Unaudited · TestnetExperimental software. Do not use real funds.
Strike
06ProofRobinhood Chain testnet · 46630

Proof

Check every claim yourself: each one links to the contract, test or transaction behind it.

Each claim Strike makes, next to the contract, transaction, test or document that backs it.

Figures are taken from the repository and link to their source. The active pricer, the price mirror audit and the activity feed are read from the chains when the page loads. Strike is unaudited: the review below is internal.

Deployment
v2
14 contracts · deploy block 125,880,607
Foundry tests
477
+ 15 Rust · 259 TypeScript · 60 bot · 10 subgraph
Coverage
99.3%
of lines · 98.8% of branches
Internal review
11/11 fixed
1 High · 3 Medium · 4 Low · 3 Info
01

Live on Robinhood Chain testnet

Addresses from 46630.json and 46630-vaults.json . Verification status checked on Blockscout on 2026-09-30.

Read on-chain nowEpochManager.pricer()RPC: public
Hide the contract list

Built from commit 1ff5382, deployed from beb4281. The testnet has no Chainlink stock feeds, so MirrorFeeds copy the mainnet rounds.

Deployed next to v2 · block 126,713,718

v3 and the Stylus risk engine

Stylus pricer + risk engine verified with cargo stylus verify: greeks, implied volatility and scenario loss in Rust, on the same program as the pricer. The vault page's Risk panel calls it live on the v2 series. v3 ran its first epoch here on 1 October, with a Claude-planned call accepted and a reckless put slashed (log ), and runs on Arbitrum Sepolia too.

Stylus program
0x6115…a4ec · 23,562 bytes · deploy tx · activation tx · risk.rs
Verified
cargo stylus verify: Verification successful, metadata hash ef5f968b0429b7b240d59acda917a4c8c7232ed1f53215e162e7afda5fbde267
Rust = Solidity
410 vectors (200 greeks, 150 implied volatilities and 60 scenario losses generated by the Rust engine) reproduced exactly by the Solidity RiskLib, plus differential fuzzing
Source
448d83b, deployed from 64fcb93 · 46630-v3.json · deployment log
cargo stylus verify --deployment-tx 0xc71b…d49a --endpoint https://rpc.testnet.chain.robinhood.com
Hide the v3 contracts
02

Price mirror audit

The testnets have no Chainlink stock feeds, so a keeper copies Robinhood Chain mainnet Chainlink rounds into MirrorFeeds. This checks every copied round against mainnet, from /api/mirror-audit. What is trusted and what is checked across Strike: trust-model.md .

Checked on the server from both chains · refreshed every 10 min
Trusted
When the keeper pushes. It is a scheduled job that copies the mainnet feed's latest round to the testnet MirrorFeed when it runs, so it decides which mainnet prints reach the testnet.
Verified
Every value it pushed. Each testnet round must equal a Robinhood Chain mainnet Chainlink round: same timestamp, same answer, to the last unit. An invented, edited or re-timed price fails the check.
Not caught
A keeper that withholds rounds: it could skip prints and push a later, real one. For a settlement, --settlement also checks that the round used is mainnet's first print after expiry.
Run it yourself (no key, read-only)
node scripts/verify-mirror.mjs --chain 46630
node scripts/verify-mirror.mjs --chain 46630 --settlement <vault>

verify-mirror.mjs and this panel run the same check, the SDK's auditMirror . Trust model · first runs

03

Stylus

Method, raw numbers and scripts: docs/gas.md .

Hide section

The live pricer is reproducibly this source

cargo stylus verify rebuilds stylus/pricer from the repository and reports Verification successful for the deployed program.

cargo stylus verify --deployment-tx 0x93fc…37fe --endpoint https://rpc.testnet.chain.robinhood.com
Deployment tx
0x93fc…37fe
Build
cargo-stylus 0.10.9, Rust 1.91.0, reproducible Docker build
Metadata hash
5773190b3eed71771269cdaa28bfd562adc3bc8888ddb49e2b901cf4ceca7045
WASM size
15,574 bytes
Activation check
The deploy script only sets it as the pricer if its on-chain quote equals the Solidity reference's (deploy-testnet.sh ).

docs/gas.md, “The live Stylus pricer is verifiably this source”

Gas: Solidity pricer against Stylus pricer

Gas used with the Solidity and the Stylus pricer
CallSolidityStylusStylus is
proposeByDeltaWhole transaction, 0.20 delta, strike solved on-chainStylus 3.3× less
1,878,918577,0413.3× less
buyWhole transaction, 5 options, live Black-Scholes quoteStylus 9% less
329,872301,4049% less
strikeForDelta0.20-delta call, 7 days (48 Black-Scholes evaluations)Stylus 6.6× less
1,546,443235,8806.6× less
quoteTSLA 250, K 275 call, 7 days, 60% volStylus 1.20× more
33,96940,6241.20× more

A single quote is cheaper in Solidity (33,969 gas against 40,624). A Stylus call pays a fixed entry cost of about 35–40k gas, and one Black-Scholes quote is cheap in the EVM's native 256-bit arithmetic. Stylus wins once a call does real work: solving a strike by delta runs 48 evaluations and costs 6.5–6.6× less.

Measured on a local Arbitrum Nitro dev node (offchainlabs/nitro-node:v3.7.1, Stylus program not cached). The first two rows are whole EpochManager transactions (L2 execution gas), the last two single pricer calls. Reproduce with stylus-gas.sh and stylus-e2e.sh .

04

Tests

Counts from README.md and docs/testing.md ; the Telegram bot's from its test files.

Hide section
  • 477Foundry

    Unit, integration, fuzz, invariant, conformance and audit-regression suites (fork, differential and formal below); 7 more are skipped: settlement rules the StockCollateral example has no use for

  • 15Rust

    Stylus pricer: accuracy against closed-form Black-Scholes, parity, bounds

  • 259TypeScript

    SDK 140, MCP server 59, example agents 60; 2 more SDK tests are opt-in live checks against the deployed v3 registries

  • 60Telegram bot

    Log scanning with range back-off, message formatting, commands, store

  • 10Subgraph

    Matchstick: vault factory, lifecycle, rejection, agent registry

  • 151Playwright

    The app at 1440 px desktop and 390 px mobile, including this page and its links; 32 of them are the opt-in UI audit at five widths

Coverage

Lines
99.3%
Branches
98.8%
Statements
99.4%
Functions
100%

make coverage: Foundry with --ir-minimum, production code in contracts/src only. CI fails below 95% of lines.

05

Invariants, forks, differential

Checks that go beyond example-based tests: random call sequences, deliberately broken code, real mainnet state and two independent pricer implementations.

Hide section
  • Invariants

    9 properties, on a call vault and a put vault

    • 256 runs × 128 calls (32,768 random calls) per invariant in the CI profile
    • Locked collateral covers the worst-case payout; the vault holds every asset it accounts for; option holders can always redeem
  • Mutation checks

    3 injected bugs, all caught by the invariants

    • Settlement payout not subtracted: caught by invariant_assetBacking
    • Premium accumulator over-credits 1%: caught by invariant_premiumSolvency
    • Payouts rounded up: caught by invariant_optionHoldersCanAlwaysRedeem
  • Fork tests

    9 tests against Robinhood Chain mainnet (4663)

    • Real TSLA, NVDA and SPY tokens and Chainlink feeds, real USDG, real ERC-8004 registries
    • The ERC-8056 multiplier is never applied twice; a full epoch runs with real tokens
  • Rust = Solidity

    The Stylus and Solidity pricers return identical results

    • Differential fuzzing of quote, rejections and strikeForDelta (10,000+ runs)
    • 300 pricer vectors generated from Rust, and the same calls on a Nitro dev node
    • On deploy, the Stylus pricer is only activated if its on-chain quote equals the reference
  • Formal properties

    9 properties proven with Halmos for every input in range, in CI

    • MandateGuard: an accepted proposal always meets the basic rules, the size cap and the yield floor; validate accepts exactly the consistent mandates
    • FeeManager: no fee without profit; rate caps. NyseTime: sessions open before they close. Settlement: call payout within the tokens sold
    • 16 more properties time out and are marked unproven, not claimed
06

Security

Static analysis, an internal adversarial review and a threat model. None of this replaces an external audit.

Hide section
Static analysis0 High

Slither 0.11, 2026-09-28. Every remaining Medium and Low finding is listed with the reason it stays. CI fails on any High.

Threat model21 threats

Each with its mitigation and the test that covers it.

Internal review, 2026-09-29: 11 findings, all fixed

1 High, 3 Medium, 4 Low and 3 Info. Each finding's test first reproduced the attack; after the fix it asserts the fixed behaviour. 19 regression tests run in make test.

  1. H-01HighA corporate action near expiry makes settlement permanently impossibleFixed
  2. M-01MediumFirst-round-of-phase fallback: a caller can choose the price, or settlement bricksFixed
  3. M-02MediumSales continue in the money, below intrinsic valueFixed
  4. M-03MediumOracle-latency arbitrage inside the 0.5% deviation bandFixed
  5. L-01LowproposeByDelta rounding gets honest agents slashedFixed
  6. L-02LowMarket-data races slash honest proposalsFixed
  7. L-03LowemergencyCancel ignores an existing settlement priceFixed
  8. L-04LowMandate validation has no protocol floor, so agent = curator = buyer can drain a vaultFixed
  9. I-01InfoShare price ignores the open option liability during an epochFixed
  10. I-02InfoERC-8004 link goes stale after the identity NFT is transferredFixed
  11. I-03InfoKeeper sigma reprices live series by orders of magnitudeFixed
07

Testnet usage

Counted from the logs of every deployment (Robinhood Chain testnet v2 and v3, Arbitrum Sepolia v3) by aggregate.ts , served by /api/stats. Each figure links to the contract it is read from.

Reading every deployment's logs

08

Live activity

Every EpochManager event since the deploy block, read from the chain's logs. Hover a time for UTC. The first live epoch's full log: 2026-09-29.md .

Reading events · refreshes every 30 sEpochManager 0x5A3b…9C99
09

Research

Hide section
  • Backtest, 2019–2026

    403 weeks of weekly vaults on TSLA, NVDA, AMZN and SPY. At 0.20 delta the covered call lagged buy-and-hold on every ticker, with 25–46% less volatility and smaller drawdowns; the put vault earned −3.8% to +3.7% a year depending on the volatility assumption.

  • Litepaper

    Mechanism and solvency argument, the mandate as a constraint system, when a reckless proposal is unprofitable, the fixed-point pricer, safety and limitations.