Launch approvers & operators
Bounded market sequence, exposure limits, liquidity plan, halt rules and approvals.
STONK launch mechanics and liquidity memo
Status: proposed baseline, not market authorization Evidence date: 2026-07-20 Applies to: Robinhood Chain mainnet, chain ID 4663
No value in this memo authorizes a funded market, treasury withdrawal, token distribution, or public launch. Final values require the approvals and evidence in docs/security/LAUNCH-GATES.md.
Decision
Launch STONK through sequential USDG bond tranches and place all protocol-owned secondary-market liquidity in one full-range Uniswap v2 STONK/USDG pool.
- Deploy and verify the protocol with zero markets first.
- Issue no premine, airdrop, scheduled emission, or free team allocation.
- Bootstrap 250,000 STONK through four non-overlapping USDG bond tranches.
- Keep aggregate live unsold capacity at or below 75,000 STONK.
- Seed at most 25,000 USDG of treasury capital into one Uniswap v2 pool only after the USDG tranches conclude.
- Require the STONK side of initial liquidity to be acquired through disclosed bond purchases or secondary purchases and contributed by a bootstrap sponsor. It must not be freely minted.
- Transfer all resulting v2 LP tokens to TRSRY, do not register the LP token in PRICE, and value it at zero for backing.
- Open no equity bond market until a live STONK price, liquidity history, governance participation, and operational record exist.
- Open no LP-token bond market at launch. Reconsider a capped acquisition tender only after the later gates in this memo pass.
This separates four jobs that should not be forced into one instrument:
| Job | Mechanism |
|---|---|
| external backing | USDG bonds, then individually approved reserve bonds |
| initial distribution | sequential capacity-capped bond tranches |
| price discovery | descending bond prices followed by a pool seeded at the conservative observed price |
| durable liquidity | directly contributed, protocol-owned Uniswap v2 liquidity |
Current evidence
Robinhood Chain venues
The following is a point-in-time venue snapshot, not a durable assumption. Recheck official deployments, live code, TVL, volume quality, routing, and user-interface support within 24 hours of every launch transaction.
| Venue | Observed role | 2026-07-20 snapshot | Launch use |
|---|---|---|---|
| Uniswap | primary public AMM; v2, v3, v4, and UniswapX | about $560.3 million combined 24-hour DEX volume and $21.42 million AMM TVL | canonical STONK liquidity venue |
| Arcus | stock-token spot and perpetual venue | about $4.26 million 24-hour spot volume | possible later listing; not initial POL custody |
| Liquid Labs | launch and AMM products | about $3.05 million 24-hour reported volume but only about $20,000 Robinhood Chain TVL | no launch allocation; activity is not matched by durable depth |
| Rialto | PropAMM and aggregator | about $1.25 million 24-hour volume; official venue with proprietary and institutional liquidity | request routing or market-maker support; hold no core POL there |
| PancakeSwap | public AMM | about $0.98 million 24-hour volume and about $43,000 AMM TVL | no launch allocation |
| long tail | launchpads and small AMMs | fragmented or immature liquidity | no launch allocation |
Sources:
- Robinhood Chain lists Uniswap as its public DEX and Rialto as its PropAMM/aggregator: https://docs.robinhood.com/chain/.
- Uniswap confirms v2, v3, v4, UniswapX, Web App, Wallet, and API support on chain 4663: https://blog.uniswap.org/robinhood-chain-is-live.
- Point-in-time DEX volume and AMM TVL: https://defillama.com/dexs/chain/robinhood-chain and https://defillama.com/protocols/amm/robinhood-chain.
- Rialto describes its proprietary baseline liquidity and institutional market-maker model: https://rialto.ghost.io/introducing-rialto/.
Verified Uniswap v2 deployment
Official deployment documentation identifies:
| Contract | Address |
|---|---|
| Uniswap v2 factory | 0x8bceaa40b9acdfaedf85adf4ff01f5ad6517937f |
| Uniswap v2 Router02 | 0x89e5db8b5aa49aa85ac63f691524311aeb649eba |
| canonical USDG | 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168 |
| WETH returned by Router02 | 0x0Bd7D308f8E1639FAb988df18A8011f41EAcAD73 |
At Robinhood Chain block 15105794, an independent public-RPC read confirmed:
- chain ID
4663; - non-empty runtime code at the factory, router, and USDG addresses;
Router02.factory()equals the factory above;Router02.WETH()equals the canonical WETH above;- USDG reports symbol
USDGand 6 decimals; and factory.feeTo()was zero, so the v2 protocol fee was not active at that block.
The official v2 deployment registry is https://developers.uniswap.org/docs/protocols/v2/deployments. Never reuse these addresses without a fresh code, interface, and official-registry check.
Protocol constraints
The plan respects the deployed contract model:
- production deployment creates zero bond markets;
- BondDepository can issue STONK only after an approved ERC-20 quote asset arrives in TRSRY;
- payout cannot exceed the received quote asset's risk-adjusted value;
- Timelock holds the production
bond_adminandcustodianroles; - TreasuryCustodian refuses a withdrawal that would leave recognized reserves below total STONK supply;
- the guardian can stop MINTR and TRSRY but cannot create or close a market, withdraw assets, or restart modules;
- stSTONK is the only voting asset; and
- the genesis Safe is a temporary Timelock proposer, not an executor or protocol administrator.
The current system has no DEX adapter, liquidity manager, LP oracle, LP fee collector, or privileged non-bond mint path. This memo does not assume one.
Initial issuance plan
Common rules
- Quote asset: canonical USDG only.
- Markets must not overlap. The next tranche may open immediately after the previous tranche fills or concludes.
- Verify supply, reserves, backing, notes, price status, aggregate unsold capacity, and control-plane state before every tranche.
maxPayoutis an accident and transaction-size bound, not a per-address allocation cap. The contract cannot prevent one participant from using multiple addresses or transactions.- Every bond note vests linearly under the current contract. Marketing must not describe the duration as a cliff.
- A tranche that does not fill is information. Do not raise its discount or capacity automatically.
Proposed tranches
| Tranche | Capacity | Max payout per deposit | Start price | Price floor | Decay | Bump | Vesting | Maximum duration |
|---|---|---|---|---|---|---|---|---|
| canary | 25,000 STONK | 1,000 STONK | $1.30 | $1.25 | $0.01/day | 200 bps | 7 days | 7 days |
| bootstrap 1 | 75,000 STONK | 3,000 STONK | derived below | at least $1.20 | start-to-floor over 7 days | 200 bps | 7 days | 7 days |
| bootstrap 2 | 75,000 STONK | 3,000 STONK | derived below | at least $1.20 | start-to-floor over 7 days | 200 bps | 7 days | 7 days |
| bootstrap 3 | 75,000 STONK | 3,000 STONK | derived below | at least $1.20 | start-to-floor over 7 days | 200 bps | 7 days | 7 days |
For each bootstrap tranche:
reference = previous tranche terminal price
start = clamp(reference x 1.025, $1.20, $1.40)
floor = max($1.20, start - $0.10)
decayPerDay = (start - floor) / 7
Round prices conservatively upward to whole PRICE units supported by proposal tooling. Publish the calculation and resulting exact integers with the proposal.
The bump raises price as capacity sells. It is intentionally modest and does not make this a uniform-price auction. The terminal and volume-weighted prices are demand signals, not declarations of fair value.
Issuance and backing envelope
At the stated minimum prices and full subscription:
| Item | Amount |
|---|---|
| STONK issued | 250,000 |
| canary USDG received | 31,250 |
| bootstrap USDG received | 270,000 |
| minimum direct USDG received | 301,250 |
| direct backing before POL | $1.205 per STONK |
If every bootstrap tranche sold at $1.40, maximum total USDG proceeds would be $347,500. Actual proceeds will fall between these bounds according to executed prices.
The maximum incremental issuance exposed to one live-market or sequencer incident is 75,000 STONK. Mainnet genesis contains no market templates or live capacity. A proposal or post-state showing more than 75,000 aggregate live unsold STONK is a launch blocker.
Price discovery and pool initialization
STONK's bond curve is a bounded descending-price sale, not a true clearing auction. Uniswap's Continuous Clearing Auction is not currently exposed for Robinhood Chain in the official Auctions interface, and its Robinhood-specific strategy factories are not documented as deployed. It also does not fit STONK's reviewed BondDepository-only mint path. Do not introduce it during launch without a new integration review and audit.
After all four USDG tranches close, calculate:
P_seed = clamp(min(all-tranche bond VWAP, final-tranche terminal price), $1.20, $1.40)
Use onchain Bond events and exact received USDG/payout amounts. Publish the event range, calculation script, output, and independent recomputation. If the two calculations disagree, do not initialize the pool.
Do not open another bond market until at least seven days after pool initialization. There must never be a live bond floor below the newly initialized pool price at genesis.
Protocol-owned liquidity
Canonical pool
- Venue: Uniswap v2.
- Pair: STONK/USDG.
- Fee: the factory's live v2 fee behavior; model 30 bps but stress 25 bps if a protocol fee is activated.
- Range: full range by v2 design.
- Hooks or custom pool logic: none.
- Alternative DEX allocations: zero.
- LP valuation for backing: zero.
V2 is selected for the initial pool because its fungible LP token, passive full-range position, simple custody, and lack of a rebalancing operator fit the current TRSRY and Timelock model. V3 or v4 concentrated liquidity may use capital more efficiently but adds position-NFT custody, range selection, fee collection, and maintenance dependencies. Those are later optimizations.
Initial POL sizing
Treasury USDG contribution is:
USDG_POL = min(25,000, riskAdjustedDirectReserves - 1.10 x STONK_totalSupply)
STONK_POL = USDG_POL / P_seed
If this produces less than 20,000 USDG, do not initialize a smaller pool automatically. Return for explicit risk approval or use a separately funded market maker.
At the worst-case issuance proceeds:
| Item | Amount |
|---|---|
| direct reserves before POL | $301,250 |
| maximum treasury USDG contribution | $25,000 |
| direct reserves after POL withdrawal | $276,250 |
| direct backing after withdrawal | $1.105 per STONK |
| LP value counted as backing | $0 |
| initial pool TVL at target size | approximately $50,000 |
| maximum treasury USDG inventory exposed to the AMM | $25,000 |
At P_seed from $1.20 to $1.40, the sponsor must contribute approximately 20,833 to 17,857 STONK. The sponsor must acquire those tokens through disclosed bond deposits or secondary purchases. If that contribution is unavailable, do not mint replacement STONK and do not withdraw treasury USDG.
Bootstrap transaction sequence
The current protocol cannot atomically withdraw treasury USDG and add v2 liquidity. Use a dedicated, canonical 2-of-3 liquidity-bootstrap Safe with no module, guard, or nonstandard fallback configuration and with an explicit retirement procedure.
- Verify the v2 factory/router code, interfaces, factory linkage, USDG identity, STONK identity, and that
factory.getPair(STONK, USDG)is zero. - Verify the signed sponsor contribution is already available.
- Publish decoded Timelock calldata withdrawing no more than
USDG_POLfrom TRSRY to the bootstrap Safe. - Simulate the Timelock execution and subsequent Safe transaction at a named current block.
- Execute the withdrawal only after the Timelock delay.
- In one Safe transaction, approve exact amounts and call Router02
addLiquiditywith 50 bps minimum-amount protection, a short deadline, and TRSRY as the LP recipient; then clear residual approvals where supported. - Return all USDG and STONK dust to TRSRY or its original contributor according to the published transaction specification.
- Verify the pool reserves, price, LP supply, locked minimum liquidity, TRSRY LP balance, Safe balances, approvals, and direct backing from an independent RPC.
- Retire the empty bootstrap Safe operationally: verify zero balances and approvals, preserve its owners for forensic continuity, prohibit reuse, and monitor it until the launch evidence is archived.
If a pair already exists, any code or address differs, the implied pool price differs from P_seed, or another party changes the pool before execution, stop and produce a new plan. Never add treasury liquidity to an unreviewed pre-existing pair.
Initial execution quality
At the worst-case P_seed = $1.20, a $50,000 v2 pool contains about 20,833 STONK and 25,000 USDG. Ignoring gas and assuming a 30 bps swap fee, a STONK sale into that pool has approximately:
| STONK sold | USDG received | Average price | Deviation from initial price |
|---|---|---|---|
| 100 | 119.07 | $1.1907 | 0.77% |
| 500 | 584.22 | $1.1684 | 2.63% |
| 1,000 | 1,141.76 | $1.1418 | 4.85% |
| 2,500 | 2,671.39 | $1.0686 | 10.95% |
| 5,000 | 4,827.00 | $0.9654 | 19.55% |
This is beta liquidity, not institutional depth or a price floor. The frontend must show expected output and price impact and must not imply that backing is redeemable through the pool.
Fee and inventory economics
At $50,000 POL value, approximate gross annual v2 fees are:
| Average daily volume | 30 bps LP fee | Gross annual return on initial POL | 25 bps stressed LP fee | Stressed annual return |
|---|---|---|---|---|
| $1,000 | $1,095 | 2.19% | $912.50 | 1.83% |
| $5,000 | $5,475 | 10.95% | $4,562.50 | 9.13% |
| $10,000 | $10,950 | 21.90% | $9,125 | 18.25% |
These are gross figures before gas, management, adverse selection, inventory change, token impairment, or tax. Do not advertise them as APY.
Constant-product divergence loss relative to passively holding both assets is approximately:
| STONK price multiple | Divergence loss |
|---|---|
| 0.5x or 2x | 5.72% |
| 0.25x or 4x | 20.00% |
| 0.1x or 10x | 42.50% |
The protocol accepts this inventory behavior to provide durable execution. Its hard launch loss budget is the $25,000 USDG placed into the pool; the LP must still be valued at zero for backing.
Initial distribution and governance bootstrap
At 250,000 STONK total supply:
- no address receives free STONK;
- approximately 17,857 to 20,833 sponsor-acquired STONK enters POL;
- the remainder stays with disclosed bond purchasers unless transferred or staked;
- the protocol does not vote the STONK held inside the LP position; and
- a transaction-level
maxPayoutdoes not establish one-person-one-allocation.
The genesis Safe may remain a Timelock proposer until all of these are independently verified:
- stSTONK total supply is at least 100,000 shares.
- At least 80% of outstanding stSTONK has delegated voting power.
- At least 20 addresses hold delegated voting balances.
- At least two non-genesis delegates independently exceed the 100 stSTONK proposal threshold.
- No single non-protocol delegate controls more than 25% of delegated votes.
- A non-critical Governor proposal completes proposal, delay, voting, queue, Timelock delay, and execution.
- That proposal receives participation of at least 10% of stSTONK supply and at least 2.5 times the required quorum, whichever is greater.
- Monitoring and incident response remain operational throughout the exercise.
Once all criteria pass, publish and schedule genesis proposer revocation within seven days. Do not treat nominal token distribution or the bare 4% quorum threshold as credible governance bootstrap by itself.
Later reserve bonds
Preconditions
Open no post-bootstrap reserve market until all are true:
- the canonical pool has operated for at least 14 continuous days;
- seven-day median daily organic volume is at least $5,000;
- protocol LP ownership and pool code have not changed unexpectedly;
- the pool retains at least 20,000 USDG quote reserves;
- direct risk-adjusted backing is at least $1.10 per STONK;
- stSTONK and delegation meet the governance-retirement thresholds above;
- there has been no unresolved oracle, sequencer, token-control, Safe, Timelock, frontend, or monitoring incident; and
- the proposed quote token passes fresh issuer, admin, pause, blocklist, upgrade, feed, liquidity, and legal review.
Exclude known protocol, sponsor, market-maker, wash-trading, and self-routing addresses when assessing organic volume. Volume alone is not evidence of demand.
Pricing rule
For a quote asset with haircut h, target new-issuance backing B = 1.10, maximum intended bond discount d = 5%, and conservative seven-day STONK/USDG TWAP S:
backingFloor = B / (1 - h)
targetBondPrice = max(backingFloor, S x (1 - d))
Round the target upward. A market is uneconomic and must not open unless S >= backingFloor / (1 - d).
Examples:
| Quote type | Haircut | Minimum bond price | Minimum TWAP for a 5% discount |
|---|---|---|---|
| USDG | 0% | $1.10 | $1.158 |
| configured equity | 10% | $1.223 | $1.287 |
For additional conservatism, the first equity market uses a $1.25 price floor, requiring a seven-day TWAP of at least $1.316 before offering a 5% discount.
Set startPrice = targetBondPrice + $0.05, minPrice = targetBondPrice, decay no faster than $0.01 per day, bump 200 bps, duration seven days, and vesting 14 days. Recompute all values for every market; never copy a stale proposal.
First equity canary
If the preconditions pass, prefer diversified SPY exposure over a single-company token for the first volatile reserve canary, subject to live token/feed/legal verification.
| Parameter | Limit |
|---|---|
| capacity | 10,000 STONK |
| max payout per deposit | 500 STONK |
| duration | 7 days |
| vesting | 14 days |
| minimum price | $1.25 |
| aggregate live volatile capacity | 10,000 STONK |
After 30 incident-free days, governance may consider up to 25,000 STONK per market and 25,000 aggregate live unsold capacity. Risk-adjusted volatile reserves remain capped at 20% of the treasury, one asset at 5%, and one sector at 10%. These are ceilings, not targets.
LP-token bonds
Do not enable LP-token bonds at launch. A STONK/USDG LP position contains STONK itself, so full-NAV backing would reflexively count the protocol's own liability. The current PRICE system also has no manipulation-resistant LP valuation, constituent accounting, or pool allowlist.
After at least 60 days, governance may consider a one-time LP acquisition tender only if:
- meaningful externally owned liquidity exists in the canonical pair;
- pool ownership concentration and position provenance are known;
- an audited adapter validates the exact factory, pair, constituents, reserves, and LP supply;
- valuation counts only conservatively withdrawable external assets and gives no backing credit to the STONK constituent;
- the acquired LP is transferred directly to TRSRY;
- acquisition capacity is fixed and expiring;
- the modeled subsidy is cheaper than direct POL, a market-maker agreement, or doing nothing; and
- the transaction preserves at least $1.10 of direct risk-adjusted backing per STONK without crediting the acquired LP.
Prefer a decoded governance tender over an evergreen permissionless market for the first acquisition.
Runtime limits and halt rules
| Condition | Required action |
|---|---|
| aggregate live unsold capacity exceeds the active phase cap | guardian shuts down MINTR; investigate proposal/post-state failure |
| direct risk-adjusted backing below $1.10 | authorize no new market, capacity, or POL withdrawal |
| direct backing below $1.05 | guardian shuts down MINTR and frontend disables bonding |
| direct backing below $1.00 | guardian shuts down MINTR and TRSRY; incident response starts |
| USDG observed below $0.98, invalid, stale, or materially divergent across sources | shut down MINTR; disable bonds; investigate |
| sequencer outage or early recovery while STK-001 remains active | shut down MINTR and TRSRY; disable writes |
| protocol LP balance changes unexpectedly | critical treasury incident |
| pool USDG reserve below $20,000 | no capacity increase or new reserve market |
| pool USDG reserve below $15,000 | show degraded-liquidity warning and investigate market-making options |
| 500 STONK sale has more than 5% modeled price impact | show degraded-liquidity warning; do not scale issuance |
| spot deviates more than 15% from one-hour TWAP | disable bond prompts and investigate manipulation or news |
| live bond price is more than 10% below conservative STONK TWAP | guardian shuts down MINTR pending governance review |
| enabled reserve token pauses, upgrades, blocklists protocol custody, or changes metadata | shut down MINTR and affected frontend paths |
| monitoring, independent RPC, or incident responders are unavailable | open no market and execute no POL transaction |
At the minimum-proceeds baseline, direct reserves after the maximum POL contribution can tolerate about a 9.5% uniform USDG impairment before falling below $1.00 per STONK. The operational halt at $0.98 intentionally acts much earlier. A slow depeg may pass PRICE's round-to-round deviation check, so independent absolute-price monitoring is mandatory.
Rollout transactions and evidence
Zero-market deployment
- complete every blocking launch gate;
- deploy from the frozen candidate;
- verify source, runtime hashes, Safes, roles, assets, feeds, sequencer disclosure, vault, Governor, Timelock, and zero markets from an independent RPC; and
- release the mainnet UI in read-only mode.
Each USDG tranche
- publish exact
createMarketcalldata and decoded units; - publish current and proposed aggregate unsold capacity;
- simulate against a current fork;
- schedule through the genesis Safe and Timelock;
- independently verify the live market and mint approval after execution;
- monitor every deposit, note, price, and backing change; and
- publish the fill/conclusion report.
POL creation
- publish the price calculation, sponsor proof, Safe transaction, router parameters, expected pair address, expected LP output and post-state lower bound, backing before/after, and failure procedure;
- execute the bootstrap sequence above; and
- archive independent post-state verification.
Governance retirement
- publish delegation and participation evidence;
- execute a non-critical Governor proposal end to end;
- schedule and execute genesis proposer revocation; and
- independently verify final Timelock roles.
First reserve market
- publish live-market, backing, concentration, TWAP, volume-quality, token-control, oracle, and legal evidence;
- apply the pricing formula and caps above;
- simulate and execute one SPY canary only; and
- observe for 30 days before any additional volatile capacity.
Required human approvals
The following fields remain intentionally unresolved and block funded launch:
| Decision | Approval |
|---|---|
| accept or revise the 250,000 STONK bootstrap target | engineering/security and operations/risk |
| accept the 75,000 maximum live unsold capacity | engineering/security and operations/risk |
| fund or identify the sponsor-acquired STONK contribution | named sponsor and Safe owners |
| accept the $25,000 treasury AMM inventory loss budget | engineering/security and operations/risk |
| approve Uniswap v2 and the dedicated bootstrap Safe workflow | security reviewers and independent auditor |
| approve jurisdiction, access, tokenized-equity, bond, and public-copy treatment | qualified legal counsel |
| accept STK-001 exposure and expiry | two named STK-001 approvers |
| authorize the first equity canary | governance after all later-market gates pass |
If an approver changes a number, recompute every dependent amount, backing ratio, price-impact table, concentration limit, and halt threshold before authorization.
Acceptance criteria
This plan is ready for execution only when:
- all required human approvals are named, signed, dated, and linked;
- the independent audit covers the exact contracts and operational workflow used;
- current official and onchain DEX deployment verification matches this memo;
- proposed market-calldata checks enforce the active capacity and pricing limits;
- monitoring implements and fire-tests every halt condition;
- the frontend accurately presents vesting, backing, liquidity, price impact, and risk;
- fork simulations cover every Timelock and Safe transaction;
- an independent operator can reproduce every calculation and post-state assertion; and
- production still has zero markets until the separately approved canary proposal executes.