1 · Request
Telegram client
01Sender fires the tip
/tip @chad 10 USDC in-group, or the Tip composer in the Mini App. Mini App calls are authenticated by HMAC-SHA256 over Telegram initData.
02Membership resolved
Sender and recipient are matched to group-scoped memberships. Data never crosses group boundaries.
03Recipient payout address
The recipient's self-registered active wallet is looked up. No wallet, no tip — the bot refuses rather than guessing.
GUARD: self-tip & amount ≤ 0 rejected
2 · Intent
BRUH server · unsigned
04Asset resolved
Symbol → mint + decimals from the supported-assets registry. SOL is native (9dp); USDC and $BRUH are SPL (6dp). Only one $BRUH mint is ever accepted — from server config.
05Amount to base units
Integer math only: amount × 10^decimals. Floats never touch the settlement path.
06Reference key minted
A random 32-byte pubkey is generated as a Solana Pay reference. It is never a signer — it is a read-only tag that makes the payment findable on-chain.
07Intent row + TTL
Stored as status: created with an expiry and a USD price snapshot for the receipt.
3 · Sign
User's wallet · keys stay local
08Solana Pay URL / QR
solana:<recipient>?amount&reference&spl-token — rendered as a deep link and a QR code.
09Wallet builds the transfer
Phantom / Solflare / Backpack constructs a System transfer (SOL) or SPL token transfer to the recipient's associated token account, with the reference key attached as a read-only account.
10Sender signs
The private key never leaves the device. The bot cannot initiate, co-sign, sweep, or reverse anything.
BRUH HOLDS NO KEYS · NO CUSTODY
11Broadcast
The wallet submits directly to an RPC node. Funds move wallet → wallet, never through a BRUH account.
4 · Settle
Solana mainnet-beta
12Validators confirm
The transaction lands in a slot and reaches confirmed commitment. Fees are ~0.000005 SOL plus any ATA rent if the recipient's token account must be created.
13Server finds it by reference
getSignaturesForAddress(reference) then getTransaction with jsonParsed. Polled on demand and by a 2-minute sweep job.
14Balance-delta proof
The recipient's pre/post balance delta for the exact mint must meet the expected base units. Wrong recipient, wrong mint, or short amount → not verified.
FAILED TX & err ≠ null ARE SKIPPED
5 · Receipt
Ledger · leaderboard · treasury
15Verified transfer recorded
Signature, slot, mint, base units and USD-at-execution are written to verified_transfers; the intent flips to confirmed. Re-checking is idempotent.
16Fee leg logged
A 1% app-level service fee (100 bps) applies on the buy and cash-out legs, paid to the treasury address and written to fee_events. It is floored, so rounding never favours the treasury. $BRUH itself has no transfer tax.
17Announce & score
Subject to quiet hours and the sender's privacy mode (public / pseudonymous / anonymous / private). Tips feed reputation, not price calls.
18Expiry path
Unpaid past TTL → expired. Nothing is ever credited without a confirmed on-chain transfer.