How the reserve works
Everything here is enforced by one immutable contract, except the lines marked as a promise. Where a number matters, the contract constant is quoted.
In one paragraph
Greenshoe trades on a launchpad on Robinhood Chain. Every trade pays 3%: the token’s 2% tax and the launchpad’s 1% fee, of which the launchpad keeps 0.3%. The other 2.7% goes to the Reserve contract, set as the token’s fee recipient at launch, which sends 40% of it to the reserve (about 1.08% of every trade) and 60% to the founder. The reserve’s ETH is swapped to USDG in capped hourly clips. When the next mega-IPO’s Stock Token is live on-chain, the founder proposes it as the target; after a 3-day public timelock, anyone can trigger purchases in hourly clips. Holders can burn their tokens at any time for a pro-rata share of everything the reserve holds, minus 2% that stays behind.
Fixed parameters
| Parameter | Value | Why |
|---|---|---|
| Split of collected fees | 40% reserve, 60% founder | FOUNDER_BPS = 6000. The founder share can only be paid to the founder address. |
| Redeem retain | 2% | RETAIN_BPS = 200. Each redemption leaves 2% behind, so it never shrinks the reserve per remaining token, and buy-collect-redeem loops don’t pay. |
| Target timelock | 3 days | TIMELOCK. Holders who disagree with a target can redeem before buying starts. |
| Price bound | about 1% spot check, 1.5% limit | Against a 30-minute average (TWAP_WINDOW = 1800). One transaction cannot set the price the reserve pays. |
| Pool depth | ≥ 30 oracle slots, 30 minutes of price history, clip ≤ ~1% depth | MIN_CARDINALITY, TWAP_WINDOW, DEPTH_BPS. A thin or brand-new pool is refused instead of overpaid. Slots are not minutes: a busy pool fills one per block, so the keeper keeps adding capacity until 30 minutes of history exist. |
| Hourly caps | set at deploy | Large reserves buy gradually instead of moving the pool. |
| Admin keys | none over funds | No upgrade, no pause, no withdraw. The founder can bind the token once and propose targets. Nothing else. |
Contract functions
harvest()claims fees from the launchpad escrow, splits new ETH 40/60, and burns any Greenshoe tokens sent to the reserve. Anyone can call it; the split happens here (and inswapEthandpayFounder), not the instant fees arrive.sweepCurve()collects fees still sitting on the bonding curve before graduation, then harvests. Anyone can call it.swapEth(amount)swaps reserve ETH to USDG on the WETH/USDG pool, within the price bound and the hourly cap. Anyone can call it.setTarget(stock, pool, maxPrice)is founder only. It accepts only a genuine Stock Token (checked against the official token factory, the proxy code hash and live supply) and a Uniswap v3 USDG pool from the official factory (the founder picks the fee tier), plus a price ceiling: the most the reserve may ever pay for one token. Then it starts the 3-day timelock. The ceiling is shown on the site the whole time, so holders can check it against the real price. The reserve never buys above it, whatever the pool says: a thin pool's price can be pushed by anyone, and the ceiling is what makes that useless. The founder can lower the ceiling at any time (lowerMaxPrice); raising it means a newsetTargetand a new 3 days. The founder can call it again to replace the target; every call restarts the 3 days, which also means purchases can be delayed indefinitely. The contract cannot judge whether a Stock Token is a mega-IPO.convert(usdgAmount)buys the target after the timelock, within the price bound, depth check and hourly cap. Anyone can call it. If the clip would move the price past the ~1.5% limit it fills partly, and the full requested amount still counts against the hour’s cap.redeem(amount)burns your tokens (approve first) and sends your share of ETH, USDG and every Stock Token held. If one Stock Token can’t be transferred, it is skipped and the rest still pays.payFounder()sends the accrued founder share to the founder address. Anyone can call it; it can only ever pay the founder.
The flywheel
The markets page lets anyone trade Stock Tokens with any token on Robinhood Chain through KyberSwap, or from and to 50+ other chains (Ethereum, Base, Arbitrum, Solana and more), which Relay bridges in or out while KyberSwap does the Robinhood Chain leg. Before anything is signed, the page reads the swap call and the bridge steps and refuses any that differ from the quote. From another chain a buy takes one signature with that chain’s own coin (a token like USDC asks once to approve first): Relay bridges and makes the buy on Robinhood Chain in the same order, and the page checks that the order makes exactly that buy, that the deposit pays for that order, and that refunds go only to you. Baskets buy several Stock Tokens in equal parts the same way, all or nothing. Each trade carries a 0.3% partner fee on its Robinhood Chain leg, taken in ETH or USDG (or in the Stock Token itself when neither side is one) and paid to the flywheel wallet 0x65B8…6E98, which is funded by nothing else. Every hour the keeper uses what has gathered (from $10, at most $500 a pass, within 1% slippage) to buy Greenshoe tokens and sends them to the Reserve, where harvest() burns them. Burned tokens leave the supply, so each remaining token's share of the reserve is larger. That share is not a price: the token trades at whatever the market pays. Before launch the fees wait and are spent on launch day.
This part runs on our keeper, not in the contract: it is a promise, kept in public. Every purchase is a transaction from that wallet, and the totals are on the home page.
Verify it yourself
- On the launchpad, the token’s fee recipient is the Reserve address in the footer of the home page.
- The Reserve’s source is verified on-chain. It has no owner, pause or upgrade function. Read it on Blockscout.
- Every harvest, swap, target and purchase emits an event. The proof feed on the home page lists them with transaction links.
- A keeper calls
sweepCurveorharvest,swapEth,convertandpayFounderabout every hour (a promise, not code). If it stops, anyone can call them.
Known limits
- No third-party audit yet. The contract passes 45 tests run against a copy of the live chain, including two attack reviews (the second one adversarial, with working proofs of concept that are now fixed and kept as tests) and a full launch rehearsal on a fork, and has been through two automated analyzers (Slither and Aderyn) with every finding reviewed. That is an internal review, not an audit.
- The launchpad owner can redirect the token’s future fees after a public 3-day timelock (the launchpad’s community-takeover process). Fees already in the reserve stay there.
- Stock Tokens can be paused or blocked by their issuer. Redemptions then skip that token and pay everything else.
- New listings may start with thin pools. The price bound, depth check and caps can make buying slow. That is intended. The depth check reads current liquidity, so it cannot rule out a pool someone has deliberately stacked.
- The founder can replace the target at any time. Each change restarts the 3-day wait, so holders always get 3 days’ notice before any purchase.
- One-signature buys and baskets are filled by Relay. If an order can't fill at the minimums you saw, nothing is bought and Relay refunds you, on the chain you paid from or as ETH on Robinhood Chain, less its gas.
- If no mega-IPO lists by 31 March 2027, the founder will propose a liquid Stock Token instead, under the same timelock (a promise, not code).
Legal
Not affiliated with, endorsed by, or connected to Robinhood Markets, Inc. or any company referenced. Stock Tokens are not available to persons in the US, Canada, the UK, Switzerland or any jurisdiction Robinhood restricts (including sanctioned countries). Nothing here is investment advice. Read the terms and risks before you use the site.