# Crash-Game RWA Desk (MSFT FLIGHT SIMULATOR)

> **Status: the desk is operating on mainnet.** MSFT FLIGHT SIMULATOR opened
> on 15 August 2026 and is served from the arcade at play.netnet.capital.
> Contract addresses are published on
> [Official Channels](/official-channels) and nowhere else.
> **Participation is restricted to persons 18 years of age or older.**
> Dollar figures on this page are the deployed parameters, quoted at the
> market price of MSFT where so labeled, and never a promise.

MSFT FLIGHT SIMULATOR is a crash game skinned as a late-1990s flight
simulator. Before takeoff the player sets one dial, the jump line: the
altitude their pilot bails out at, anywhere from just above the runway at
1.01× to the 16× service ceiling. The ticket then buys a flight whose true
ceiling is sealed inside a future round of a public randomness beacon. If
the flight's revealed ceiling reaches the jump line, the pilot jumps and the
ticket pays the stake times the line, in MSFT, the tokenized Microsoft
equity that trades on Robinhood Chain through Rialto. If the ceiling falls
short, the plane goes down on screen and the stake is lost.

This game is not even-money, and the documentation says so first. **The
board carries a house edge that is printed on the machine.** The chance the
flight's ceiling reaches an altitude `m` is exactly `0.90 / m`, so **every
position on the slider returns 90% of the stake on average**, and a flat
**5% fee** applies on top of that, for a combined expected return of about
**85.5%**. One flight in ten never clears the runway at all. The edge lives
in the survival curve and in the fee, both disclosed, and neither is buried
in the animation. This is the Superstore's honesty model, not COINflip's:
COINflip's coins are exactly fair and its fee is the whole edge, and that
sentence is false about this game, so it does not appear here.

The game is a cabinet in the fund's RW-PLAY thesis: tokenized real-world
assets are natural play pieces for on-chain games. In MSFT FLIGHT SIMULATOR
a tokenized equity is the stake, the pot, and the prize, settled in seconds.
Every USDG ticket is a live Rialto fill into MSFT at placement, and every
sell-back after a win is another.

The consumer application speaks plain English by design. Its HOUSE RULES
panel carries the edge disclosure and the fee disclosure in full and links
here. This page is the controlling description of the mechanics.

## The game

* **One input: the jump line.** A log-scaled slider from **1.01× to 16×**,
  set before takeoff and committed in the bet itself. The slider prices the
  position as it moves: the payout if the flight reaches the line, and the
  printed chance that it does. Nothing the player does after placing the
  ticket changes any outcome; there is no in-flight control.
* **The sealed ceiling.** Placing a ticket names a future round of the
  randomness beacon. That round's signature, once published, fixes the
  flight's ceiling `C` with `P(C ≥ m) = 0.90 / m`. The ticket **wins if and
  only if `C` reaches the committed jump line**, and a win pays the stake
  times the line, in MSFT.
* **The flight is a replay.** The outcome is fixed on chain before the
  animation begins, and the flight the player watches plays that settled
  truth: the altimeter climbs toward the orange jump line, and either the
  pilot jumps there, or the plane noses over at its revealed ceiling below
  the line, or it never rotates at all on a sub-1× draw. The application
  renders the on-chain crash altitude, never an invention of its own.
* **Minimum ticket.** The all-in amount, stake plus fee together, must be
  worth at least **$5** in the application; the contract's own dust floor is
  $1 at the price feed's mark.
* **Maximum ticket.** Set by the coverage cap described under the house fund
  below, and shown live in the application at the slider's current position.
* **Lifecycle.** Placing a ticket locks the stake and fee, names the
  randomness round, and **reserves the ticket's full payout from the house
  fund**, stake times the jump line. A ticket the fund could not pay is
  refused at placement rather than owed later. Once the round publishes,
  settlement verifies the beacon's signature on chain, resolves the ceiling
  against the line, and pays or absorbs the stake. Tickets are
  non-transferable, and each reservation is held individually.

## The survival curve, and the edge printed on it

The board is deliberately negative expected value, and the curve that makes
it so is printed on the machine, on the slider itself and on the placard.
This is the whole disclosure and it is never softened into a fairness claim.

The chance the ceiling reaches an altitude `m` is `0.90 / m`, for any `m`
from 1× up. Worked rows:

| Jump line | 1.5× | 2× | 3× | 4× | 8× | 16× |
|---|---|---|---|---|---|---|
| Chance it holds | 60% | 45% | 30% | 22.5% | 11.25% | 5.625% |
| Payout on $10 staked | $15 | $20 | $30 | $40 | $80 | $160 |

Every row multiplies out to the same expected value: **0.90 times the
stake**. The slider trades the chance of winning against the size of the
win, and it never trades the edge. The contract asserts at deployment that
the return constant is inside a tight band around 0.90, so the board can
never be quietly rigged to pay less than it advertises. That assertion
protects the player. **It is not a claim that the game is even-money,
because it is not.**

The consequence of an average is the part that matters to a player, so it is
stated alongside rather than left implied. One flight in ten draws a ceiling
below 1× and never clears the runway. A player who rides the slider high
should expect most tickets to lose outright: a 16× line holds about once in
eighteen flights. The 90% arithmetic is a statement about the board, not a
forecast of any one flight. Playing MSFT FLIGHT SIMULATOR is not a way to
make money, and nothing in this documentation should be read as suggesting
it is.

## The jump line trades chance against size, never edge

Where the slider sits changes what a ticket wins and how often, and it
changes nothing else. A cautious line near the runway wins often and pays
little; the ceiling line wins rarely and pays sixteen-fold; both return the
same 90% of the stake on average. There is no clever position, no timing,
and no skill anywhere in the game, and the application does not suggest
otherwise. The beacon is the outcome.

## Every leg is MSFT

The stake, the payout, the house's liability, and the house's bankroll are
all denominated in MSFT units. One MSFT staked against a multiple of MSFT
owed is solvent at any price, so the game itself never depends on a price
feed. The only legs that need a price are the two conversions, and those are
exactly the legs gated on market hours:

* **Ticket in MSFT.** No conversion and no price needed. MSFT tickets run
  around the clock, weekends included.
* **Ticket in USDG.** The desk takes the fee from the USDG side, then
  converts the full stake to MSFT through Rialto at placement, one live fill
  per ticket, and the game proceeds MSFT-native from there. Off-hours a
  stale feed pauses that on-chain conversion, so the application buys the
  MSFT in your own wallet at the live market price and boards that instead:
  a USDG ticket is never blocked, though the off-hours fill pays a wider
  spread and is refused in the rare case that MSFT has moved too far from
  the oracle.
* **Win.** The payout arrives as MSFT from the house fund, so a winner is
  holding Microsoft stock. A one-tap sell-back converts MSFT to USDG through
  Rialto while the market is open; on a weekend the button queues the sale
  for the reopen, and the queued sale executes at the reopen price, not the
  price at the time of the tap.
* **Loss.** The staked MSFT joins the house fund. Nothing converts.

## The fee, and where it goes

The fee is **5% of the stake, fee-inclusive**. The amount entered is the
total spent, and the stake is that amount divided by 1.05, so the fee is
never a surprise added at the end. The 5% splits in half, and both halves
are immutable constants of the deployed contract:

* **2.5% to the Manager.** The management company's revenue from the game,
  accrued in the currency each ticket was placed in and swept to the team
  multisig.
* **2.5% to the NetNet RWA Sleeve**, the disclosed portfolio of tokenized
  real-world assets the Manager holds for the protocol's benefit, described
  under [Real World Bonds](/rwa-desk). MSFT-side fees sweep to the Sleeve
  directly; USDG-side fees convert to MSFT at sweep time, while the market
  is open, and follow.

Two clarifications belong next to the split. First, **nothing from this
product reaches the Treasury**. Second, the Sleeve is **not part of the
fund's on-chain reserves (RFV) or backing**, and no NET is backed by Sleeve
assets. Any future use of the Sleeve to support the fund is at the Manager's
discretion, as disclosed on the [Real World Bonds](/rwa-desk) page.

Fee sweeps are permissionless: `sweepFees()` is callable by anyone at any
time, and the fund's keeper calls it on a thirty-minute cadence. Cumulative
sweeps to the Manager and the Sleeve always equal cumulative fees charged;
neither half can be redirected or zeroed at any ticket size.

The 5% fee is separate from the board edge and is disclosed separately. The
board returns 90% of the stake on average, the fee takes 5% of the stake,
and the combined expected return is about **85.5%**. The desk states both
numbers rather than folding the fee into the curve: the slider's payout is
always the true payout, and the fee is always shown as its own line.

## The house is the Manager

The bankroll behind the game is the Manager's own capital, and this is
disclosed as the product's central operational fact rather than softened.

* The Manager seeded the house fund with about **$10,000**, converted to
  MSFT at launch through Rialto. Liabilities are MSFT-denominated, so the
  fund's solvency does not depend on the MSFT price; the price exposure on
  the bankroll is the Manager's alone.
* Anyone may add to the house fund. Only the Manager may withdraw, and a
  withdrawal is **coverage-floored**: it reverts if it would leave the fund
  below the total payouts reserved on open tickets, and it further reverts
  if it would leave a nonzero bankroll below an operating floor of 2 MSFT,
  so the advertised ceiling can never be stranded unbettable by an
  accidental partial withdrawal. **A placed ticket's reservation can never
  be defunded.**
* Above those floors the bankroll is operational. The Manager may withdraw
  and refill at will, with no timelock, and the application's live coverage
  readout reflects whatever is actually there.
* The house fund is **never protocol funds**. The Treasury, the fund's
  reserves (RFV), and protocol-owned liquidity are not a betting
  counterparty, and no code path lets them seed, top up, or backstop the
  bankroll.

### The coverage cap

The maximum payout reserved against any single ticket is an immutable
formula: **5% of the free bankroll**, where free means the house's MSFT
minus everything already reserved. Because a ticket reserves its full
payout, stake times the jump line, the cap bounds the ticket through the
line: at the launch seed the largest reserved payout is about **$500**, so a
16× line clears at stakes up to about $31 and a 2× line at up to about
$250. Tickets that share one beacon round are additionally capped in
aggregate by the same formula. The application shows the live maximum at the
slider's position. Raising the limits means the Manager seeding more; a
shrinking bankroll shrinks them automatically.

## Market hours

Robinhood's stock tokens trade 24/5, from Sunday 8 PM ET through Friday
8 PM ET, and are closed on weekends. The desk maps onto that calendar the
only honest way:

* **The game itself never freezes.** MSFT-in, MSFT-out tickets run through
  the weekend, because no leg of an MSFT ticket needs a price.
* **Boarding never waits; cashing out does.** The on-chain USDG conversion
  is gated on the market being open and the Chainlink MSFT feed being fresh
  within a four-hour window, because converting at a frozen Friday price
  would hand a free option against the house. When that gate is closed, a
  USDG ticket still goes through, since the application buys the MSFT in
  your wallet at the live off-hours price and boards that; a sell-back from
  MSFT to USDG is what waits for the reopen.

A player who holds MSFT over a weekend, whether by choice or because a
queued sell-back is waiting for the reopen, carries the stock's weekend
price risk. That is what holding a stock is.

## Randomness, and how to check it

The outcome of every flight comes from [drand](https://drand.love), the
public distributed randomness beacon, on its quicknet chain. The machinery
is the same as the Superstore's, COINflip's, and SPACEX INVADERS', and it
has no operator input anywhere in the outcome path.

1. The ticket names its round **at placement**, by arithmetic anyone can
   repeat: the first quicknet round due at least **15 seconds** after the
   ticket's timestamp. The delay exists so that the round **cannot exist
   yet** when the ticket is placed. A threshold of independent drand nodes
   must jointly sign a round before it exists, so nobody, the fund included,
   can know any flight's ceiling at placement. The 15-second figure carries
   a wide margin over the chain's measured timestamp skew, and the contract
   fails closed on both ends: a ticket that would name an already-published
   round reverts, and a settle whose round turns out to have been published
   before the ticket reverts.
2. Once the round publishes, anyone may relay its signature. The contract
   verifies the BLS signature on chain against drand's group public key,
   using the chain's BLS12-381 precompiles, and rejects anything the drand
   network did not sign. **The ceiling derives from that one verified
   signature**: the flight's seed is `keccak256(signature ‖ ticket id)`,
   read as a uniform draw `U`, and the ceiling is `C = 0.90 / U`. The ticket
   wins if and only if `C` reaches the committed jump line. The per-ticket
   id salts each draw, so flights that share one round land independently.
3. Settlement is **permissionless and unpaid**. The fund's keeper settles
   every flight at its own expense the moment the round is public, and the
   point of the permission being open is that **a bettor can always settle
   their own ticket** without anybody's cooperation.
4. **If the beacon fails.** If a ticket's round is still unpublished two
   hours past its due time, the bettor, and only the bettor, may void the
   ticket for a **full refund of stake and fee**, releasing the reservation.
   Because settlement is permissionless, any beacon that exists is settled
   long before that deadline; the void exists for a true drand outage, not
   as anyone's discretion over a live ticket.

The application's fairness surface shows the round number, the signature,
and the derivation for every historical flight. To audit one: fetch the
round from any public drand node, verify the signature, hash it with the
ticket id, and confirm the ceiling the contract recorded.

## Fairness, stated per actor

The desk does not claim to be even-money, because it is not. The
provable-fair claim is scoped to the randomness: the draw is tamper-proof
and every result is self-verifiable. What follows is true per actor.

* **The bettor, and any third party.** Every flight's ceiling is a pure
  function of the ticket's named round and the beacon's signature. Nothing a
  bettor signs, times, or resubmits changes a value locked at placement, and
  no post-placement action exists in the game at all.
* **The operator.** The operator cannot choose an outcome, cannot bias one,
  and cannot annul one. Settlement is permissionless, the void is
  bettor-exclusive, and the halt switch stops new tickets only: no post-bet
  step, not settlement, not sell-back, not a coverage-floored withdrawal,
  can be halted by anyone. What the operator can do is set the edge, and the
  edge is printed on the machine for anyone to read before they play.
* **The sequencer.** Aiming a ticket at a known round would require the
  chain operator to falsify timestamps beyond the measured-skew margin
  inside the 15-second delay, and the fail-closed checks turn a larger skew
  into reverted transactions rather than exploitable tickets. This is
  disclosed as the design's residual trust assumption rather than argued
  away.

## The arcade at play.netnet.capital

play.netnet.capital is the fund's arcade hub, presented as a desktop from
another decade. MSFT FLIGHT SIMULATOR, SPACEX INVADERS, and COINflip run
there natively; **WinNET**, **CLIMB, INC.**, and **the Superstore** appear
as icons that link out to their own venues. The About window carries the
fund framing and the Manager's RW-PLAY letter, and each game's own long-form
disclosure is the controlling document for that game.

Network fees on Robinhood Chain are paid in ETH. An account created with an
email address or a passkey never has to hold any: tickets are gas-sponsored
through the same infrastructure as WinNET's entries, subject to per-account
rate limits. A player who connects an external wallet pays their own network
fees in the ordinary way.

The cabinet is a parody dress. MSFT is the ticker the tokenized stock
identifies itself by on chain; the cockpit, the gauges, and the terrain are
the fund's own pixel art. MSFT FLIGHT SIMULATOR is not affiliated with,
sponsored by, or endorsed by Microsoft Corporation, and the tokenized stock
carries the issuer and redemption mechanics of its tokenization, which are
not the fund's to control.

## What the desk can never do

* **Touch the Treasury, protocol-owned liquidity, reserves, or emissions.**
  The desk holds no permission on any fund contract, is never exempt from
  the trading fee, and never touches the canonical NET pair. No leg of a
  ticket involves NET at all.
* **Pay out more than it holds.** Every ticket reserves its full payout at
  placement; the contract's invariants require the desk's MSFT balance to
  cover the house fund, every reserved payout, every unsettled stake, and
  accrued fees, at the end of every transaction.
* **Defund a placed ticket.** Reservations release only at settlement or a
  bettor-elected void, and owner withdrawals revert below the coverage
  floor and the operating floor.
* **Pay less than the printed curve.** The return constant is asserted at
  deployment to sit within a tight band around 0.90, so the board can never
  be quietly re-marked worse than the machine reads. The 5% fee, its 50/50
  split, the coverage-cap formula, the jump-line bounds, the ceiling
  derivation, and the refusal to price against a closed market are
  immutable. The Manager's settable surface is the minimum ticket, the halt
  on new tickets, and sweep execution, every change event-logged.
* **Keep a fee it did not disclose.** Cumulative sweeps equal cumulative
  fees charged, verifiable on chain.

## Program terms

1. **Operator.** NetNet Capital Management. The house bankroll is the
   Manager's own capital; participant stakes and reserved payouts are
   contract-escrowed, and the operator cannot settle, void, or redirect a
   ticket's outcome.
2. **Eligibility.** Participants must be **18 years of age or older**.
3. **Costs.** The board is negative expected value by design, returning 90%
   of the stake on average at every slider position, and a 5% fee-inclusive
   fee applies on top, for a combined expected return of about 85.5%. The
   survival curve is printed on the machine and the fee is stated
   separately. USDG tickets and sell-backs execute through Rialto at the
   quoted market price. No leg pays the fund's NET trading fee, because no
   leg touches NET.
4. **Randomness.** Every outcome is seeded by the public drand beacon and
   verified on chain. Settlement is permissionless; results are
   independently auditable. Provable fairness here means the randomness is
   tamper-proof and self-verifiable, not that the game is even-money.
5. **Amendments.** The fee, fee split, coverage-cap formula, jump-line
   bounds, ceiling derivation, solvency invariants, the asserted return
   band, and halt scope are fixed in the deployed contract. Changes require
   a successor deployment, not an in-place edit.

## Parameters

| Parameter | Value |
|---|---|
| The jump line | One committed input per ticket, 1.01× to 16×, log-scaled slider |
| Ceiling distribution | `P(ceiling ≥ m) = 0.90 / m`; one flight in ten never clears the runway |
| Board expected return | 0.90× the stake at every slider position, asserted within a tight band at deployment |
| Fee | 5% of the stake, fee-inclusive (stake = input / 1.05); split 50/50 Manager and Sleeve, immutable |
| Combined expected return | About 85.5% of the amount spent, board and fee together |
| Minimum ticket | $5 all-in in the application; $1 contract dust floor at the feed mark |
| Maximum reserved payout | 5% of the free bankroll per ticket, and per beacon round in aggregate, immutable formula |
| House seed at launch | About $10,000, converted to MSFT at launch |
| Operating floor | 2 MSFT; withdrawals may wind the fund down to zero but never strand a nonzero bankroll below it |
| Round naming delay | 15 seconds |
| Void deadline | 2 hours past the named round's due time, bettor-exclusive, full refund |
| USDG legs | On-chain conversion needs market open plus a 4-hour feed-freshness gate; off-hours a USDG ticket still runs by buying MSFT in the player's wallet first, while sell-back waits for the reopen. MSFT legs run 24/7 |
| Fee sweeps | Permissionless; keeper cadence 30 minutes |
| Halt scope | New tickets only; settlement, sell-back, and floored withdrawals can never be halted |
| Owner functions on any fund contract | **None** |

## Risk factors

* **The board is negative expected value, and every ticket is expected to
  lose.** Every slider position returns 90% of the stake on average, and the
  5% fee applies on top, so the combined expected return is about 85.5% of
  the amount spent. The edge is printed on the machine, not hidden, but it
  is real. High lines also lose outright most of the time: a 16× line holds
  about once in eighteen flights, and one flight in ten never clears the
  runway at any line. Playing MSFT FLIGHT SIMULATOR is not a way to make
  money, and nothing in this documentation should be read as suggesting it
  is.
* **Market risk on MSFT.** Winnings arrive as tokenized Microsoft stock, and
  a USDG ticket becomes MSFT at placement. The stock's price moves,
  including while a sell-back waits for the market to reopen, and a queued
  weekend sale executes at the reopen price.
* **Market hours.** Boarding always works, but off-hours a USDG ticket
  routes through an in-wallet MSFT purchase that pays a wider spread, and
  cashing out from MSFT to USDG is unavailable on weekends and whenever the
  price feed is stale. A player holding MSFT through a weekend carries the
  gap risk of the stock.
* **The bankroll is operational.** The house fund is Manager capital,
  withdrawable at will down to the floors. Reserved payouts on placed
  tickets are always protected, but maximum ticket sizes rise and fall with
  the bankroll and are not a commitment.
* **Liveness.** Settlement requires someone to relay the beacon and call
  settle. Both are permissionless and the bettor can do both personally; the
  two-hour bettor-exclusive void with a full refund is the backstop for a
  beacon outage. The operator cannot choose an outcome, but it can be slow.
* **Sequencer trust.** The round-naming delay assumes the chain's sequencer
  reports honest timestamps within the measured skew margin, with
  fail-closed checks behind it. This is disclosed above rather than
  mitigated.
* **Tokenization risk.** MSFT is a tokenized stock and carries the issuer
  and redemption mechanics of its tokenization, which are not the fund's to
  control.
* **Smart-contract risk.** The desk is a new contract, in addition to the
  Rialto, Chainlink, and drand infrastructure it composes with.

Full fund mechanics are in [The Fund (Mechanism)](/mechanism); the Sleeve
that receives half of every fee is described under
[Real World Bonds](/rwa-desk); the complete risk section is
[Risk Factors](/risks). Nothing here is investment advice.
