POXYX
⚠ Generation 1 Seals In
--d --h --m
After seal: acquisition via marketplace only
🏆
Founder Status Achieved

You own all 5 base Gen 1 items. Your Founder badge has been permanently unlocked. You are eligible for a permanent platform discount on all future case openings, applicable from the London club launch date.

POXY Box Appraisal Guide — Current Estimated Market Values

Valuations are dynamically calculated using rarity scarcity coefficients multiplied by character weight factors. These are estimated reference values; actual marketplace prices are determined by peer-to-peer supply and demand. All values expressed in PX (Poxy Coin).

Sign in to access the store.

Collect what's
actually yours.

A calm place to open, own, and trade unique digital figures. No noise, no rush, just a collection that feels like a real shelf.

Closed economy today Every figure has a passport Yours to keep, gift, or resell
Why collect POXY?

Reasons to start.

A few simple things that make POXY worth your shelf.

S

Secure

Your account and your collection are yours. 2FA and device control keep them that way.

I

Invest

Show up early and grow with it. The first collectors are the ones who build the place.

O

Open

Clear costs, honest odds, no tricks. You always know how a box works.

S

Social

Gift figures, follow collectors, show your shelf. It means more when others can see it.

P

Powerful

Seasons, mutations, traits, certificates. Every figure carries real depth.

U

Unique

Each POXY is numbered, with its own passport and history. One specific thing, not one of a crowd.

F

Fundamental

A real company, a real roadmap, infrastructure meant to last. Not a weekend drop.

D

Developing

Always moving. New collections, new features, bigger plans as we grow.

B

Belonging

A club where the people inside take it seriously. You collect alongside thousands.

Three steps. No spinning wheels.

Opening a POXY is a ritual, not a slot machine. The box opens, the figure forms, and it lands in your collection.

STEP 1

Open a box

Pick a box in the tier you want. The cost is shown up front in coins, with no hidden odds.

STEP 2

Watch it form

Full screen, top to bottom, the figure generates in front of you. Slow and deliberate, because the wait is the point.

STEP 3

Keep it on your shelf

It lands in your collection with its own passport. Keep it, gift it, or list it on the market.

Trusted, not hyped.

POXY is a considered collectibles world. Clear rules, real ownership, and a roadmap that grows with you.

A closed economy, for now

Today, coins and figures live inside POXY, which keeps everything simple, fair, and easy to trust. As the project grows, we plan to open the economy further over time, so collecting early means being here before the next chapter starts.

Fair by design

Fixed costs, visible odds, nothing rigged.

Your account, secured

2FA by default, devices you control.

Real ownership

Every figure has a serial and a passport.

Your shelf is waiting.

Pick a username, open your first box, and start a collection that's actually yours.

POXY FAQ

This FAQ answers the basic questions about POXY WORLD: what it is, how it works, and how it stays safe.

POXY keeps evolving and adding new features, so some details may change as we grow. We update this page as the project moves forward.

General

POXY WORLD is a place to open, own, and trade unique digital collectible figures. Think of it as a shelf for one of a kind exhibits. Each figure has its own identity, history, and number.

No. You sign up with a username and email, and everything inside works with simple in app coins. No wallets, no seed phrases, nothing technical to learn.

A bit of both. You collect and open figures like a game, and you can trade and resell them like a marketplace. But the heart of it is collecting something that feels real and yours.

Creating an account and looking around is free. Opening boxes and trading uses coins, which you top up when you're ready. You can explore without spending anything.

POXY is built mobile first and works in your browser. You can link multiple devices to one account and switch between them safely.

Collecting and Opening

You pick a box, and instead of a spinning wheel, the figure generates in front of you on a full screen, forming top to bottom. It's a slow reveal, made to be felt, not rushed.

Every figure has a serial number, an edition like 1 of 250, traits, and a passport that documents it. No two are quite the same.

Collections come in seasons, and within them figures can appear in different mutations, which are variations in look and rarity. It keeps every collection worth chasing.

Yes. You can list it on the market, or use Sell for coins to dissolve it instantly and add the coins straight to your balance.

A passport is the identity page for a figure. It shows the serial, edition, traits, and history of ownership, so you always know exactly what you hold.

Economy and Coins

Coins are the in app currency you use to open boxes and buy figures. Your balance is shown with the coin icon, always visible while you browse.

Not at this stage. Today POXY runs as a self contained world, which keeps it simple and fair. Opening up the economy further is part of our longer term plans as the project grows.

That's the direction we're heading. As the company grows, we plan to open up more over time. Collecting early means you're here before that chapter starts.

The market is driven by collectors. Rarer figures and complete editions tend to hold more interest. You can look at price history before you buy or sell.

You'll top up from inside your account when that opens. Costs are always shown up front, with no surprises.

Account and Security

Pick a unique username, add your name, email, and a password. You verify your email, set up two factor authentication, and you're in.

A username is your identity here. It's clean, memorable, and yours. We keep sign up simple and free of clutter.

Two factor authentication is part of setup, and you can link or remove trusted devices by QR. You stay in control of every session.

You can recover through your verified email or your 2FA backup codes. Recovery is safe and rate limited, so no one else can poke at your account.

Yes. Link a new device by scanning a QR from one you're already signed in on, similar to how Telegram handles devices. You can revoke any device later.

Safety and Trust

No. Costs are fixed and shown up front, and the world is closed by design. We built it specifically to stay clear of gambling mechanics.

POXY WORLD is built by NULLSPACE LABS LTD, a registered company. There's a real team and a real roadmap behind it, not an anonymous drop.

We follow serious security practices across the platform and only collect what we need to run your account. The Policy page has the full picture.

Your collection stays tied to your account. As POXY grows and adds features, what you already own grows in context with it.

News

Where POXY is right now and what's coming next. Follow along as the world takes shape.

Development

POXY WORLD is getting ready for testing

We're entering the testing phase. The core of the product is built, the design system is in place, and we're now putting everything through its paces before the first collectors arrive.

15 Jun 2026
Announcement

Coming soon: POXY WORLD opens to the public

The next announcement on this page will be the one we've been working toward: POXY WORLD going live, with the first season of figures and an open market for collectors.

15 Jun 2026
Development

POXY WORLD is getting ready for testing

15 Jun 2026

We've reached a real milestone. After months of building quietly, POXY WORLD is moving into its testing phase. The foundation is done: the platform, the security layer, the economy, and the visual identity all sit on solid ground, and now it's time to make sure everything holds up before we open the doors.

Testing is where a product stops being an idea and starts being a thing you can trust. We're checking how boxes open, how the figure generation feels, how the collection and passport screens behave on real devices, and how the account and security flows hold up. Nothing ships until it feels calm, fast, and right.

Why share this now? Because the people who pay attention early are the ones who shape what POXY becomes. We'd rather bring you in while it's still forming than present a finished box and hope you like it. If you're reading this, you're early, and that matters here.

The next big step is opening POXY to the public. When testing is done and the first season is ready, we'll announce the launch and the moment the world becomes something you can actually step into. Keep an eye on this page.

Announcement

Coming soon: POXY WORLD opens to the public

15 Jun 2026

This is a look at what's coming. Once testing wraps, POXY WORLD will open to the public, and the first people will be able to sign up, open their first boxes, and start real collections.

Launch brings the first season of figures, each with its own mutations and rarity, and the market where collectors buy, sell, and resell among themselves. From day one the goal is simple: a place that feels like a real shelf, where what you own is genuinely yours.

We're also building toward more. As the project grows, we plan to expand what the economy can do over time, opening it up step by step. Arriving at launch means being part of the base the whole world grows from, before the bigger chapters begin.

We'll post the exact date here when it's locked. If you want to be among the first, this is the page to watch.

Policy

In plain language: what we collect, how we protect it, and how the economy works today. Written to be read, not skipped.

Your account and data

We collect only what we need to run your account: your username, name, email, and the security information that keeps you safe. We don't sell your personal data, and we don't trade it to advertisers.

Your collection, your balance, and your activity belong to your account. You stay in control of your trusted devices and can revoke any session at any time.

Security

Two factor authentication is part of account setup. Devices are linked through QR and can be removed whenever you choose. We apply security practices across the platform, including rate limiting, encryption in the places that matter, and regular review.

No system is perfect, and we won't pretend otherwise. What we promise is to take security seriously and to be honest with you if something ever goes wrong.

The closed economy

At this stage, coins and figures live inside POXY. There is no withdrawal to real money today. This keeps the platform simple and clear of gambling and financial regulations while the project is young.

Any future changes to the economy, including a wider economy, will be introduced carefully, transparently, and with proper safeguards when the time comes.

Cookies and tracking

We use only what's needed to keep you signed in and to understand how the product is used at a basic level. We don't run invasive advertising trackers across the platform.

When richer settings arrive, you'll be able to manage your preferences from your account.

Changes to this policy

As POXY grows, this policy grows with it. When we make meaningful changes, we'll surface them clearly rather than burying them. Continued use of POXY means you're comfortable with the current version.

Formal terms will accompany the full public launch.

About POXY WORLD

Our philosophy, our economy, and where the project is headed. The full picture in words.

What POXY WORLD is

POXY WORLD is a calm, considered place to collect unique digital figures. We started from a simple feeling: collecting something should feel like holding a real object, a thing with weight and identity and a place on your shelf, not like staring at another flashing game.

Every figure is a single, numbered exhibit. It has a serial, an edition, traits, and a passport that records what it is and where it came from. When you open one, you aren't pulling a card from a pile. You're receiving an object that is specifically, provably yours.

Our design philosophy

We believe in trust over hype. The brands people rely on, like Apple and Telegram, earn that trust not by shouting, but by never letting you down. Every detail sits where you expect it, nothing tries to overstimulate you, and the whole thing feels safe to lean on.

That's why POXY is quiet. One accent colour, generous space, slow and deliberate motion. The figure is the only loud thing on the screen, and everything around it stays calm, like a glass case in a gallery. We call it a showcase, not a fair.

How the economy works today

Right now, POXY runs as a closed world. You buy coins, open figures, trade, and gift, all inside the platform. There's no withdrawal to real money at this stage, and that's on purpose. It keeps the experience simple, fair, and easy to trust while we grow.

This isn't where the story ends. It's where it starts.

Where we're going

As NULLSPACE LABS grows and the budget allows, we plan to open POXY up. That means expanding the marketplace, deepening the economy, and over time exploring a wider economy around the figures people collect.

We're building the foundation first, on purpose. The collectors who arrive early aren't just early users. They're the base the whole world grows from. Getting in now means being here before the bigger chapters begin.

Who we are

POXY WORLD is built by NULLSPACE LABS LTD, a company registered in the United Kingdom. Behind it is a small, focused team that cares about doing this properly: real infrastructure, real security, and a roadmap meant to last rather than a one off drop.

We'd rather move carefully and earn your trust than move loud and lose it.

Getting started

When POXY opens, starting is simple. You pick a username, set up your account, and open your first box. From there your collection is yours to grow, show, gift, and trade.

If you're reading this before launch, you're early, and that's the best time to arrive.

POXY WORLD

A calm place to open, own, and trade unique digital figures. Built by NULLSPACE LABS.

About

Product

CollectOpen boxesMarketSeasons

Account

SecurityDevices

Company

NULLSPACE LABSContactPrivacyTerms
POXY WORLD

Welcome back

Sign in to your collection.

or
New to POXY?

Create your account

Pick a username and you're on your way.

@
3–20 characters, letters and numbers.

By continuing you agree to our Terms and Policy.

Already have an account?

Check your email

We sent a 6-digit code to confirm it's you.

you@email.com
Didn't get it?
Protected by 2FA · Need help?
Welcome back, @Player
0
0
Player
🎭
Win Reveal

Home

Your world at a glance.

Welcome to POXY

Open your first box to start a collection. Everything you own lives on your shelf, with its own passport.

0
Figures
0
Balance

Open a box

Pick a tier. The box opens, then your figure forms on a full screen.

POXY
SYSTEM ACCESS

REWARD DECRYPTER

Mythic POXY claimed this month: 0/10
view_in_ar
diamond
token
stars
view_in_ar
diamond
token
?
PITY TRACKER · Standard case
Opens 0 Epic pity 30/30 Leg pity 80/80
Epic+ 15/15 Mythic 50/50
CASE WALLET · FREE OPENS

Welcome back, Operative

ELITE MEMBER
military_tech –
local_fire_department 0-day streak
toll
POXY PX
0PX
stars
POXY POINTS
0PX
inventory_2
TOTAL POXIES
0Assets
emoji_events
GLOBAL RANK
#––
local_fire_department
WIN RATE
–Elite

Quick Actions

inventory_2 My Collection

Manage your digital heritage.

COMPLETION
0%

Asset Rarity & Tiers

Discover the hierarchical structure of POXY assets. Rarity coefficients dictate base value, emission rates, and utility within the ecosystem. Lower drop rates yield exponentially higher ecosystem influence.

Global Ranks

The elite echelon of POXY WORLD.

Top 100 Players

MAJOR UPDATE • v2.4.0

The Obsidian Protocol:
Route Overhaul

Experience completely redesigned tactical routing, enhanced economy mechanics, and the new visual engine deployment.

Economy v2.3.5 • Oct 12

Economy Balance Adjustments

Comprehensive tweaks to market transaction fees and resource regeneration rates to ensure long-term sustainability across all server clusters.

Read More arrow_forward
Hotfix v2.3.4 • Oct 10

Authentication Gateway Stability

Resolved intermittent connection drops during peak hours. Login queues optimized for faster throughput.

Read More arrow_forward
campaign

Latest Founders Broadcast

Join us for a deep dive into the upcoming Q4 roadmap, featuring exclusive sneak peeks at new terminal interfaces and the highly anticipated syndicate wars expansion.

Patch Dispatch — Subscribe

Get notified for every major update, hotfix, and seasonal event drop.

Loading news…

Explore

Platform intel, policies, news, and support — your POXY World command reference.

support_agent Help Desk

For account issues, asset disputes, billing questions, or partnership proposals, reach the POXY World operations team directly.

Response time: 24–72 business hours. Include your registered email and username in every message for faster resolution.

Scope: Login problems, missing assets after purchase, marketplace disputes, VIP Club eligibility, and security reports.

✸
THE POXY CODEX
Immutable Digital Heritage

I. The Asset Philosophy

Every POXY is an immutable cryptographic entity. From the precise nanosecond of its generation, each asset carries a permanent, unalterable chain of custody — a digital fingerprint that follows the asset through every transaction, trade, and transfer in perpetuity.

Ownership is not a permission granted by a platform. It is a verifiable mathematical fact recorded on an immutable ledger. Your POXY belongs to you in the most absolute digital sense possible.

Rarity tiers — Common through Mythic — represent genuine scarcity coefficients baked permanently into the generation algorithm.

II. London Private Club Roadmap

POXY World is building a digital collectible-backed private member's club in central London. Legendary or Mythic tier POXY confer provisional membership candidacy.

🍸 Private Mixology Bar

Members-only cocktail programme by internationally certified bartenders.

🎱 Billiards Rooms

Three championship tables with bespoke POXY-branded equipment.

💼 Executive Networking

Closed-door sessions with curated speakers — verified holders only.

🎁 Heavyweight Merchandise

Limited physical runs paired with unique digital asset codes.

🏆 Custom Figurines

Hand-finished resin figurines stamped with your exact serial — max 10 per variant.

London club opening: target Q4 2026. Full membership deed and physical keycard at launch for qualifying holders.

gavel Terms of Service

Platform Utilisation: Access requires acceptance of these terms. Automated bots, credential resale, and coordinated market manipulation are prohibited.

Asset Ownership: PX and POXY acquisitions are limited digital asset records. Revocation applies only in documented fraud or security remediation cases.

Virtual Currency: PX has no cash value and cannot be withdrawn or refunded. Chargebacks may result in immediate suspension pending investigation.

Marketplace Conduct: No platform fee in the current version. Wash trading and artificial price inflation result in permanent termination without refund.

policy Privacy Policy

Data Collection: Email, username, avatar URL, and usage metadata (collection, transactions, sessions) are collected strictly for platform operation. No data is sold for marketing.

Cookies: Auth tokens use secure httpOnly sameSite cookies via Supabase Auth. No third-party tracking or fingerprinting.

Asset Security: PostgreSQL row-level security — only owners can read or transfer their assets.

Retention: Data kept for active membership. Deletion requests to worldpoxy@gmail.com processed within 30 days.

newspaper News & POXY Chat

The news feed and global POXY CHAT now live on the top-level News route in the main header.

update Platform Updates

  • Latest

    Explore Hub & Stitch Navigation

    Support, Codex, legal docs, news, and contact now live under the Explore tab with unified premium UI.

  • Marketplace

    Stitch Marketplace Terminal

    Buy and list flows redesigned with rarity filters, VIP lock overlays, and obsidian card grid.

  • Club

    POXY Club — Founders Circle

    VIP case openings, club feed, governance proposals, and member-exclusive flash sales.

  • Economy

    Daily Quests

    Rotating daily objectives for PX rewards.

mail Contact

Direct line to POXY World operations for support, partnerships, press, and legal enquiries.

mail worldpoxy@gmail.com

Please include your registered email and username. Typical response within 24–72 business hours.

GENERATIONS // TIMELINE LAYER_01 // CIRCULATING: 12,450 UNITS
GEN 2 [ACTIVE]

Obsidian Strike

YIELD_RATE:1.45x
RARITY_CAP:MYTHIC
NETWORK:L2 SECURE
001 // CORE
002 // CHASSIS
003 // OPTICS

ARCHIVE ARCHITECTURE

lock CAPSULE CLOSED 1

GEN 1: NEON DRIFT

SUPPLY: 5,000STATUS: EXHAUSTED
verified MASTERED 0

GEN 0: GENESIS BLOCK

SUPPLY: 1,000STATUS: IMMORTALIZED
link
DETECTING INCOMING TRANSMISSION

GEN 3: [CLASSIFIED]

23:14:05

Telemetry data suggests a high-density asset drop approaching the outer rim. Keep terminal nodes online.

P © 2026 POXY WORLD. ALL RIGHTS RESERVED.

Telemetry

Real-time asset lifecycle explorer and network statistics.

Total Minted database
24,891 PX
Active Burn Rate local_fire_department
1.2% / 24H
Market Cap monitoring
$14.2M
arrow_drop_up +5.4% 7D VOL

Provenance Chain

ASSET ID: PX-8820
token
Genesis Mint Block 149201
sync_alt
Secondary Sale 0.45 ETH
local_fire_department
Burn Event Pending
Live Tracking Active
Documentation
V2.4 Specification

Protocol Roadmap

The strategic deployment timeline for POXY WORLD infrastructure, detailing mainnet integrations and ecosystem expansion phases.

lightbulb I. The Asset Philosophy

Every POXY is an immutable cryptographic entity. From the precise nanosecond of its generation, each asset carries a permanent, unalterable chain of custody — a digital fingerprint that follows the asset through every transaction, trade, and transfer in perpetuity.

Ownership is not a permission granted by a platform. It is a verifiable mathematical fact recorded on an immutable ledger. Your POXY belongs to you in the most absolute digital sense possible.

lock II. Cryptographic Ownership Model

At the core of every POXY asset is an ED25519 keypair generated server-side at mint time. The public key is permanently embedded in the asset record and used to verify all downstream events. No key is ever reused.

# Asset identity generation (pseudocode)
private_key, public_key = ed25519.generate_keypair()
poxy_hash = sha256(f"{serial_id}:{public_key.hex()}:{timestamp_ns}")
genesis_payload = {"poxy_hash": poxy_hash, "pub_key": public_key, "tier": tier}
signature = ed25519.sign(private_key, canonical_json(genesis_payload))
# private_key is destroyed — never stored

The private key signs the genesis event payload, then is permanently destroyed. The public key and signature are recorded in the immutable ledger, and all subsequent ownership proofs reference this chain.

verified III. Immutable Heritage

Rarity tiers — Common through Mythic — represent genuine scarcity coefficients baked permanently into the generation algorithm. Once set, these values are immutable at the protocol level and cannot be altered by any administrative action.

Scarcity Enforcement

Tier probabilities are hardcoded into the RNG module. An audit trail of every roll is publicly queryable.

Chain of Custody

Every transfer, trade, and burn is a signed ledger event, cryptographically linked to the genesis record.

deployed_code Phase 1: Genesis Deployment

The initial phase establishes the core operational framework — deployment of server-side seed generation infrastructure, the ED25519 signing pipeline, and the baseline POXY tokenomics architecture.

  • Launch of POXY Identity Substrate (PIS) with ED25519 keypair generation.
  • Commit-reveal RNG validation loop deployed to production edge functions.
  • Append-only ledger initialized — no records deletable or mutable after write.
  • Release of the beta Terminal UI for early adopters.

terminal Core Logic: Cryptographic Engine

The POXY cryptographic engine uses a commit-reveal RNG pattern to guarantee provably fair outcomes. The server commits to an entropy seed before any user action, then reveals and combines it with a client-supplied nonce to produce the final result.

# Server-side seed generation (Edge Function)
def generate_commit(round_id: str) -> dict:
    server_seed = secrets.token_hex(32)          # 256-bit CSPRNG
    commit_hash = sha256(server_seed.encode()).hexdigest()
    # Store commit_hash publicly; server_seed locked until reveal
    ledger.insert({"round_id": round_id, "commit_hash": commit_hash})
    return {"commit_hash": commit_hash}

def reveal_and_resolve(round_id, client_nonce):
    row = ledger.get_commit(round_id)
    combined = row["server_seed"] + ":" + client_nonce
    result_hash = sha256(combined.encode()).hexdigest()
    tier = map_hash_to_tier(result_hash)            # deterministic tier assignment
    sig = ed25519.sign(SERVER_PRIVATE_KEY, canonical_json({"round_id": round_id, "result": tier}))
    ledger.append({"round_id": round_id, "result": tier, "sig": sig})
    return {"tier": tier, "sig": sig, "server_seed": row["server_seed"]}

After the reveal, anyone can independently verify the result by computing sha256(server_seed + ":" + client_nonce) and confirming it matches the stored result hash. The ED25519 signature confirms the server did not alter the seed post-commit.

storage Append-Only State Architecture

All POXY state transitions are stored in a strictly append-only ledger. No record is ever deleted or modified — ownership changes are represented as new events with cryptographic back-references to prior events, forming an unbroken chain from genesis.

-- Ledger schema (simplified)
CREATE TABLE poxy_events (
  id          UUID        PRIMARY KEY DEFAULT gen_random_uuid(),
  poxy_hash   TEXT        NOT NULL REFERENCES poxy_assets(poxy_hash),
  event_type  TEXT        NOT NULL,  -- genesis | transfer | burn | verify
  payload     JSONB       NOT NULL,
  signature   TEXT        NOT NULL,  -- ED25519 over payload
  prev_hash   TEXT,                   -- NULL for genesis, else sha256(prev event)
  seq         BIGINT      GENERATED ALWAYS AS IDENTITY,
  created_at  TIMESTAMPTZ DEFAULT now()
);
-- Row-Level Security prevents any deletion or update
ALTER TABLE poxy_events ENABLE ROW LEVEL SECURITY;
CREATE POLICY insert_only ON poxy_events FOR INSERT TO service_role WITH CHECK (true);

hub Phase 2: Syndicate Expansion

Following a successful Genesis, the protocol scales to support complex user hierarchies known as Syndicates — introducing governance mechanisms and shared resource pooling capabilities.

Governance Modules

On-chain voting for protocol parameter adjustments via the DAO structure. Proposals must pass a 67% supermajority to take effect.

Resource Pooling

Syndicates can aggregate yield-generating assets into unified vaults for amplified collective returns and shared verification rights.

layers Phase 3: Syndicate Tiers

Syndicate tiers are determined by the cryptographic weight of the aggregated identities. Higher tiers unlock advanced protocol features, governance voting weight, and exclusive access to premium syndicate vaults.

  • Tier 1 (Initiate): Base access to governance proposals and standard yield pools.
  • Tier 2 (Operative): Enhanced voting power multiplier (1.5x) and access to priority transaction relays.
  • Tier 3 (Architect): Maximum protocol influence (3x voting weight), custom syndicate vault deployment, and zero-fee identity minting.
SYS_LOG: Cryptographic verification required for tier ascension. Node consensus mandatory.

layers Tier Architecture

POXY Syndicates operate on a five-tier hierarchy. Each tier unlocks progressively deeper protocol access, governance weight, and revenue participation rights.

Tier I — Recruit

Base access. Can participate in public drops and standard market operations.

Tier II — Operative

Unlocked by holding 5+ unique assets. Priority queue access for limited drops.

Tier III — Sentinel

Minimum 1 Rare or above. Governance voting rights activated.

Tier IV — Warlord

Minimum 1 Mythic asset. Revenue-sharing participation and vault creation rights.

group Collective Operations

Syndicates may pool verified assets into collective vaults. Vault operations are governed by multi-signature authorization, requiring consensus from a configurable threshold of vault keyholders.

gavel Usage Rights & Jurisdiction

POXY assets are digital collectibles with fully assigned ownership rights. The holder of a verified POXY asset is entitled to: (1) display rights across any personal or commercial medium, (2) transfer or resale of the asset on authorized secondary markets, and (3) protocol governance participation at the applicable tier level.

POXY World Ltd. operates under jurisdiction of England and Wales. All disputes are subject to binding arbitration under LCIA rules.

policy On-Chain Governance

Protocol parameter changes require a governance proposal submitted on-chain. Eligible voters are Sentinel-tier and above. A 67% supermajority is required for ratification. Emergency security patches may be deployed by the core team within a 24-hour notice window, subject to retroactive ratification within 7 days.

Privacy Policy

User data is processed in accordance with UK GDPR. No on-chain identity data is linked to personally identifiable information without explicit consent.

Cookie Policy

Functional cookies only. No third-party tracking cookies are deployed on any POXY World domain.

shield VERIFICATION PROTOCOL

Verification
Playground

Enter a POXY hash, event ID, or RNG round ID to receive a step-by-step cryptographic proof. No login required.

account_tree Validation Path
check
Phase 1: Commit
Initial payload anchored to ledger.
c_hash: 8f4e...2a1d
check
Phase 2: Entropy
Network consensus random seed injected.
seed: 9b2c...5f4e
Phase 3: Reveal
Computing final state…
Valid Signatures verified Verified

Asset Proof Receipt

Timestamp
—
link POXY Hash
Enter a hash above and click Verify
data_object Ledger Event ID
—
casino RNG Round ID
—
sys_log // poxy_crypto_core
> initializing poxy_crypto_core v2.4.1...
> awaiting input vector...
> [OK] secure channel established
> listening on verification endpoint...
> status: ready — enter hash to begin
> _
storefront

Tactical Terminal

Premium assets

Asset Previewer

Live simulation engine

view_in_ar
👾
@player
Operative
Exchange terminal
0 PX
Dust balance 0
Collection 0 items

Active uplinks

bolt Member perks online
local_offer Zero market fees

Premium caches

Acquire exclusive visual modifications.

Sign in to access the store.
Rank –

PLAYER

OPERATOR: @player // SYSTEM_ID: #PX-––––

TOTAL ASSETS –
RARE+ UNITS –
LOGIN STREAK –
TOTAL DUST –
ECOSYSTEM RANK #–

DAILY STREAK

Claim each day for PX + XP bonuses

0d

Longest: 0 days

Next reward: 50 PX + 50 XP

SHOWCASE MATRIX

0/5 SLOTS

BADGE WALLET & PERKS

ACTIVE PASSES
No badges yet.

ACHIEVEMENTS

0 / 14

DAILY DIRECTIVES

Sign in to load directives…

Settings

Settings/Your Account

Manage your account settings, password, and identity verification.

Account Information

@player
Joined —

Usernames are unique across POXY WORLD, like on X. Letters, numbers, and underscores only.

Language

Interface language for POXY WORLD. Saved on this device.

Change Password

Session

Sign out of POXY WORLD on this device. You can sign back in anytime.

Danger Zone

Deactivate Account

Temporary deactivation can be reversed within 30 days. Contact support to process a full account closure.

Two-Factor Authentication

Authenticator app (TOTP)

Require a one-time code when signing in from a new device.

SMS backup codes

Receive backup codes via verified phone — rollout Q3.

Sessions

Sign out everywhere except this browser. Use after a suspected login or device loss.

Recent Login History

Delivery Preferences

In-app notifications

Show toasts and badges inside POXY WORLD.

Email digests

Weekly summary of trades, news, and club activity.

Browser push alerts

Daily bonuses, rare drops, market offers, and streak reminders.

Mentions

Chat @mentions

Trade Requests

Incoming trade offers

Trade completed

News

Patch notes & major updates

Hotfixes & maintenance

Theme

Accent Color

Font Size

Performance & Audio

Performance mode

Reduces motion, blur, and heavy UI animations across the app.

HUD inventory hover sounds

Onboarding

Re-experience the interactive cinematic tour shown on first login.

Tactical Archive

Your complete operational inventory. Manage assets, review metadata, and deploy tactical units to the grid.

TOTAL ASSETS inventory_2
— +0 THIS WEEK
LEGENDARY CORE stars
— TOP 5% HOLDERS
EST. VALUE account_balance_wallet
— PX
DEPLOY SQUAD rocket_launch
3 UNITS READY FOR ACTIVE DUTY

Active Inventory

DISPLAYING: — OF —
GEN CHINA MAGIC
Season Atlas
0 / 6 Collected

Friends & Social

Compact roster with live presence, hot-key macros, and full profile viewports.

Enter exact username (letters, numbers, underscores).
Search results
Enter a username and press Find
My friends
👾verified

–

@–

– POXY Member

Bio

Identity Tags

Network Rank

–

Global Standing

insights
Featured POXY 👾

–

Recent Drops

Send a Gift

Choose an item from your inventory.

🎁
👾
–
–
Asset Exchange
sort
deployed_code
Mythic Rare verified Featured

VOID WALKER EXOSUIT

Serial ID: #0001-ALPHA

Current Ask
85,000 PX

Market Pulse

24h Volume 1.2M PX
Floor Price 4,500 PX
Active Listings —
ADD FUNDS

Treasury & card form are on the Dashboard.

lock POXY CRYPTO CORE
Cryptographic Whitepaper · v1.0

POXY Cryptographic
Core System

A production-grade cryptographic integrity system running inside Supabase. Every POXY asset is uniquely hashed, ED25519-signed, and anchored into an append-only Merkle-verified ledger — providing blockchain-grade tamper-resistance inside a centralized database.

architecture System Architecture

POXY uses a layered cryptographic stack. Each layer independently verifies the one below it — no single point of trust can corrupt the system without breaking the chain.

┌─────────────────────────────────────────────────────────────────┐
│                  PUBLIC TRANSPARENCY LAYER                       │
│         /verify — anyone can audit any asset or event           │
├─────────────────────────────────────────────────────────────────┤
│                    EDGE FUNCTION LAYER                           │
│  ┌───────────────┐  ┌────────────────┐  ┌──────────────────┐   │
│  │  mint_poxy    │  │ transfer_poxy  │  │  public_verify   │   │
│  │  (JWT req.)   │  │  (JWT req.)    │  │  (public, anon)  │   │
│  └───────┬───────┘  └───────┬────────┘  └────────┬─────────┘   │
│          │ ED25519 sign      │ ED25519 sign        │ ED25519 verify│
├──────────┼───────────────────┼─────────────────────┼─────────────┤
│                   DATABASE INTEGRITY LAYER                        │
│  ┌──────────────┐ ┌─────────────────┐ ┌──────────────────────┐  │
│  │ poxy_assets  │ │  ledger_events  │ │     merkle_roots     │  │
│  │ (SHA-256 id) │ │ (hash-chained)  │ │  (state snapshots)   │  │
│  │ immutable    │ │ append-only     │ │  every 24h           │  │
│  └──────────────┘ └─────────────────┘ └──────────────────────┘  │
│  ┌──────────────┐ ┌─────────────────┐ ┌──────────────────────┐  │
│  │  crypto_keys │ │   rng_rounds    │ │  security_audit_log  │  │
│  │ (pub keys)   │ │ (commit-reveal) │ │  (every action)      │  │
│  └──────────────┘ └─────────────────┘ └──────────────────────┘  │
│  Triggers block UPDATE/DELETE · RLS restricts access             │
└─────────────────────────────────────────────────────────────────┘
│                  CRYPTOGRAPHIC PRIMITIVES                         │
│   SHA-256 (identity + chaining)  ·  ED25519 (signing)           │
│   Merkle Trees (bulk integrity)  ·  Commit-Reveal (fair RNG)    │
└─────────────────────────────────────────────────────────────────┘
🔐
SHA-256
Deterministic 256-bit fingerprint for asset identity and event chaining. Collision-resistant and standardized.
✍️
ED25519
Elliptic-curve digital signature. 128-bit security, 64-byte signatures, constant-time verification.
🌲
Merkle Trees
Binary hash tree over all assets and events. A single root hash proves the integrity of the entire dataset.
🎲
Commit-Reveal
Two-phase RNG protocol. Server commits to a seed before the client provides theirs — neither party can bias the output.
fingerprint POXY Identity Hash System

Every POXY receives a deterministic, permanent SHA-256 identity hash at the moment of minting. This hash is the asset's cryptographic fingerprint — immutable forever, impossible to forge without all 7 inputs.

The hash pre-image is constructed from fields controlled entirely server-side:

hash_input = creator_id
           + "|" + mint_timestamp_microseconds
           + "|" + serial_number
           + "|" + rarity_seed
           + "|" + collection_id
           + "|" + generation_version
           + "|" + server_salt

poxy_hash = SHA256(UTF8(hash_input))  →  64 lowercase hex characters

Why is this safe? SHA-256 is a one-way function. Given only the hash, it is computationally infeasible to reconstruct the inputs (pre-image resistance). The server_salt is a randomly generated per-asset secret that is never published — making brute-force enumeration impossible even if an attacker knows all other fields.

What prevents duplication? The combination of timestamp (microsecond precision) + server_salt has negligible collision probability. Additionally, poxy_hash has a UNIQUE constraint in the database, enforced at the storage layer.

What makes it immutable? PostgreSQL triggers block any UPDATE or DELETE on the poxy_assets table. The hash cannot be changed after insertion without a physical database attack, which would be visible to the audit log.

verified_user Hash Verification

Anyone with the poxy_hash can request a verification. The system recomputes the hash server-side (the salt stays inside the database) and confirms the stored value matches. Use the Verify tab to do this interactively.

verify:  recomputed_hash = SHA256(all_7_inputs)
         ok = (recomputed_hash == stored_poxy_hash)
key ED25519 Signature System

Every POXY hash is digitally signed by the server's ED25519 private key at the moment of minting. This proves the asset was created by the legitimate server — not injected directly into the database.

At mint time:
  signature = ED25519_SIGN(server_private_key, poxy_hash)

At verification time:
  valid = ED25519_VERIFY(registered_public_key, poxy_hash, signature)
  → true  iff signature was produced by the matching private key

Key separation: The private key exists only inside Edge Function secrets (Supabase's encrypted environment). It never touches the database. The public key is registered in crypto_keys and is publicly readable for audit.

What this proves: A valid signature over a valid hash means both: (1) the hash was not tampered with after signing, and (2) a legitimate server process performed the mint. A database administrator with direct table access cannot forge a valid signature without the private key.

autorenew Key Rotation

Every signature permanently records its key_version. When a key is rotated:

1. A new keypair is generated and the new public key is registered with dual-control approval.
2. New signatures use the new key. Old signatures remain verifiable forever — the old public key stays in crypto_keys.
3. The old private key secret is retired from Edge Function secrets.

Signature history is never lost. Any asset can be verified against its original key, regardless of how many rotations have occurred since.

receipt_long Append-Only Event Ledger

All system actions — mints, transfers, trades, upgrades, destructions — are recorded in ledger_events. This table is strictly append-only: PostgreSQL triggers reject any UPDATE or DELETE with an unrecoverable error.

Each event is chained to its predecessor via SHA-256, forming a structure equivalent to a blockchain hash chain:

event_hash[0] = SHA256("GENESIS\n" + canonical_body[0])

event_hash[n] = SHA256(event_hash[n-1] + "\n" + canonical_body[n])

canonical_body = stableStringify({
  type, asset_id, from, to, nonce, timestamp, ...payload
})

Why is this tamper-evident? Changing any event's content changes its hash. Because subsequent events include the previous hash, every event after it also changes. A verifier comparing stored hashes to recomputed hashes immediately detects any alteration.

Concurrency protection: A pg_advisory_xact_lock serializes all ledger writes, preventing two concurrent transactions from computing a hash chain fork (the same prev_event_hash used twice).

event_list Event Types

The ledger records the following event types, each with a fully canonical JSON body:

MINT — new asset created. TRANSFER — ownership changed by admin. TRADE — peer-to-peer swap. UPGRADE — rarity elevation. FUSION — two assets combined. DESTROY — asset burned. ADMIN_ACTION — privileged operation.

The state machine enforces valid transitions: e.g., a DESTROYED asset cannot be transferred. Invalid transitions are rejected at the database layer before any event is written.

casino Provably Fair RNG System

POXY uses a commit-reveal protocol for random number generation. This means neither the server nor the player can bias the outcome:

Phase 1 – COMMIT (before player input):
  server_seed  = cryptographically random 32 bytes
  commit_hash  = SHA256(server_seed)
  → commit_hash is published; server_seed is hidden

Phase 2 – REVEAL (after player provides client_seed + nonce):
  result_hash  = SHA256(server_seed || client_seed || nonce)
  server_seed  is revealed

Verification (anyone can do this):
  check_commit = SHA256(revealed_server_seed) == commit_hash  ✓
  check_result = SHA256(server_seed || client_seed || nonce) == result_hash  ✓

Why can't the server cheat? The server commits to its seed before the player's input is known. Changing the seed after seeing the player's input would change the commit_hash — which was already published and is immutable in the database.

Why can't the player cheat? The player provides their seed after the server's commit is already published. The server's seed is hidden until after the player's seed is submitted. Neither party alone controls the final result_hash.

balance Trust Architecture — Honest Disclosure

We believe in mathematical honesty. Here is precisely what is and is not guaranteed:

check_circle Cryptographically Enforced

Hash integrity: The poxy_hash is a mathematical commitment to the 7 identity fields. It cannot be altered without detection.

Signature authenticity: An ED25519 signature cannot be forged without the private key. A valid signature proves server origin.

Ledger tamper-evidence: The hash chain means any event modification breaks every subsequent hash — detectable by anyone.

RNG fairness: The commit-reveal protocol is information-theoretically fair — verified mathematically, not by trust.

warning Tamper-Resistant, Not Trustless

Centralized custody: POXY runs on Supabase (PostgreSQL + Deno Edge). It is not a decentralized blockchain. The operator controls the infrastructure.

Private key trust: The ED25519 private key is held by the server. If the server is compromised, an attacker could sign fraudulent assets — though the hash chain would still reveal unauthorized events.

Audit, not consensus: There is no peer-to-peer consensus. Integrity is enforced by cryptographic constraints and auditing, not distributed agreement.

A blockchain migration roadmap exists for anchoring Merkle roots to Ethereum or a public L2, enabling true trustless verification while keeping the gaming database centralized.

visibility Publicly Auditable

Public key: The ED25519 public key is in crypto_keys. Anyone can verify any signature without contacting the server.

Event hashes: Ledger event hashes are publicly readable. Anyone can reconstruct the hash chain from scratch.

Merkle roots: Daily state snapshots (Merkle roots over all assets and events) are stored immutably and publicly readable.

RNG proofs: Every RNG round's server seed, client seed, nonce, and result are published after reveal. The fairness proof is fully reproducible offline.

security Threat Model

The following threats are explicitly addressed. Each is described with the attack vector and the technical countermeasure.

ThreatCountermeasureStatus
Duplicate minting UNIQUE constraint on poxy_hash. Even if two mint calls run concurrently, identical hashes are rejected at the DB layer. ✓ Enforced
Replay attacks Every signed request carries a unique nonce + ISO timestamp. The nonce is consumed atomically; reuse or stale timestamps are rejected. ✓ Enforced
Signature forgery ED25519 signature security is 128-bit. The private key exists only in Edge Function secrets — not in the database, not in source code. ✓ Enforced
Event rewriting INSERT-only triggers reject UPDATE/DELETE on ledger_events. Hash chain verification detects any storage-level tampering. ✓ Enforced
Database tampering Hash chain and signatures are verifiable from the public key alone. A DB admin inserting a fraudulent event cannot forge a valid ED25519 signature. ✓ Cryptographic
RNG manipulation Commit-reveal: server commits before seeing client input. Server cannot change seed; client cannot predict it. Result is deterministic from both inputs. ✓ Provably fair
Admin abuse Dual-control key approval required for key changes. All admin actions are logged in security_audit_log with hash-chained entries. ⚠ Logged + audited
Client spoofing All state transitions require a valid user JWT. Ownership verification is enforced by the Edge Function before any DB write. ✓ Enforced
Race conditions pg_advisory_xact_lock serializes all ledger writes. Prevents concurrent hash chain forks at the transaction level. ✓ Serialized
Server compromise A compromised server could sign fraudulent assets. However, unauthorized events are detectable in the public ledger. Key rotation immediately invalidates the compromised key. ⚠ Detectable

Verification Playground

Enter a POXY hash, event ID, or RNG round ID to receive a step-by-step cryptographic proof. No login required.

Running cryptographic verification…
List POXY for sale
Set your price in PX
Confirm Purchase
👾
Elite Tier

–

verified

@–

Unranked POXY Member

Notifications

No recent activity yet.

No pending gifts. Friends can send POXY from their profile.

🎁

RARE

💎

Gift revealed

PX-XXXXXX

POXY Support

Loading FAQ…

Loading tickets…

Preview

Ticket
open
Preview
👾
Player
Direct Message

Initiate Poxy Trade

Select POXY from your inventory to offer.

0 selected

Select showcase asset

Choose a POXY from your collection.

POXY ID – TIER
view_in_ar
#–
VERIFIED OWNER 0x···
SECURE UPLINK // POXY WORLD CORE VERIFIED
ASSET INTELLIGENCE

PX-––––––

–– TIER
ISSUED DATE –
COMPONENT STATUS ACTIVE / SECURED
NETWORK MAINNET
SYSTEM ARCHITECTURE POXY PROTOCOL v4.2
SERIAL KEY –
PINNED COLLECTION TOP
–
DNA SEQUENCE
RELIC SCORE
0
CERTIFICATE OF AUTHENTICITY
POXY WORLD — GEN CHINA MAGIC
✦
PX-——————
—
ISSUE DATE—
MINT BLOCK—
DNA HASH—
ED25519 SIGNATURE—
PROVENANCE CHAIN—
Cryptographically Verified by POXY WORLD
POXY · WORLD
👤
is sharing their POXY with you
PX-——
DNA SEQUENCE
RELIC SCORE —
Sign in to start collecting
POXY PROTOCOL

TREASURY
DEPOSIT

CURRENT BALANCE 0 PX
EXCHANGE RATE £2.50 = 50 PX
NETWORK ONLINE
MODE TEST

Poxy PX funds cases, marketplace trades, and premium terminal unlocks. Standard case costs 50 PX (£2.50).

REFERRAL PROTOCOL
--------
Refs 0 Month 0 Earned 0 PX

Friends get +50 PX & 500 XP · You earn 20% first purchase, 5% lifetime.

PX PACKAGES
CUSTOM GBP
Custom amounts convert at tier rates — packages offer better value.
Enter GBP amount
PAYMENT METHOD

or pay with card

CARD NUMBER
EXPIRY
CVV

Funds are applied instantly to your POXY wallet in test mode. No real charges are made.

✦ Welcome to POXY World
@operative

You've entered the digital void where 5,000 unique cryptographic dragons await.

Every dragon has a mathematical proof of existence. Every drop is verifiable on-chain.

Your First Dragon
🐉
PX-XXXXXX
COMMON • GEN 1
SHA-256: …

Cryptographically unique. Forever yours.

Open More Cases

1 / 3
Stay in the loop
Push notifications

Get alerts for daily bonuses, rare drops, market offers, and streak reminders — even when POXY is in the background.

Daily login

DAY 1 STREAK!

🔥 1 day in a row!

Today's reward

Day 1/30

Day 7: +500 PX · +1 VIP Case Token

Flash case offer

Standard case for 25 PX — limited window before price returns to 50 PX.

10:00