# StonkBrokers on Robinhood Chain — protocol deep dive

Generated 2026-08-16. Primary source: [official StonkBrokers documentation](https://stonkbrokers.io/docs). Chain observations are pinned to Robinhood Chain block **38,127,520** (`0xefbf…44e0`, 2026-08-16 16:42:21 UTC). “Documented” below means a first-party claim; “observed” means reproduced by the local collector. Neither means audited or safe.

## Executive thesis

StonkBrokers is not one contract system. It is three economic machines sharing the STONKBROKER token, broker NFTs and Clock In reward sink:

1. **Anvil NFT AMM** makes each broker a fixed-price trade and collateral unit. Activation then turns it into a tier-weighted recipient whose payout route can be elected by its owner.
2. **Safety Deposit Box** wraps time-bounded liquidity custody in a transferable ownership NFT. The lock deed separates fee-collection and eventual withdrawal rights from the original depositor.
3. **Broker Box** pairs inventory-backed chance games with fully collateralized bearer certificates. Both depend on stock-token routes; the game additionally depends on certified future entropy, price feeds and liability reservations.

The chain evidence confirms runtime bytecode at all **33 documented mainnet addresses**: 29 first-party addresses and four shared external dependencies. Blockscout reported verified source for all 33 at collection time. That is strong deployment evidence, not proof of the docs’ accounting, ownerless, solvency or randomness claims. See the [machine-readable audit](evidence/contract-audit.json).

## Anvil: a broker as inventory, collateral and reward weight

The collection is documented as 4,444 minted-out ERC-721s with ERC-6551 token-bound accounts. On Anvil, the ordinary buy path exchanges **666,666 STONKBROKER plus an ETH fee** for the next broker in vault inventory; snipe selects a particular broker. The docs state native fees of 10% for a swap and 15% for a snipe ([Anvil section](https://stonkbrokers.io/docs#anvil-nft-amm)).

Activation creates the payroll state. Stated token fees rise from 66,666 at Base to 1,666,666 at T4 while weights rise from 100× to 333×. The default split is 50% burn / 50% protocol, and a true ownership transfer clears activation. This makes the reward right intentionally non-portable even though the token-bound wallet travels with the NFT.

Clock In v2 replaces the retired Stock Booster v1 and Overtime paths. An activated broker may direct its share to as many as three listed tokens; when the reward pot is ready, any caller can crank the process, swap by aggregate election, and credit brokers pro rata by tier. The docs expressly classify these as promotional marketing rewards rather than dividends ([activation and distributions](https://stonkbrokers.io/docs#activation-distributions-clock-in), [legal disclaimer](https://stonkbrokers.io/docs#disclaimer-rewards-are-not-dividends)).

### Loans

The Loan Vault uses the same 666,666 STONKBROKER anchor as full principal. The documented borrower pays a 15% APR fee on ETH notional up front, receives token principal, and escrows a broker. Repayment returns exactly the principal; overdue loans add an ETH late fee. The fee split is stated as 70% StockBooster / 30% protocol ([loans](https://stonkbrokers.io/docs#loans)).

The symmetry is legible, but it creates shared risk: the usefulness of the loan principal depends on STONKBROKER liquidity and the AMM exit path. Runtime code at the AMM Vault, Loan Vault, Escrow and Activation Manager was observed; economic invariants were not formally proved.

## Safety Deposit Box: transferable rights over time-locked liquidity

The docs describe five desks—Uniswap V3, Uniswap V4, up. Slipstream, up. v2 and plain-token vesting—while publishing addresses for the V3/V4 locker cores, their ownership NFTs, and the fee router. All five published first-party addresses had runtime bytecode at the pinned block.

Each lock chooses an immutable fee mode and time window. The current advertised modes are 0.5% of principal up front or 20% of collected swap fees; a legacy 1%-on-withdraw mode remains for old locks. Hard locks delay all principal until the end window, linear locks vest continuously, and permanent locks use a maximum timestamp so release never begins. The transferable lock NFT carries collection, vested-withdrawal and release authority ([Safety Deposit Box](https://stonkbrokers.io/docs#safety-deposit-box-liquidity-locker)).

Locker protocol fees are documented to flow through Safety Deposit Clock In with a 90% community / 10% protocol split. ETH/WETH feed the Stock Booster pot; other tokens create pull-based allocation rounds for activated broker wallets. The docs call this router ownerless. This review observed code and generic proxy state but did not reconstruct every role or mathematically prove early withdrawal impossible. The linked Hashlock-certified report is a first-party-linked audit artifact, not re-performed here.

## Broker Box: certificates plus inventory-backed chance

Nine production machines are documented for GME, AAPL, AMZN, NVDA, GOOGL, MSFT, SLV, SPCX and USO. All nine had runtime bytecode at the pinned block and Blockscout reported verified source. They share a Factory, Stonk Certificate collection, Certificate Counter, VRNG Conductor, USDG/ETH Exchange and StonkStockRouterV2.

### Certificate Counter

The counter is documented as a non-chance 1× purchase: ETH, minus a flat $2 fee, routes to stock; exact output is sealed inside the certificate’s ERC-6551 vault. The deed is transferable and the stock should leave only when redemption burns the deed. The fee splits $1 to StockBooster and $1 to treasury. The docs state a 3.33% certificate royalty capped at 5% ([Broker Box](https://stonkbrokers.io/docs#broker-box-world-wide-stonk-exchange)).

### Degen Mode

Tickets use ETH or USDG. A round reserves enough stock for the worst 50× outcome before accepting a pull. Once future entropy is fulfilled, stock settles to the player, who may keep it, seal the full amount into a certificate, or sell it back for 95% of the live mark. The documented prize table ranges from 0.70× to 50× and sums to a **90.00% design RTP**. Design RTP is a bytecode distribution claim, not a user return guarantee.

The stated 10% game edge is 2.5% creator, 2.5% StockBooster and 5% protocol. Official machines route creator share to StockBooster. A separate 5% sell-back spread stays in bankroll. The important solvency boundary is therefore free inventory minus reserved worst-case payouts and player-owed amounts—not the contract’s raw token or ETH balance.

### Randomness and liveness

The production path uses DERP-certified future entropy rather than Chainlink VRF. A pull commits before its word exists; production machines are described as reading three prints ahead with a roughly 45-second settle-delay floor. Anyone may fulfill after the word exists. If entropy health fails, new sales should stop while settlement, rescue, redemption and cash-out remain open; an unfulfilled pull becomes refundable after 48 hours.

This architecture limits selective aborts only if the conductor, certified-print rules, machine integration and fulfillment math behave as described. This run did not independently reproduce a round or recompute a word. Conductor liveness and miner concentration remain external risks.

## Stonk Exchange and external dependency boundary

The docs call the up.-powered ve(3,3) exchange live for swaps, v2/Slipstream liquidity and gauges, while its separate pool section still says “coming soon” and demonstrates a Uniswap V3 PositionManager. That copy conflict is preserved rather than silently resolved. The four shared addresses in this inventory—WETH9, Uniswap V3 PositionManager, Uniswap V4 PoolManager and V4 PositionManager—are external and excluded from first-party contract counts.

The exchange adds UP emissions, gauge governance, route liquidity and tokenized-stock dependencies. Integrators should heed the docs’ warning that Slipstream uses `int24 tickSpacing`, not Uniswap V3’s fee-keyed pool convention ([Stonk Exchange](https://stonkbrokers.io/docs#the-stonk-exchange-powered-by-up-vdex)).

## Lifecycle and legal boundary

- **Live/documented:** NFT collection, STONKBROKER, Anvil trade, activation, Clock In v2, loans, V3/V4 locker contracts, Stonk Exchange, Certificate Counter and nine Broker Box machines.
- **Retired but deployed:** Clock In v1 and Overtime Booster. They remain in evidence for historical completeness and are never counted as current routes.
- **Upcoming:** Stonk Launcher, permissionless community Broker Boxes and covered-call options. No official mainnet address was supplied for LauncherFactory or CoveredCallVault, so neither appears in the mainnet inventory.
- **Testnet archive:** the faucet and demo Uniswap/launcher addresses belong to chain 46630 and are excluded.
- **Regional/legal:** the docs restrict stock-token play and counter minting in the United States; settlements, rescues, redemptions and cash-outs are said to remain available. Rewards are expressly not dividends, equity, profit share or investment income.

## Risk register

1. **Contract and role risk:** verified source is not an audit; custom admin patterns may evade generic EIP-1967 checks.
2. **Solvency risk:** raw balances do not establish free inventory after reservations, owed payouts and protocol accrual.
3. **Oracle/route risk:** stock prices, USD conversion and sell-back depend on external feeds and executable liquidity routes.
4. **Entropy/liveness risk:** a healthy DERP print cadence is required for new games and prompt settlement.
5. **Liquidity coupling:** STONKBROKER anchors AMM buys and loan principal, joining NFT liquidity and token liquidity.
6. **Custody semantics:** transferable lock deeds are powerful bearer instruments; loss or sale transfers economic rights.
7. **Product-status ambiguity:** live/upcoming language is internally inconsistent around exchange pool tooling.
8. **Regulatory risk:** tokenized-stock and chance-game access is jurisdiction-sensitive and UI geofencing is not an on-chain guarantee.

## Reproduction

Run `node scripts/collect-stonkbrokers-evidence.mjs` for a new pinned snapshot, then `node scripts/test-stonkbrokers-artifacts.mjs`. The HTML source archived during this run is `evidence/primary-docs.html`; URLs, hashes, commands and limitations are recorded in `release-receipt.json`.
