Docs

How a coin fledges

Two small contracts with no owner. Everything else is Uniswap and Robinhood’s own stock tokens.

The coin

Every Fledge coin is a clone (EIP-1167) of one contract, FledgeCoin. It is an ordinary ERC-20 with 18 decimals and a fixed supply of 1,000,000,000, all of which starts inside the coin itself: 800,000,000 to sell on its curve, and 200,000,000 held back for its Uniswap pool. Each launch also creates the coin’s 1% Uniswap v3 pool against WETH, which stays empty until the coin fledges.

The curve

Until it fledges, the coin is its own market: a constant-product curve between the curve coins it still holds, plus 266,666,666.67 virtual coins, and a reserve of ETH that starts with a virtual 1 ETH. A buy of net ETH after the fee receives coinReserve × net ÷ (ethReserve + net) coins, rounded down. A sale is the mirror image. The page computes both with the contract’s own integer formulas and sends a minimum 1% below its quote.

The virtual coins are chosen so the numbers meet exactly. Selling all 800M curve coins raises exactly 3 ETH, and the curve’s last price, (1 + 3) ETH ÷ 266.67M coins, equals 3 ETH ÷ 200M coins, the price at which the raised ETH and the held-back coins are worth the same. So the pool opens at the price the curve ended on, with no jump for anyone to snipe. A new coin starts at a market cap of 0.94 ETH and fledges at 15 ETH.

The fee

Chosen at launch, from 0.25% to 10% in steps of 0.25%, and stored in the coin. No function changes it: there is no owner and no admin, in the coin or in the factory. Every buy and every sell on the curve pays it, in ETH, and none of it goes to the creator or to Fledge. After fledging, the pool’s own 1% fee takes over (see below).

Fledging

The buy that takes the last curve coin pays only what the rest of the curve costs, and the remainder of what it sent is refunded in the same transaction. Then, still in that transaction, the coin:

  1. closes the curve for good (buy and sell now refuse with CurveClosedAlready), and wraps the ETH it raised into WETH;
  2. computes the pool price at which that ETH and the 200M held-back coins are worth the same, and opens the pool there;
  3. adds all of it as one full-range position owned by the coin contract. The pool rounds amounts up, so a few wei of dust can be left over: leftover coins are burned and leftover ETH goes to the nest.

The coin contract has no function that removes liquidity, and no owner who could add one. The position stays in the pool for good.

Nobody gets into the pool first. Until the coin has fledged, the coin refuses any transfer into its own pool, so nobody can add liquidity on the coin’s side there. Someone can still open the empty pool at a price of their choosing, and add liquidity that holds only ETH. Fledging then moves the price back to the curve’s price before adding the position. Moving it back can only sell coins to that ETH-only liquidity above the curve’s price, so it costs the nest nothing, and whatever extra ETH arrives goes into the nest. Each step moves the price by at most a factor of two, and the coin gives up a step if gas runs low. So a pool strewn with positions can make fledging take more than one transaction, but can never make it impossible. Anyone can finish it with fledge(), and the coin page shows a button for it.

After fledging

The coin trades in its Uniswap pool through any wallet, router or aggregator. The position earns the pool’s 1% fee on every trade, all of it, because it is the pool’s only liquidity at launch. harvest() collects those fees. Fees paid in ETH (from buys) join the nest’s pending ETH and are swapped into the stock under the same fair-price guard. Fees paid in the coin (from sells) are burned, which shrinks the supply and raises every remaining coin’s share of the nest. Anyone can harvest, and every redeem collects the fees first so a burn is always paid on current numbers. unharvested() shows what is waiting, computed the way the pool computes it.

The fair-price guard

The nest buys its stock in two hops: ETH → USDG in Uniswap’s WETH/USDG 0.01% pool, then USDG → the stock in the pool chosen at launch. Before swapping, the coin reads both pools’ time-weighted average price (30 minutes, or 10 then 2 if a very busy pool has overwritten that much history). It sets the swap’s minimum to what the averages say the ETH is worth, less both pools’ fees and 2%.

A price pushed inside the current block carries no weight in an average. So an attacker who moves a pool and then triggers a purchase gets nothing: the swap fails its minimum, the ETH stays in the coin as pendingEth, and the next trade, harvest, or anyone calling convert tries again once the pool is back. The trade itself always goes through.

One refusal is deliberate. A transaction with too little gas left for the swap, or for fledging, reverts with NeedsMoreGas instead of quietly deferring the work. Wallets estimate the smallest gas at which a transaction does not revert, and without that refusal their estimates would starve every purchase.

Burning for the nest

Anyone holding coins can burn them with redeem. They receive exactly nest × coins ÷ totalSupply of the stock, plus the same share of any fee ETH still waiting. The share is taken over the whole supply, including coins still in the curve or in the pool, so nobody can take more than their fraction, and every burn leaves each remaining coin backed by at least as much stock as before. It works before and after fledging. The coin page shows whether burning or selling pays more for your amount.

The picture and links

At launch, the picture, description and up to three links are ABI-encoded and stored as the code of a tiny contract (SSTORE2), 24 KB at most. Your browser crops the picture square and shrinks it to under 16 KB first. meta() returns them byte for byte, and nothing depends on a server.

The contracts

WhatAddress
FledgeFactory0x6B51ac421fEec8774242649189916c71Bc6eABD1
FledgeCoin implementation0x9f157443d504491E81a2F9c6B62AC0A5c7349931
CREATE2 deployer (Arachnid’s, deterministic)0x4e59b44847b379578588920ca78fbf26c0b4956c
Uniswap v3 factory0x1f7d7550B1b028f7571E69A784071F0205FD2EfA
Uniswap SwapRouter020xCaf681a66D020601342297493863E78C959E5cb2
WETH / USDG 0.01% pool0x52e65B17fB6E5BA00Ed806f37Afcd2DaA50271Ca

The factory’s address is keccak256(0xff ++ deployer ++ salt ++ keccak256(initCode)), with salt 0xa42f468ea184e22738eccb387ce26445a236b0661c743851c1c8a599717255c7 and init-code hash 0xa62f78e931f94063e09bbf15884d6918f03afd42fbb70ad8faa0beb26e3d85cf. So the address is the code: anyone can deploy it, and whoever does puts exactly this code there. The first launch does it automatically. Source: FledgeFactory.sol, FledgeCoin.sol, and Uniswap’s TickMath.sol; solc 0.8.26, optimizer 1000 runs, via-IR, Cancun. Status right now: checking…

How it was tested

Every property below runs on a private fork of live Robinhood Chain (anvil, started fresh at the newest block for each property). The real CREATE2 deployer deploys the factory, coins launch on real stock tokens, every nest purchase swaps through the real Uniswap pools, and every fledged coin opens a real Uniswap pool, all in the state the chain is in right now. Nothing is broadcast and nothing is mocked. Expected numbers are computed in the test from the formulas written out there, never by asking the contract.

The last run: 15/15 properties and 280 checks passed against live state (30 Sep 2026), for the factory at 0x6B51ac421fEec8774242649189916c71Bc6eABD1.

#PropertyChecks
P1The factory lands at the address its code fixes, with the implementation beside it7
P2Launch refuses every bad input with the error named for it, and accepts a good one20
P3Buys and sells pay exactly the curve and the fee, and every fee reaches the nest63
P4A round trip never makes money, and everyone can always sell back20
P5The nest only buys near the average price; a pushed pool defers the buy until it is not15
P6The price read is Uniswap's, in both token orders and every fee tier, and the swap matches the quoter
NVDA through its 0.05% pool: 0.005 ETH bought 0.058531 NVDA, 3 bp above what the 30-minute average said (the floor allows 206 bp below)
SPCX through its 0.05% pool: 0.005 ETH bought 0.089185 SPCX, 3 bp above what the 30-minute average said (the floor allows 206 bp below)
TSLA through its 0.3% pool: 0.005 ETH bought 0.037845 TSLA, 22 bp below what the 30-minute average said (the floor allows 231 bp below)
MSTR through its 1% pool: 0.005 ETH bought 0.086731 MSTR, 91 bp below what the 30-minute average said (the floor allows 301 bp below)
17
P7Redeeming pays exactly the holder's share of the nest and nothing more28
P8Too little gas is refused outright rather than silently deferring the fee6
P9A coin keeps its picture and links on chain, byte for byte6
P10The coin is an ordinary ERC-20, refuses stray ETH, and cannot be re-initialised8
P11The buy that empties the curve pays exactly the rest, is refunded the remainder, and fledges the coin at the curve's own price25
P12After fledging the coin trades on Uniswap, and the pool's fees feed the nest: ETH buys stock, coins burn21
P13Nobody can get into the pool first: coins cannot enter it before fledging, and a price set there is moved back at no cost to the nest22
P14Fledging a pool someone has pushed far away can take more than one transaction, but never fails and never strands the coin15
P15A launch whose first buy is bigger than the curve fledges at once and refunds the launcher to the wei7

Then a sabotage sweep plants 24 bugs, one at a time, in copies of the contracts. Among them: the fair-price guard removed, the pool opened at the wrong price, the pool left open to coins before fledging, a buy-out that is not refunded, liquidity added by the wrong amount, coin fees that are not burned. Each run requires the property named for its bug to fail. 24/24 were caught by the property named for them.

And in a real browser: headless Chrome drove these pages with a test wallet against a private copy of the live chain. It launched the first coin from the launch page (deploying the factory on the way), bought, sold and burned on the curve, bought the rest of the curve and watched the coin fledge, then bought and sold it on Uniswap and harvested the pool fees into the nest. 10/10 journeys and 47 checks passed, and the harness read each outcome back from the chain itself (30 Sep 2026).

Risks

  • Unaudited. The contracts are tested, not audited.
  • Coins can go to zero. The nest gives each coin a floor only as high as the stock it holds. A coin can trade far above it and fall back to it.
  • Locked means locked. The pool position can never be removed, by anyone, for any reason. That is the point, and it is also final.
  • Stocks fall, and Robinhood controls its stock tokens. Robinhood can pause, block or burn its tokenized stocks. A paused stock cannot be bought (fees wait) or paid out (burns revert until it resumes).
  • Thin pools make the nest wait. If the stock’s pool is too thin for a fair fill, fees accumulate as ETH until it is not, and burns still pay that ETH out pro rata.