ROBINHOOD CHAIN: TWO VAULTS, ONE PIPELINE.
The Robinhood Chain deployment is two independent perp stacks: a boring-and-correct majors vault, and a heavily bounded degen vault for graduated froth.meme tokens, both connected to the froth.meme launchpad and FrothSwap DEX. Here is the design, including the parts built to fail safely.
THE DUAL-VAULT DESIGN
KLP: MAJORS
- ETH, BTC, and stables. Robinhood's own majors basket
- 25–50x leverage
- Same pool design as Flow's KLP, but a fully separate pool with its own basket and its own LPs
- Majority of fees to KLP, share to sPUNCH, rest to protocol ops
dKLP: DEGEN
- Seasoned froth.meme graduates only
- 2–5x leverage, per-position profit caps
- Fully synthetic: PnL settles in stables, the vault never holds a graduate token
- Its own vault, router, order book, keepers, and fee streams
SEPARATE RISK DOMAINS
HOW dKLP IS BOUNDED
Perps on young tokens are where venues die, so every bound below is a launch requirement, not a fast-follow:
- Synthetic, stables-settled markets. The vault warehouses no graduate tokens, so there is nothing to dump on it.
- Net open-interest caps from block one. Gross OI can grow, but net exposure (long minus short) per market stays small. Synthetic settlement without netting would be worse than holding the token, so the two ship together or not at all.
- Per-market OI ceilings set to the smaller of a small share of dKLP TVL or a fraction of the token's real 24-hour spot volume.
- Per-position profit caps, elevated spreads, and elevated borrow fees.
- LP withdrawal cooldown, so LPs cannot front-run a manipulation event they see forming.
- No trade-to-earn multipliers at launch. dKLP volume earns no T2E, points, or airdrop weighting until funding and skew modules are live with real listing history. See Lose-to-Earn.
Fast-follow modules (shipped after security review): funding fees keyed to long/short imbalance, where the crowded side pays hourly, and skew-adjusted execution pricing that gives the crowded side a worse entry.
THE PIPELINE: FROTH.MEME → PUNCH
froth.meme and FrothSwap are the market-formation layer Punch builds on: they turn a fresh meme into a standardized, permanently liquid spot market that Punch can safely price. The four stages on the front page expand into six here:
1. LAUNCH
A token launches on the froth.meme public bonding curve, priced in ETH. No allocations. The curve is the distribution.
2. GRADUATE
At the 8 ETH graduation target, the curve reserve seeds a token/WETH pair on FrothSwap and the LP is burned. Nobody can ever pull that baseline liquidity, including the creator.
3. PRICE
Burned liquidity makes the token safely priceable. The classic TWAP attack (pull liquidity, push the price cheap) is impossible by construction.
4. SEASON
The pair accrues history against the seasoning gate: a published formula denominated in cumulative fees actually paid plus depth. Every swap pays a fixed 30 bps LP fee that stays with liquidity, plus immutable per-pair fee legs (creator royalty, bid-wall buy-and-burn, FROTH buy-and-burn), so faking the gate costs real money.
5. LIST
Graduates that clear the gate become eligible for dKLP perpetual markets.
6. RETURN
Perp fees pay LPs, protocol ops, and sPUNCH stakers. On FrothSwap, the pair's royalty and buy-and-burn legs keep flowing independently of Punch fee routing.
The seasoning gate's entry condition is a published formula. Listed markets can still have parameters tightened or be delisted when integrity checks require it; those changes are announced before they take effect.
THE dKLP ORACLE STACK
Fresh graduates have no Pyth or Chainlink feed, so dKLP marks come from two legs:
- Primary: TWAP off the FrothSwap pair, whose burned LP makes its depth permanent. Moving that TWAP means holding a bad price against arbitrage through that depth for the full window.
- Secondary: a protocol signed median feed that samples the FrothSwap pair plus external pools and publishes a signed median for the mark-price path.
- The mark price is a bounded combination of both legs, with circuit breakers on top: per-candle move limits, OI freezes on deviation, and per-position profit caps as the final bound.
OPENS CAN PAUSE; EXITS STAY OPEN
The signed median is a protocol oracle input, not the sole mark. It is always cross-checked against the TWAP and constrained by the deviation pauses and profit caps. Seasoned tokens with multi-venue volume can graduate to independent custom feeds.