Whitepaper · Draft v0.1 · 2026-10-06
Game money with rules a player can check. Owned by players.
GooCoin (GOO) is a game-economy currency on its own Cosmos-SDK chain. A transaction is final in about one second, the network fee is zero for players, the supply is exactly 1,000,000,000 GOO with minting disabled, and the key always belongs to the player. Studios buy GOO from the treasury in bulk and run their economies on it; players earn in one game and spend in another. This paper is written for the developers who will integrate it and the players who will hold it: every number comes from the live testnet and can be checked against the chain.
The whole design
00In one page
Game economies today are rented. A studio builds rewards, shops and seasons on top of a database, players grind for a balance that exists only inside one game, and when the studio shuts the servers down, the balance disappears with it. Moving value between games means building bridges nobody maintains. GooCoin replaces the rented balance with a currency: one GOO, one chain, every game.
The rules fit in a paragraph and are frozen at genesis: exactly 1,000,000,000 GOO; distribution 70% payout treasury, 15% team, 15% network reserve; minting disabled; a block final in about one second; zero fee for players, because the game pays their gas through feegrant; keys created in the player's browser, never on a server. Studios buy GOO from the treasury in bulk, distribute it however they like, and can sell leftovers back slightly below sale price. Extra supply can only be created by an on-chain validator vote.
If you read nothing else: GooCoin is one currency across every game, with a finality of about one second, zero player fees, and keys that always belong to the player. It is small, early, and live: the goocoin-1 testnet has been running since October 5, 2026. Section 10 tells you what can go wrong.
01The problem: game economies are rented
The balance is a database row
A player grinds two hundred hours for a reward. What they received is a row in the studio's database and a promise that the studio will keep paying for servers. If the studio closes, the row disappears. If the player wants to trade the reward outside the game, the studio builds and maintains a marketplace. If another studio wants to accept that reward as payment, there is no mechanism at all.
Fees eat micro-payments
Where studios do use a public chain, a reward of a few cents meets a transaction fee of a few cents. The economy stops making sense at exactly the moment it becomes interesting: small, frequent rewards. Chains that promise near-zero fees do it with thousands of confirmation-waiting users per validator, sidechains with their own trust assumptions, or rented rollups.
Keys end up on someone's server
Custodial wallet services solve the UX problem by keeping the key themselves. The player's ownership becomes an account with a password reset. That is a database row with extra steps.
GooCoin is designed so that small frequent rewards are free, final in about a second, and the key is created where the player is — in their browser — and never leaves it.
02The money rules
The supply schedule is deliberately boring, and boring is the point.
- Exactly 1,000,000,000 GOO, created at genesis. Distribution: 70% payout treasury, 15% team, 15% network reserve. All three addresses are visible in the genesis file of the live testnet.
- Minting disabled. The x/mint module parameters are zeroed: no new GOO appears outside the genesis balances. The module stays in the chain so the supply policy can only be changed by governance vote, never by a quiet config edit.
- Extra supply = governance vote. If the ecosystem ever needs more than the treasury holds, a proposal changes the inflation parameters on-chain, with every validator voting and the result recorded forever.
- Buyback, not burn. The treasury sells GOO to studios and buys leftovers back slightly below sale price. The spread is the service fee. Returned coins go back into the fund for resale: the supply never changes, the treasury never runs dry by design.
- Rules discount. Studios that keep payouts transparent and withdrawals free buy their next batch cheaper. The discount schedule is published with the treasury policy.
| Fund | Share | Purpose |
|---|---|---|
| Payout treasury | 70% | sells GOO to studios, buys back leftovers |
| Team | 15% | development, infrastructure, integrations |
| Network reserve | 15% | validator grants, growth, governance-funded work |
Checkable, not promisable. The genesis of the live testnet carries the full distribution: treasury goo1glhne… 700,000,000 GOO, team goo1m0fxm… 150,000,000 GOO, reserve goo1rx8f0… 150,000,000 GOO, four validators with genesis delegations, and the mint parameters set to zero. Every number in this paragraph is one REST call away at api.goocoin.xyz.
Parameters
| Parameter | Value |
|---|---|
| chain-id | goocoin-1 |
| Denom | ugoo (micro-GOO), display GOO, 6 decimals |
| Address prefix | goo (goo1…) |
| MAX supply | 1,000,000,000 GOO, fixed at genesis |
| Mint | disabled (inflation parameters zeroed at genesis) |
| Burning | none; buybacks return coins to the treasury |
| Block time | ~1 second (timeout_commit = 1s) |
| Minimum gas price | 0 on federation validators (zero-fee policy) |
03Consensus and network
GooCoin runs CometBFT consensus: validators propose and vote on blocks in rounds, and a block commits when more than two-thirds of the voting power signs it. A committed block is final. There is no fork to wait out, no confirmation counter, no probabilistic finality: a game can credit a payout the moment the transaction lands.
- Federation of four validators runs the testnet, operated by the project on its own hardware and two rented servers. The set grows toward sixteen as the network takes on external operators, then opens through governance.
- Zero-fee policy. Federation validators run
minimum-gas-prices = 0ugoo: transactions carry no fee. Spam is a policy question handled by feegrant limits and app-level rate limits, not by pricing players out. - Public RPC nodes run separately from validators. The API endpoint api.goocoin.xyz fronts one of them with HTTPS; studios and wallets read balances and broadcast transactions there.
- Hardware. A validator is a regular server. The network's total power draw is measured in light bulbs, not warehouses.
Because the federation is small and known at the start, the honest description is: GooCoin launches as a sovereign federation and decentralizes on a schedule — external validators join through governance as the ecosystem grows. Section 09 covers what an attacker can and cannot do at each stage.
04Zero fees: feegrant
A player with an empty balance can still act. The studio's backend grants a feegrant allowance to the player's address: from that moment the player signs their own transactions and the gas is paid by the studio's hot wallet.
- Spend limit and period. An allowance caps the gas a player can burn per window, so one abusive client cannot drain a wallet.
- Batches. Grants are issued in batches at registration, revoked per player when needed.
- Hot wallet. The payer wallet holds a working balance with a hard cap; the treasury tops it up on schedule. A drained hot wallet is an inconvenience measured in GOO, never in treasury.
- Zero minimum gas price. Federation validators accept zero-fee transactions. Studios that prefer a deposit-based model can require players to hold dust; the default flow assumes nothing.
The player's experience: press a button, the action happens, no wallet popup, no token to buy first, no gas math. The studio's experience: one configuration line per game server and a hot-wallet balance to keep above zero.
05Game object ownership
GOO is the money layer; the ownership principle extends to what the money buys.
- The key is the player's. Wallets are generated in the browser, encrypted with a passphrase, and stored on the player's device. A studio can credit a player's address; it cannot move funds out of it.
- Withdrawals are unconditional. An in-game balance is a claim on GOO held on-chain. The withdrawal is a transfer to the player's own address and cannot be refused without breaking the studio's discount tier.
- Cross-game spending. GOO does not care which game earned it. A reward from game A pays for an item in game B: the transfer is an ordinary bank/send.
- Objects, later. The same principle extends to game items as native objects (Game Object Ownership) once studios ship economies that need them; the currency layer ships first.
06For studios
The integration path is deliberately short:
- Buy. Place an order on the site, pay in BTC/TRX/USDT-TRC20, receive GOO on the address you name. The treasury delivers from its fund; no order books.
- Integrate. The game backend talks to the public REST API: balances, transfers, multisend payouts (one transaction, hundreds of recipients), feegrant grants. A thin proxy for key isolation and idempotent payouts ships with the mainnet release.
- Scale. Run your own RPC node next to the game server (a Docker image and a systemd unit are published) — read latency drops to LAN level.
- Comply with the rules, pay less. Transparent payouts and free withdrawals are the condition for the volume discount. The chain enforces nothing here; the treasury pricing does.
What a studio does inside its game remains entirely its own decision: prices, drop rates, seasons. The chain sees only transfers of GOO.
07The treasury and buyback
The treasury is the counterparty of every studio transaction: it sells new GOO and buys leftovers back. Two numbers define its behaviour:
- Sale price. Set by the project in the treasury policy and published on the site. It changes rarely and is announced before it changes.
- Buyback price. Sale price minus the spread. The spread is the service fee; it funds development instead of charging per-transaction fees.
The treasury fund is 700,000,000 GOO at genesis. At the mockup rate of 200,000 GOO per dollar, that is a 3,500-dollar float across the whole ecosystem's starting economy — deliberately small. The point of the buyback is that a studio's unused stock is a claim on the treasury, not a write-off, and the treasury can serve years of studios from the fund without ever touching the supply cap.
Extra supply, if the ecosystem ever votes for it, mints new coins into the treasury and dilutes everyone equally, including the team. That asymmetry is the incentive to keep the fund adequate in the first place.
08Governance
Governance is the only mechanism that changes the rules above.
- Who votes. Bonded validators, voting power weighted by stake. Today: the four federation validators. Tomorrow: every external validator that joins.
- What requires a vote. Enabling inflation, changing the zero-fee policy, adding validators to the set after the federation stage, treasury policy changes that touch on-chain parameters.
- What does not. The site, the treasury's off-chain pricing, the studio integrations — those are product decisions and stay off-chain.
A governance decision is a transaction, visible forever. There is no mechanism in the chain for a change that skipped it.
09Security model
Players
Keys are generated in the browser and encrypted locally. The server sees addresses and public transactions, nothing else. Worst case for a player device: restore from the seed on any other device.
Studios
A studio's exposure is its hot wallet, capped by policy. The treasury fund is separate and offline. A compromised game server loses the hot-wallet float, not the stock, not the treasury, not the players' funds.
The network
CometBFT halts rather than forking when validators misbehave: a double-sign attempt stops the chain until the offending validator is removed, which is a federation decision today and a governance vote after decentralization. An attacker controlling fewer than two-thirds of validators can halt the chain but cannot rewrite it, reverse a transaction, or mint.
The honest stage note
Today the federation is four validators operated by one party. That is a launch stage, not the end state: the set is designed to grow to sixteen, and external operators join through governance. Until then, the project's reputation is the security model — which is exactly why the money rules were frozen in code before anything else was built.
10Risks, honestly
- Stage risk. GooCoin is a testnet. The chain restarts, parameters change without notice, and testnet GOO has no value. Everything above describes intent verified on the testnet, not a launched product.
- Federation concentration. Four validators, one operator. The chain can be halted or rewritten by the operator until external validators join. Trust is concentrated at the start; the schedule to reduce it is the roadmap, not a fact.
- Treasury concentration. 70% of the supply sits in one address controlled by the project. The buyback and discount mechanics depend on it. The mitigation is governance and the published policy; the risk itself is real.
- Price risk. GOO is traded against payment currencies at rates the treasury sets at first and the market sets later. Studios buying large batches carry that volatility; the buyback softens it but does not remove it.
- Adoption risk. A game currency is worth what games accept it. The ecosystem starts at zero games.
- Regulatory risk. Selling a crypto asset on a website touches financial regulation in most jurisdictions; the launch plan accounts for it, but the burden is real and external.
11Roadmap
- Sovereign chain: goocoin-1 testnet live, 4 validators, zero-fee policy, public API
- Public RPC infrastructure on two internet servers
- Site with purchase flow, web wallet, explorer
- Thin proxy with key isolation and idempotent payouts (mainnet release)
- First studio integrations with plugins for Unity, Godot and UE5
- External validators through governance
- Public listing after the first studio economies ship
12Disclaimer
This whitepaper describes software at the testnet stage. Testnet GOO has no value and makes no claim to have any. Nothing here is investment advice, an offer, or a solicitation in any jurisdiction where such an offer would be unlawful. The network is operated by a small federation at this stage; the properties described are properties of the current code and configuration, which can change without notice until the rules are frozen for mainnet. Anyone buying or holding GOO should read section 10 and assume the worst item on the list is true until proven otherwise.
© GooCoin project, 2026. Code and documentation are published in the project repository.