Repository records bind a Robinhood Chain deployment identity, but do not authenticate current chain state or service availability. This page separates the source-pinned runtime, reviewed scope, and privacy boundary.

Repository binding

The current deployment lists the network, contracts, deployment initial fee, and proving files pinned by repository browser source.

Security review

The audit report summarizes the earlier review dated 25 August 2026. Formal verification explains the modeled Robinhood deposit and withdrawal properties and their explicit assumptions.

Recovery today

The Transfer Console scans public encrypted recovery records after verifying a bound wallet signature, decrypts matching bundles locally, checks spent state, and waits for explicit note selection. A bearer recovery note is a recommended optional fallback because exact wallet-signature reproducibility remains an operational assumption. Lean models the broader recovery policy conditionally. Its current implementation binding remains historical and stale against active source, so Robinhood wallet recovery still carries MODEL_ONLY formal evidence rather than source- or deployment-level coverage. A separate exact policy-module refinement checks that single-deposit wallet submission requires matching recovery material, proof preflight, and staged recovery without requiring copy, download, or acknowledgement; it does not close the broader recovery or deployment gaps.

Privacy today

Recovery secrets and proof witnesses stay in your browser. Amounts, destinations, timing, and transaction submitters remain public onchain. Read What Nullark keeps secret for the full breakdown.