ROBINHOOD CHAIN / 69836193ANYONE CAN RUN MONEY.
EVERYONE CAN READ THE RECORD.
- TOTAL BACKED
- $0
- FUNDS CREATED
- 02
- FILLS ON RECORD
- 00
- LISTED STOCKS
- 08
The first trade starts the record.
Latest block
THE TERMS OF YOUR FUND
WRITTEN INTO THE CONTRACT
Fees can only go down. Lockups can only get shorter. The asset list can only narrow.
YOUR SHARE
Withdraw your slice of every holding once your lockup ends.
ON THE FLOOR / LIVE RECORD
YOUR NEXT MANAGER STARTS HERE ↓Opening Bell
0xDa6b…2ac6+0.00%SINCE OPENING$0BACKED
Opening Bell
0xDa6b…2ac6Every trade this fund makes goes on the record.
- PERFORMANCE FEE
- 20%
- ANNUAL FEE
- 0%
- LOCKUP
- None
- HOLDINGS
- No holdings yet
0x9c01D5CC040fC704Adf68CD882fc38C3F6D0bCd5
- HELD BY
- Fund contract 0x9c01…bCd5 ↗
- MANAGER
- Trades the fund’s approved assets within its rules.
- YOU
- Withdraw your share of each asset after lockup.
Reading what you hold…
Your USDG goes to this fund’s contract. The manager cannot spend the rest of your wallet. Withdrawals return USDG and any stock tokens held, after lockup.
Highwater
0xDa6b…2ac6+0.00%SINCE OPENING$0BACKED
Highwater
0xDa6b…2ac6Every trade this fund makes goes on the record.
- PERFORMANCE FEE
- 20%
- ANNUAL FEE
- 0%
- LOCKUP
- None
- HOLDINGS
- No holdings yet
0x4D463aE3884810d011039CB5F6c68ed13a0116d0
- HELD BY
- Fund contract 0x4D46…16d0 ↗
- MANAGER
- Trades the fund’s approved assets within its rules.
- YOU
- Withdraw your share of each asset after lockup.
Reading what you hold…
Your USDG goes to this fund’s contract. The manager cannot spend the rest of your wallet. Withdrawals return USDG and any stock tokens held, after lockup.
WHAT A FUND MAY HOLD
08 STOCKS + USDGYOUR FUND. YOUR CALL.
Name the fund. Set the terms.
Put your strategy on the record.
01Open a fund
Name it. Set the terms. Make it yours.
Open a fund
Name it. Set the terms. Make it yours.
Open a fund
One transaction and it exists. No licence to hold, no minimum to bring, nobody to ask. Everything below is yours to set now and printed on the fund's page forever. Afterwards you can only ever move them in your backers' favour.
Name it
Free text, written into the contract at the moment it is created. This is the name people read on the board.
The cut you keep
You are paid this share of the profit, and only above the price each depositor came in at. Somebody who backs you at the top pays you nothing until the fund passes that point again, and nobody pays you while the fund is down.
The yearly fee
Taken whether the fund wins or loses, as a slice of the whole fund per year. It is paid by minting you shares rather than by moving money out, so you are still only ever paid as a share holder. Leave it at zero and your record says you are paid for being right and nothing else.
Your own money in it
You cannot trade until your own shares are worth at least this much of the fund. Without that floor the best move for a manager is to gamble with other people's money and keep a cut of whatever survives.
How money comes and goes
A lockup buys you the room to run a slow strategy without being sold out of it. A minimum keeps the share register small. A cap is you saying out loud that your strategy stops working above a size, which is the rarest and most credible thing a manager can say. All three can be left empty.
What you may buy
Narrow it and the contract will refuse anything else for the life of the fund. You can give one up later, never take one back.
Connect a wallet and this becomes one transaction.
What you will be able to do, and what you will not
Money only leaves to its owner
There is no path in the contract that sends money anywhere except back to a depositor taking out their own shares. Your fees are shares, so you leave the same way they do.
You name a token, never a call
A trade names the token to sell and the token to buy. You never hand the fund a call to make, so the fund cannot be made to call a contract you wrote.
Terms only ever ease
You can lower either fee, shorten the lockup, give up an asset and close to new money. There is no function that raises a fee or lengthens a lockup on somebody already in.
02Manage your funds
Place trades, update terms, and write your thesis.
Manage your funds
Place trades, update terms, and write your thesis.
Reading the manager’s desk…
WE TRIED
TO BREAK
THE RULES.
Five attempts the contract refuses.
One ordinary trade it lets through.
01Withdraw someone else’s moneyREFUSED+
There is no door. The only path that moves value out of a fund is withdraw, and withdraw pays the caller a proportional slice of the shares the caller holds. The manager holds none of the depositor's, so the call dies on NoShares and their balance at the end of it is still zero.
02Buy an unlisted tokenREFUSED+
Both sides of every trade have to be on a list fixed when the fund was built. The fresh token is not on that list, so the trade is refused with NotAllowed before any money moves. This is also why a fund here can only hold stock: the moment any token can be bought, any token can be used to steal, and no guard can tell the two apart.
03Call an outside contractREFUSED+
The test knocks on the five doors an escape hatch usually hides behind: execute, call, multicall, sweep, rescue. None of them are there. No function anywhere in the fund takes a target address or calldata, so this attempt cannot even be written down.
04Trade without permissionREFUSED+
The depositor, whose money it actually is, tries to move it herself. NotManager. Permission to trade and ownership of the money are two separate things in this contract, and neither one can reach across into the other.
05Accept an off-market fillREFUSED+
This is how trading vaults are really drained. The manager sets the slippage limit to zero, accepts a dreadful price, and collects the difference as the other side of the trade. A fund that only honours the manager's own promise waves this through, so this one measures the price the trade actually got and checks it against Chainlink afterwards. The fill was refused, and the fund is holding no NVDA at the end of it.
06Trade, then withdraw your sharePASSED+
The five refusals are worth nothing if the fund no longer works. So the last one is the ordinary day: money in, NVDA bought at the real pool price, and the investor withdrawing her exact proportional slice of what the fund is holding.
Contract tests are not a guarantee against loss.
Markets and smart contracts carry risk.
01How a fund works
Shares, fees, and the rules behind every trade.
How a fund works
Shares, fees, and the rules behind every trade.
How a fund works
Somebody who is good at picking stocks opens a fund in one transaction. Anyone can put money in. When the manager buys NVDA, every backer's share buys NVDA in the same proportion. The manager takes a cut of the profit and can never take the money itself.
Everything on this page is a description of code you can read, not a promise this site is making. Where a sentence says the contract refuses something, there is a test that tried it. Those are on the Security page.
Why it can exist here
To let a person manage your money in the old world you have to hand it over. That handover is what pulls in the licence, the custodian, the minimum, the paperwork and the regulator. Every rule in asset management is downstream of somebody else holding your money.
With a wallet nothing is handed over. The money sits in a contract you can exit in one transaction, and the manager can only point at a trade. They never hold it.
The second half is the asset. Copy-trading vaults elsewhere follow a perpetual future, which is a bet, or a basket of DeFi tokens. Here it is NVDA. This format has not been pointed at real equities before, because until Robinhood Chain there were no real equities to point it at.
The three walls
The manager gets exactly enough power to be a fund manager and not one bit more. Each wall exists because removing it is a way to steal.
1. Money only leaves to its owner
test_Attack_ManagerCannotWithdrawwithdraw pays the caller a proportional slice of every holding the fund has. There is no other function that moves value out, and no argument anywhere that names who to pay. Both fees are paid in shares, so the manager leaves the same way a backer does.
2. The manager names a token, never a call
test_Attack_NoArbitraryCallPathA trade names the token to sell and the token to buy. No function takes a target address or calldata, so the fund cannot be made to call a contract the manager wrote.
3. Both sides on the list, and the fill is checked afterwards
test_Attack_ZeroSlippageSelfSandwichA slippage limit alone is not enough. A manager can set it to zero and collect the difference as the other side of their own trade, which is how trading vaults are usually drained. So the check is on the price the trade actually got, compared against Chainlink after the swap, not on the minimum the caller promised.
Wall 3 is also why this is stocks only. The moment any token can be bought, any token can be used to steal, and no guard can tell the difference between a real one and one the manager minted this morning.
The terms a manager sets
A fund is opened with its terms written into it. They are printed on its page and read from the fund itself. What matters is not how many there are, it is which of them can move afterwards and in which direction.
| Term | Set at | Afterwards |
|---|---|---|
| Cut of the profit | Opening, at most 30% | may only be lowered |
| Yearly fee | Opening, at most 2% | may only be lowered |
| Lockup | Opening | may only be shortened |
| Manager's own money in it | Opening | fixed |
| Smallest deposit, fund cap | Opening | fixed |
| Which assets it may buy | Opening | may only be narrowed |
| Open to new money | Opening | may be closed once, never reopened |
| Price band, feed staleness | The same for every fund | never |
There is deliberately no function that raises a fee, lengthens a lockup, widens the asset list or reopens a closed fund. A term that can be raised on somebody already inside is not a term, it is a trap.
How the manager is paid
Two ways, both capped, both paid in shares rather than in money.
- A cut of the profit, at most 30%, charged only above the share price each backer came in at. Somebody who backs a manager at the top pays nothing until the fund passes that point again, and nobody pays while the fund is down. The mark is held per backer, so a late arrival never pays a fee on profit earned before they got there.
- A yearly fee, at most 2%, charged whether the fund wins or loses. This is capped ten times harder than the profit cut because it is charged for showing up rather than for being right. Above that a fund can lose money every year and still pay its manager well, and the record stops meaning anything.
- The manager must hold shares in their own fund before the contract will let them trade it. Without that floor the best strategy is to gamble with other people's money and keep a cut of whatever survives.
Paying in shares is what keeps the first wall standing. The manager's slice grows and everyone else's shrinks, but nothing is transferred to anybody who is not a share holder.
The days a fund cannot be priced
Stock feeds run 24 hours a day, five days a week, and pause outright while a corporate action is processed. The pools never stop. So for most of any given week there is no honest price for a fund holding stock. The contract splits that in two.
- Deposits refuse. Issuing shares needs a price, and guessing one hands the difference to whoever deposits at the right moment.
- Exits always work. You are paid a proportional slice of each holding, which needs no price at all. The only thing that needs one is the fee, so when the fund cannot be priced you still leave with your exact slice and the manager is simply not paid.
Whether a given fund can be priced this second is on the Status page.
What a fund can hold
Only assets with both a real Chainlink feed and a real pool on this chain: NVDA, SPCX, TSLA, MU, AMZN, MSFT, GOOGL and AAPL, with USDG as the quote. That is fewer than it sounds. It is about the number of positions a real retail fund carries. The list was fixed when the factory was built and cannot be added to, which is what stops a manager buying a token they minted themselves.
A manager may narrow it further at opening, and give one up later. Giving one up stops the fund buying it again for good and still allows selling, so nothing already held is trapped.
02Security
What the contract enforces, and how it is tested.
Security
What the contract enforces, and how it is tested.
What we tried to steal
Five ways to take money out of a fund you manage, each written as a test that actually runs against a fork of Robinhood Chain mainnet, using the real NVDA pool and the real Chainlink feed. All five are refused. The names below are the tests: they are in the repository and they run in about twelve seconds.
This is not an audit. It is the set of attacks we could think of, run against real liquidity rather than a mock. An attack nobody thought of is not on this page.
The attacks
The manager calls withdraw on money that is not theirs
test_Attack_ManagerCannotWithdrawRefused. There is no path that pays anyone but a share holder, in proportion to their shares.
The manager mints a token, then makes the fund buy it with everything
test_Attack_BuyOwnWorthlessTokenRefused. Both sides of a trade must be on the list the factory was deployed with, and that list cannot be added to.
The manager hands the fund a contract to call
test_Attack_NoArbitraryCallPathRefused. No function takes a target or calldata, so the argument does not exist to pass.
Somebody who is not the manager places a trade
test_Attack_OutsiderCannotTradeRefused.
The manager promises no minimum and takes a deliberately terrible fill, collecting the difference on the other side
test_Attack_ZeroSlippageSelfSandwichRefused on the price the trade actually got. This is the one a slippage limit alone cannot stop, because the manager sets the limit.
An ordinary trade, then a backer leaves
test_HonestTradeAndExitPassed. 10,000 USDG in, 5,000 traded into 23.355 NVDA, fund worth 9,997.05 afterwards. A cost of 0.03%.
The rules, one question each
| Question | Answer | Test |
|---|---|---|
| Can a manager take any cut of the profit they like? | No. The factory refuses anything above 30%. | test_FactoryRefusesAGreedyFee |
| Can they charge any yearly fee they like? | No. Capped at 2%. | test_FactoryRefusesAGreedyAnnualFee |
| Can they trade before putting their own money in? | No. | test_ManagerMustBeInvested |
| Are they paid while the fund is down? | No. | test_NoFeeOnALoss |
| Does a late backer pay a fee on profit earned before they arrived? | No. The high-water mark is held per backer. | test_LateDepositorPaysNoFeeOnSomebodyElsesProfit |
| Can somebody leave while the feed is frozen? | Yes, in kind, and the manager is not paid. | test_ExitWorksWhileTheFeedIsFrozen |
| Can a manager raise a fee after you are in? | No. There is no function that raises one. | test_TermsOnlyEverEase |
| Does shortening a lockup free people already in it? | Yes. It is measured from each deposit rather than stamped as a deadline. | test_ShorteningTheLockupReleasesPeopleAlreadyIn |
| Can giving up an asset trap what the fund already holds of it? | No. A retired asset can still be sold. | test_RetiringAnAssetStopsBuyingAndStillAllowsSelling |
| Does taking the performance fee create new shares? | No, and it used to. See below. | test_TakingTheFeeMintsNothing |
A bug this found
The performance fee was being minted rather than moved. The fee is supposed to come out of the shares a leaving backer is redeeming and be handed to the manager. The helper that credited the manager also increased the total share count, so every fee taken created a second copy of itself and quietly diluted everybody who stayed.
It was invisible in ordinary use and invisible to every test that only checked the manager got paid. What caught it was the fork test asserting that after the last backer leaves, the only shares still in existence are the ones the manager earned.
// before: this bumped the supply, whether shares were being
// created or only changing hands
function _credit(address who, uint256 shares, uint256 price) private {
...
totalShares += shares;
}
// after: the callers say which it is
_credit(msg.sender, shares, price);
totalShares += shares; // a deposit creates shares
_credit(manager, feeShares, price); // the fee only changes handsPinned by test_TakingTheFeeMintsNothing, which checks the arithmetic directly rather than waiting for a fork to disagree.
What is not covered
- No third-party audit. Nobody outside this project has reviewed the contract.
- The venue is trusted. A fund routes through one Uniswap V3 router and reads Chainlink. If a feed reports a wrong price confidently, the fund believes it.
- The manager can still be bad at their job. None of this stops somebody losing your money honestly, which is the ordinary way money is lost.
The Risk page is the longer version of this list.
03Risk
Understand the limits before backing a fund.
Risk
Understand the limits before backing a fund.
What can still go wrong
The contract stops a manager taking your money. It does not stop you losing it. Those are different sentences and the rest of this page is the difference.
If you only read one line: the most likely way you lose money here is that the manager you picked is wrong about a stock, and nothing on this site protects you from that.
Losing money the ordinary way
- The manager is bad at it. A public record makes that visible afterwards. It does not make it less likely.
- A short record proves nothing. A manager up 40% over two weeks is mostly telling you the market went up. There is no length of record this site can enforce.
- Concentration. A fund is allowed to hold one stock with everything. Its holdings are on its page; a fund holding one thing is a bet on one thing.
- The fee is real money. A yearly fee is charged whether the fund wins or loses. Over several flat years it is the whole of your loss.
Things about this system in particular
- Deposits are shut most of the week. Stock feeds run five days a week and pause during corporate actions. Issuing shares needs a price, so a deposit refuses when there is not one. Exits always work.
- A lockup means what it says. If a fund has one, you cannot leave inside it, including on the day you decide the manager is wrong. It is printed on the fund's page before you deposit and it can only ever be shortened.
- Every fill costs something. A trade pays pool fees and moves the price against itself. Measured on a real pool an honest round trip cost 0.03%. A manager who trades constantly pays that constantly, out of your money.
- You are paid out in kind. Leaving gives you a proportional slice of whatever the fund is holding, which may be stock rather than cash. Selling it is your problem and your cost.
Things that could break underneath
- The contract is not audited. Five attacks were written and refused, and they are named on the Security page. An attack nobody thought of is not on that page.
- Chainlink is trusted completely. Every price check, every valuation and every fee depends on a feed. A feed reporting a wrong price confidently would be believed.
- One venue. A fund routes through a single Uniswap V3 router. If that router is compromised or the pool is empty, trades fail or fill badly.
- The chain is young. Robinhood Chain is new. Its liquidity is thin next to the venues these stocks normally trade on, and thin liquidity is what makes a fill bad.
Things outside the code entirely
- Managing other people's money without a licence is a real regulatory shadow, even where nothing is ever custodied and the manager cannot touch the money. Nobody has tested where that line sits for a contract like this one.
- Tokenised stock is not stock. What a fund holds is a token that tracks a share. What that entitles you to, and from whom, is set by whoever issues it, not by this contract.
- This site can go away. The funds do not. Every number here is read from the chain and every fund can be withdrawn from by calling it directly.
04Chain status
Contracts, prices, and the latest block.
Chain status
Contracts, prices, and the latest block.
Reading chain status…
05Privacy
What this site reads and stores.
Privacy
What this site reads and stores.
Privacy
What this software does with a request. Read what it is not before you read the rest.
This is not a legal privacy policy. It does not name a data controller, give a contact address or state a governing law. It describes the behaviour of the code, which you can check.
What it does not do
None of the following appears in this application's source or its dependencies.
- No analytics and no telemetry. There is no analytics package, no product-metrics SDK, no session recorder and no error reporter.
- No cookies. Nothing is written to your browser to identify you across visits. There is no consent banner because there is nothing to consent to.
- No account. There is no sign-up, no email field and no password anywhere in this application. Connecting a wallet is not an account: it is your browser telling the page an address it already knows.
- No third-party embeds. No pixels, no ad tags, no social widgets, no chat bubble. The only asset loaded from outside this origin is a font.
What it does do
- It reads the chain. Every number on this site is read from Robinhood Chain over an ordinary RPC call. Those calls carry no identity of yours, only which contract is being read.
- It asks your wallet to sign. Depositing, trading and opening a fund each build a transaction and hand it to your wallet. This site never sees a private key and never holds funds.
- Its host keeps ordinary server logs. Whoever serves these pages sees the request: an IP address, a page path, a time. That is true of every website and is not something this application controls or reads.
What is public whether we like it or not
Everything a fund does is on a public chain, and that is the point of the product rather than an accident of it.
- Your deposit, your withdrawal and the size of your position are visible to anybody.
- The address that opened a fund is its manager, permanently and in public.
- A profile handle or a line of text a manager writes is written into a contract. It cannot be deleted afterwards, by them or by us.
If you would rather your position was not tied to an address people already know, use a different one. That is the only privacy control that actually works here, and it is not one this site can give you.




