> For the complete documentation index, see [llms.txt](https://htxdao-1.gitbook.io/htx-dao-staking-en/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://htxdao-1.gitbook.io/htx-dao-staking-en/htx-dao-staking-guide/protocol-mechanism.md).

# Protocol Mechanism

HTX DAO Staking adopts the following contract operational rules, serving as the baseline for development, auditing, and governance updates.

1\. Architecture

The staking protocol is built on the ERC-4626 token vault standard, providing strong composability.

Asset Flow: When staking, $HTX is deposited into the StakedHTX contract, and sHTX is minted. During redemption, sHTX is burned, and $HTX is withdrawn from the contract or the Silo buffer.

Value Growth: Rewards are periodically injected by the REWARDER\_ROLE. The conversion between sHTX and $HTX is calculated as:

sHTX conversion rate = Total $HTX in contract / Total sHTX supply

&#x20;

As rewards are injected, the numerator increases. Therefore, each sHTX becomes redeemable for more $HTX over time.

2\. Roles and Permission Management

The contract defines five core roles to ensure operational security and compliance.

| Name               | Role                        | Description                                                                                                 |
| ------------------ | --------------------------- | ----------------------------------------------------------------------------------------------------------- |
| DEFAULT\_ADMIN     | Highest-level administrator | Manage role members, configure contract upgrades, control transfer switches                                 |
| OPERATOR           | Protocol operator           | Set the setCooldownDuration parameter (currently 48 hours; the actual value displayed on the page is final) |
| PAUSE              | Emergency control           | Disable staking, unstaking, and withdrawals in extreme market conditions                                    |
| REWARDER           | Reward distributor          | Transfer reward assets into the contract                                                                    |
| BLACKLIST\_MANAGER | Blacklist administrator     | Restrict sanctioned or illegal addresses to ensure regulatory compliance                                    |

&#x20;

3\. Security Protection Measures

Anti-Sandwich Protection: Rewards are injected every 2 hours and vest linearly over the next 2 hours, preventing attackers from performing flash staking to dilute others' rewards.

Cooldown Protection: The waiting period between redemption request and withdrawal prevents single-block flash exploit attacks.

Anti-Donation Attack: The contract enforces a minimum non-zero total supply (initial value equivalent to 1 $HTX) to improve mathematical robustness.

Principal Protection: The contract ensures reward transfers are always positive. Staked principal will never decrease due to protocol logic.

&#x20;
