The treasury
Two percent of every trade enters the market's TreasuryVault, comes out as tokenized
stocks, and is airdropped to the token's holders. Here is the full path.
The three actors
The trader does nothing special: they buy or they sell. The fee is taken by the hook in the same transaction.
The contracts decide everything. The vault knows which basket it must hold, at which price bounds it will trade, and what it refuses. No function changes the basket. The price bounds and the conversion threshold are settings of StockFun's owner since 2026-10-05, read live by every vault; beyond them, only an upgrade of the vault by StockFun's owner can change its rules.
The keeper is an offchain worker that only triggers. It picks the moment, names the amount of each step, and proposes routes and minimum amounts, which the vault refuses if they are looser than its own price bound; it chooses neither the assets, nor how the cash is split between them, nor the prices. Whatever it names, it cannot divert an asset, loosen a bound, change the basket's weights, or choose who receives the airdrop.
The path
NVDA · MSFT · GOOGL · SPY · QQQ] S -->|wrapped, to Ethereum| AD[AirdropDistributor] AD -->|airdrop, 100 %, pro rata| H[Token holders]
Every leg is bounded by an independent Chainlink oracle: by default 50 basis points on ETH → USDC, 200 on the leg that buys the stocks. The vault measures what it actually receives and refuses the transaction if it falls short of the keeper's minimum, itself never looser than the bound (since 2026-10-05; until then, short of the bound). It trusts neither the keeper, nor the rail, nor the price it is quoted.
The conversion threshold
The vault does not convert on every trade. Once every 24 hours, just before the airdrop, it converts what it has accumulated — provided that is at least 0.1 ETH, the default threshold. Below that, gas and slippage would eat the operation: nothing happens that day, and the ETH waits for the next cycle, even if trades take it over the threshold later that day. The keeper checks it at its first pass after the airdrop window closes, 13:00 UTC by default; it holds to this since 2026-10-06, and until then converted a vault's ETH at any of its passes during the session once the vault held the threshold.
The default threshold is calibrated so a market that has exhausted its first liquidity band has always crossed it: by then it has received about 0.159 ETH, and it converts at the next daily cycle.
Since 2026-10-01 each step converts an amount the keeper names, never less than the threshold on the ETH step, instead of the whole balance. A vault that has grown past what its venue fills within the bound converts in slices, and the rest waits for the next cycle. Until then, such a vault could never convert again.
The basket's weights
The cash is set aside stock by stock, at the basket's weights, as it arrives. Each stock
spends only its own share. A stock that cannot be bought on a given day, because its issuer
froze it, its feed went quiet, its pool is too thin or, since 2026-10-06 on Robinhood Chain,
it is going through a corporate action that pauses its token's oracle, keeps its share for a
later cycle.
Since 2026-10-05 its leg fails on its own (LegFailed), and the basket's other stocks are
bought in the same call; until then one failing leg made the whole purchase fail.
Since 2026-10-01 the keeper therefore cannot change the composition by skipping stocks. Before, a skipped stock's share was split again across the whole basket.
Since the security pipeline of 2026-10-01, an emergency that takes a vault's cash below what is reserved voids every reservation: what is left, and every later inflow, is split afresh at the weights. See Emergency mode. At each purchase, the keeper holds back n−1 units of the last stock's share, n being the number of stocks; they stay reserved for the next call. See The keeper.
What a vault can hold
At any instant a vault holds a mix of:
- ETH — received, not yet converted
- USDC then USDG — in transit to the remote chain
- Tokenized stocks — the final state, on Robinhood Chain
All three are shown as the treasury awaiting the next airdrop; only stocks are distributed, once bought. A vault full of USDC is not a broken vault; it is a vault in transit.
What cannot happen
Nobody can withdraw from a vault. No withdraw, no transfer, no sweep, no owner:
calling them fails because they do not exist.
A treasury's assets leave it in three ways only: conversion into tokenized stocks, the hand-over of those stocks to the airdrop contract for the token's holders, and emergency mode, by which StockFun's owner moves them to any address, at once. Nothing else in the current code can move them. Since 2026-10-02 StockFun's owner can upgrade the vault, with immediate effect: see Trust model.
Two contracts besides the vaults hold the protocol's assets for several markets at once:
the airdrop contract and the remote hub. Since 2026-10-05, after an emergency transfer out
of either, no market is paid with another's assets, not even with assets that have arrived
for another market and are not credited yet: what is missing waits until the assets are
brought back (restore; a plain transfer does not count), or until StockFun's owner writes
the loss off the market that suffered it. Only what is missing waits: a claim still pays the
other stocks, and an emergency transfer charged to one market on the remote hub keeps every
other market's payouts going. See Emergency mode.