Documentation

Pawcket protocol

A fixed term pawn shop for onchain bags, with one twist: the collateral can sell itself while the loan stays open. Everything below describes the contract that is live on Robinhood Chain today.

Overview

Pawcket lends ETH against two collateral classes on Robinhood Chain: screened memecoins with real Uniswap v4 liquidity, and tokenized stocks and ETFs issued by Robinhood. Loans are fixed term with a flat fee taken up front. There are no margin calls and no health factor: a price move never closes a loan early, only the due date does.

Inside a loan the borrower can arm exits. A take profit, a stop loss or a ladder of both tells the contract which slices of the collateral it may sell into ETH and at which prices. The ETH stays parked inside the loan and comes back on repayment. That is the difference from every other memecoin lender: collateral that can still sell itself.

Borrowers

ETH now, upside intact

Fixed term, flat fee, no liquidation before the due date, exits on the collateral.

Lenders

A cut of every fee

Deposit ETH, receive pool shares, watch the share price step up with each loan.

Token holders

70% of all fees

Airdropped in ETH on a random 5 to 10 day cadence. No staking, no claim.

Architecture

One Solidity contract, LendingPool, holds the ETH pool, every collateral position, the price history and the exit logic. Two helpers sit next to it: CreditOracle publishes scores, Disperse batches holder payouts. Offchain, a worker runs the attestor, the exit engine, the keeper, the screener and the reward loops.

Borrower walletSigns every borrow, arm, repay and withdraw. Nothing moves without it
LendingPool contractHolds collateral and pool ETH, enforces tiers, gates and exits
AttestorPushes prices once a minute and signs valuations for borrows
EngineFires armed exits and liquidates overdue loans through Uniswap v4

Roles are narrow by design: the attestor cannot move funds, the engine can only sell inside the limits the borrower armed.

Collateral custody

Collateral is transferred into the contract when a loan opens and leaves only through repayment, an exit sale, a liquidation or a top up in the other direction. There is no admin function that moves a borrower's collateral. Pool ETH belongs to the lenders; the owner can withdraw only the surplus above their deposits.

Liquidation

After the due date anyone may call liquidate. The keeper earns a bounty from the collateral, the pool recovers the debt from any ETH the loan had parked, and the rest of the collateral goes to the liquidation wallet to be sold, with the sale proceeds returned to the pool first. The engine can also sell the whole position on Uniswap v4 in one call and settle the loan the same way.

Loan lifecycle

Lock collateralApproved token moves into the vault, ETH lands in your wallet in the same block
Term runsNo margin calls. Arm exits, top up, partial repay or extend at any time
RepayDebt paid: collateral and any parked ETH come back in one transaction
Miss the dateAnyone can liquidate. Collateral is sold or seized, the pool is made whole first

Two ways a loan ends. A price drop never closes it early; only the due date does.

  • Borrow. Approve the token, get a signed valuation from the attestor, send one transaction. The contract checks the valuation against its own price history and pays the net amount in the same block.
  • Manage. Partial repayments reduce the debt. Top ups add collateral for free. Extend before the due date for another tier fee, as long as the collateral still covers the debt at the attested price.
  • Repay. Send the gross amount. The remaining collateral and every wei of parked exit proceeds come back in the same transaction. The credit score moves up.
  • Default. Miss the date and the collateral is forfeit. The debt is written off against the pool and recovered from the collateral. The borrower keeps the ETH. The credit score takes the hit.

Tiers and fees

Tiers are constants in the contract. The fee is flat, taken from the gross loan at origination; you repay the gross amount. gross = value × LTV, fee = gross × feeBps, you receive gross − fee.

Memecoins

Most ETH

Express

Maximum borrowing power. Best for short plays where you need the most capital.

30%LTV
2days
3%fee
Borrowed 30%Collateral buffer 70%
Start borrowing at this tier
Popular

Quick

Balanced option. More time to repay with a comfortable loan to value ratio.

25%LTV
3days
2%fee
Borrowed 25%Collateral buffer 75%
Start borrowing at this tier
Safest

Standard

Lowest LTV means the most room before the collateral only covers the debt. A full week to repay.

20%LTV
7days
1.5%fee
Borrowed 20%Collateral buffer 80%
Start borrowing at this tier

Tokenized stocks and ETFs

Quick week

Stock Express

Seven day loan at 50% LTV. Best when you need capital fast and plan to repay within a week.

50%LTV
7days
2.5%fee
Borrowed 50%Collateral buffer 50%
Start borrowing at this tier
Balanced

Stock Quick

Fifteen day loan at 60% LTV. The sweet spot: more cash, more time.

60%LTV
15days
3.5%fee
Borrowed 60%Collateral buffer 40%
Start borrowing at this tier
Most ETH

Stock Standard

Thirty day loan at 70% LTV, our highest. Maximum capital, a full month to repay.

70%LTV
30days
5%fee
Borrowed 70%Collateral buffer 30%
Start borrowing at this tier

In vault exits

After the loan funds you arm a bracket onchain: a take profit price, a stop loss price, the maximum slice per fire and the total budget. That transaction is your consent. Without it the engine cannot touch a token.

TAKE PROFIT · sells a slice into ETHSTOP LOSS · protects the loanentry priceslice 1 fires

One transaction arms both lines. The engine can only sell between them and never below the last attested price minus the slippage cap.

Inside the bracket you define legs offchain, in USD, ETH, market cap or a multiple of the current price. The engine fires each leg when its trigger is met, selling that slice of the original collateral into ETH straight from the vault through Uniswap v4. The ETH stays inside the loan, the debt and the due date do not change, and a 1% protocol fee is taken from the proceeds.

  • The engine may never sell below the latest attested price minus the category slippage cap (25% memes, 10% stocks). A thin pool makes the transaction revert instead of dumping your bag.
  • USD and market cap triggers are resolved to ETH terms every tick; the onchain bracket carries a 10% buffer so a moving ETH price cannot lock the engine out.
  • Trailing stops are not enforceable onchain without resigning the bracket and are not offered.
  • Repay at any time and the parked ETH comes back with the remaining collateral. Repayment itself still has to be paid in ETH.

Pricing and oracles

The attestor pushes a price for every token with an open loan, an armed order or a warm request once a minute. The contract keeps the last 32 samples per token and refuses to lend unless the history is deep enough and the spot is not running away from the average.

30 minute TWAPTWAP + 15%: borrow refused above thisone sample a minute · 32 kept · at least 8 and five minutes of history before the first loan

A pump in the last minutes lifts the spot above the average. The contract values collateral at the lower of the two and refuses to lend when the spot runs more than 15% above the average.

  • Latest sample at most 120 seconds old, at least 8 samples and five minutes of history.
  • Spot at most 15% above the 30 minute average. Collateral is valued at the lower of the two.
  • The signed valuation may exceed the onchain valuation by at most 3%. One update may not move the feed more than a hundredfold.
  • Before signing, the attestor needs two independent sources to agree: the Uniswap v4 pool and GMGN for memecoins within 5%, the Robinhood quote and the USDG pool for stocks within 2%.

A fresh token needs its feed warmed first. Selecting it on the dashboard starts the warm up and the borrow button unlocks once the history exists, usually within six minutes.

Fee structure

Of every fee, 10% stays in the pool for lenders and 90% goes to the protocol fee wallet, where it is split again: 70% to holders of the Pawcket token, 10% to referrers and 10% to the protocol reserve. A loan with no referrer sends that 10% to holders too. Exit fees follow the same split.

70%10%10%10%
Token holders · 70%Airdropped in ETH on a random 5 to 10 day cadence
Lenders · 10%Stays in the pool the moment a loan funds
Referrers · 10%Rolls to holders while a loan has no referrer
Protocol reserve · 10%Gas for engines, audits, keeper bounties

Distribution flow

Every fee event is indexed into a ledger. On a random moment inside each 5 to 10 day window the worker snapshots the Pawcket token balances onchain, excludes DEX pools and protocol wallets, credits tokens locked as collateral to their borrower, and pays every holder above the dust threshold in one batched Disperse transaction.

Lenders

Deposits mint pool shares at the current share price. Ten percent of every fee is credited to the pool at origination, so the share price steps up the moment a loan funds. Defaults are written off against the pool and recovered from the seized collateral. Withdrawals are limited to ETH not currently lent out.

TierBorrower feePool shareGross APR at full utilization
Express · 2d3%0.30%55%
Quick · 3d2%0.20%24%
Standard · 7d1.5%0.15%8%
Stock Express · 7d2.5%0.25%13%
Stock Quick · 15d3.5%0.35%9%
Stock Standard · 30d5%0.50%6%

Real yield scales with utilization and drops when a default is written off before its collateral is sold. See it live on the Earn page.

Liquidation and keepers

Liquidation is permissionless. Once the due date passes, any wallet can call liquidate(id) and receive the keeper reward, 5% of the collateral by default. The rest of the collateral moves to the liquidation wallet for sale, and any ETH the loan had parked from exits repays the pool first. The engine can instead call sellAndLiquidate, selling the whole position through Uniswap v4 in one transaction with a floor derived from the last attested price.

Defaulted the Pawcket token is burned rather than sold. Everything else is sold and the net profit flows into the same four reward channels as fees.

Credit system

Every repayment, extension, exit and default moves a 300 to 850 score computed from six onchain factors: repayment history 35%, liquidation history 20%, loan volume 15%, account age 10%, collateral diversity 10%, engagement 10%. The worker publishes changed scores to the CreditOracle contract, where any protocol can read them.

TierScoreWhat it means
Bronze300 to 499New or shaky history
Silver500 to 649Every borrower starts here
Gold650 to 749Repeat borrower, no defaults
Platinum750 to 850Large, diverse, spotless

Today the score is reputation. Tier gated LTV and fees need a contract upgrade and ship once volume justifies the audit. Credit page.

Security model

  • Noncustodial. Your keys never leave your wallet. The protocol signs valuations, not your transactions.
  • Narrow roles. The attestor can only push prices inside the contract's tolerance. The engine can only sell inside a bracket the borrower armed, above a floor the contract computes.
  • Onchain gates. TWAP window, staleness, sample count, pump guard and valuation tolerance are enforced by the contract, not by the server.
  • Two source pricing. No valuation is signed unless two independent sources agree.
  • Screened collateral. Every memecoin passes a contract safety check, a holder concentration check, a 30 day drawdown screen and a live sell test before it can be enabled.
  • Open verification. Both contracts are public on Blockscout and every number on the stats page is derived from chain state.

Ownership currently sits on the operator key while the protocol is small. Moving it to a hardware wallet with a timelock is the first change once real volume arrives. Security page.

Wallet model

There are no custodial wallets and no deposit addresses. You borrow from the wallet that holds the collateral: MetaMask, Rabby, Phantom or any wallet that speaks Robinhood Chain (chain id 4663). Signing in to the dashboard is a message signature that proves ownership; it never grants the site permission to move funds.

Supported tokens

6 memecoins and 68 tokenized stocks and ETFs are enabled today.

Memecoins

Bluechip screen: ETH pool on Uniswap v4, no honeypot or blacklist, tax at most 5%, top 10 holders at most 40%, no 50% drop inside 48 hours over the last 30 days, and a live buy and sell round trip from the engine wallet.

Stocks and ETFs

Allowlisted from Robinhood's asset registry, pinned to one contract address each, enabled only while the USDG pool holds enough inventory to sell a liquidated position.

Submission outcomes

  • Approved. Passed every gate and the listing bar (liquidity at least $300k, 24 hour volume at least $100k, market cap at least $3M, 2,000 holders, 14 days old). Enabled by the operator with a per token cap.
  • Review. Safe but below the bar. Sits in the queue and is rescreened as it grows.
  • Declined. Failed a hard gate. Resubmit once the contract or the holder picture changes.

Enabled tokens are rechecked every five minutes. Two consecutive failures on liquidity or volume disable new loans against the token; existing loans run to term.

API and integration

The site runs on a small public JSON API. Everything a page shows, you can fetch.

EndpointReturns
GET /api/tokensApproved collateral with prices, liquidity, logos and caps
GET /api/quote?token&amount&optionValue, gross, fee, net and due date for a loan
GET /api/feed?tokenOnchain price feed readiness for a token
POST /api/warmStarts pushing prices for a token so its feed becomes ready
GET /api/statsEverything on the stats page as JSON
GET /api/loans?walletLoans and exit orders of a wallet
GET /api/credit?walletScore, tier and factors
POST /api/tokens/submitScreens a memecoin contract and answers with the verdict

Transaction flow

  1. Approve the collateral token for the LendingPool contract.
  2. Sign in with the wallet and call POST /api/attest with token, amount and tier. The attestor answers with a signed valuation valid for a few minutes.
  3. Call borrow(token, amount, category, option, attestation) from the same wallet. ETH arrives in that block.
  4. Optionally call armExit(id, takeProfit, stopLoss, maxSlice, total) and define legs through /api/exits.

Governance

Tier constants, the fee split, the reward window and the screener bar are parameters, not code. Once the Pawcket token is live, holders vote on them offchain with one token one vote, and the operator commits to implement a passing vote within 14 days. Security parameters, contract upgrades and emergency pauses stay with the operator. Governance page.

Contracts