Contract addresses
Chain details for Robinhood Chain and its testnet, and the address table you will fill in at deployment.
Nothing is deployed yet. Every address on this page reads TBD at deployment, and it will stay that way until the deployment transaction has run and its report has been published. Treat any address you find elsewhere claiming to be Fyber as fraudulent until it appears here.
Chain details
| Mainnet | Testnet | |
|---|---|---|
| Name | Robinhood Chain | Robinhood Chain Testnet |
| Chain id | 4663 | 46630 |
| Stack | Arbitrum Nitro rollup | Arbitrum Nitro rollup |
| Native currency | ETH | ETH |
| RPC | https://rpc.chain.robinhood.com | https://rpc.testnet.chain.robinhood.com |
| Explorer | Blockscout, https://explorer.chain.robinhood.com | https://explorer.testnet.chain.robinhood.com |
| Faucet | — | Available on the testnet portal |
Notes that matter when you integrate:
- The sequencer orders transactions first-come, first-served. Whether a public mempool exists, and whether transactions can be reordered, determines if a liquidator or a
CollateralSalebuyer needs protection against value extraction. Verify this yourself before you assume either way. - Time is
block.timestampeverywhere in Fyber.block.numberis used only for the same-block guard and the offset guard. The sequencer may shift timestamps by minutes, and every threshold in the protocol carries at least ten minutes of margin (Rule R-3.0.2). - Gas costs change when the launch subsidy expires. Every keeper mechanism assumes marginal cost.
Core contracts
| Contract | Instances | Mainnet | Testnet |
|---|---|---|---|
FYUSD | 1 | TBD at deployment | TBD at deployment |
BranchRegistry | 1 | TBD at deployment | TBD at deployment |
LiquidationEngine | 1 | TBD at deployment | TBD at deployment |
RedemptionRouter | 1 | TBD at deployment | TBD at deployment |
InterestRouter | 1 | TBD at deployment | TBD at deployment |
Backstop | 1 | TBD at deployment | TBD at deployment |
PoolIncentive | 1 | TBD at deployment | TBD at deployment |
PSM | 1 | TBD at deployment | TBD at deployment |
RateFloor | 1 | TBD at deployment | TBD at deployment |
Router | 1 | TBD at deployment | TBD at deployment |
Closer | 1 | TBD at deployment | TBD at deployment |
Endowment | 1 (address only) | TBD at deployment | TBD at deployment |
Per-branch contracts
Twenty branches are deployed at genesis. SPY and QQQ are active from day zero; the other eighteen are dormant and activate on their own criteria. The four broad-market and gold branches are listed below.
| Branch | Tier | Status at genesis | Branch | OracleAdapter | LiquidityOracle | SortedTroves | StabilityPool | sfyUSD | CollateralSale | Probe |
|---|---|---|---|---|---|---|---|---|---|---|
| SPY | A | Active | TBD | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
| QQQ | A | Active | TBD | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
| VTI | 1 | Dormant | TBD | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
| GLD | 1 | Dormant | TBD | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
| SLV | 2 | Dormant | TBD | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
Registry slots six through ten are the zero address, permanently.
External addresses each branch depends on
Every one of these is immutable in the contract that reads it, and none of them can ever be repointed.
| Dependency | Where it is fixed | Mainnet | Testnet |
|---|---|---|---|
| Stock Token, per branch | Branch and OracleAdapter constructors | TBD at deployment | TBD at deployment |
| Chainlink price feed proxy, per branch | OracleAdapter constructor | TBD at deployment | TBD at deployment |
| Sequencer uptime feed | OracleAdapter constructor; zero if none exists | TBD at deployment | TBD at deployment |
| Reference Uniswap pools, at least two per branch | LiquidityOracle constructor | TBD at deployment | TBD at deployment |
| Valve TWAP pool, per branch | OracleAdapter constructor; zero disables it permanently | TBD at deployment | TBD at deployment |
| USDG | PSM constructor | TBD at deployment | TBD at deployment |
| Reference Morpho market and market id | RateFloor constructor | TBD at deployment | TBD at deployment |
| Canonical incentive pools, one or two | PoolIncentive constructor | TBD at deployment | TBD at deployment |
| Closer Safe (2 of 3) | Closer constructor | TBD at deployment | TBD at deployment |
How to verify an address
When the addresses are published, do not take them on trust. The deployment produces a report, published in the repository, that asserts contract by contract (Rule R-16.5.1):
- No
owner(), noAccessControlrole and noTimelockControlleranywhere in the address graph. - No ABI entry whose name begins with
set,add,remove,update— other thanupdateMintFreeze—grant,revoke,upgrade,transferOwnershiporpause. - No storage variable holding a risk constant; all of them are
immutableorconstant. fyUSD.isMintertrue for exactly the twenty branches and the PSM, and nothing else.BranchRegistry.allBranches()returning five distinct addresses on five distinct tokens, with slots six to ten zero.Closer.safeequal to the published Safe, andCloser.expiresAtequal toDEPLOY_TS + 365 days.- Each
Branch.adapter.tokenequal to that branch's own token, and every cross-address non-zero. - Every constructor relation from the parameter assertions verified by reading.
- The deployed bytecode of each module equal to the compiled bytecode of the frozen specification.
- No source group weighs more than half the composite, for every branch, read from each
OracleAdapter.
You can re-run all ten checks yourself against the deployed addresses. That is the point of publishing them.
Contract verification
Source will be verified on Blockscout for both networks at deployment, with the compiler pinned to Solidity 0.8.26 and the exact optimiser settings published alongside. If a contract at one of these addresses is not verified, do not integrate it.
Deployment shape
The whole system is deployed by one atomic script. It deploys the nineteen modules, resolves the circular address references using precomputed CREATE2 addresses, activates SPY and QQQ, seeds the Probe contracts with 1e6 wei each, and asserts the final state before finishing (Rule R-3.0.3).
The deployer address holds no residual power afterwards, and there is nothing for it to renounce, because no module ever grants it anything.
Last reviewed: 2026-09-07 · Spec v0.4