S · P · Q · R
The Empire, end to end — what ROHME is, how staking, bonds, and the treasury work, and how the Senate governs every reserve it holds.
THE DEFI EMPIRE
ROHME is the only RWA-backed DAO on Robinhood Chain using traditional (3,3) staking. It accumulates a treasury of tokenized real-world assets, backs every ROHM with treasury value, pays staking rewards to DENARI holders, and is governed end to end by gROHM voters through an on-chain Governor and Timelock that own the treasury.
USDG, and WETH — each valued live through Chainlink feeds. ROHM is minted only against excess reserve value.| Token | Role | Dec |
|---|---|---|
| ROHM | Native token — minted only against treasury value | 9 |
| DENARI | Staked ROHM, rebasing (sOHM mechanics) | 9 |
| gROHM | Governance ROHM (gOHM mechanics) — non-rebasing ERC20Votes wrapper, timestamp clock | 18 |
ROHME lives on Robinhood Chain, an Arbitrum Orbit L2. Mainnet is chain 4663; testnet is 46630. You are reading the Robinhood Chain documentation — use the network switcher in the header to change chains.
THE FLYWHEEL
Stake ROHM to receive rebasing DENARI, or mint non-rebasing gROHM directly — one transaction takes you from ROHM to voting power.
THE RWA ENGINE
Bond depositories sell ROHM at a discount for real-world-asset quote tokens. The DAO acquires the reserve into the treasury and mints ROHM against it — the mechanism that grows backing.
USDG, WETH, and tokenized equities / ETFs. The open markets on Robinhood Chain are quoted in USDG (#0) and SNDK (#1) and SPCX (#2) and MU (#3) and GME (#4).PROTOCOL-OWNED LIQUIDITY
An LP bond buys liquidity itself. You add ROHM and a paired asset to a Uniswap V2 pool, receive the pool’s LP token, and bond that LP token to the treasury for discounted ROHM on the same vesting terms as any other bond. The liquidity stops being yours and becomes protocol-owned liquidity — the treasury holds the LP permanently, so the depth it adds cannot be pulled back out from under the market. This is the classic Olympus LP bond, unchanged.
An LP bond is an ordinary bond market whose quote token happens to be an LP token, so everything from the Minting section still applies — the vesting note, the price floor, the mint-against-excess rule. The only thing that changes is how the deposited asset is valued.
Pairs
A pair is bondable only once the Senate has registered its LP as a reserve — until then the pool exists but the treasury will not take it.
| Pair | Haircut | LP token | Status |
|---|---|---|---|
| ROHM/WETH | 10% | 0xdb1b…5E5e0xdb1b2bd5D8c0fdd202B3629cD9Ead455C8EF5E5e | Reserve · enabled (genesis POL) |
| ROHM/NVDA | 20% | 0xCB54…7D160xCB549c9C9E8cf3e52BF37B26Fc208AeD3b3f7D16 | Pending a decree (equity pair) |
| ROHM/GME | 20% | 0x7442…F6390x744270585eDFfB51E9783574c0b95c4063BCF639 | Pending a decree (equity pair) |
ROHM/WETH is the pool the fair launch seeded, and the deploy script registered its LP as a reserve in the same transaction — an LP bond market for it needs only the operator to price it, no vote. The equity pairs are further along than they look and further back than they look: the pool and its valuation contract are both deployed and on-chain, but a decree still has to run setPriceFeed + enable(RESERVETOKEN) on each before a single LP token can be deposited. Read the status column, not the existence of the pair.
How the LP is valued
Conservatively, and in a way that cannot be pushed up. The valuation counts only the externally-backed side of the pool — the protocol never marks its own ROHM as backing — and no swap or flash loan can raise the mark, because a pool’s balances can only be traded along its curve, never inflated by one. A haircut and a circuit-breaker band sit on top, so an LP is never marked more generously than the asset inside it. The exact formula and its edge cases are in For Developers.
Risks
An LP bond carries every risk a plain bond does, plus the pool’s.
LastPriceFeed adapter keeps those reserves priceable across the gap by republishing the last answer, which is what lets equity bonds stay open at all. The honest trade: a deposit made on Sunday is priced at Friday’s close. If the equity gaps over the weekend, the mark is wrong until the feed wakes up — the 20% haircut is what absorbs that, and a move larger than the haircut is a real loss to the treasury. Past a hard backstop the adapter reverts and the bond simply closes rather than pinning a dead price.THE RESERVE
The treasury holds a diversified, marked-to-market portfolio of tokenized RWA. Every asset is priced live through a Chainlink feed, discounted by a conservative per-asset haircut, and settled in 9-decimal USD (1e9 = $1).
Backing keeps Olympus semantics: one ROHM is mintable per $1 of excess reserve value — value above what already backs the circulating supply. Haircuts are the oracle analog of “reserves are never marked up” — a downward-only discount, so a price spike can never be minted against 1:1.
S · P · Q · R
The Timelock is the treasury’s authority, so every mutation — registering a reserve, launching a bond, allocating reserves, changing emissions — is a decree that walks the full Cursus Honorum: propose, vote with gROHM, timelock, then execute.
Voting weight is your gROHM at the moment a proposal snapshots, and protocol-held gROHM — the treasury’s, staking’s, the bond depository’s — is excluded from the eligible supply, so quorum is measured against tokens that can actually vote. A defeated, canceled, or expired decree simply ends there; only the full path reaches execution.
Standing Rules
Governor & timelock parameters — read live from chain.
DAO-IN-A-BOX
The launchpad turns ROHME into a factory for mini-ROHMEs. Every launch is not a memecoin but a complete OlympusDAO (3,3) system — its own token, treasury, bond markets, staking, and Governor, shaped exactly like ROHME and scaled down — with liquidity on Uniswap V4. A single launch() transaction deploys thirteen per-DAO contracts and opens two V4 pools, then hands the DAO off to its own Governor.
ERC20Votes governance token, staking + distributor, a treasury, bond markets (including the LP option), a redemption-module rage-quit, and a RohmeGovernorV2 Governor with a Timelock that owns the treasury. The byte-identical contracts inherit ROHME’s audits and tests verbatim.How fees flow
V4 LP fees → a permissionless crank → an exact 50/50 split.
Launched tokens carry no transfer tax; all revenue is trading fees on the permanently locked liquidity. The fee opens high — an anti-MEV window that makes open-snipers pay the DAO — and decays to a ~1% steady rate. Anyone can trigger the fee sweep at any time, and every sweep splits exactly 50/50 between the DAO’s own treasury (where it becomes backing) and ROHME. No keeper, no permission, no middleman fee.
The token price is display-only. A DAO’s quoted price is a smoothed read of its pools, and it feeds market-cap and the trade panel — nothing on-chain. No mint, no bond floor, and no backing derive from it, so a manipulated spot price cannot reach the money. Backing comes only from the treasury’s own conservative marks.
THE FORGE
Launching is near-zero-config: you choose a name, a symbol, an image, and a staking cadence, and a single signed launch(name, symbol, metadataURI, epochLength) transaction ships the whole DAO. Every other economic and governance knob is a fixed protocol default read from the registry, so there is nothing else to tune and nothing to get wrong.
A staged create → build → open flow deploys and wires every child contract across three transactions (each under the chain gas ceiling), reads the live WETH and gROHM feeds, mints the 2.5% ROHME grant as gTOKEN — there is no founder allocation — seeds both single-sided curves, opens the gate bond markets at their floors, and hands the DAO to its own Timelock — the factory keeps nothing (asserted on-chain). msg.sender becomes the creator, and because a revert persists nothing there is no seed escrow and no abandon step.
The image is uploaded, not linked
The image is uploaded — the form stores it in Vercel Blob and writes the returned hosted URL on-chain as the token’s metadataURI. There are no IPFS links. The image is optional: if you upload nothing, or a deployment has no Blob store configured, the launch degrades to a neutral placeholder and still ships in one transaction.
Fixed protocol terms
Everything economic — supply, the curve split, governance timings, bond floors — is a protocol default, identical for every DAO and tunable only by ROHME within hard bounds. A founder cannot weaken their own DAO’s guardrails, and a buyer never has to read a per-launch config to know the rules. The full table of defaults and bounds is in For Developers.
The staking cadence — 1h / 2h / 4h / 8h — is the one knob the creator sets, and the reward rate is normalized to it so daily emissions are identical whichever cadence is chosen: a 1h DAO just rebases 8× as often at 1/8 the size as an 8h one. Emissions run from genesis but are gated by excess reserves — a fresh DAO already has backing at birth because its locked curve legs count as reserves, so rebases are not stuck at zero; a DAO with no excess reserves simply mints nothing on rebase rather than reverting.
Why ~$5 and low supply. A launched token starts like ROHM did — thousands of tokens, 9 decimals, and a ~$5 target set in USD. The start tick is derived at launch from live feeds and rounded up to spacing so the pool never opens below target (a below-target open would hand the first swapper a DAO-funded discount). Low supply also keeps the backing gate reachable and stays clear of the bond math’s overflow limits.
THE TRUST BOUNDARY
The upgradeable half of every DAO runs behind OpenZeppelin UpgradeableBeacons owned by ROHME, so one beacon upgrade rolls a logic improvement to every DAO at once — no per-DAO migration, no redeploy, no vote in each DAO. The other half — the money contracts — is immutable and can never be upgraded, so ROHME can improve mechanics but can never touch a DAO’s backing, its redemption floor, or its supply.
| Contract | Class | Upgradeable |
|---|---|---|
| Staking | Logic · beacon proxy | Yes |
| Distributor | Logic · beacon proxy | Yes |
| BondDepository | Logic · beacon proxy | Yes |
| Governor | Logic · beacon proxy | Yes |
| PolicyGuard | Logic · beacon proxy | Yes |
| LpBondLister | Logic · beacon proxy | Yes |
| Treasury | Money · immutable | Never |
| RedemptionModule | Money · immutable | Never |
| CurveLegReceipt | Money · immutable | Never |
| Token | Money · immutable | Never |
The trust boundary. ROHME can improve how a DAO stakes, bonds, prices, and governs — but it can never mint into your supply, move your reserves, or weaken your rage-quit. The mechanics are upgradeable; the money is not.
THE ENGINE ROOM
The low-level material the overview sections summarize: exact formulas, function surfaces, the reserve/feed table, and the launch defaults. Building an interface or integration? The launchpad docs ship downloadable agent skills that package all of this for a coding agent — see Build your own interface (hosted ABIs and the address manifest included).
Staking surface
stake(to, amount, rebasing, claim) — ROHM in; rebasing=true mints DENARI, false mints gROHM directly. wrap(to, amount) / unwrap(to, amount) convert DENARI ↔ gROHM. Warmup is 0 at launch (kept in code, governor-settable).ROHM.balanceOf(staking) ≥ DENARI.circulatingSupply() — the staking contract always holds at least as much ROHM as DENARI in circulation.Bond math
marketPrice = max(computed, minPrice) in both the view and the deposit path; when PolicyGuard opens a market it recomputes minPrice = ceil(1.1 × backing per ROHM) from oracle values, so a bond can never sell ROHM below 1.1× its backing.NoteKeeper, redeemed with redeem(user, indexes, sendGov). On deposit the treasury re-audits (auditReserves()) and treasury.mint issues ROHM only against excessReserves() = totalReserves − baseSupply.LP valuation — UniV2FairLpFeed
min(vOther, sqrt(vRohm × vOther)), divided by LP supply. vRohm values the ROHM leg at the flat $1.00 backing target (never live backing — that would put the feed inside the sum it feeds); vOther is the externally-backed leg, and the min caps the mark at it, so the protocol never counts its own token as backing.k is swap-invariant, so no swap or flash loan can raise the mark. Haircuts on top: 10% on the genesis ROHM/WETH LP, 20% on equity LPs; a maxPrice band at 4× fair value at listing skips an out-of-band answer as unpriceable (values at 0) rather than minting against it.Reserve assets & feeds
Every registered reserve with its haircut, heartbeat, and Chainlink feed on Robinhood Chain.
OracleLib.getPrice enforces the sequencer-uptime gate, the feed heartbeat (1h–48h), a positive answer, round completeness, and a per-asset sane-price band — reverting rather than pricing a glitched feed. auditReserves() is permissionless; a stale or reverting feed values that asset at 0 rather than overstating backing.Verified RWA catalog. Robinhood Chain’s official contracts page enumerates only a subset of the live tokens, and name-alike impersonators exist on mainnet (a thirdweb clone of GME, third-party wIONQ / wASML wrappers), so every asset above was matched by address, never by symbol: the issuing creator, the BeaconProxy Stock implementation, a byte-identical runtime codehash against the reference TSLA/AAPL tokens, a live ERC-8056 surface (uiMultiplier() / oraclePaused()), and a served Robinhood CDN logo. Each is paired with its canonical Chainlink RH<SYM> / USD feed from the reference directory. BE and QCOM are canonical tokens but the directory publishes no feed for either — with no feed the Treasury cannot value them (OracleLib reverts), so both are deliberately excluded from the bondable catalog.
Launchpad integration
launch(name, symbol, metadataURI, epochChoice) founds a DAO (epochChoice: 0=1h · 1=2h · 2=4h · 3=8h). A gROHM launch fee is pulled by transferFrom and burned — read launchFeeGRohm() live and approve it first. The staged create → build → open path does the same in three transactions when gas demands it.launchCount() + getLaunch(id) enumerate every DAO and return all per-DAO addresses; gate trading surfaces on isOpened(id). Fees settle via the permissionless locker.collectAndSplit(launchId) — the WETH pool splits WETH (TOKEN fees convert first, floored on a 30-minute TWAP), the gROHM pool splits gROHM in kind, and a stranded leg escrows for claim() instead of blocking the crank.totalReserves(); the mint gate = excessReserves(); the quoted token price is a TWAP cross-checked between both pools and is display-only.Launch defaults (ROHME-tunable within bounds)
| Default | Value | ROHME-tunable bound |
|---|---|---|
| totalSupply | 2,500 tokens | 1,000 – 5,000 · ~$12.5k FDV at $5 |
| creatorAllocBps | 0% | removed · founder buys from the curve |
| wethPoolBps | 70% | 50% – 90% · TOKEN/WETH vs TOKEN/gROHM |
| curvePreset | Project | Standard – Deep · 1/3/5/7 positions |
| epochLength | 1h / 2h / 4h / 8h | creator-chosen at launch · rebase cadence |
| rewardRatePpm | on | normalized per cadence · excess-reserve gated |
| votingDelay | 1h | 1h – 30d · flash-vote floor |
| votingPeriod | 24h | 24h – 90d |
| timelockDelay | 48h | 48h – 30d · execution delay |
| proposalThresholdBps | 0.25% | ≤ 1% of live gTOKEN |
| quorumBps | 10% | 4% – 25% · ROHME-like quorum |
| bondFloorBps | 70% | 50% – 100% of launch price |
| gateMarketCapBps | 2% | 0 – 3% of supply per gate market |
| bondVesting | 5d | 10m – 30d · note cliff |
| seedWethWei | 0 | ≤ 1,000 ETH · optional POL seed |
Units & conventions. ROHM, DENARI, and launched tokens are 9-decimal; gROHM and launched gTOKENs are 18-decimal; USD values across the protocol are 9-decimal (1e9 = $1.00). Governance clocks are timestamps, not block numbers. The chain’s transaction gas ceiling is 32,000,000.
THE LEDGER
ROHME is live on Robinhood Chain (chain 4663). Every address below is the deployed contract — tap any to open it in the Blockscout explorer.
Tokens
Core protocol
Governance
Launchpad