Franklin OnChain U.S. Government Money Fund (FOBXX), BENJI token
Ethereum: can freeze a holder, pause transfers, claw back, gate who may hold, mint, change the code. A contract can freeze a holder. Role token owner key: a single key.
Polygon: can freeze a holder, pause transfers, claw back, gate who may hold, mint, change the code. ModuleRegistry owner key: a single key.
Arbitrum: can freeze a holder, pause transfers, claw back, gate who may hold, mint, change the code. ModuleRegistry owner key: a contract.
Avalanche: can freeze a holder, pause transfers, claw back, gate who may hold, mint, change the code. Role token owner key: a single key.
Base: can pause transfers, claw back, mint, change the code (allowlist, freeze unverified). Role token owner key: a single key.
Solana: can freeze a holder, claw back, gate who may hold, mint, change the code. An account only a program can sign for can freeze a holder and claw back tokens. A single key can change the code with no delay.
This file replaced an earlier record on 2026-09-24. Superseded to record the Avalanche contract’s freeze and allowlist powers, which the file had marked unverified because the explorer did not answer. The reader now reads them from the verified source: the Avalanche BENJI contract can freeze a holder and limit holders to a list, as on the other chains. Superseded records.
Research and shelf status are on the memo: Franklin OnChain U.S. Government Money Fund (FOBXX), BENJI token Favorable research; shelf not set
Who may buy, hold, transfer, and redeem
Each answer rests on the issuer’s own words, quoted from the document named under it. Ketju re-reads each document and records whether the words are still there. Where the documents say nothing, the row says so.
- What the holder owns
A share of a registered money market fund. Franklin calls each share a BENJI token.
“Fund shares, or BENJI tokens, are offered without a sales charge.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Prospectus, Your Account, ”Buying Shares” · words found 2026-09-23
- Who may hold it
U.S. residents where the fund may be sold in their state. With very limited exceptions it is not offered elsewhere.
“The Fund and other Franklin Templeton funds are intended for sale to residents of the United States, and, with very limited exceptions, are not registered or otherwise offered for sale in other jurisdictions.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Prospectus, Your Account, ”Buying Shares”, after the network minimums · words found 2026-09-23
- First purchase minimum
$20 for most accounts, which means Stellar; each other chain has a higher first-purchase minimum, up to $5,000,000 on Ethereum.
“The minimum initial purchase for most accounts is $20, although you may be subject to a higher investment minimum.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Fund summary, ”Purchase and Sale of Fund Shares” · words found 2026-09-23
- Account types
Individuals through the app and institutions through the portal. No IRAs, Roth IRAs, or employer retirement plans.
“The Fund does not permit investments by employer sponsored retirement plans, SIMPLE-IRAs, SEP-IRAs, SARSEPs or 403(b) plan accounts, IRAs, IRA Rollovers, Coverdale Education Savings Plans or Roth IRAs.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Prospectus, Your Account, ”Buying Shares” · words found 2026-09-23
- Who it may be transferred to
Holder to holder, at any hour, but only between wallets the transfer agent has whitelisted.
“Before transferring Fund shares, you (as the transferor) and the potential transferee must each have an active, permissioned (i.e., “whitelisted”) wallet registered with the Fund’s transfer agent on any approved blockchain network.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Prospectus, Your Account, ”Peer-to-Peer Transfer of Shares” · words found 2026-09-23
- How a holder redeems
Through the app or portal only, for dollars to a linked bank account, within seven days; ACH generally arrives in two to three business days.
“Redemption proceeds will be sent by electronic funds transfer (ACH or Fed Wire) from your App or Institutional Web Portal account to your bank account within seven days after we receive your request in proper form.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Prospectus, Your Account, ”Selling Shares” · words found 2026-09-23
- Who keeps the official record
Franklin Templeton Investor Services, the transfer agent, keeps the official record in a system that joins its own database to the chains.
“The Fund’s transfer agent maintains the official record of share ownership via a proprietary blockchain-integrated system that utilizes features of traditional book-entry form and one or more public blockchain networks.”
SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · Fund summary, ”Use of Blockchain” · words found 2026-09-23
- What the issuer says it can freeze or take back
The transfer agent holds separate administrative keys that can correct, freeze, move, or restore any holder’s record, whoever holds the wallet key.
“The Administrative Controls permit FTIS to maintain, correct, freeze, migrate, or restore the official record of share ownership in the Integrated System.”
SEC Division of Investment Management, staff no-action letter to Franklin Templeton (Aug. 12, 2026) · SEC staff response, Background · words found 2026-09-23
| Fact | What the file records |
|---|---|
| Who onboards the holder | issuer |
| Voting rights | Yes |
| Distributions | new tokens |
| SIPC coverage of the wallet | No |
The transfer agent’s SEC record
A transfer agent registers with the SEC on Form TA-1 and reports each year on Form TA-2: how many securityholder accounts it keeps and for how many issues it keeps the master securityholder file, the list that says who owns each share.
| Agent | SEC file | TA-2 period | Accounts | Issues with master file | Work it hires out |
|---|---|---|---|---|---|
| FRANKLIN TEMPLETON INVESTOR SERVICES LLC /TA | 084-01036 | 2025-12-31 | 1,218 | 1 | FIS Investor Services LLC |
Who can change the record
Powers read from the deployed contracts and their verified source: the token and every contract it consults on transfer. A power recorded here is the issuer’s ability, not evidence it has been used.
| Chain | Freeze a holder | Pause | Claw back | Gate holders | Change the code | Keys held by |
|---|---|---|---|---|---|---|
| Stellar | Yes | No | Yes | Yes | Yes | A multisig can freeze a holder and claw back tokens. |
| Ethereum | Yes | Yes | Yes | Yes | Yes | A contract can freeze a holder. Role token owner key: a single key. |
| Polygon | Yes | Yes | Yes | Yes | Yes | ModuleRegistry owner key: a single key. |
| Arbitrum | Yes | Yes | Yes | Yes | Yes | ModuleRegistry owner key: a contract. |
| Avalanche | Yes | Yes | Yes | Yes | Yes | Role token owner key: a single key. |
| Base | Unverified | Yes | Yes | Unverified | Yes | Role token owner key: a single key. |
| Solana | Yes | No | Yes | Yes | Yes | An account only a program can sign for can freeze a holder and claw back tokens. A single key can change the code with no delay. |
Who holds the keys
Every current holder of each power, read from the chain on 2026-09-24. A single key is one private key: whoever holds it acts alone. A multisig needs the stated number of signers. A timelock makes every action wait, so holders can see it coming.
| Chain | Key | What it can do | Held by | Address |
|---|---|---|---|---|
| Stellar | Issuer account | mint new tokens, freeze a holder, claw back tokens, decide who may hold | a multisig | GBHNGL…ZIW5 |
| Ethereum | ModuleRegistry owner | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Admin role | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role token owner | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role token owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Ethereum | Role token owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Ethereum | Role token owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Ethereum | Role authorization admin | decide who may hold, freeze a holder | a contract | 0xa2bd…8b66 |
| Ethereum | Admin role | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Ethereum | Admin role | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Ethereum | Admin role | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a contract | 0x48a6…c1fc |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Ethereum | Role module owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Polygon | ModuleRegistry owner | grant and revoke these powers | a single key | 0x8eed…00ba |
| Polygon | Admin role | grant and revoke these powers | a single key | 0x8eed…00ba |
| Polygon | Role token owner | grant and revoke these powers | a single key | 0x8eed…00ba |
| Polygon | Role token owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Polygon | Role token owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Polygon | Role token owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Polygon | Role token owner | grant and revoke these powers | a single key | 0xc69c…de8a |
| Polygon | Admin role | grant and revoke these powers | a single key | 0x8eed…00ba |
| Polygon | Role module owner | grant and revoke these powers | a single key | 0x8eed…00ba |
| Polygon | Role module owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Polygon | Role module owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Polygon | Role module owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Polygon | Role module owner | grant and revoke these powers | a single key | 0xc69c…de8a |
| Arbitrum | ModuleRegistry owner | grant and revoke these powers | a contract | 0xc5d3…30b6 |
| Avalanche | ModuleRegistry owner | grant and revoke these powers | a contract | 0xe4b2…7af4 |
| Avalanche | Admin role | grant and revoke these powers | a contract | 0xe4b2…7af4 |
| Avalanche | Role token owner | grant and revoke these powers | a contract | 0xe4b2…7af4 |
| Avalanche | Role token owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Avalanche | Role token owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Avalanche | Role token owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Avalanche | Admin role | grant and revoke these powers | a contract | 0xe4b2…7af4 |
| Avalanche | Role module owner | grant and revoke these powers | a contract | 0xe4b2…7af4 |
| Avalanche | Role module owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Avalanche | Role module owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Avalanche | Role module owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Base | ModuleRegistry owner | grant and revoke these powers | a contract | 0xa490…e898 |
| Base | Admin role | grant and revoke these powers | a contract | 0xa490…e898 |
| Base | Role token owner | grant and revoke these powers | a contract | 0xa490…e898 |
| Base | Role token owner | grant and revoke these powers | a single key | 0x42cc…a2d6 |
| Base | Role token owner | grant and revoke these powers | a single key | 0x64d4…23e6 |
| Base | Role token owner | grant and revoke these powers | a single key | 0xb671…b24f |
| Solana | Mint authority | mint new tokens | an account only a program can sign for | 5Tu84f…FxA1 |
| Solana | Freeze authority | freeze a holder | an account only a program can sign for | 5Tu84f…FxA1 |
| Solana | Permanent delegate | claw back tokens | an account only a program can sign for | 5Tu84f…FxA1 |
| Solana | Transfer-hook authority | decide who may hold, change the code | an account only a program can sign for | 5Tu84f…FxA1 |
| Solana | Hook program upgrade authority | change the code | a single key | AJyEpT…sXeJ |
Role holders on Arbitrum could not be read from the public event indexes on the last reading; the table shows only what was confirmed.
Stellar: 4 contract reads at block 64577934, 0 functions in verified source, 2026-09-23
- auth_required=true
- auth_revocable=true
- auth_immutable=false
- auth_clawback_enabled=true
Ethereum: 6 contract reads at block 26040958, 6 functions in verified source, 2026-09-23
- eip1967.implementation=0x20ca56f1215c3376b25bba1f2f9d3701c5def4c5
- moduleRegistry=0xd7644d80575678c027ced844bbeef5ad12277d40
- getModuleAddress(MODULE_AUTHORIZATION)=0x55dd370dede1ad474d3543be06452615d3b5b162
- getModuleAddress(MODULE_TRANSACTIONAL)=0x648a6e41b4e445506b848ce49ffef827651ab4f5
- getModuleAddress(MODULE_INTENT_VALIDATION)=0xba5314385d4a849f8d8dbfb867b67547683f8a93
- getModuleAddress(MODULE_TRANSFER_AGENT)=0x8c8bfc3151c2161a4bad77268e246a08e5d9c666
- authorizeAccount in verified source 0x555e…e850
- freezeAccount in verified source 0x555e…e850
- disableERC20Transfer in verified source 0x20ca…f4c5
- burnShares in verified source 0x20ca…f4c5
- mintShares in verified source 0x20ca…f4c5
- upgradeTo in verified source 0x20ca…f4c5
Polygon: 4 contract reads at block 94313731, 6 functions in verified source, 2026-09-23
- eip1967.implementation=0xc1df95cf7f96f020f511f2f03fbf6cc18f8464b2
- moduleRegistry=0xc8cfac89e292a6486775fb86f789612bcc692c7d
- getModuleAddress(MODULE_AUTHORIZATION)=0x026d556acce6e9599ca6d85cd034f663f0ffe2bd
- getModuleAddress(MODULE_TRANSACTIONAL)=0x9119ead895210d841cb4f556248a3cc054294fb0
- authorizeAccount in verified source 0xc8ec…75df
- freezeAccount in verified source 0xc8ec…75df
- disableERC20Transfer in verified source 0xc1df…64b2
- burnShares in verified source 0xc1df…64b2
- mintShares in verified source 0xc1df…64b2
- upgradeTo in verified source 0xc1df…64b2
Arbitrum: 4 contract reads at block 508157429, 6 functions in verified source, 2026-09-23
- eip1967.implementation=0x956a399818c7cbabbd0b868a60f61ec9027136cd
- moduleRegistry=0xcb788286abca7b681feb056877b62c778f0a37df
- getModuleAddress(MODULE_AUTHORIZATION)=0xb1ef38b2ef8ffcffa70e41afad175e7bae15f517
- getModuleAddress(MODULE_TRANSACTIONAL)=0x9c012931e13f2546d64b75401fdf7eec6b651cbd
- authorizeAccount in verified source 0xb472…b873
- freezeAccount in verified source 0xb472…b873
- disableERC20Transfer in verified source 0x956a…36cd
- burnShares in verified source 0x956a…36cd
- mintShares in verified source 0x956a…36cd
- upgradeTo in verified source 0x956a…36cd
Avalanche: 4 contract reads at block 96028024, 6 functions in verified source, 2026-09-24
- eip1967.implementation=0x5c118e6a0bd2de0af66655806e3001727c13d105
- moduleRegistry=0x5bb59a51e1c469537eeab04af6b44c2e980fba5c
- getModuleAddress(MODULE_AUTHORIZATION)=0xdf67bf51f121297fcad7a65ccc98579b43ac6c56
- getModuleAddress(MODULE_TRANSACTIONAL)=0x9ac1580474da8c725735555036ebac9d486e47f3
- abi:routescan:43114:0x2203f744bd827d8e4b953dab960be7952e6145c1#authorizeAccount
- abi:routescan:43114:0x2203f744bd827d8e4b953dab960be7952e6145c1#freezeAccount
- disableERC20Transfer in verified source 0x5c11…d105
- burnShares in verified source 0x5c11…d105
- mintShares in verified source 0x5c11…d105
- upgradeTo in verified source 0x5c11…d105
Base: 4 contract reads at block 51693294, 4 functions in verified source, 2026-09-23
- eip1967.implementation=0xab12adb95bbbb71007669cde208a0b1f89d1a101
- moduleRegistry=0x59ecee0bb35a5355b0940280ca195cbc49e148be
- getModuleAddress(MODULE_AUTHORIZATION)=0x0a18c08dc0063e0d02a01675d782c119e8922fcf
- getModuleAddress(MODULE_TRANSACTIONAL)=0x5ba6b6701266b17427c120d87dcb8cb82c07f8f1
- disableERC20Transfer in verified source 0xab12…a101
- burnShares in verified source 0xab12…a101
- mintShares in verified source 0xab12…a101
- upgradeTo in verified source 0xab12…a101
Solana: 4 contract reads at block 449737357, 0 functions in verified source, 2026-09-23
- mintAuthority=5Tu84fKBpe9vfXeotjvfvWdWbAjy3hqsExvuHgFqFxA1
- freezeAuthority=5Tu84fKBpe9vfXeotjvfvWdWbAjy3hqsExvuHgFqFxA1
- permanentDelegate=5Tu84fKBpe9vfXeotjvfvWdWbAjy3hqsExvuHgFqFxA1
- transferHook=huk3EPrNreTdUUjVKVkGSGKF1WC4P9BiUKBkn2kFWnP
Where it trades
| Venue | Kind |
|---|---|
| Benji app (individuals) and Benji Institutional web portal | issuer primary |
How it exits
| Path | Cutoff | Settlement | Fee | Settles in |
|---|---|---|---|---|
| Redeem with the fund at NAV by the daily cutoff | 14:00 America/Los_Angeles | Through the Benji app or the institutional portal only, at the next NAV the fund works out (hourly, 8 a.m. to 5 p.m. Eastern); the daily cutoff is 2 p.m. Pacific. Dollars go by ACH or wire to a linked bank within seven days; ACH generally arrives in two to three business days. | 0 bps | USD |
- Any freeze, clawback, pause, whitelist, or upgrade reading changes on a chain in this file, or a BENJI module address or implementation moves
- Franklin publishes a new BENJI contract, adds or drops a chain, or the Aptos token becomes readable
- The Authorization modules on Avalanche and Base are verified, settling whitelist and freeze there
- Stellar issuer signers or thresholds change, or the Solana program upgrade key changes
- A new prospectus or supplement changes who may hold, the minimums, transfer rules, or the redemption cutoff
- The transfer agent changes, or the SEC staff modifies or withdraws its August 12, 2026 position
What the monitor reads daily
Every control function in the table above and the contracts the token consults on transfer; the token’s on-chain supply against yesterday’s; and its market quote against its one-dollar value. Every document quoted above is re-read too, and a quote that leaves its document reopens the file. EDGAR is read for the transfer agent’s registration; a new filing reopens the file. A change opens a review item in the governance queue and reopens the file before any client action.
Sources
- SEC EDGAR: Franklin Templeton Trust Form N-1A post-effective amendment 11 (485BPOS), prospectus and SAI effective August 1, 2026 · primary · accessed 2026-09-23
Supports: claim, who may hold, minimum by chain, account types, transfer, redemption, official record, transfer agent controls, suitability framework, no retirement accounts - SEC Division of Investment Management, staff no-action letter to Franklin Templeton (Aug. 12, 2026) · primary · accessed 2026-09-23
Supports: FTIS master securityholder file, Administrative Controls, freeze and migrate, multi-party computation signers - Franklin Templeton Digital Assets: Benji deployed contract addresses · primary · accessed 2026-09-23
Supports: Stellar issuer, EVM token and module addresses, Solana mint and programs, Aptos token - Franklin Templeton Digital Assets: Benji page (chains and retail availability) · primary · accessed 2026-09-23
Supports: retail on Stellar only, daily yield as new tokens - Stellar Horizon: BENJI asset flags and issuer account signers · primary · accessed 2026-09-23
Supports: auth required, auth revocable, clawback enabled, issuer signers and thresholds - Sourcify: MoneyMarketFund_V5, the BENJI token implementation on Polygon (exact match) · primary · accessed 2026-09-23
Supports: whitelist on transfer, frozen account check, admin burn, transfer switches, UUPS upgrade