DeFiPunk'd

Robinhood Chain Bridge

Canonical Bridge

TVL $290.4M
Type Canonical Bridge
Chain Ethereum
View on DeFiLlama ↗
Control criteria
Upgradeability Upgradeable Bug bounty Governance forum Docs docs.robinhood.com
About

Robinhood Chain is a permissionless Arbitrum Orbit Layer 2 built by Robinhood for tokenized real-world assets (stocks, ETFs) and onchain financial services. Users can deposit ETH or ERC-20 tokens via the canonical bridge (Delayed Inbox on Ethereum L1), with deposits settling in ~10 minutes and withdrawals requiring a 6d 8h BoLD challenge period before claiming on Ethereum. The bridge uses Arbitrum Nitro's retryable ticket system and inherits Ethereum security through fraud proofs, though challengers are currently whitelisted to 2 EOAs. The protocol also includes Stock Tokens — ERC-20-compatible tokenized equities managed through an AccessControlsRegistry that controls minting, burning, pausing, and blocking.

Risk analysis

One card per dimension, sorted by severity. Only Verifiability and Autonomy carry automated signals in Phase 0. See methodology for scope.

Audit a dimension yourself · DEFI@home Contribute an LLM-run assessment — any model, any dimension. Three agreeing runs merge automatically into the public record.

DEFI@home is a distributed audit network modeled on SETI@home: instead of CPU cycles, it crowdsources LLM reasoning. Paste a slice prompt into Claude, ChatGPT, Gemini, or any browsing-capable model, and submit the JSON output as a pull request. The quorum bot merges it once ≥3 independent runs (from different models) reach the same grade — no single model, and no single contributor, can move the needle alone. How it works →

  • Address discovery 34 addresses on file · 1 run Submit run ↗
  • Verifiability Unverified Submit run ↗
  • Control Unverified Submit run ↗
  • Ability to exit Unverified Submit run ↗
  • Autonomy Unverified Submit run ↗
  • Open Access Unverified Submit run ↗
  • Audit all 5 dimensions · one prompt Submit run ↗
  1. Verifiability tentative
    No public repo or audits

    Neither a GitHub repository nor any audit is recorded. At Phase 0 this is the most conservative verifiability signal DeFiPunk'd can assign.

    Run your own prompt Submit run ↗
  2. Autonomy tentative
    External message validators reduce autonomy

    Bridges rely on an external validator set, guardian signatures, or light-client proofs — a category-level autonomy risk independent of any specific implementation.

    Run your own prompt Submit run ↗
3 dimensions not yet assessed (Control, Ability to exit, Open Access)
  1. Control unknown Unverified
    Not yet assessed

    Who holds admin privileges, how contracts can be upgraded, and how quickly. No automated heuristic grades this at Phase 0; a real assessment arrives when onchain discovery reads roles, owners, and timelocks.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  2. Ability to exit unknown Unverified
    Not yet assessed

    Whether users can exit on their own terms if the team disappears or acts adversarially. Requires per-protocol review; not available at Phase 0.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗
  3. Open Access unknown Unverified
    Not yet assessed

    Whether the protocol depends on privileged operators, whitelists, geo-restrictions, or off-chain infrastructure. This is not a signal DeFiLlama carries in a usable form; crawler-based detection lands in a later phase.

    No model has graded this dimension yet. Run the slice prompt through any LLM and submit the JSON — once ≥3 independent runs agree, the quorum bot merges the verdict here.

    Submit run ↗

Stage

Preview of the Phase-3 maturity framework. DeFiPunk'd will adopt DeFiScan v2's stages verbatim; the section is rendered below in its intended shape so the structure is visible today.

Robinhood Chain Bridge has not yet been assessed under the DeFiScan v2 stage framework.
The walkaway test is the central criterion. Once stages land, protocols reach Stage 1 only if users can exit in the presence of malicious operators even when the emergency council disappears.
Scope of assessment
Stages are assessed per-protocol against DeFiScan v2's criteria: governance structure, upgradeability path, timelock durations, emergency-council scope, and the walkaway test. The analysis depends on onchain discovery (roles, owners, timelocks) and deeper review of deployed contracts — neither of which DeFiPunk'd automates at Phase 0.
Stage 0 requirements pending
Governance is largely off-chain, contracts are upgradeable with short or no timelock, and the protocol depends on a multisig or team with full discretion. At Phase 0 DeFiPunk'd does not automatically evaluate these; the assessment lands with crawler-based onchain discovery.
Stage 1 requirements pending
Users can exit or opt out on their own terms even if the team disappears. Upgrades run through a meaningful timelock with an emergency security council clearly scoped. The walkaway test is the headline criterion.
Stage 2 requirements pending
Protocol is fully permissionless and immutable, or upgrades require a supermajority of token holders with a long timelock and no emergency override. This is the terminal stage of the DeFiScan v2 framework.
Learn more about DeFiScan v2 stages →
Stages are an opinionated assessment of maturity, not a rating of security or safety. A protocol can sit at Stage 2 and still carry substantial technical or economic risk; the framework exists to incentivize decentralization, not to rank protocols.

Contract surface

Every contract in scope for this protocol — pooled from DeFiLlama's TVL adapter (mechanical) and DEFI@home discovery submissions (LLM-curated). Verified-source flags come from Etherscan + Sourcify; owner / multisig metadata is read on-chain when available. Reviewer audit context, not a slice score. A lending protocol's adapter set will list third-party collateral tokens alongside its own contracts; attribution is the grader's job.

  • 34addresses
  • 0verified source
  • 0proxies

Control fetched 2026-08-20.

Ethereumadmin (UpgradeExecutor — central access-control contract for upgrades)0x5526…b4bfdiscovery
Ethereummultisig (2-of-3 Safe — legacy multisig, member of 7-of-8 and 6-of-8 Safes)0x1f3b…31c5discoverymultisig
Ethereummultisig (3-of-7 Safe — nested member of 7-of-8 and 6-of-8 Safes)0x0fc5…44acdiscoverymultisig
Ethereummultisig (6-of-8 Safe — can propose and cancel TimelockController actions)0xbfc2…ca1ddiscoverymultisig
Ethereummultisig (7-of-8 Safe — direct executor; can upgrade all core contracts with no delay)0x7ae5…84b6discoverymultisig
Ethereumother (Delayed Inbox — L1→L2 deposit and message entry point)0x1a07…7a2ddiscovery
Ethereumother (EdgeChallengeManager — BoLD fraud proof challenge logic)0x6f38…d4fadiscovery
Ethereumother (EOA Batch Poster — submits transaction batches to SequencerInbox)0xdaa5…87f4discovery
Ethereumother (EOA Validator 1 — can propose state roots and submit fraud proofs)0x992d…8aa0discovery
Ethereumother (EOA Validator 2 — can propose state roots and submit fraud proofs)0xa0a1…ec4cdiscovery
Ethereumother (L1 Multicall)0x7cdc…df5ediscovery
Ethereumother (Outbox — processes L2→L1 withdrawal messages)0xf0ce…3de9discovery
Ethereumother (RollupEventInbox — sends config data over bridge during init)0xc34f…5bd4discoverybridge
Ethereumother (RollupProxy — central config, state assertions, fraud proof entry point)0x23a1…2d94discovery
Ethereumother (SequencerInbox — batch poster submits L2 batches here)0xbd0d…ba96discovery
Ethereumproxy_admin (L1 ProxyAdmin / CoreProxyAdmin — admin of all L1 upgradeable proxies)0x1232…90fddiscovery
Ethereumproxy_admin (ProxyAdmin — second ProxyAdmin instance on Ethereum)0x4e39…1839discovery
Ethereumrouter (L1 Gateway Router — maps tokens to correct escrow gateway)0x6a2e…75bbdiscoveryrouter
Ethereumtimelock (TimelockController — 7-day minimum delay; executor of UpgradeExecutor)0xe1e8…f465discoverytimelock
Ethereumtoken (L1 Weth — canonical WETH9 token on Ethereum)0xc02a…6cc2discoverytoken
Ethereumvault (Bridge — ETH escrow; manages allowed Inboxes and Outboxes)0xdf87…64b3discoverybridge
Ethereumvault (L1 Arb-Custom Gateway — custom token bridge gateway)0x9368…cee1discoverybridge
Ethereumvault (L1 ERC20 Gateway — escrow for deposited ERC-20 assets)0x8500…6da0discoverybridge
Ethereumvault (L1 Weth Gateway — WETH escrow for canonical bridge)0xf7e1…cf1bdiscoverybridge
Robinhood Chainadmin (L2UpgradeExecutor — ArbOS chain owner; manages chain-owner set and transaction filterers)0x2a15…5c09discovery
Robinhood Chainguardian (TransactionFilterer — authorized to register/remove tx hashes in ArbFilteredTransactionsManager)0xebdc…24b7discoveryguardian
Robinhood Chainmultisig (L2 SafeL2 3-of-7 — nested member of L2 7-of-8 and 6-of-8)0x3a0c…7a1cdiscoverymultisig
Robinhood Chainmultisig (L2 SafeL2 6-of-8 — can propose/cancel L2 timelock actions)0x4c03…2462discoverymultisig
Robinhood Chainmultisig (L2 SafeL2 7-of-8 — direct executor on L2; can upgrade with no delay)0x6b9f…3fdcdiscoverymultisig
Robinhood Chainother (AccessControlsRegistry — shared access control and upgrade beacon for Stock Tokens)0xe10b…1b00discovery
Robinhood Chainother (L2 EOA — direct executor of L2UpgradeExecutor; can upgrade L2 contracts with no delay)0x6637…c5d0discovery
Robinhood Chainproxy_admin (L2 ProxyAdmin — admin of L2 TimelockController proxy)0x672d…a3efdiscovery
Robinhood Chainproxy_admin (L2 ProxyAdmin — admin of L2UpgradeExecutor proxy)0xa3ac…67dfdiscovery
Robinhood Chaintimelock (L2 TimelockController — 7-day minimum delay on L2)0x560c…8173discoverytimelock

Protocol Info

Links

[defillama] Source: DeFiLlama [:] Source: DEFI@home quorum

Security

[defillama] Source: DeFiLlama
Audits
unknown
Bug bounty
unknown
Security contact
unknown

Technical

[:] Source: DEFI@home quorum
Upgradeability
Upgradeable

Provenance

[defillama] Source: DeFiLlama
Review status
listed
Updated
2026-08-10 07:25 UTC