VAULT is a fully on-chain collection on Robinhood Chain. Half of every mint is sealed into a common reserve - crack your safe at any moment and take your exact share. The art lives in the contract. The pool is locked by construction. Nobody holds admin keys, because there are none.
Five doors, one ladder. Your price, live.
- NOW ENTER THE FLOORA balance you can crack out, any time.
- / SAFE ENTER THE ARTRendered by the chain. Explore all 3333 here.
KECCAK-PROVEN 3333/3333 ENTER THE ROULETTEAn hourly ticket. Wins mint safes, free.
- ENTER $VAULTBorn inside a locked pool. Fees in kind.
- BURNED ENTER ENGINE ROOMBytecode, invariants, verified sources.
8/8 VERIFIED / 131 TESTS ENTERThree live rehearsals, then the real thing: 131 tests green, full-collection keccak parity, eight contracts deployed and verified on Robinhood Chain. The deployer holds nothing - everything is steel now.
Prices step up by token number - early doors cost less, late doors weigh more. Every safe carries a yield weight (model × finish) that decides its share of the holder pot. All five prices are immutable constants, calibrated by simulation before deploy.
CONNECT A WALLET TO OPEN A DOOR.
Reads are already live - actions need a signature. The console runs against the rehearsal deployment; one constant flips it to mainnet at launch.
Most collections quote a floor somebody else must agree to pay. VAULT keeps one in a contract: an ETH balance every safe can claim against - readable by anyone, spendable by no one but crackers.
50% of every mint and 25% of every sell fee flow in. There is no owner withdrawal function - the bytecode simply does not contain one.
Burn your safe, receive exactly reserve ÷ safes alive - instantly, permissionlessly, at any moment from mint to forever. The door is the exit.
A crack pays R÷N and leaves R′÷N′ identical for everyone left. The R/N invariant is machine-tested - your neighbour leaving cannot lower your share.
CONNECT A WALLET TO SEE YOUR SAFES.
Every safe you hold is listed with its live render, and the exit is one honest button away - with the exact payout in front of it.
tokenURI() is the artwork - pure SVG assembled by the contract, worst case 2,181,688 gas of drawing. Every render below is produced by this page with the same integer-exact algorithm, proven byte-identical to the chain across all 3333 tokens by keccak256. And the art is alive: each safe displays its current floor share, so when the reserve grows, all 3333 change.
Every wallet can claim a soulbound slip each hour and spin it against the chain itself. Wins mint safes - free, instantly, with no daily schedule and no lifetime cap. The only throttles are the odds themselves and the end of the collection: the chance is priced so that farming spins costs more in gas than it wins until the floor is high - and every free safe dilutes the floor back down. The thermostat is physics, not policy.
One slip per wallet per hour. It cannot be transferred, sold, or farmed into a bag - a slip is attendance, not an asset.
Commit your slip. The contract pins it to a future block - you cannot pick your luck, and neither can we.
The next block’s hash decides at 0.05% per spin - during a quiet market PULSE multiplies that up to ×8.
A win is a safe, minted free and instantly - straight to your wallet, no queue, no redeem step, no quota that can eat it. Want more turns? Extra spins cost 0.00000025 ETH, and that ETH is swapped into $VAULT and burned.
There is no win schedule and no free-supply cap - a hit mints a safe on the spot, and the only hard end is the collection itself (3333). What keeps it honest is arithmetic: at 0.05% a full spin cycle costs more gas than its expected value until the floor clears ≈0.0063 ETH, and every farmed mint dilutes the floor back under that line. Bots fight the thermostat, not a rule. Bonus spins for traders (96/day) and relic-forge spins (24/day per wallet) feed the same funnel. Paid mints: no daily cap, 20 per wallet lifetime.
CONNECT A WALLET TO CLAIM AND SPIN.
One free slip an hour, settled by the next block’s hash. A win mints the safe straight into your wallet.
CONNECT A WALLET TO FEED THE FORGE.
Holding a dead token from this chain? Burn it to 0xdEaD and collect roulette spins - chances, never safes, capped at 24 a day. The relic list and its rates are frozen into the contract at deploy.
After 36 silent hours the machine starts breathing for the collection: mint prices melt 25% / day down to a quarter of the ladder, and roulette odds double every dead day, up to ×8 - from 0.05% to 0.4% per spin.
A single paid mint resets the melt; the odds fall back as life returns. At sellout PULSE freezes forever. Every parameter of the revival is an immutable constant - the failsafe cannot be turned off, tuned, or abused.
No presale, no allocation table, no vesting cliff to survive. At deploy the token mints its entire supply to itself, seeds the Uniswap v4 pool single-sided, and locks the position - all in one transaction nobody can repeat or reverse.
The pool runs through a Uniswap v4 hook with flags 0x1044, mined into its very address. Fees are taken in whatever the trader is moving:
Buys pay in $VAULT - taken from the pool and burned on the spot. Every purchase makes the token scarcer.
Sells pay in ETH - split 25 / 50 / 25: a quarter under the NFT floor, half into the holder pot, a quarter to the treasury. Every exit strengthens the people who stayed.
Burn $VAULT to activate a safe for 30 days and the pot pays you by weight. Trades over 0.002 ETH earn bonus roulette spins.
The on-site swapper routes through the same locked v4 pool. If it’s ever unavailable, the Uniswap link below trades the exact same pair - nothing else to trust.
CONNECT A WALLET TO ACTIVATE YOUR SAFES.
Burn $VAULT to switch a safe on for 30 days - active safes split the holder pot by weight. The burn is the sink; the pot is the reward.
The pool opens at a 40% fee that decays to 2% over 12 hours - smooth, block by block, no cliff to time. Bots that rush the first candles pay the collection for the privilege; their ETH stays in the pool as depth for everyone after.
Simulation across sniper-capital scenarios showed the window converts sniping from a tax on holders into a donation to them.
Everything below is verifiable right now: sources on Blockscout, invariants in the test suite, parity proven with keccak - not claimed, measured.
R/N invariant. Cracks pay exactly reserve/liveSupply and cannot lower anyone else’s share. Fuzzed and invariant-tested.
initWiring fires once. One wiring pass at deploy; a second call reverts NotDeployer. After it, no privileged surface exists.
LP locked by construction. The v4 position is owned by the token contract, which has no function to remove liquidity. Not timelocked - impossible.
Slips are soulbound. Transfer paths revert; a slip can only be claimed, spun, or expired. Luck cannot be bought second-hand.
Fee settlement proven on real v4. take() + return-delta parity held to the wei against the live PoolManager - swap in, split out, sums exact.
Money is integers. Micro-ETH accounting, truncated 5-decimal formatting; no float ever reaches chain or canvas. The renderer is integer-exact.
Deployed and verified in the one launch command - is_verified = true via the explorer API, solc 0.8.28 / via-ir / cancun. Click to view, tap the address to copy.
Reference first. The art engine was written as a deterministic integer-exact JS reference - xorshift32, integer coordinates, truncated 5-decimal money. Then it was ported to Solidity and pinned with keccak fixtures: 42 feature renders, then the entire collection. If one byte drifts, a test screams.
Fork before broadcast. Every mechanic rehearsed on a fork of the live testnet, then broadcast for real - three full rehearsals. Rehearsal #2 caught a genuine deploy-killer: the CREATE2 proxy made msg.sender the proxy, not the human, which would have burned the mined hook address on mainnet. That is what rehearsals are for.
One command to launch. The deploy script self-mines the hook salt, deploys all seven contracts, wires them once, lets the token seed and lock the pool, and submits every source for verification - inputs: a key and a treasury address. Nothing manual left to fumble on the day.
function seedAndLock(...) external { if (msg.sender != deployer) revert NotDeployer(); if (seeded) revert AlreadySeeded(); seeded = true; // ETH/VAULT pool, hook bound at birth IPoolManager(poolManager).initialize(poolKey, sqrtPriceX96); // 99% of supply in, one-sided; the TOKEN owns the LP. // No function anywhere removes it. Locked by construction. IPoolManager(poolManager).unlock(abi.encode(tickLower, tickUpper, liq)); } function unlockCallback(bytes calldata data) external { ... // if the pool ever asks for ETH, the seed is wrong - abort if (delta.amount0() < 0) revert NotOneSided(); ... }
Most projects blur this line on purpose. We drew it in steel - read both columns before you spend a single wei.