Cipolla Protocol — Layer Zero
Dynamic value distribution — first
Provenance Royalties NFT
A public experiment in a new economic mechanism tested on a collection of 250 NFTs: after every resale, a percentage of the sale price is automatically shared among all previous owners — permanently, immutably, on-chain.
The problem we are solving
In asset markets — whether tokenized or not — value is typically distributed to current holders only. Past participants receive nothing after selling.
In NFT markets, creator royalties (ERC-2981 standard) attribute a percentage of each resale to the original creator. But only to the creator.
Cipolla Protocol extends this logic: every historical holder — not just the creator or the last seller — receives a fraction of each future resale, automatically and permanently.
This approach is currently being tested on a collection of 250 NFTs.
If this experiment proves conclusive, the approach could be adapted to any tokenized asset — real estate, securities, intellectual property — subject to applicable regulations in each jurisdiction and asset class.
Our approach
We propose a model that permanently encodes two types of royalties directly into the smart contract: creator royalties and holder royalties — both automatically distributed after each resale.
Every time an asset is resold, royalties are distributed to all wallets that have ever owned it. The list of historical owners grows automatically with each transfer, creating a living record of participation that is transparent, immutable, and self-executing.
This mechanism produces two simultaneous effects that emerge naturally from the principle itself — without any additional rules or enforcement:
Effect 1 — Value distribution
A form of social distribution of collectively created value. Every participant who contributed to building the asset's reputation and liquidity continues to benefit from its future appreciation.
Effect 2 — Organic alignment
Every former owner becomes an economically incentivized ambassador for an asset they once held. The community of historical owners naturally becomes a self-regulating force, collectively motivated to trade on marketplaces that honor the protocol.
"No governance. No rules. No enforcement. Just shared economic interest, working quietly in the background of every transaction."
How it works
On every secondary sale, 15% of the sale price is distributed automatically via the smart contract:
| Recipient | Share |
|---|---|
| Creator (permanent) | 10% |
| All historical owners (equal split) | 5% |
| Seller | 85% |
The pool grows with every new owner. The earlier you enter the ownership chain, the more distributions you accumulate over time.
Two ways to own a token. One way to live off it.
Buying on a marketplace (OpenSea, etc.): full price freedom, but the buyer does NOT enter the Provenance Royalties ownership history — no future royalties.
Buying via buyP2P() on the Cipolla site: the buyer enters the ownership history and receives perpetual royalties on all future resales of the token, even after reselling it. The minimum price is protected by an on-chain oracle (getMarketAverage()), which prevents wash-trading attacks where a malicious actor could otherwise enter the ownership history for free and capture future holder-pool royalty distributions.
If a token is bought and sold alternately on a marketplace and via buyP2P(), only the buyers who went through buyP2P() enter the holder pool that receives royalties — marketplace buyers never enter it.
The collection — 250 NFTs
The collection is limited to 250 unique NFTs, each based on an original physical artwork by Anastasia Smirnova Vincent. Each token is numbered, belongs to a specific layer, and participates in the provenance royalties mechanism from the moment of its first resale (via buyP2P()).
Within each of the 5 layers, one token is an intruder — a rare variant with a distinctive visual identity. Its position was determined before the first mint using a provably fair random process (commit-reveal mechanism). The seed will be publicly revealed 30 days after launch, allowing anyone to independently verify the intruder positions were not altered after the fact.
| Layer | Tokens |
|---|---|
| Genesis Seed (creator) | #1 — reserved |
| Genesis Core | #2 – #11 (10 tokens) |
| Inner Layer | #12 – #51 (40 tokens) |
| Middle Layer | #52 – #151 (100 tokens) |
| Outer Layer | #152 – #230 (79 tokens) |
| Surface Layer | #231 – #250 (20 tokens) |
A reveal is scheduled 30 days after the mint opens, unveiling the true image and layer identity of each token.
Transparency & permissions
We believe the fastest path to trust is a complete and honest description of what the creator can and cannot do.
The team can
The team cannot
Known risks
-
Smart contract risk
The contract has undergone a thorough internal review (Slither, Foundry, 82 automated tests) and an independent external security review by a Code4rena/Sherlock-experienced auditor. No audit guarantees the complete absence of vulnerabilities. This V1 is an experiment — never participate more than you are prepared to lose.
Long-term vision
This collection is not the end goal. It is the first live test of a model designed for a much broader application.
If this experiment proves conclusive, the mechanism could extend beyond digital art — to any asset whose value is built collectively by a chain of participants — subject, in each case, to applicable regulatory frameworks.
250 NFTs. First live test of the Provenance Royalties mechanism. Community of Founding Nodes.
Additional collections deployed on the Cipolla Protocol. These future collections will integrate even more advanced sharing mechanisms. Founding Nodes receive priority access.
Other creators deploy their collections with native Provenance Royalties. A feature will also be offered to let existing ("old fashion") NFT collections retroactively benefit from the model.
A native trading platform where royalty distribution is atomic, automatic, and non-negotiable. No intermediaries. Just code.
We are actively open to venture capital, crowdfunding, and business angels who wish to participate in building this infrastructure. contact@cipollaprotocol.io
Security notice. No smart contract audit can guarantee the complete absence of vulnerabilities. Security reviews are bounded by time, scope, and the current state of knowledge. We have conducted a thorough internal review and will continue to monitor, improve, and iterate. This V1 deployment is an experiment — participation carries inherent risk. Never invest more than you are prepared to lose.