Proof
Check every claim yourself: each one links to the contract, test or transaction behind it.
Each claim Strike makes, next to the contract, transaction, test or document that backs it.
Figures are taken from the repository and link to their source. The active pricer, the price mirror audit and the activity feed are read from the chains when the page loads. Strike is unaudited: the review below is internal.
Live on Robinhood Chain testnet
Addresses from 46630.json and 46630-vaults.json . Verification status checked on Blockscout on 2026-09-30.
EpochManager.pricer()RPC: publicHide the contract list
- EpochManagerEpochs, proposals, mandate checks, sales and settlement0x5A3b…9C99 Verified on BlockscoutSource
- Stylus pricerActive pricerBlack-Scholes and strike solver in Rust/WASM: the active pricer0x60e9…d04c Verified with cargo stylus verifySource
- BlackScholesRefSolidity reference pricer, kept for the on-chain equality check0x4261…5A1A Verified on BlockscoutSource
- TSLA covered-call vaultERC-4626 vault holding testnet TSLA0xADFF…1D4e EIP-1167 clone of the verified implementationSource
- TSLA cash-secured-put vaultERC-4626 vault holding USDG0xE33E…67d7 EIP-1167 clone of the verified implementationSource
- StrikeVault implementationCode behind every vault clone0x900e…797D Verified on BlockscoutSource
- VaultFactoryCreates vaults with an immutable mandate0x5665…6beC Verified on BlockscoutSource
- AgentRegistryAgent bonds, slashing and ERC-8004 identity0xE5b7…8D32 Verified on BlockscoutSource
- StockOracleSafeStockFeed checks and settlement prices0x7bb3…aB89 Verified on BlockscoutSource
- MarketCalendarNYSE sessions and weekly expiries0x214d…95F4 Verified on BlockscoutSource
- FeeManagerPerformance fee and the agent's share0x6b23…B621 Verified on BlockscoutSource
- OptionTokenERC-1155 option positions0x5570…c9DB Verified on BlockscoutSource
- TSLA MirrorFeedTestnet only: copies mainnet Chainlink TSLA rounds0x5476…1230 Verified on BlockscoutSource
- USDGPaxos stablecoin: premium, put collateral, bonds0x7E95…802F Paxos contract, verified by its issuerExternal
Built from commit 1ff5382, deployed from beb4281. The testnet has no Chainlink stock feeds, so MirrorFeeds copy the mainnet rounds.
v3 and the Stylus risk engine
Stylus pricer + risk engine verified with cargo stylus verify: greeks, implied volatility and scenario loss in Rust, on the same program as the pricer. The vault page's Risk panel calls it live on the v2 series. v3 ran its first epoch here on 1 October, with a Claude-planned call accepted and a reckless put slashed (log ), and runs on Arbitrum Sepolia too.
- Stylus program
- 0x6115…a4ec · 23,562 bytes · deploy tx · activation tx · risk.rs
- Verified
cargo stylus verify: Verification successful, metadata hash ef5f968b0429b7b240d59acda917a4c8c7232ed1f53215e162e7afda5fbde267- Rust = Solidity
- 410 vectors (200 greeks, 150 implied volatilities and 60 scenario losses generated by the Rust engine) reproduced exactly by the Solidity
RiskLib, plus differential fuzzing - Source
448d83b, deployed from64fcb93· 46630-v3.json · deployment log
cargo stylus verify --deployment-tx 0xc71b…d49a --endpoint https://rpc.testnet.chain.robinhood.comHide the v3 contracts
- EpochManager0x256D…929F Verified on Blockscoutv3-contracts
- RiskLensRead-only risk view of v3 series0xFDb8…Cc6D Verified on Blockscoutv3-contracts
- BlackScholesRef + RiskLib0x2B6A…62d0 Verified on Blockscoutv3-contracts
- FeeManager (high-water mark)0x8DBE…2Fa7 Verified on Blockscoutv3-contracts
- AgentRegistry (EIP-712 consent)0x1c42…052f Verified on Blockscoutv3-contracts
- VaultFactory0x97ab…215e Verified on Blockscoutv3-contracts
- StrikeVault implementation0x2E67…76D9 Verified on Blockscoutv3-contracts
- OptionToken0xfbeb…46B6 Verified on Blockscoutv3-contracts
- StockOracle0x5BCd…989A Verified on Blockscoutv3-contracts
Price mirror audit
The testnets have no Chainlink stock feeds, so a keeper copies Robinhood Chain mainnet Chainlink rounds into MirrorFeeds. This checks every copied round against mainnet, from /api/mirror-audit. What is trusted and what is checked across Strike: trust-model.md .
- Trusted
- When the keeper pushes. It is a scheduled job that copies the mainnet feed's latest round to the testnet MirrorFeed when it runs, so it decides which mainnet prints reach the testnet.
- Verified
- Every value it pushed. Each testnet round must equal a Robinhood Chain mainnet Chainlink round: same timestamp, same answer, to the last unit. An invented, edited or re-timed price fails the check.
- Not caught
- A keeper that withholds rounds: it could skip prints and push a later, real one. For a settlement,
--settlementalso checks that the round used is mainnet's first print after expiry.
node scripts/verify-mirror.mjs --chain 46630
node scripts/verify-mirror.mjs --chain 46630 --settlement <vault>verify-mirror.mjs and this panel run the same check, the SDK's auditMirror . Trust model · first runs
Stylus
Method, raw numbers and scripts: docs/gas.md .
Hide section
The live pricer is reproducibly this source
cargo stylus verify rebuilds stylus/pricer from the repository and reports Verification successful for the deployed program.
cargo stylus verify --deployment-tx 0x93fc…37fe --endpoint https://rpc.testnet.chain.robinhood.com- Deployment tx
- 0x93fc…37fe
- Build
- cargo-stylus 0.10.9, Rust 1.91.0, reproducible Docker build
- Metadata hash
- 5773190b3eed71771269cdaa28bfd562adc3bc8888ddb49e2b901cf4ceca7045
- WASM size
- 15,574 bytes
- Activation check
- The deploy script only sets it as the pricer if its on-chain quote equals the Solidity reference's (deploy-testnet.sh ).
docs/gas.md, “The live Stylus pricer is verifiably this source”
Gas: Solidity pricer against Stylus pricer
| Call | Solidity | Stylus | Stylus is |
|---|---|---|---|
proposeByDeltaWhole transaction, 0.20 delta, strike solved on-chainStylus 3.3× less | 1,878,918 | 577,041 | 3.3× less |
buyWhole transaction, 5 options, live Black-Scholes quoteStylus 9% less | 329,872 | 301,404 | 9% less |
strikeForDelta0.20-delta call, 7 days (48 Black-Scholes evaluations)Stylus 6.6× less | 1,546,443 | 235,880 | 6.6× less |
quoteTSLA 250, K 275 call, 7 days, 60% volStylus 1.20× more | 33,969 | 40,624 | 1.20× more |
A single quote is cheaper in Solidity (33,969 gas against 40,624). A Stylus call pays a fixed entry cost of about 35–40k gas, and one Black-Scholes quote is cheap in the EVM's native 256-bit arithmetic. Stylus wins once a call does real work: solving a strike by delta runs 48 evaluations and costs 6.5–6.6× less.
Measured on a local Arbitrum Nitro dev node (offchainlabs/nitro-node:v3.7.1, Stylus program not cached). The first two rows are whole EpochManager transactions (L2 execution gas), the last two single pricer calls. Reproduce with stylus-gas.sh and stylus-e2e.sh .
Tests
Counts from README.md and docs/testing.md ; the Telegram bot's from its test files.
Hide section
- 477Foundry
Unit, integration, fuzz, invariant, conformance and audit-regression suites (fork, differential and formal below); 7 more are skipped: settlement rules the StockCollateral example has no use for
- 15Rust
Stylus pricer: accuracy against closed-form Black-Scholes, parity, bounds
- 259TypeScript
SDK 140, MCP server 59, example agents 60; 2 more SDK tests are opt-in live checks against the deployed v3 registries
- 60Telegram bot
Log scanning with range back-off, message formatting, commands, store
- 10Subgraph
Matchstick: vault factory, lifecycle, rejection, agent registry
- 151Playwright
The app at 1440 px desktop and 390 px mobile, including this page and its links; 32 of them are the opt-in UI audit at five widths
Coverage
- Lines
- 99.3%
- Branches
- 98.8%
- Statements
- 99.4%
- Functions
- 100%
make coverage: Foundry with --ir-minimum, production code in contracts/src only. CI fails below 95% of lines.
Invariants, forks, differential
Checks that go beyond example-based tests: random call sequences, deliberately broken code, real mainnet state and two independent pricer implementations.
Hide section
Invariants
9 properties, on a call vault and a put vault
- 256 runs × 128 calls (32,768 random calls) per invariant in the CI profile
- Locked collateral covers the worst-case payout; the vault holds every asset it accounts for; option holders can always redeem
Mutation checks
3 injected bugs, all caught by the invariants
- Settlement payout not subtracted: caught by invariant_assetBacking
- Premium accumulator over-credits 1%: caught by invariant_premiumSolvency
- Payouts rounded up: caught by invariant_optionHoldersCanAlwaysRedeem
Fork tests
9 tests against Robinhood Chain mainnet (4663)
- Real TSLA, NVDA and SPY tokens and Chainlink feeds, real USDG, real ERC-8004 registries
- The ERC-8056 multiplier is never applied twice; a full epoch runs with real tokens
Rust = Solidity
The Stylus and Solidity pricers return identical results
- Differential fuzzing of quote, rejections and strikeForDelta (10,000+ runs)
- 300 pricer vectors generated from Rust, and the same calls on a Nitro dev node
- On deploy, the Stylus pricer is only activated if its on-chain quote equals the reference
Formal properties
9 properties proven with Halmos for every input in range, in CI
- MandateGuard: an accepted proposal always meets the basic rules, the size cap and the yield floor; validate accepts exactly the consistent mandates
- FeeManager: no fee without profit; rate caps. NyseTime: sessions open before they close. Settlement: call payout within the tokens sold
- 16 more properties time out and are marked unproven, not claimed
Security
Static analysis, an internal adversarial review and a threat model. None of this replaces an external audit.
Hide section
Slither 0.11, 2026-09-28. Every remaining Medium and Low finding is listed with the reason it stays. CI fails on any High.
Internal review, 2026-09-29: 11 findings, all fixed
1 High, 3 Medium, 4 Low and 3 Info. Each finding's test first reproduced the attack; after the fix it asserts the fixed behaviour. 19 regression tests run in make test.
- H-01HighA corporate action near expiry makes settlement permanently impossibleFixed
- M-01MediumFirst-round-of-phase fallback: a caller can choose the price, or settlement bricksFixed
- M-02MediumSales continue in the money, below intrinsic valueFixed
- M-03MediumOracle-latency arbitrage inside the 0.5% deviation bandFixed
- L-01Low
proposeByDeltarounding gets honest agents slashedFixed - L-02LowMarket-data races slash honest proposalsFixed
- L-03Low
emergencyCancelignores an existing settlement priceFixed - L-04LowMandate validation has no protocol floor, so agent = curator = buyer can drain a vaultFixed
- I-01InfoShare price ignores the open option liability during an epochFixed
- I-02InfoERC-8004 link goes stale after the identity NFT is transferredFixed
- I-03InfoKeeper sigma reprices live series by orders of magnitudeFixed
Testnet usage
Counted from the logs of every deployment (Robinhood Chain testnet v2 and v3, Arbitrum Sepolia v3) by aggregate.ts , served by /api/stats. Each figure links to the contract it is read from.
Reading every deployment's logs
Live activity
Every EpochManager event since the deploy block, read from the chain's logs. Hover a time for UTC. The first live epoch's full log: 2026-09-29.md .
Research
Hide section
Backtest, 2019–2026
403 weeks of weekly vaults on TSLA, NVDA, AMZN and SPY. At 0.20 delta the covered call lagged buy-and-hold on every ticker, with 25–46% less volatility and smaller drawdowns; the put vault earned −3.8% to +3.7% a year depending on the volatility assumption.
Litepaper
Mechanism and solvency argument, the mandate as a constraint system, when a reckless proposal is unprofitable, the fixed-point pricer, safety and limitations.