Built on Robinhood Chain

An NFT that owns
a book of stocks.

5 000 shelves. Every round, the pot buys Robinhood Stock Tokens and splits them equally across every live shelf, into a vault that only the NFT holder controls. Sell the NFT, sell the book.

One vault per NFTOfficial Stock TokensEqual split, every round
Your shelf
SHELF #0001
AAPLNVDATSLAMSFTGOOGLMETA
Book value $39.80 · next round 02:09:49
ERC-721 + one vault per idOfficial Robinhood Stock TokensNo lockup, withdraw any blockLive Robinhood prices
The problem

A stock you can hold, but not carry.

Tokenised stocks sit in a wallet like any other ERC-20. There is no object that packs a basket of them, keeps buying, and moves as one thing.

Before
A basket you rebuild by hand
  • Ten swaps, ten approvals, ten balances to watch
  • Selling the basket means selling ten positions
  • Nothing keeps buying while you are away
  • No object to hold, show or hand over
After
A shelf that fills itself
  • One NFT, one vault, ten enamel plates
  • Every round delivers the next stock to every shelf
  • Sell the NFT and the whole book goes with it
  • Withdraw any token, any block, no one to ask
Core features

Three rules, printed on chain.

Everything below is a contract constant or a contract read. Nothing is a setting we can change quietly.

A vault per NFT

Each shelf has a CREATE2 vault derived from its id. The vault asks the NFT who holds it on every call. Transfer the NFT and the vault follows; nothing to unwrap.

  • Address known before deployment
  • Only the current holder withdraws
  • No admin path to holder tokens
Real Robinhood Stock Tokens

The pot buys official Robinhood Stock Tokens on Uniswap: plain ERC-20s with USDG pools. AAPL, NVDA, TSLA, MSFT, GOOGL, META, COIN, CRCL, PLTR, SPY.

  • Ten tokens, one per round, in order
  • Rotation changes behind a 24 h timelock
  • Codehash check against Robinhood's proxy
Equal split, every round

A round is one swap and one counter write. Every live shelf gets the same share regardless of when it minted. Shelves minted since the last round wait one round.

  • O(1) in shelves
  • TWAP floor on the swap
  • Anyone can call after the keeper's hour
How it works

From mint to a full shelf.

Three contracts, one path. Every step is a call you can read on the explorer.

01
Mint

Burn 100 000 $SHELF and pay 0.02 ETH in one transaction. 0.018 to the pot, 0.002 to the protocol.

02
Round

When the pot holds 0.05 ETH and 6 h have passed, round(minOut) buys the next stock on Uniswap behind a TWAP floor.

03
Split

counter[token] += bought / liveShelves. One storage write. Every live shelf reads the same share.

04
Deliver

deliver(id, token) moves the share into the shelf's own vault. Withdraw whenever you like.

5 000
shelves, ids from 1
0.02 ETH
per mint, 90% to the pot
100 000
$SHELF burned per mint
0.0312 ETH
in the pot, read on chain

Mint price, burn, threshold and interval are contract constants; the pot figure is read from ShelfPot every 30 seconds.

The book, by size

The image is the vault.

The NFT image is picked from what the vault holds: 0, 3, 6 or 10 plates. Metadata is served live from this site.

Shelf with 0 plates
0 platesat mint
Shelf with 3 plates
3 platesafter 3 rounds
Shelf with 6 plates
6 platesafter 6 rounds
Shelf with 10 plates
10 platesfull rotation
Live state
On-chain
Pot
0.0312 ETH
Next round
02:09:49
Minted
1 284 / 5 000
Rounds
37
Live shelves
1 275
$SHELF burned
128 400 000
Threshold
0.050 ETH
Buys next
CRCL
Delivered
$22 018
The accounts
/api/config →
Security

What the contract actually guarantees.

Four properties, each covered by a test in the repo. Being on chain is not the same as being audited.

Holder tokens are untouchable

There is no function that moves an ERC-20 anywhere except deliver and withdraw. rescue only moves ETH above the reserved pot.

Rounds cannot be sandwiched below the floor

minOut must clear a 30 minute TWAP on both hops times floorBps. A fake keeper quote protects nothing; the pot reads its own price.

The rotation cannot point at a fake token

Every proposed address must carry the runtime codehash of Robinhood's Stock Token proxy, then wait 24 hours in public.

Supply and burn are fixed

5 000 shelves, ids from 1. 100 000 $SHELF to 0x…dEaD inside every mint. Constants, not settings.

The contracts have not been through a third-party audit. 99 unit tests and 5 fork tests against Robinhood mainnet pass; the adversarial review and its fixes are in the docs. Rules, not returns.

FAQ

The short answers.

What is a shelf?
An ERC-721 on Robinhood Chain with its own vault. The vault holds Robinhood Stock Tokens bought by the pot in rounds. Whoever holds the NFT controls the vault.
What do I need to mint?
100 000 $SHELF and 0.02 ETH. The $SHELF is burned inside the mint transaction. Before $SHELF exists, minting is closed; there is no ETH-only mint.
When do rounds happen?
When the pot holds at least 0.05 ETH and 6 hours have passed since the last one. The keeper calls first; after an hour anyone can. If inflows stop, rounds stop.
Can I lose money?
Yes. A shelf's book can be worth less than the mint cost. Stock Tokens can fall, be paused, or be adjusted by Robinhood. $SHELF can go to zero. Nothing here promises a return.
Is there a lockup?
No. deliver and withdraw work at any block. Sell the NFT and the book goes with it.
What is deployed right now?
ShelfNFT, ShelfPot and the vault factory are live on Robinhood Chain and verified on Blockscout; $SHELF trades on Pons V2 with the pot as fee recipient. The contracts are not audited by a third party: 99 tests and 5 fork tests pass, and every address is listed under The accounts. Only @ShelfRH publishes addresses.
$SHELF

The token that feeds the pot.

Live on Pons V2 with the pot as creator fee recipient: every trade feeds the next round. Each mint burns 100 000 $SHELF inside the transaction. The only valid address is the one under The accounts and on @ShelfRH.

Launch
Pons V2
Fee recipient
ShelfPot
Burn / mint
100 000
Burn address
0x…dEaD