Status

This book describes the protocol as decided. Part of what it describes is not in the code yet. This page says precisely which part.

Decided and implemented

  • The fee, 5 % by default, and its two schedules
  • The TreasuryVault, its oracle bounds and its absence of a withdrawal
  • The BuybackBurner and the $STOCKFUN flywheel
  • Emergency mode, immediate since 2026-10-05
  • The cross-chain rail to Robinhood Chain, prepared and tested in simulation, one way since the return path was removed on 2026-09-28, and run end to end on two testnets over LayerZero on 2026-10-06 (below)
  • The single-sided launch of the $STOCKFUN protocol token
  • The removal of the creator buyback, on 2026-09-28
  • The launch redesign, on 2026-09-28: no bonding curve and no graduation any more; each market is created with its two locked positions, 700M and 300M by default, and the creator's optional buy in the same transaction
  • The creation fee, 0.001 ETH by default, an owner setting since 2026-10-05
  • The decaying anti-snipe and the creator's whitelist, at most 20 addresses by default, exempt when trading through the official router; the official router stays changeable by the owner
  • Creator fees held on the hook, market by market, and claimed by the creator; since 2026-10-01 the team and buyback shares too, paid by claims anyone can trigger
  • Holdings recorded onchain for each market token and for $STOCKFUN, since 2026-10-02 by the holding recorder, which each token calls on every transfer. On 2026-10-01, with the record still in the tokens, it cost about 52,000 to 61,000 more gas per transfer between two wallets, above the 20,000 to 40,000 estimated when it was decided. The Uniswap PoolManager is not recorded, so a swap pays for the trader's side and, since 2026-10-01, one write for the recorded supply: 113,529 gas for a buy through the router and 137,250 for a sell, for a wallet that already holds the token (125,862 and 150,416 before the fixes of 2026-10-01, which also removed two sends from every trade)
  • No Uniswap LP fee on StockFun pools by default, since 2026-09-29: the tax is the whole cost of a trade
  • The fixes of the 2026-09-29 security audit, applied on 2026-09-30 and 2026-10-01: liquidity from the liquidity lock only; team and buyback shares claimed outside any trade; conversions in amounts the keeper names, with the cash reserved stock by stock; the recorded supply, the airdrop's denominator, in every token; a Robinhood Chain rail where one market no longer blocks a batch and a paused remote hub still applies role changes. Each fixed finding has regression tests
  • The security pipeline of 2026-10-01, a second audit round that completed several of those fixes: on Robinhood Chain, a v3 route runs one pool at a time and a canonical accounting ticket pays no more records than it queued; an emergency that takes a vault's cash below its reservations voids them; the keeper holds back n−1 units on a basket's last stock. Each fix has regression tests
  • The upgradeable redesign of 2026-10-02: every module but the tokens, the liquidity lock and the remote vault deployer behind a proxy, upgradeable by StockFun's owner with immediate effect; the vaults one proxy per market, on both chains; the tokens reduced to a plain ERC-20 with one setter, setRecorder, and, since 2026-10-05, its rescues; the holding record in its own module; the hook's proxy mined with all 14 v4 permissions; the liquidity lock's end mode, with its 30-day notice; the storage layouts recorded and checked by a script. A swap costs about 27,000 more gas, measured in isolation: a buy 237,190 gas instead of 210,105, a sell 285,031 instead of 258,278
  • The airdrop contract, on 2026-10-04: AirdropDistributor on Ethereum, upgradeable and bound to the factory, fed by sendToAirdrop on both vaults, and the airdrop route on the remote hub. Daily cycles whose window closes at 13:00 UTC, shares computed from the recorded holdings, a claim by each holder at their own cost, with no expiry, cap or minimum, an exclusion list per token, stocks held aside for a window without eligible holdings, emergency mode. The 514 tests outside the fork suites pass, a stateful invariant included; LayerZero is mocked in the tests. Codex reviewed the design, the code and the fixes twice, and its final check found no bug. Not deployed
  • The decisions of 2026-10-05: no team allocation, the whole $STOCKFUN supply in its locked position; an immediate emergency transfer and an immediate adapter change; every number of the protocol an onchain setting of the owner, on both chains, today's values being the defaults, with each pool keeping the LP fee and tick spacing it was created with. Coded and tested, not deployed
  • The founder's design rule of 2026-10-05: one failure never blocks the rest, and every contract that can hold funds has a lever to move out what is stuck, with one deliberate exception, the token's report to its holding recorder; see Architecture. The fourth audit loop of that day put it in the code: bridge deliveries that never block another market, claims that pay what they can, each purchase leg, airdrop stock and batch market on its own, debts kept for a recipient that refuses ETH instead of a halted market, a Lens that reads one vault at a time, and rescues on the modules without emergency mode. Coded and tested, not deployed
  • The five audit loops of 2026-10-05 and their fixes, among them: books settled after an emergency transfer, never paid out of another market; the bridge batch reserved to the keeper, and the pre-deployment of mirror vaults to the keeper and the owner; a recorder named on a live token that no longer breaks trading nor measures a window before it; the $STOCKFUN launch operator excluded from the airdrop before the mint; the canonical rail's tickets priced at the base fee; the storage check at every depth; the rule above. Each fix has a regression test; at the end of the day 614 Foundry tests pass, three fork suites skipped without an RPC. Not deployed
  • The keeper's airdrop step and the dapp's claim screen, on 2026-10-05, with the keeper's new duties: paying what the hook and the lock keep for a recipient, alerting on what keeps failing, planning each stock leg on its own, a state file that survives restarts, and the daily collection of LP fees. Not deployed
  • The fifth audit loop's offchain pass, on 2026-10-06: the keeper converts a vault's ETH once per airdrop window, as decided on 2026-09-27, records each transaction before its receipt is awaited and holds a lock on its state folder, and no longer pays an Ondo attestation for a purchase that can only fail; a basket holds at most five stocks; the Lens carries each vault's state and debts; the $STOCKFUN launch script resumes a stopped run; the app counts the ETH owed to a vault, leaves claims room for a stock still on its way, remembers a stock its token refused, and never shows an unread figure as nothing. 619 Foundry tests pass, three fork suites skipped without an RPC. A rehearsal on a private chain the same day ran the keeper end to end through two windows and passed its six scenarios. See The keeper and The dapp. Not deployed
  • The rehearsal's findings, fixed on 2026-10-06: the keeper places the stocks the airdrop contract holds aside for a market even when its vault has nothing new to send, so a market that traded once and went quiet no longer keeps its first airdrop out of its holders' reach; it records a vault found under the threshold by its window, never by its own clock; and the local deployment file is checked against the chain before the keeper, the app or the worker use it. 620 Foundry tests pass, three fork suites skipped without an RPC. See The keeper. Not deployed
  • The sixth audit loop, fixed on 2026-10-06: on the canonical bridge the keeper watches every ticket until it knows it redeemed, whatever its transfer's credit, and credits a transfer by the remote hub's events only; a vault's USDC goes once after each conversion of its ETH and at most once per window otherwise, as decided for the ETH on 2026-09-27, the purchases on Robinhood Chain still running at every pass; a held-aside search that can place nothing, for a vault with nothing to send, is no longer sent every day; a vault under the threshold is checked on a balance read after the window closes; each vault is quoted on its own router; the app marks the $STOCKFUN price "(last read)" while the Lens cannot read it. See The keeper. Not deployed
  • The seventh audit loop, fixed on 2026-10-06: the keeper sends to the airdrop only what is worth what sending it costs, the dust the bridge cannot carry no longer counting as something to send; it reads each canonical ticket from the receipt of its creation first, so a live deposit is never taken for executed; every log search stops a few blocks below the latest block; it refuses to start on an RPC serving another chain than configured; its alert webhook keeps and sends again what it did not take; an empty setting takes its default. The app's data Worker reads each upgradeable contract on its own, shows the 24-hour volume as unknown while its trade reads fail, and checks each endpoint's chain; the price chart places each point at its time. 620 Foundry tests pass (615 outside the fork files, and the five of the Robinhood Chain fork suite on its public RPC; the three Ethereum fork suites skipped without an RPC); the keeper's 277 tests, the shared package's 51, the back end's 9 and the worker's 137 pass. See The keeper and The dapp. Not deployed
  • The price-feed protections on Robinhood Chain, coded on 2026-10-06: the oracle holds a stock's price back while its token says its oracle is paused for a corporate action, on for every stock, and every price while Chainlink's sequencer uptime feed says the sequencer is down or just back up. No such feed exists for Robinhood Chain, so that second check is off at deployment, by an explicit choice, until one is published. Both are owner settings, off on Ethereum. See The Robinhood rail. Not deployed
  • The eighth audit loop, fixed on 2026-10-06: the app's launch form offers only the baskets read from the chain and checks the chosen one again before sending; the keeper follows a bridge batch once its block is a few blocks deep, tells the bridge's dust from a stock whose fee cannot be quoted, keeps one waiting alert per distinct alert, holds a state file of another chain until it has read its RPC's chain, requires both chain identifiers, reads a ticket a few blocks below the latest one and counts the local rail's opening once; the keeper, its preflight and its inspector, the Worker and the app learnt the price-feed protections; the Worker's trade window never moves back, and the trade panel charges a whitelisted wallet the normal tax. 640 Foundry tests pass (633 outside the fork files, and the seven of the Robinhood Chain fork file on its public RPC; the three Ethereum fork suites skipped without an RPC); the keeper's 306 tests, the shared package's 51, the back end's 9 and the worker's 155 pass. See The keeper and The dapp. Not deployed
  • The airdrop delivery's gas under Ethereum's Glamsterdam upgrade, which Sepolia activated on 2026-10-06: the founder's decision of that day, the keeper simulating each delivery and choosing its gas within bounds StockFun's owner sets on the remote hub, and re-executing a delivery still stuck, with an alert on a second failure. Coded and tested, applied on the testnet run by upgrade, not deployed on mainnet. See The keeper
  • The ninth audit loop, fixed on 2026-10-06, with the findings of the LayerZero testnet run: the keeper reads at the block of its own last transaction for a minute and estimates there the gas of what it sends next, gives each transaction its estimate plus 25 %, delivers its waiting alerts in the order they were last raised, no longer alerts a ticket its own redeem deleted, and its preflight runs on the testnet deployment; the Worker keeps what it learnt of its RPCs when its Cloudflare object sleeps, and records Robinhood Chain's own block; the app gives each write its own gas limit, marks a pot that is an estimate, and never takes an approval it could not read for none. Since this loop a second agent reviews each fix before it is pushed, and its findings are fixed the same way. 653 Foundry tests pass (646 outside the fork files, and the seven of the Robinhood Chain fork file on its public RPC; the three Ethereum fork suites skipped without an RPC); the keeper's 370 tests (372 after the gate's last fix), the shared package's 51, the back end's 9 and the worker's 189 pass. See Testing and verification. Not deployed on mainnet
  • The tenth audit loop, fixed on 2026-10-06: every deployment broadcast takes the node's gas estimate, the deployment tool's own figure being short for every creation under Glamsterdam; a bridge batch's last step on Robinhood Chain gets a base plus a part per market, at most 17 markets a batch, the keeper sending no more and saying where a stalled batch stands; the keeper's emergency watch names its contracts in groups, its error texts keep an RPC address's host only, and it reads every market through Multicall3; the app never shows a transaction the wallet cancelled as done, and reads at no earlier than its own last transaction's block for a minute. The testnet's bridge adapter was upgraded and carried its next batch. 662 Foundry tests pass (655 outside the fork files, and the seven of the Robinhood Chain fork file on its public RPC; the three Ethereum fork suites skipped without an RPC), with the 2 of the LayerZero testnet project; the keeper's 400 tests, the shared package's 51, the back end's 9 and the worker's 210 pass. See Testing and verification. Not deployed on mainnet
  • Leftovers of an interrupted cycle finished at the next cycle, decided on 2026-09-27: the keeper moves on the cash a vault still holds whatever the threshold, in the next window at the latest

An implementation order, in steps that leave the repository compiling, is recorded in projet/docs/FUNCTIONAL_AUDIT_2026-09-28.md.

Decided 2026-09-27, not yet implemented

The creator buyback and the bridge's return path were removed from the contracts, keeper and back end on 2026-09-28. Since 2026-10-04 the airdrop contract is in the code, and since 2026-10-05 the keeper's airdrop step and the dapp's claim screen: coded and tested, not deployed. The stock adapters are not in the code yet: see below. The app in the repository no longer displays the Treasury Ratio.

Nothing any more. The keeper's daily airdrop step and the holders' claim screen in the dapp are in the code since 2026-10-05, and the leftovers of an interrupted cycle are finished at the next cycle, the keeper moving on the cash a vault still holds whatever the threshold: see above.

The documents in doc/ and the landing specification were aligned with this decision on 2026-09-27. In the code, the removal of the creator buyback is done, since 2026-10-04 the airdrop contract, with its share computation and its claims, and since 2026-10-05 the keeper's step and the claim screen.

Decided 2026-09-28, not yet implemented

  • The stock adapters that carry the wrapped stocks to Ethereum, one per stock: the lockbox adapter on Robinhood Chain and its OFT on Ethereum. They need LayerZero's oft-evm package and are not in the repository for mainnet; the tests use mocks, and the LayerZero testnet run of 2026-10-06 used test adapters built on that package. The claim on Ethereum is coded since 2026-10-04, and its screen in the dapp since 2026-10-05
  • The stock adapters' LayerZero configuration held by the owner, without delay and with no cap on withdrawals

Decided 2026-09-11, partially propagated

The move from Ondo to Robinhood Chain is settled and the rail's code exists. The project's source documents have not all been updated — see Source errata.

Never verified under real conditions

  • No mainnet deployment has taken place
  • No LayerZero transport has been exercised on mainnet. On 2026-10-06 the LayerZero testnet run carried the bridge batches and the airdrop deliveries between Sepolia and Robinhood Chain's testnet over LayerZero's real testnet endpoints, DVN and executor, seven hourly windows and six airdrop cycles, every claim exactly its computed share. It used test stocks, test adapters, a test USDG and mock feeds: it proves neither Paxos's USDG pair, nor Robinhood's stocks and their adapters, nor real feeds and liquidity, nor mainnet's gas, fees and finality. See The Robinhood rail
  • The existing formal proofs do not cover the current cross-chain rail
  • Seven rules of the LiquidityLock formal specification remain undecided on the prover for one method, lockProtocolLiquidity, even with a longer time limit; they hold on every other method. The re-run of 2026-10-01, on the fixed code, found no violated rule
  • The formal specifications are being updated for the redesign of 2026-10-02: their last full prover run, on 2026-10-01, predates it. For the airdrop of 2026-10-04, the five specifications touching the changed contracts typecheck, with no prover run. On 2026-10-05 the specifications were updated for the settings, then for the audit loops of that day, which added rules on the hook's debts and strays, the lock's kept shares and every rescue: they typecheck, with no prover run since 2026-10-01. So do the oracle's new rules for its price-feed protections, written on 2026-10-06
  • The keeper's debt payments, LP-fee collection, alerts and state file, written on 2026-10-05, are covered by its tests and, since 2026-10-06, by a rehearsal on a private chain: conversions once per window, the airdrop, a vault refusing ETH and its debts paid, kills mid-flight with the state file and its lock, LP fees. The bridge rail did not run there; it ran end to end on the LayerZero testnet run of 2026-10-06, by the keeper, never under real conditions
  • No external review has been conducted

Still to settle before mainnet

  • An up-to-date survey of feed coverage on Robinhood Chain, and, should Chainlink publish a sequencer uptime feed for that chain, setting it on the oracle (none exists on 2026-10-06)
  • The size limit of the LayerZero pathway Paxos's USDG takes to Robinhood Chain, read before the first batch, and the cap on a bridge batch's markets set to match if it differs from the default 10,000 bytes (since the tenth audit loop)
  • Starting FDV and upper bound for the $STOCKFUN position
  • The airdrop's remaining work, listed above: the stock adapters. Its parameters are set since 2026-10-04: no keeper push, no cap, no minimum, no expiry, an exclusion list per token
  • The metric that replaces the Treasury Ratio, and the slogan and tagline, which describe a treasury that accumulates
  • The findings of the audit's second round, on 2026-10-01, still awaiting the owner's decision: the contract side of the last stock's margin, which changes the documented allocation rule (R2T-1); and, optionally, having the factory deploy the $STOCKFUN vault itself (R2F-2). Since 2026-10-05 a vault that refuses ETH no longer halts its market, so the halt R2F-2 described no longer follows from such a vault

Settled on 2026-10-05. Of the 2026-09-29 audit: Ondo attestations that anyone who saw one could spend (M-7) and routers that accepted themselves as recipient (L-4) are fixed, and the bridge adapter's rotation (M-2, and L-8, tied to it) stays as it is, by the owner's decision. Of the second round: taking the buy tax as PoolManager claims (R2F-1, option b) is declined, the tax staying as it is taken; an emergency on the remote hub's recorded cash, whose records were then paid out of other markets' cash (R2H-1), is covered by the settlement tools of that day's audit loops plus a procedure, the owner pausing the remote hub before the transfer on the canonical rail; and a cash token that refuses one mirror vault (R2H-2) no longer blocks anything since the fourth audit loop: that vault's delivery waits on its own, and the other markets are paid.