readable through the contract function rewardReserve(), from which program rewards are paid. It is a finite pool funded from the token supply. Its role is covered in depth in Sections 6 and 7.
Keeping these two reserves separate is a core design principle. The attested fleet value describes the real maritime economy the program connects to; the reward reserve describes the on-chain pool that actually funds member rewards and enforces the program's solvency guarantee.
The following are on-chain facts read from the deployed contracts, not design proposals.
| Property | Value |
|---|---|
| Symbol | $SHIPEX |
| Token contract | 0x7489597fA2D93f47604b6132a21655369Fc71275 |
| Program contract (ShipexStakingV2) | 0x5939Fb9F6B8f0a1cC162e3654d053d084E0DcE8c |
| Decimals | 2 |
| Total supply | 1,200,000 $SHIPEX |
| Reward reserve | 200,000 $SHIPEX |
| Network | BNB Smart Chain (testnet chainId 97; mainnet chainId 56 via env flip) |
| Reference value | 0.4285 USD (testnet constant; see 5.3) |
The 2-decimal precision is a deliberate simplification appropriate to a loyalty-utility token: amounts read cleanly in the interface and in worked examples, and the on-chain accrual mathematics is defined against this precision.
$SHIPEX is a utility token used only to access the loyalty program and its benefits. Its function is access and participation: a member acquires $SHIPEX, verifies identity, and participates in a loyalty tier to receive program rewards. The token grants no ownership or financial rights; it is the key to the program, not a claim on anything.
Three negative properties define the token as sharply as its function does. It carries no redemption right: SHIPEX has no obligation to buy the token back or to exchange it for money or any other value. It carries no claim on the fleet: members own no part of any vessel, have no right to charter revenue, and the attested fleet is verification context, not collateral held for members. And it makes no stability promise: the token's value is not pegged or referenced to the vessels, to any currency, or to any other value or right. These properties are stated here because they are what keeps the token in the utility category described in Section 8.4.
At mainnet, the token is designed to be permissioned under the ERC-3643 standard, so that only verified, eligible wallets can hold or transfer it. The current testnet token is a simplified build; the permissioning model is documented in Section 8.
On testnet there is no liquid $SHIPEX market pair, so the application uses a fixed reference value of 0.4285 USD purely to render human-readable estimates. This constant is clearly a placeholder: for production it is intended to be wired to a decentralized exchange pair or an oracle so that displayed values reflect a real market. No member should treat the testnet constant as a market price.
For reference only, multiplying the entire 1,200,000 supply by that constant gives about 514,200 USD. This is an arithmetic reference against a testnet placeholder, not a valuation and not a claim about market value.
Two allocation figures are on-chain facts: the total supply of 1,200,000 $SHIPEX and the reward reserve of 200,000 $SHIPEX (about 16.7 percent of supply) that funds program rewards.
The remainder of supply, roughly 1,000,000 $SHIPEX, covers circulating and program supply, member acquisition, the community, and operations. A precise breakdown of that remainder is a design choice (planned, subject to change) rather than an on-chain fact, and it is presented here only illustratively:
| Bucket | Share of supply | Status |
|---|---|---|
| Reward reserve (on-chain) | 200,000 (16.7 percent) | On-chain fact |
| Program and community | remainder | Designed / planned |
| Operations and reserves | remainder | Designed / planned |
The only figures a reader should rely on are the two on-chain numbers. Everything else in this subsection is labeled as designed or planned.
A member participates by activating a chosen amount of $SHIPEX in a fixed-term loyalty tier. Doing so creates an on-chain position inside ShipexStakingV2. Each position records the amount, the opening time, the term end time, the reward rate locked at the moment of joining, the time of the last reward claim, the tier, and any carried reward. Members can claim accrued rewards during the term, and can release the tokens they participated with once the term ends. The program is non-custodial throughout: the member signs every action in their own wallet, and SHIPEX never holds member funds or keys.
There are four tiers. Longer tiers carry higher reward rates. The rates below are the indicative design values; the live rate on each tier is always read on-chain from the program contract and may differ, and rates are variable and never guaranteed.
| Tier | Tier duration | Indicative reward rate | On-chain rate source | Basis points |
|---|---|---|---|---|
| Daily | 1 day | about 8 percent | dailyAPR() |
800 |
| Monthly | 30 days | about 11 percent | monthlyAPR() |
1100 |
| Quarterly | 90 days | about 14 percent | quarterlyAPR() |
1400 |
| Yearly | 365 days | about 20 percent | yearlyAPR() |
2000 |
The reward rate a member sees at the moment they join is the rate that position keeps, stored on the position as its locked reward rate. If the team later adjusts the tier rates, existing positions are unaffected; only new positions take the new rate.
A typical first participation is two on-chain steps, plus later claim and release:
approve on the token contract.createPosition). The member activates a chosen amount in a chosen tier. This creates the position and locks its reward rate.claimRewards). At any time during the term, the member collects the rewards accrued so far on a position. Claiming resets the position's last-claim timestamp and carries any residual reward forward.withdrawPrincipal). After the term ends, the member releases the tokens they participated with. The tokens are returned to the member; they were never at risk of being consumed by the reward engine.Rewards accrue continuously and are computed per position. The program contract, ShipexStakingV2, uses the following formula, and the application mirrors it exactly for its live estimates:
accrued = amount * lockedAPR * elapsed / (10000 * 31536000)
Where:
lastClaimTimestamp), which the contract resets on each claim, capped so it never runs past the term end (maturityTimestamp).Two properties of this formula matter for correctness. First, accrual is measured from the last claim, not from when the position opened, so claiming does not double-count time already paid. Second, because each position stores its own locked reward rate, an administrative rate change on the tiers does not retroactively change what an open position earns.
All examples use human token units and the indicative tier rates. Live results always come from the contract.
Example A: Yearly tier, full term. A member participates with 1,000 $SHIPEX in the Yearly tier at 20 percent (lockedAPR 2000) and keeps the position open for the full 365 days (elapsed 31,536,000 seconds).
accrued = 1000 * 2000 * 31536000 / (10000 * 31536000)
= 1000 * 2000 / 10000
= 200 $SHIPEX
The member accrues 200 $SHIPEX in rewards over the year, and can then release the original 1,000 $SHIPEX.
Example B: Monthly tier. 5,000 $SHIPEX, Monthly tier at 11 percent (lockedAPR 1100), 30 days (elapsed 2,592,000 seconds).
accrued = 5000 * 1100 * 2592000 / (10000 * 31536000)
= 45.2 $SHIPEX (approximately)
Cross-check with the simplified estimate used in the calculator: 5000 * 0.11 * (30 / 365) = 45.2 $SHIPEX.
Example C: Daily tier. 10,000 $SHIPEX, Daily tier at 8 percent (lockedAPR 800), 1 day (elapsed 86,400 seconds).
accrued = 10000 * 800 * 86400 / (10000 * 31536000)
= 2.19 $SHIPEX (approximately)
Cross-check: 10000 * 0.08 * (1 / 365) = 2.19 $SHIPEX.
Example D: Quarterly tier. 2,500 $SHIPEX, Quarterly tier at 14 percent (lockedAPR 1400), 90 days.
2500 * 0.14 * (90 / 365) = 86.3 $SHIPEX (approximately)
| Example | Amount | Tier | Rate | Duration | Accrued rewards |
|---|---|---|---|---|---|
| A | 1,000 | Yearly | 20 percent | 365 days | 200 |
| B | 5,000 | Monthly | 11 percent | 30 days | about 45.2 |
| C | 10,000 | Daily | 8 percent | 1 day | about 2.19 |
| D | 2,500 | Quarterly | 14 percent | 90 days | about 86.3 |
These are estimates. The live figure for any position is what the contract computes, and rewards are variable and never guaranteed.
Program rewards are paid from the on-chain reward reserve, currently 200,000 $SHIPEX, readable through rewardReserve(). This finite pool is the mechanism that keeps the program solvent, and it drives a hard safety property covered in Section 9: a reward claim that the reserve cannot fully cover reverts rather than underpaying.
The reserve's capacity is easy to reason about. Consider the heaviest reasonable draw, the Yearly tier at 20 percent held for a full year. The reserve of 200,000 $SHIPEX is exactly enough to fund 1,000,000 $SHIPEX participating at 20 percent for one year, since 1,000,000 * 0.20 = 200,000. Shorter tiers and lower rates consume the reserve more slowly. For instance, the same reserve funds far more token-time at the Daily 8 percent rate than at the Yearly 20 percent rate.
This is an illustrative capacity calculation, not a cap on participation or a promise. Actual consumption depends on the mix of tiers, amounts, and durations members choose, and the reserve can be replenished over time: charter activity from the attested fleet is the designed replenishment source, and replenishment, like every reward figure, is variable and never guaranteed. What the calculation demonstrates is that the reserve is sized deliberately against the token supply, and that the program's solvency does not depend on hope: it is enforced by the contract, which will not pay what the reserve cannot cover.
Proof of Reserve in SHIPEX ties the program to attested vessels a member can inspect. Rather than asserting that value exists somewhere off-chain, the project anchors each vessel's attested value on-chain to its permanent IMO number, so what the program is built around maps to real vessels shown in the application under Vessels. This is the transparency answer to the verification gap described in Section 3.3.
One boundary keeps this surface honest: Proof of Reserve is verification, not collateralization. Members hold no mortgage, lien, or other claim over any vessel, and nothing in the reserve surface creates a right of redemption against SHIPEX or a claim on charter revenue. The fleet is the attested context the program is built around, not collateral owned by members.
The current fleet is three vessels attested by IACS member class societies, worth about 101.7 million USD in total.
| Vessel | Type | IMO | Class society | Class status | Attested value | On-chain stage |
|---|---|---|---|---|---|---|
| MR II Oil Tanker | MR2 product tanker, 49,990 DWT, built 2016 (Hyundai Mipo) | 9456231 | DNV | In class | 28.5 million USD | Trading, largely on-chain |
| Chemical Carrier II | IMO Type II stainless chemical tanker, 25,400 DWT, built 2018 (Fukuoka) | 9612874 | Lloyd's Register | Conditions | 19.2 million USD | Onboarding |
| LNG Carrier | Membrane LNG carrier, 174,000 cubic metres, 2026 newbuild | 9789845 | Bureau Veritas | Survey due | 54.0 million USD | Pre-delivery |
Each vessel carries a real operating profile. The MR2 tanker trades refined petroleum products on a 36-month time charter at 24,800 USD per day, with off-hire days covered by loss-of-hire insurance and a 14-day dry-dock reserve pre-funded so planned yard time does not interrupt the charter activity that replenishes the reward reserve. The chemical carrier is entering a spot-indexed parcel-trade pool at about 18,300 USD per day, smoothing voyage activity into monthly pool points. The LNG carrier is a newbuild slated for a 10-year bareboat charter at 92,500 USD per day under a letter of intent, a long-dated and predictable profile in which the charterer bears operating costs.
These profiles matter to the program in exactly one way: charter activity is the designed source that replenishes the on-chain reward reserve. Charter payments flow to the vessels' commercial operation, not to members; members receive program rewards only from the reserve and receive no share of charter revenue.
The three class societies named, DNV, Lloyd's Register, and Bureau Veritas, are IACS members. A class-society attestation certifies the vessel's structural condition against class rules and underpins the independent valuation that sets its attested value. SHIPEX carries the class status forward to members honestly: In class, Conditions, or Survey due. A condition of class, such as the ballast-tank coating condition on the chemical carrier, is surfaced and tracked to clearance rather than concealed, and a survey-due newbuild is shown as pre-delivery until its initial class survey and gas trials complete.
The project is explicit about what is a live on-chain read and what is a design-intent figure. The share of a vessel's attested value already brought on-chain is presented as a representative figure to be wired to the real VesselRegistry value before it is shown to members as a live metric; class status and survey notes describe the attested registry and the program's safety intent, not live oracle readings. This candor is itself part of the reserve model: the reserve surface is trustworthy precisely because it does not overstate what is verified.
SHIPEX is designed so that compliance is part of the architecture, not a layer added afterward. The compliance model is designed in line with the MiCA (European Union) and VARA (Dubai) regulatory frameworks, and identity gating is intended to restrict eligible participation to verified members. The governing terms of the project name the United Arab Emirates, with Dubai as the jurisdiction, consistent with a VARA-aligned posture.
The compliance model is built around ERC-3643, the permissioned, identity-gated token standard. Under ERC-3643, transfers are checked against an on-chain identity and eligibility layer, so that at mainnet only verified, eligible wallets can hold or transfer the permissioned token. This is what makes institutional-grade real-world value participation possible: the token itself enforces that only KYC-verified, eligible members can hold and transfer it, at the protocol level rather than through off-chain promises.
Stage note: the current testnet token is a simplified build, and full ERC-3643 permissioning applies as the permissioned token is deployed at mainnet. The project is transparent that testnet is an evaluation environment and that the permissioning model activates at the mainnet stage.
Identity verification is a required step before a member can join the loyalty program, completed once in the application. The verification establishes a single verified identity bound to the member's wallet. The design intent is one identity, every vessel: a single verification is meant to unlock participation across every vessel as it is brought on-chain under ERC-3643, with no repeat checks as the fleet grows.
The data collected for verification, described in the project's privacy policy, includes full name, date of birth, address, government-issued identification images, and a selfie, gathered specifically to satisfy the permissioned-token standard. The project does not collect passwords or private keys. On-chain data is permanent and public by nature; off-chain verification data is handled under the privacy policy, and members may request deletion of off-chain data.
The MiCA framework has become the reference standard for regulated entry into on-chain real-world value markets, mandating transparency and participant protections, and VARA is a purpose-built regulator for the sector with multi-tier licensing frameworks. Against those frameworks, the intended classification of $SHIPEX is specific. MiCA describes a utility token as a crypto-asset intended only to provide access to a good or a service supplied by its issuer; access to the loyalty program is the only function $SHIPEX has. The token is not designed as an asset-referenced token, because it does not purport to maintain a stable value by referencing any other value or right, and not as an e-money token, because it references no official currency. ESMA's guidance on when a crypto-asset qualifies as a financial instrument turns on rights such as ownership, repayment of money, or a share in profits; $SHIPEX grants none of these.
Two further statements keep this section honest. First, classification is a legal conclusion that only a regulator or a court can settle; the description above is careful design intent, not a regulatory determination. Second, SHIPEX is not licensed or authorized by ESMA, by any EU national competent authority, by VARA, or by any other regulator; no authority has reviewed or approved this document, and it is not a crypto-asset white paper notified to a competent authority under MiCA. What the design does deliver is alignment in substance: transparent, verifiable vessel records; identity-gated participation; explicit risk disclosure; and a utility framing that does not represent the token as a security or a financial product. Members remain responsible for ensuring their own participation complies with local law.
The program is non-custodial. Every action, approve, participate (createPosition), claim (claimRewards), and release (withdrawPrincipal), is signed by the member in their own wallet. SHIPEX never holds member funds or keys. The tokens a member participates with sit in a program position that only the member can release at term end; they are never routed away from the member's control.
The most important safety property in the reward engine concerns what happens when a reward claim would exceed the available reward reserve. ShipexStakingV2 does not pay a partial, best-effort amount. It reverts with InsufficientRewardReserve when a position's pending reward exceeds the funded reserve.
This design choice has two consequences that both favor the member. First, the program can never quietly pay less than it computes: a member either receives the full accrued reward or the transaction reverts and their state is unchanged, so there is no silent shortfall. Second, and by the same token, the reserve can never be drained below zero, which protects every other member's future claims. Solvency is enforced by the contract itself.
The application is built to respect this property honestly. The interface never displays more claimable reward than the reserve can cover, and the claim action surfaces the revert as a readable error rather than misrepresenting the on-chain amount. The reserve check governs rewards only; it never touches the tokens a member participated with, which remain releasable regardless of the reserve state.
There is a strict separation between the tokens a member participates with and the rewards the program pays. Rewards are drawn exclusively from the reward reserve. The reward engine has no path by which it consumes the member's participated tokens to pay rewards, to itself, or to anyone else. At term end, the member releases exactly the tokens they participated with. Reward-reserve exhaustion can delay or block a reward claim; it cannot reduce the tokens a member gets back.
Each position stores its own locked reward rate at the moment it is opened. If the tier rates are later adjusted, open positions continue to accrue at their original locked rate; only new positions take the new rate. The application computes each position's accrual from that stored rate rather than from the current tier rate, so a rate change can never retroactively inflate or deflate what an existing position earns. This is both a correctness property and a fairness property.
The SHIPEX smart contracts are undergoing an independent security assessment by CertiK as part of the project's security process. The project states plainly what an assessment is and is not: an independent assessment reduces risk, but it does not guarantee the absence of bugs or vulnerabilities. Smart-contract risk remains, and members should only participate with funds they can afford to lose. This candor is deliberate and is retained in the project's public disclaimers.
Security is not only about the contract; it is also about the surface that reads it. The application reads live totals and reward rates on-chain at render time, and it is engineered so a degraded RPC endpoint cannot blank the interface or mislead a member. Reads run through a viem fallback transport across multiple RPC endpoints with bounded timeouts and a single retry, so one dead endpoint cannot take the dApp down. Reads that cannot complete degrade gracefully to a null state rather than to a stale or invented figure. Immutable values such as token decimals are read once and cached, and tier rates are cached briefly, to avoid exhausting public RPC quota. The result is an interface whose honesty about live state is itself a safety feature.
SHIPEX is built on BNB Smart Chain. It is currently live on the BNB Smart Chain testnet (chainId 97), with mainnet (chainId 56) promotion designed as a single environment change rather than a code rewrite. The choice of network is driven by low transaction costs, broad wallet support, and a mature ecosystem suited to a consumer-facing loyalty program.
Two contracts anchor the system: the $SHIPEX token at 0x7489597fA2D93f47604b6132a21655369Fc71275 and the ShipexStakingV2 program contract at 0x5939Fb9F6B8f0a1cC162e3654d053d084E0DcE8c. The program contract exposes the reads and actions the application uses, including totalStaked, activePositionsCount, the four tier-rate functions, rewardReserve, getUserActivePositions, previewReward, createPosition, claimRewards, and withdrawPrincipal. These identifiers are contract-level names and are stable.
The application reads these values with viem, using a fallback transport across several BNB Smart Chain RPC endpoints. Because network and contract wiring are read from environment variables, moving from testnet to mainnet is a configuration flip, not a redeployment of the frontend.
The public surface is a Next.js application rendered with incremental static regeneration (ISR), so pages are fast for the first visitor while still reflecting live on-chain totals and rates read at render time. On-chain reads are bounded so a stalled RPC can never hang a render, and callers fall back to a safe null state instead of blocking. The dApp reads a connected member's own live figures, balance, amount participating, claimable rewards, and positions, to provide specific, current guidance.
The application works with any major BNB Smart Chain wallet, including Binance Web3 Wallet, MetaMask, Trust Wallet, Coinbase Wallet, OKX, and Rabby. Because the program is non-custodial, the wallet is the member's sole point of control.
SHIPEX today is operated by its founding team, and the project is transparent about that. Certain parameters, such as the tier reward rates and the replenishment of the reward reserve, are administrative functions. The safety properties described in Section 9 constrain what those functions can do to a member: rate changes cannot rewrite open positions, and no administrative action can consume the tokens a member participated with.
The stated direction is toward broader decentralization over time. The published roadmap moves from a testnet foundation with the loyalty program live and an independent security assessment initiated, through mainnet migration and expanded fleet backing, toward on-chain governance and compliance infrastructure for international markets. On-chain governance is named as a later-stage objective rather than a present-day claim, consistent with the project's practice of not representing planned capabilities as shipped.
The project discloses risk plainly, and this section structures the main risks and the mitigations built into the design. None of these mitigations eliminates risk. Members should only participate with funds they can afford to lose.
| Risk | Description | Mitigation in the SHIPEX design |
|---|---|---|
| Smart-contract risk | A bug or vulnerability in the contracts could cause loss or malfunction. | Independent CertiK assessment in progress; non-custodial design; reserve-guarded claims that revert rather than underpay; open, honest disclosure that an assessment does not guarantee bug-free code. |
| Reward-reserve exhaustion | The finite reward reserve could be insufficient to cover a claim. | The contract reverts with InsufficientRewardReserve rather than underpaying; the interface never shows more claimable than the reserve can cover; the reserve can be replenished; the tokens participated with are never affected. |
| Market risk | The token's value is volatile, and the testnet reference value is a placeholder. | Explicit disclosure; no guaranteed value; production price feed intended to be wired to a market source; rewards described as variable and never guaranteed. |
| Regulatory risk | Rules may change across jurisdictions, and SHIPEX holds no license from any regulator. | Compliance-first design aligned to MiCA, ESMA guidance, and VARA; ERC-3643 identity gating; no license claimed and no regulatory guarantee made; members responsible for local compliance; explicit forward-looking-statement disclaimer. |
| Attestation and oracle risk | On-chain vessel figures could drift from physical reality. | Class-society attestation anchored to IMO numbers; honest labeling of design-intent figures versus live reads; staged onboarding that does not mark a vessel active before its attestation record exists. |
| Custody and key risk | Loss of a private key means loss of access. | Non-custodial design keeps keys with the member; SHIPEX never holds funds or keys; no collection of passwords or private keys. |
| Infrastructure risk | A degraded RPC could blank or mislead the interface. | viem fallback transport across multiple endpoints; bounded timeouts; graceful degradation to null rather than stale or invented data. |
| Liquidity risk | Releasing tokens is bound to tier completion. | Tier durations are disclosed up front; the member chooses the tier; tokens release at term end. |
The following are the real frames and sources the SHIPEX design and this document draw on.
0x7489597fA2D93f47604b6132a21655369Fc71275, ShipexStakingV2 0x5939Fb9F6B8f0a1cC162e3654d053d084E0DcE8c.This whitepaper describes a project that is live on BNB Smart Chain testnet. Reward rates, reserves, and totals are read live on-chain and may change. $SHIPEX is a utility token used only to access the loyalty program and its benefits. It is not an investment, a security, e-money, or a financial product, and it grants no ownership, no redemption right, and no claim on any vessel or on charter revenue. SHIPEX is not licensed by any regulator, and no authority has reviewed or approved this document. Nothing here is financial, legal, or tax advice.