Back to Free
Free gift program

Risk disclosure and incident response

Effective 31 August 2026. Applies to the Free gift program at free.plusmore.xyz.

1. Purpose and summary

The Free gift is a real, free gift of tokens to whitelisted wallets. It is capped in code, it takes no payment and no gas from you, and you can verify every part of it on-chain. It is not a deposit, not interest and not a return on money, and it still carries the risks set out below. This page explains those risks in plain terms and sets out, publicly, what we do if something goes wrong. Nothing here is financial, legal, tax or investment advice.

2. Value risk

is a utility token. Its market value is set by third parties outside the Company's control, it can change at any time, and it can be zero. The gift is granted free of charge. It is not interest, not a deposit, not a savings product and not a return on money, and no amount of value is promised. If you later hold or trade , you carry that price risk yourself.

3. Smart-contract risk

The gift runs on an immutable smart contract on Base. Immutable means its coded rules cannot be changed after deployment, which protects you from the rules being altered, but it also means a bug cannot be patched in place. Smart contracts, even when reviewed and audited, can contain errors. The gift logic has passed an external audit and a suite of 207 tests, but an audit reduces risk and does not guarantee the absence of bugs. A loss caused at the contract level may be unrecoverable.

4. Blockchain, wallet and infrastructure risk

The program depends on public infrastructure the Company does not control. The Base and Ethereum networks, RPC providers, wallet software and other third-party services can fail, be delayed or behave unexpectedly, which can delay a delivery. You alone control your wallet and your keys. If you lose your keys, or if you approve a malicious transaction somewhere else, that is your risk and it is irreversible. The Company cannot reverse, freeze or recover a transaction you authorise, and it never takes custody of your funds, your tokens or your keys.

5. Redemption and partner risk

The DeFi protocol and the redemption marketplace launch in September 2026 and will carry their own additional terms. Redemption is provided by independent third-party Rewards-as-a-Service partners, not by the Company, and each partner applies its own terms and its own compliance checks. Gift-card brands are separate third parties and are not issued by the Company. A partner or a brand can delay, deny, change terms, run low on stock or become insolvent, any of which can affect whether and how you redeem. Disputes about a redemption are between you and the relevant partner or brand.

6. Regulatory and jurisdiction risk

Rules for tokens and digital assets differ by country and can change without notice, and a change can restrict or affect your participation. You are responsible for confirming that your participation is lawful where you live and for your own tax position. Participation is subject to sanctions and compliance screening, and the program is not offered where it would be unlawful.

7. Program-discretion risk

The program is discretionary and variable. The Company may pause, resume, amend or end it at any time. The smart contract that holds and delivers the gift is immutable, so its coded rules cannot be altered, but continued participation and future deliveries are not promised. already delivered to your wallet stays yours.

8. How the design limits the damage

The program is built so you can verify it and so the worst case is bounded. These measures limit the risk; they do not remove it:

  • The smart contract is immutable. Its emission rate of 0.1 percent per day and its hard caps are fixed in code and published on-chain, and no administrator can change them.
  • Each wallet can receive at most 30 in total from the program.
  • The distribution pool can hold at most 1,000 at any time. This caps the blast radius: the most that could ever be lost from the pool in a single incident is what is in it, not more.
  • The operator wallet 0xB352417F099177d7bD757A5D2B2959eE8C16779a holds only an operator role. It can trigger deliveries within the coded caps. It cannot drain the pool, mint , change the caps or take user funds.
  • A separate admin key, held by the Company and kept offline as the security model matures, can pause where the contract allows and can revoke the operator role if the operator key is ever compromised.
  • Everything is verifiable on BaseScan: the gift contract at 0x5563cEE1845B67f8DEEAa6e4Ace650f5670b5E81 and the token at 0x18b66b63625a07d3671eb0A119A5e4DF4708936E.
  • The Company never takes custody of user funds, and never asks for your keys, your seed phrase, a payment or gas.

9. Incident and security response

This is our public protocol for a security incident. It exists so you can see, in advance, what we can and cannot do.

What we monitor and the size of the exposure. We monitor the gift contract, the operator wallet and the distribution pool. Because the pool holds at most 1,000 at a time, that cap bounds the maximum exposure of any single incident. It does not prevent an incident, but it limits how large one can be.

If the operator key is compromised. The operator role can only trigger deliveries within the coded caps. A compromised operator key cannot drain the pool, cannot mint , cannot change the caps and cannot take user funds. Our response is that the admin key revokes the operator role and, where the contract allows, pauses deliveries, then a new operator key is put in place.

If a contract vulnerability is discovered. Because the contract is immutable it cannot be patched in place. Our response is to pause deliveries where the contract allows, stop funding the pool so no further is put at risk, communicate what we know, and, where necessary, migrate to a new reviewed contract for future deliveries. already delivered to your wallet is unaffected, because it is yours and sits in your own wallet.

Communications during an incident. We publish updates only through the official domain free.plusmore.xyz and the official channels linked from it. During an incident we will never send you a direct message asking you to connect a wallet, move funds or share keys. Treat any such message as fraud, no matter who it appears to be from.

What we will not do. The Company holds no insurance for user losses and offers no bailout. We do not guarantee reimbursement for any loss, and we will never ask for your seed phrase or your private key.

Responsible disclosure. If you are a security researcher and you find a vulnerability, please report it to us privately, before any public disclosure, through the support route published at plusmore.xyz, and give us a reasonable time to respond.

What you should do. Keep your keys offline and never share your seed phrase or private key with anyone. Verify that you are on the official domain free.plusmore.xyz, and check the contract addresses above on BaseScan yourself. Be sceptical of urgent messages, of anyone asking you to act fast, and of any request to connect your wallet or move funds outside the official site.

10. No advice and acknowledgement

Everything on this page is information only. It is not financial, legal, tax or investment advice, and it is not a recommendation to acquire, hold or dispose of any token. By participating in the Free gift program you accept the risks set out above.

Discretionary and variable, not interest, not a deposit. The value of can change and can be zero. Screening applies. Information, not financial advice.Gift terms Privacy Back to Free