The airdrop

Since 2026-09-27, a market's treasury has one use: 100 % of the tokenized stocks it buys are airdropped to the holders of its token, pro rata to their holdings, every 24 hours. The creator buyback that preceded it is removed.

Coded and tested, not deployed. The airdrop contract, AirdropDistributor, was coded and tested on 2026-10-04, with the paths that feed it from both vaults; the keeper's daily airdrop step and the dapp's claim screen were written on 2026-10-05. LayerZero is mocked in the tests, and nothing is deployed. Still to do: the LayerZero adapters of the stocks. See Status.

What is distributed

Everything the treasury buys: the 2 % of every trade, buys and sells, plus the anti-snipe surplus of the market's first ten blocks, once converted into the stocks of the market's basket.

The distribution is in kind: holders receive the tokenized stocks, in wrapped form on Ethereum (see below), never cash. ETH, USDC or USDG still waiting for conversion is not distributed as such; it is, once converted into stocks.

To whom, and where

To the holders of the market's token, pro rata to their holdings. The protocol's own addresses receive nothing.

Holdings are counted as each wallet's average balance over the 24 hours before the cycle, Mondays included: holding the token for one hour counts for 1/24 of a full day. A buy just before the window closes earns almost nothing. Since 2026-09-28 each wallet's holdings are recorded onchain over time, so a contract computes every share on Ethereum; the keeper never supplies them. Since 2026-10-02 the record is kept outside the tokens, by a module, the holding recorder: every token reports each balance change to it, and if the report fails, the transfer fails. That is deliberate, the one exception to the protocol's rule that one failure never blocks the rest: a report allowed to fail would let a holder starve it of gas on their own transfer, so that the record skips the move and their share grows. See Architecture and the operating rule below.

Since 2026-10-01 the record also keeps each token's recorded supply over time: every balance outside the Uniswap PoolManager. It gives the share its denominator:

share = average balance over the window
        ÷ (average recorded supply − averages of the excluded addresses)

The excluded addresses are those that receive nothing: the burn address, always, and the addresses on the token's exclusion list; see the exclusions below. The recorder gives the recorded supply on hour boundaries only, so the airdrop's windows start and end on one. It costs every swap one more storage write. A token's first swap of each hour, buy or sell, costs about 28,000 to 30,000 gas more, measured as its own transaction on 2026-10-01, before the record left the tokens; the 23,000 this page gave until the security pipeline of 2026-10-01 was measured inside one transaction. A wallet's gas estimate taken late in an hour can therefore fall short, if the transaction lands as the next hour's first swap. Since Ethereum's Glamsterdam upgrade (live on Sepolia since 2026-10-06, on mainnet when it forks) that write creates its storage slot at the new price: on Sepolia an hour's first swap cost 123,216 gas more. The app gives a trade that may land as an hour's first swap 150,000 more gas: a higher limit only, since a transaction pays for the gas it uses.

Holdings are measured on Ethereum, where the token trades, and since 2026-09-28 the stocks are distributed there too. They are bought on Robinhood Chain, locked there in LayerZero adapters deployed by StockFun, one per stock, and sent to Ethereum as wrapped stocks, one wrapped stock for each locked stock. Each holder claims their share on Ethereum and pays the gas of the claim. To hold the real stock, a holder sends the wrapped one back across the bridge to Robinhood Chain, at their own cost. StockFun's owner holds the adapters' LayerZero configuration, with no delay and no cap on withdrawals: see Trust model.

The rule applies to every treasury, including $STOCKFUN's, which is airdropped to $STOCKFUN holders.

Every 24 hours

The airdrop runs as a daily cycle, market by market. Its time, 13:00 UTC by default, closes the window over which holdings are measured, before the US stock market opens, all year: the open is at 13:30 UTC in summer and 14:30 UTC in winter. The cycle's purchases then run during the session that follows, and its sends, by default, once that session is over:

  1. If the market's treasury has accumulated at least 0.1 ETH, the keeper converts it, sends it across the bridge and buys the basket's stocks.
  2. Once the day's session is over, by default, the keeper sends the stocks bought to the airdrop contract on Ethereum, wrapped, where 100 % of them become claimable by the token's holders. Since the seventh audit loop, on 2026-10-06, it sends them once they are worth what sending them costs, the window's opening included; otherwise they wait in the vault for a later window, with what accumulates (see The keeper). Since the tenth audit loop the keeper reads a vault that had nothing to send after the close again only at the next session, so a stock given to a vault after the close, outside its purchases, goes with the next session's send, into a later window; what the day's purchases bring still goes in the window that ended that day.

Below 0.1 ETH, nothing happens for that market that day: the ETH waits for the next cycle. At 2 %, reaching the threshold takes about 5 ETH of volume on the market, buys and sells combined. Crossing it during the day triggers nothing: the conversion only happens in the daily cycle. The keeper checks each vault at its first pass after the window closes and converts its ETH once in that window; it holds to this since 2026-10-06, and until then converted a vault's ETH at any of its passes during the session, as soon as the vault held the threshold. Cash already waiting in a vault goes on, threshold or not: since the sixth audit loop, on 2026-10-06, a vault's USDC once after each of its ETH conversions and at most once per window otherwise, and a mirror vault's USDG at every pass.

Stocks can only be bought while the US stock market is open. There is therefore no cycle at weekends or on NYSE holidays: Friday's fees are distributed on Monday.

The threshold and the calendar are the keeper's rules: the airdrop contract knows neither. It knows the windows, and credits each send to the last window closed when it arrives.

The cycle's length and closing time, the threshold, 0.1 ETH, and the airdrop contract's limits below are settings of StockFun's owner since 2026-10-05; the values on this page are the defaults. A new schedule applies to the windows not opened yet: a cycle already open keeps its window.

A cycle that fails along the way — a late bridge, a stale feed, a refused bound — stops only what the failure touches. Since 2026-10-05 each stock's purchase goes on its own: a stock whose leg fails keeps its cash for a later cycle while the basket's other stocks are bought, and a market left out of a bridge batch waits while the others cross. What did not go on waits in the market's vaults, on Ethereum or on Robinhood Chain, and is finished at the next cycle, even if the treasury has not reached 0.1 ETH again. StockFun's owner can also move it, at any time, with the emergency transfer, which is immediate: see Emergency mode.

How a cycle works

In the airdrop contract, since 2026-10-04:

  • The window. A cycle's window is the period before its end: 24 hours ending at 13:00 UTC by default. StockFun's owner sets the length and the closing time, in whole hours (setCycleSchedule). A send belongs to the window that ends at the last closing time at or before its arrival, never to one earlier than the market's latest open cycle.
  • Opening freezes the numbers. The first send of a window opens its cycle. The keeper can open it first, with openCycle, which anyone may call: it does so once the window has closed, before the stocks arrive, so each delivery only adds to the cycle. Opening freezes, for good: the token's holding recorder, the exclusion list in force when the window closed, whenever the cycle opens, and the denominator, the recorded supply over the window less the holdings of the burn address and of the listed addresses. Every holder of a cycle is measured against the same numbers, whatever changes afterwards.
  • One cycle per window. Later sends in the same window add to the same cycle.
  • The keeper decides when. It triggers the sends; it never names a window, a holder or an amount. A send that arrives after the next closing time is therefore measured over the next day's window. That is accepted and documented.

How the stocks get there

Two paths, and nothing else credits a cycle.

  • From Robinhood Chain. The keeper calls the market's mirror vault, sendToAirdrop(stocks), and pays the LayerZero fees; what it pays in excess is refunded to it. Since 2026-10-06 the call also names the gas each delivery gets on Ethereum, sendToAirdrop(stocks, receiveGas, composeGas), which the remote hub holds between a floor and a ceiling StockFun's owner sets (see The Robinhood rail and The keeper). For each listed stock, the vault sends its whole balance through the adapter the remote hub names for that stock, to the airdrop contract the remote hub names, with the market's id as payload. LayerZero carries six decimals: under 10^12 units of an 18-decimal stock, a millionth of a token, stays in the vault for a later send. On Ethereum, the stock's OFT mints the wrapped stock to the airdrop contract, then LayerZero's endpoint calls it. The contract credits the delivery only if it comes from its endpoint, from a stock OFT that StockFun's owner registered, from Robinhood Chain, sent by the mirror vault of the market the payload names, and that market exists.
  • From Ethereum. On a vault that buys its stocks on Ethereum, the local rail, the keeper calls sendToAirdrop(stocks) on the market's TreasuryVault. The vault approves the exact amounts, the airdrop contract pulls them and credits what it actually received, and the approvals are closed again. Only the market's own vault can send for it. A vault wired to the bridge hub refuses this path: its stocks are on Robinhood Chain.

In both, the keeper decides when, never how much, what or where: the amount is the vault's balance, the destination is the contract the protocol names, and a stock listed twice or outside the basket makes the call fail.

Since 2026-10-05 each listed stock goes on its own. A stock whose issuer froze it, whose balance cannot be read, or, from Robinhood Chain, that has no adapter or whose fee the keeper's payment does not cover stays in the vault, with an event (AirdropSendFailed), and the others go; it goes with a later send. When no stock goes, the call fails and says why.

Shares and claims

  • The holder claims. Each holder claims their own share, on Ethereum, and pays the gas: one cycle with claim, several with claimMany. Nobody can claim for someone else, and the keeper sends nothing. Since 2026-10-05 the dapp's claim screen lists every window the wallet can claim and sends the claims, five cycles per transaction (ten until 2026-10-06): see The dapp.
  • The amount. For each stock of a cycle:

    due = floor(amount × holding over the window ÷ eligible holdings)
          − what the holder was already paid
    

    never more than the cycle has left in that stock. A send after a claim raises the amount, and the holder claims the difference. What rounding leaves stays in the contract.

  • No expiry, no cap, no minimum. A share can be claimed at any time, with no deadline. There is no cap per wallet and no minimum amount.
  • Excluded addresses claim nothing.
  • Never paid from another cycle. Since 2026-10-05 the airdrop contract keeps, stock by stock, what it owes and what backs it, and pays a stock only while what backs it covers what it owes. What backs it is counted from the stocks credited to cycles, never read from the contract's balance, which also holds deliveries not credited yet: stocks on their way to another market never pay a claim. After an emergency transfer that took part of a stock, claims of that stock wait, in every market that holds it, until the stock comes back through restore, which anyone can call (a plain transfer does not count), or StockFun's owner writes the loss off the cycle that lost it. While nobody has claimed that stock from the cycle, any part of it can be written off, every holder losing the same share; once some holders have been paid, only the whole remainder can, which the holders not yet paid lose. What reaches the cycle after such a write-off is shared pro rata among all its holders, as if the written-off amount had never been there. See Emergency mode.
  • A claim pays what it can. Since 2026-10-05 claim and claimMany pay every stock they can. A stock the books are short of, as above, or whose transfer is refused, for instance because its issuer froze it, is deferred (ClaimDeferred): it stays due, and a later claim pays it. claimMany skips a cycle whose exclusion list names the caller; claim refuses it (Excluded). A claim that pays nothing fails and says why: the books short of a stock (Underfunded), a refused transfer (TransferRefused), or nothing to claim (NothingToClaim). Until then one such stock made the whole claim fail, and an excluded cycle the whole claimMany.
  • The cost. A claim of a cycle of two or three stocks costs roughly 120,000 to 210,000 gas as measured in the tests, which run with warm storage. Measured cold on 2026-10-05, with five stocks per cycle, a first cycle costs about 508,000 to 528,000 gas as a whole transaction, and each further cycle of the same claimMany about 321,000 to 332,000: about 3.4 to 3.5 million gas for ten cycles, then the size of the claim screen's batches, and up to about 5.3 million when each cycle's stocks are cold too. Those are the gas prices before Ethereum's Glamsterdam upgrade. Under it, active on Sepolia since 2026-10-06, a new storage slot costs about five times as much, and each stock a claim pays can write three: on Sepolia a claim of a three-stock cycle cost 1,177,679 gas for the cycle's first claimer and 878,713 to 888,051 for the next ones. Ten five-stock cycles would take about 8 to 14 million gas, within the 16,777,216 that EIP-7825 sets per transaction (under Glamsterdam, on its execution gas), and the claim screen's batches are five cycles.

claimable tells what an address can claim from a cycle, stock by stock.

Exclusions

Each token has its own list, set by StockFun's owner: at most 16 addresses by default (setMaxExcluded), none twice, none zero. The burn address, 0x…dEaD, is always excluded and stays off the list. Each change makes a new version of the list, dated: a window is measured against the list in force when it closed, whenever its cycle opens, and a change applies to the windows that close afterwards.

By default only the burn address is excluded on a market's token. The Uniswap PoolManager is never recorded, so it needs no entry. The only liquidity provider of StockFun pools is the liquidity lock, which holds nothing outside a launch. A pool on another exchange holding the token would be an ordinary recorded holder, which the owner can list.

On $STOCKFUN, the list also carries the launch operator, who holds the whole supply for the few blocks between the mint and the lock. Since 2026-10-05 the launch script lists that address before the token exists, on the address the token will take, then mints, so no window can close between the mint and the list: the operator receives nothing. If the owner changes that list before the first window after the launch has closed, the new list must keep that address.

Stocks held aside

A send for a window without eligible holdings is held aside for the market: stocks sent the day a market launched, for instance, for a window that ended before it existed.

Held-aside stocks go to the first window with eligible holdings after the last one found without, whoever looks and whenever. openCycle, or a send, for the very next window takes them along. Otherwise assignUnassigned, which anyone may call, checks the ended windows in order, at most 30 per call by default (setMaxWindowsPerAssign), and opens the first one with eligible holdings, even if later cycles are already open. Cycles can therefore open out of order.

That holds as long as, in between, the cycle schedule does not change and the token's holding recorder is not replaced. A new schedule re-cuts the windows not opened yet, including those the held-aside stocks are still to look at; a recorder replaced in between measures no window that started before it, and the stocks wait for the first window it covers in full (see the operating rule below).

A send that finds no eligible holdings itself, while earlier windows are still unchecked, fails: assignUnassigned first, then the send again. A delivery from Robinhood Chain stays stored on Ethereum and can be run again: since 2026-10-06 the keeper runs a stored delivery again itself, once its simulation goes through, and alerts with the command to run it by hand when it cannot (see The keeper). Since 2026-10-05, a send for a window that ends at or before the last one checked, which a change to longer windows can cause, joins the stocks held aside instead: a market holding stocks aside keeps receiving its sends.

The principles

  • An airdrop of assets, never a buyback of shares. Nobody hands a token back to the vault. Holding the token is what counts.
  • It rewards holding, not trading.
  • No promised amount. An airdrop depends on past volume, not on a rate. It may be zero, and nothing promises there will be volume tomorrow.
  • No redemption. A holder receives their share of each airdrop and nothing else: there is still no withdrawal right on the vault.
  • The keeper triggers, it never chooses. The split is computed by a contract from the holdings the holding recorder keeps. The keeper chooses when it sends, never how much, what, where or for whom, and it cannot allocate a share to itself or to anyone outside that computation.
  • Never more than a cycle holds. Each cycle pays at most what it holds, stock by stock, and no holder receives more than their pro-rata share, rounded down.
  • One failure stops only itself. Since 2026-10-05 a stock that cannot be sent or paid, or a market that cannot cross, waits on its own, and the others go. See Architecture.

Emergency mode applies to the airdrop contract like any contract holding the protocol's assets: the owner's transfer, immediate, moves stocks and leaves the shares as they are. Since 2026-10-05 the other cycles never pay for it: claims of a stock the transfer took defer that stock, and pay the others, until the stock comes back through restore or the owner writes the loss off the cycle that lost it (see above and Emergency mode). The owner's procedure never lets the books go short: write the cycle down first (writeDownCycle, or writeDownUnassigned for held-aside stocks), then move the stock. The airdrop contract's pause stops the sends, the opening of cycles and the placing of held-aside stocks; it moves nothing and never stops a claim. The airdrop contract and the holding recorder are upgradeable by StockFun's owner, with immediate effect, like every module but the tokens and the liquidity lock.

One operating rule follows: a token's holding recorder is upgraded in place, which keeps its whole history; it is not replaced on a live token. Since 2026-10-05 a replacement no longer breaks trading: the new recorder starts from the token's supply outside the Uniswap PoolManager at that moment, a recorder that recorded the token before refuses it, and, since the second audit loop of that day, a token refuses a recorder bound to another PoolManager than the one its pool lives in, which would count the pool as a holder. Since the third loop, the new recorder starts a new record at the switch: the airdrop contract measures no window that started before it, whose stocks wait, held aside, for the first window the new recorder covers in full, and the token reports the burn address's balance at the switch, so burned tokens stay excluded. But the new recorder does not know the holders' balances: a holder it has not seen move reads as having held nothing until their next move, so a window they span pays them less, and nobody more. The cycles already open keep the recorder they froze. A recorder that must be replaced is switched right after a window ends, once the cycles of the windows already closed are open. Until 2026-10-05 a fresh recorder started from a supply of zero: every sell failed, and the shares of the cycles opened afterwards were broken for good.

Because a failing report fails the transfer, StockFun's owner keeps two immediate levers, one transaction each: an upgrade of the recorder in place, or setRecorder(0) on the token, which stops its record. While a token has no recorder, the airdrop contract opens no cycle of it, and the stocks sent for it are held aside until a recorder is named.

What was open, and how it was settled

The project's register, doc/DECISIONS.md, tracked three open points as TBD 5, 7 and 8. All three were settled on 2026-10-04:

  • A keeper push (TBD 5). No: only the holder claims, for themself, at their own cost.
  • The limits (TBD 7). No cap per wallet, no minimum amount, and shares never expire.
  • The exclusions (TBD 8). A list per token, set by StockFun's owner, at most 16 addresses by default, the burn address always excluded; by default the burn address alone. See above.

What remains

  • The stock adapters. The LayerZero adapters that carry each stock to Ethereum, one per stock: the lockbox adapter on Robinhood Chain and its OFT on Ethereum. They are not in the repository; the tests use mocks
  • A deployment. Nothing is deployed

The keeper's airdrop step and the dapp's claim screen, listed here until then, were written on 2026-10-05: see The keeper and The dapp.

What about the Treasury Ratio?

The Treasury Ratio — treasury value divided by circulating market cap — was the product's signature metric. It no longer means anything: the treasury is emptied at each distribution. It has been obsolete since 2026-09-27.

The metric that replaces it is still to be decided. The current proposal: the cumulative value of the stocks distributed to a market's holders, in dollars. Between two distributions, the dapp keeps showing what the treasury holds, awaiting the next airdrop.

What about the creator buyback?

Removed. From 2026-08-27 to 2026-09-27, a market's creator could have treasury stocks sold to buy back and burn their token. The creator now has no power over the treasury: they receive stocks only as any holder does, if they hold the token.

With it goes the bridge's return path, from Robinhood Chain to Ethereum, which served only the creator buyback. The bridge now runs one way. The stocks cross back the other way for the airdrop, wrapped, through the stock adapters: a different path, which carries only stocks.

The $STOCKFUN buyback-and-burn is not affected: the 0.5 % of every trade that buys $STOCKFUN and sends it to the burn touches no treasury, and it stays. See $STOCKFUN.

The wording

Proposed wording for the dapp, to be validated:

The stocks the treasury buys are airdropped to token holders, pro rata, at each distribution. This is neither a yield nor a guarantee.

The forbidden vocabulary applies in full to the airdrop. The project never writes passive income, earn stocks, returns or your stocks are safe in the vault, and never presents a future airdrop amount as certain.

Tokenized stocks issued by Robinhood, not available to US persons.