contents07 Contracts
07, fairness & security
Contracts
A map of every RHR contract, what each can and cannot do, and who holds which key, with addresses published after deployment.
on this page
Every dollar RHR looks after for you lives in smart contracts on Robinhood Chain. Below is the full list, what each contract is allowed to do, and which keys can instruct them.
Networks
- Robinhood Chain testnet, chain ID 46630. Deployed first. Tokens here have no monetary value.
- Robinhood Chain mainnet, chain ID 4663. Real money.
Gas on both is paid in ETH.
The contracts
| Contract | What it does | Address |
|---|---|---|
Vault (RHRVault) | Holds every deposit. Accepts signed settlement checkpoints, pays signed withdrawals, and runs the escape hatch | Published after deployment |
Staking (RHRStaking) | Holds locked $RHR and the USDG that streams to stakers. Rewards are pulled in before they are announced | Published after deployment |
Jackpot (RHRJackpot) | Pays daily jackpot winners against signed vouchers. Has its own bankroll and cannot touch the vault | Published after deployment |
Fee splitter (RHRFeeSplitter) | Splits creator fees and hood mint proceeds: 30% jackpot, 20% stakers, 20% tournaments, 20% house, 10% buyback | Published after deployment |
Rake router (RHRRakeRouter) | The vault's only rake destination. Splits net rake: 12% stakers, 10% jackpot, the rest to the house | Published after deployment |
Buyback (RHRBuyback) | Buys $RHR with the buyback share and burns it, within spend caps | Published after deployment |
Hoods (RHRHoods) and renderer (RHRHoodRenderer) | The ERC-721 hood collection and the contract that draws each hood as an on-chain SVG | Published after deployment |
| $RHR token | The token itself. It is not launched yet | Published after launch |
| USDG | The money that moves through all of the above. Issued by Global Dollar, not by RHR | See the next section |
Deployed addresses
Read from the deploy scripts’ output for each network when this site was built. This site points at Robinhood Chain Testnet.
Robinhood Chain Testnet
chain id 46630
this sitenot deployed yetAddresses appear here after deployment. Until then, do not trust an RHR address from anywhere else.
Robinhood Chain
chain id 4663
not deployed yetAddresses appear here after deployment. Until then, do not trust an RHR address from anywhere else.
Mainnet comes after the testnet, an audit and legal review. The contracts are unaudited until then.
USDG, the one address that already exists
USDG ("Global Dollar") has 6 decimals. Its Robinhood Chain mainnet address is:
0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168This address belongs to the token's issuer, not to RHR. Check it on the explorer yourself. The issuer can freeze addresses or pause the token, and nothing in the contracts below can undo that.
Keys and roles
Only a few keys can send instructions to the contracts, and the contracts, not RHR, set the limits on each.
| Role | Held by | Can | Cannot |
|---|---|---|---|
| Settler | The game server | Sign settlement checkpoints and withdrawal vouchers | Mint value, overdraw the vault, or exceed the per-checkpoint limits |
| Owner | A multisig Safe in production | Replace the settler after a 48-hour timelock, and tune bounded parameters | Move player balances, or block the escape hatch |
| Guardian | A separate key | Pause settlement and withdrawal vouchers, and cancel queued large withdrawals | Move or take funds, or block the escape hatch |
| Jackpot signer | The game server | Sign jackpot vouchers, one claim per day | Touch the vault or any player balance |
| Keeper | An automated key | Trigger the daily buyback within spend caps | Pick a destination, or spend beyond the caps |
| Treasury | The house wallets | Receive the house share | Touch player balances |
Every role is stored in the contracts, so you can read who holds it from a block explorer once the contracts are deployed.
What the vault checks on every checkpoint
In short: the next number in sequence, a signature from the current settler, matching and capped lists, changes plus rake that net to zero, no negative balances, bounded rake and bounded total movement, and a vault that still holds at least what it owes. Custody and your money goes through each check and then explains what the checks cannot see.
Fixed by design
- No upgradeable proxies. A deployed RHR contract's code does not change.
- Immutable splits. The fee splitter and the rake router shares are set at deployment, in basis points that must sum to 10,000. Anyone can trigger them.
- Signatures use EIP-712 with the domain name "RHR" and version "1".
- Escape hatch. A 24-hour delay, then 3 days to execute before the request expires. It pays the lowest balance since the request, never more than the balance. It works while the vault is paused and with no settler.
- Settler rotation. Behind a 48-hour timelock, longer than the escape hatch, so players can leave before a new settler can sign. The owner must accept it within 7 days after that, or the proposal expires.
- Withdrawal queue. Large withdrawals wait for a delay and can be cancelled by the guardian. The instant limits and the delay are set in the contract.
- Staking. Claims and withdrawals can never be paused. The owner cannot withdraw stake or reward tokens, and ownership cannot be renounced to the zero address.
Before you trust an address
- Compare it with the address on this page, which only appears after deployment, and check this page is on the real site.
- On the explorer, look for verified source code. A contract without verified source is a red flag.
- Never send funds to an address because a message, a DM or an ad told you to.
What lives outside the contracts
- The game server. It runs the games and holds the settler key. See Custody and your money.
- The USDG issuer. It can freeze addresses or pause the token.
- The chain. Robinhood Chain itself is outside RHR's control.
- The website. The escape hatch works without it, because it is a function on the vault.
About "unaudited"
These contracts have not been reviewed by an independent security firm. They are tested with unit tests, fuzz tests and invariant tests, but tests are not an audit. A bug could lose funds, possibly all of them. Treat everything on this page as unaudited until an audit says otherwise.