House rules · read before you pawn

The docs

How the shop works, in plain words, with the real numbers. Figures marked with a dotted underline are read live from the server's /api/config, which reads them from the contracts, so this page can't drift from the code.

What Pawnhood is

A pawn shop for tokenized stocks on Robinhood Chain. You hold tokenized shares (SPY, NVDA, TSLA and others) and need cash, but you don't want to sell. You pawn the shares at the counter, take USDG right away, and get them back when you repay the loan. Need cash? Keep your shares.

Three things make it different from a normal DeFi lending market:

  • No liquidation before the due date. If the price crashes at 3am, nothing happens. Your shares sit in the contract until the due date plus the grace period, whatever the price does.
  • Flat fee, fixed term. You pick 7, 14 or 30 days. The fee is a flat percentage of the loan taken up front. No variable interest, no surprises.
  • An honest window. If you don't come back, your shares are sold in a public falling-price auction, and 90% of anything above your loan goes back to the ticket holder.

Every loan is a pawn ticket: an NFT (ERC-721) with its artwork drawn on-chain. The ticket can be moved or sold; whoever holds the ticket gets the shares when it is redeemed. The cash comes from the till, a vault anyone can lend USDG to.

How to pawn, step by step

  1. Get the shares and a little ETH for gas on Robinhood Chain (chain id 4663). The shares must be one of the stocks on the counter (see the list below).
  2. Open the counter and connect your wallet. Pawnhood asks your wallet to switch to Robinhood Chain if needed.
  3. Pick the shares (the hanging price tags), enter how many to pledge, and pick a term: 7, 14 or 30 days.
  4. The counter shows a live quote: the appraisal price, the value of your shares, your LTV, the maximum loan, the fee, what you receive, and the due date. You can tick "Borrow less than the maximum" to take a smaller loan and keep a bigger cushion.
  5. Approve the counter to move that stock (one wallet prompt), then Pawn (a second prompt). The pawn call carries a minimum you will accept (99% of the quoted amount), so if the price moves against you between quote and signing, the transaction refuses instead of paying you less.
  6. You receive loan − fee in USDG, the shares are locked in the counter contract, and the pawn ticket NFT lands in your wallet. It shows up under My tickets.

What you owe is the loan, not the loan plus interest. The fee was already taken. Repay exactly the loan amount any time before the grace period ends.

How the appraisal works

Each stock has one Uniswap V3 pool against USDG, checked to be the real pool from the Uniswap factory. When you pawn or extend, the counter reads three prices from that pool:

  • Spot: the pool's price right now.
  • 30-minute average (TWAP): the time-weighted average over the last 30 minutes.
  • 6-hour anchor: the time-weighted average over the last 6 hours.
appraisal price = the lowest of (spot, 30-minute average, 6-hour anchor) value = shares × appraisal price max loan = value × LTV

Taking the lowest of three means a pump has to be held for hours, not seconds, before it can lift a loan, and even then the cap and the speed limit below keep the damage small.

The two price guards

  • Spot vs 30-minute: if spot is more than 200 ticks (about 2%) away from the 30-minute average, the counter refuses (PriceDeviation). Someone may be pushing the pool, or the market just jumped; it waits until the two agree again, usually minutes.
  • 30-minute vs 6-hour: if the 30-minute average is more than 500 ticks (about 5%) away from the 6-hour anchor, the counter refuses (AnchorDeviation). A move that big in half an hour is news or manipulation, and the shop doesn't lend into either.
  • No history, no loan: if the pool can't report its 30-minute or 6-hour history, the appraisal fails (ObserveFailed). There is no fallback price; the counter refuses rather than guess.

The guards apply to pawning, extending and sending a ticket to the window. Redeeming never checks a price, so you can always pay back and take your shares.

The watchdog and the guardian

A pool can be wrong even when it agrees with itself. So the shop's server runs a watchdog that compares each pool's 30-minute price with the real stock's reference price. If they drift apart by more than 12% while the market is open or 20% while it's closed (twice in a row), it acts through the guardian key: it disables that stock for new loans, or pauses all new pawns if several stocks go wrong at once or the reference feed dies while pools move.

The guardian can only stop things: pause new pawns or disable a stock, instantly. It can never unpause, re-enable, raise a limit, or touch any funds or shares. Only the owner can switch things back on. Redeem, extend, the window and the till keep working while paused.

The speed limit

On top of each stock's cap there is a lending speed limit: new loans against one stock can use at most an eighth of its cap per 6 hours. Think of a bucket that holds cap ÷ 8 and refills steadily over 6 hours (for SPY, with a 5,000 cap, that's 625 USDG). When it's empty the counter says RateLimited; try a smaller loan or come back a bit later. Each price tag on the counter shows the cap room and the room left this 6 hours.

LTV classes and terms

LTV (loan to value) is how much of the appraised value you can borrow. It depends on how jumpy the stock is:

ClassWhatBase LTV
AIndex & commodity funds50%
BMega caps40%
CVolatile names30%

Then the term:

TermFlat feeLTV changeThen grace
7 days1.5%none24 hours
14 days2.5%none24 hours
30 days4.5%−5%24 hours
your LTV = class LTV − term cut − weekend cut + punch card bonus (never above 60%)

The stocks on the counter

Loading the list…

The weekend rate

Tokenized stocks trade around the clock, but the real stock market doesn't. When it's closed, the pool price has nothing to follow and can drift. So while the market is closed the counter lends 5% less LTV.

The contract counts as "weekend": all of Saturday and Sunday, Friday from 20:00 UTC, and Monday before 14:30 UTC. The contract works in UTC, so this window is wide enough to cover the Friday close and the Monday open in both US summer and winter time. NYSE holidays are not known on-chain, so on a weekday holiday the normal rate applies even though the market is closed; be aware that prices can drift on those days too.

The weekend rate is fixed into your ticket when you pawn. It does not change your ticket later.

Fees and the 80/20 split

The fee is a flat percentage of the loan for the term you pick, taken from the loan up front. There is no interest after that. The fee is split:

  • 80% to the till, the lenders whose USDG you borrowed. It vests into the share price over 7 days (see the till).
  • 20% to the house. The house is paid by pull: its share waits in the counter (houseOwed) until anyone calls claimHouse(), which sends it to the house (buyback) wallet. A frozen or broken house wallet can never block a loan. The house buys $PAWN with it; buybacks are listed in the ledger.

Worked example

Pawn NVDA worth 2,500 USDG, class B (40%), 14 days max loan = 2,500 × 40% = 1,000.00 USDG fee = 1,000 × 2.5% = 25.00 USDG (20.00 to the till, 5.00 to the house) you receive = 1,000 − 25 = 975.00 USDG you owe = 1,000.00 USDG, by the due date + 24 hours of grace

The $PAWN holder discount

If the wallet that pawns (or extends) holds at least the minimum amount of $PAWN, the fee is 25% lower. The check is a plain balance check at the moment you sign; nothing is locked or staked. The minimum is set on the counter after launch.

$PAWN launches on Pons. At go-live the owner first sets the minimum hold and only then the token address (the contract refuses the token without a minimum, MinHoldNotSet). Until then there is no discount for anyone. Because the check reads the live balance, the same bag could be passed between wallets to get the discount several times; that costs the shop at most a quarter of a fee each time, and is accepted.

$PAWN is a community token: it has no claim on fees and no promise of return. The house buys it back with its 20% share of fees.

Redeem and extend

Redeem

Pay back the loan in USDG any time while the ticket is active and before the grace period ends. Two wallet prompts: approve USDG, then redeem. The shares go to whoever holds the ticket at that moment (anyone may pay, the shares always go to the holder). The ticket stays in your wallet, stamped "Redeemed".

If the stock's issuer pauses transfers

Tokenized stocks are issued by a third party that can pause or block transfers. If that happens when you redeem, the loan still closes: your payment is taken, the ticket is marked redeemed, and your shares wait in the counter marked as pending. When the issuer allows transfers again, the ticket holder presses Collect on My tickets (collect(id)) and the shares come out.

Extend

Only the ticket holder can extend. It works even if the stock has since been disabled for new loans, because extending never adds to the loan; the LTV is still checked against today's price. Pick a new term and pay its fee on the remaining loan, optionally paying down part of the loan at the same time. The new due date is the later of the old due date and now, plus the new term, and it can't be more than 31 days from today. Because the shop is lending again, the loan after paydown must fit under today's appraisal and LTV (same three prices and guards as a new pawn), and stay at or above the minimum loan. To pay off everything, use Redeem.

The grace period

After the due date there are 24 hours of grace. You can still redeem or extend, no penalty. When grace ends, the ticket can no longer be redeemed: anyone (usually the shop's keeper bot, right away) can send it to the window. Sending it there uses the same price guards; if they fail, it simply waits and anyone retries.

Set a reminder. Due dates are shown in UTC and in your own time on your ticket. The contract does not care about time zones, holidays or wallet trouble: grace ends when it ends.

The window

When a ticket goes to the window, the contract values the shares from the seller's side, at the higher of spot and the 30-minute average, and starts a falling-price sale (a Dutch auction):

price starts at 110% of that window value falls in a straight line to 60% over 24 hours then stays at 60% × the lower of (the window value, today's 30-minute value) until someone buys

The after-auction floor only uses today's price while the price guards pass; otherwise it stays at 60% of the window value. Nobody can buy in the same block the ticket enters the window. Anyone can buy at the current price on the window page. The buyer pays USDG and gets the shares. Then:

  • Price above the loan: the loan goes back to the till. The surplus is split 90% to the ticket holder (claim it on My tickets) and 10% to the house.
  • Price below the loan: the till gets the whole price and carries the rest as a loss, shared by all till lenders.

The loss is booked the moment the ticket enters the window, not when it sells: the till writes off the part of the loan above 60% of the window value right away (a "provision"). If the sale goes better, the difference comes back to the till, vesting over 7 days like a fee. This is so lenders can't see a loss coming and withdraw just before it lands, or jump in just to catch a recovery.

Example: a ticket owes 1,000 USDG and the shares sell for 1,400. The till gets 1,000, the house 40, the ticket holder can claim 360.

The punch card

Regulars get a better rate. A redemption that counts punches one hole in the original borrower's punch card (the wallet that pawned, not whoever holds the ticket), up to 5 holes. Each hole adds 1% LTV to that wallet's future pawns and extensions (still capped at 60%).

A redemption counts when the loan was at least 250 USDG, the ticket was held at least 7 days, and the wallet hasn't been punched in the last 24 hours (one punch per day at most). The rules make farming holes with tiny or same-day loans pointless. The card lives on-chain and can't be bought or moved.

Lending to the till

The till is an ERC-4626 vault over USDG. Deposit USDG on the till page and you receive TILL shares. The till's value is its idle USDG plus every loan that's out, minus fees that are still vesting; fees raise it, losses lower it.

  • Income vests over 7 days. The till's share of each fee, and anything a window sale recovers above its provisioned loss, flows into the share price steadily. A deposit made just before a fee or a sale and withdrawn right after earns nothing from it; the income goes to lenders who stayed while the loans were out.
  • Losses are booked early, and eat unvested income first. When a ticket enters the window, its expected loss is written off at once (see the window), so nobody can dodge a loss everyone can already see. A loss first cancels income that hasn't vested yet, and only the rest lowers the share price.
  • Utilization cap: the counter only lends while the loans out stay under 85% of the till.
  • Withdrawals are limited by idle cash. You can take out up to what's sitting in the drawer. If most of the till is lent, you wait for redemptions and window sales. There is no queue: try again later.
  • Returns are trailing, not promised. The till page shows last week's fees as an APR. It moves with how much people pawn and drops with losses.
  • Only the counter contract can borrow from the till. The owner cannot move till funds.

Limits and what the owner can do

  • Loan per ticket: 10 USDG to 25,000 USDG. The maximum can never be set above 25,000 USDG.
  • Each stock has a cap on total loans out against it, set from what it would cost to manipulate its pool: the USDG needed to push the stock's price up by 1 ÷ LTV (×2 at 50%, ×2.5 at 40%, ×3.33 at 30%), walked tick by tick through the real pool. cap = min(15% of that cost, 5% of the USDG in the pool, 50,000), rounded down to 1,000 A stock whose cap would be under 2,000 is not listed. That's why a big name can have a small cap: pushing SPY's pool ×2 costs only about 37,000 USDG, so its cap is 5,000. No cap can ever exceed 50,000 USDG. The counter shows each stock's live cap and room.
  • The speed limit: at most an eighth of a stock's cap can be lent per 6 hours (above).
  • New listings start small. Stocks added after launch share one limit of 25,000 USDG of loans out between them for their first 30 days, on top of their own caps. When it's full the counter says CapExceeded and shows the room left.
  • The owner can pause new pawns (redeem, extend and the window keep working), and tighten a stock (lower LTV or cap, or disable it) right away.
  • Anything that adds risk waits behind a timelock, visible on-chain before it applies: 72 hours for a new stock or a new pool (which must be the factory's own pool for that pair), 24 hours for a higher LTV or cap on the same pool, re-enabling a stock, or new loan limits. LTV can never exceed 60%.
  • There is no upgrade path, ownership can't be renounced, and the owner cannot move pledged shares, surpluses or till funds.

Go-live order

  1. The till and the counter are deployed with the checked stock list; the till is tied to the counter for good.
  2. The keeper starts watching for tickets past grace.
  3. $PAWN launches on Pons. The owner sets the minimum hold, then the token address (in that order), which turns on the holder discount.

Risks

Not financial advice. Loans can be lost. Unaudited contracts. Read this section before you pawn or lend.

  • Not audited by a third party. The contracts are tested (unit, fuzz, invariants, and on a fork of Robinhood Chain mainnet) and went through an internal adversarial review, but no outside firm has audited them. A bug could lock or lose funds.
  • Borrowers: you can lose your shares. If you don't redeem before grace ends, the shares are sold in the window. You keep the loan and get back 90% of any surplus above it, but if the sale price is low you may get nothing back.
  • The owner chooses listings. After 72 hours of public notice the owner can list a new stock on a real pool; new listings share a 25,000 USDG limit for their first 30 days. Ownership is meant to move to a multisig.
  • Lenders: losses are shared by the till. If shares fall more than (1 − LTV) before a ticket is due and the window sells below the loan, every till lender shares the loss. A lender who withdraws during the grace period, before the ticket is sent to the window, can still avoid that ticket's loss; the keeper sends tickets as soon as grace ends to keep that gap short.
  • Held price manipulation. Someone who pushes a pool and holds it there for about 6 hours passes both guards. The caps (15% of the cost to push), the speed limit (an eighth of the cap per 6 hours) and the watchdog's reference-price check mean they'd keep tens of times more money at risk against arbitrage than they could take. Caps must be re-checked when pool liquidity changes; the owner can tighten instantly.
  • Weekend and holiday drift. When the stock market is closed, pool prices can drift away from where the stock reopens. The weekend rate, the three-price appraisal and the guards help, but don't remove this. NYSE holidays aren't known on-chain.
  • Pool data can run short. A pool keeps a limited ring of past prices. If someone spams it with trades until less than 6 hours of history is left, pawns, extensions and sending to the window pause on that stock until the history recovers. Redeem and Collect always work. The server watches each pool's history length and raises an alert well before it gets short.
  • The watchdog is off-chain. The guardian that pauses on price divergence runs on the shop's server and uses outside reference prices. If it is down or its feed is wrong, the on-chain guards still apply, but the extra stop doesn't. It can only pause or disable, never move funds.
  • Withdrawal timing. Till withdrawals are limited by idle cash and can be delayed when utilization is high.
  • Third-party tokens. Tokenized stocks and USDG are issued by third parties that can pause or freeze them. A paused stock is handled by Collect; a paused USDG would block repayments for everyone, which no contract can fix.
  • Not affiliated. Pawnhood is not affiliated with Robinhood Markets, Pons, Uniswap, or any company whose stock is listed. Tickers are used only to name the shares; no company logos are used.
  • $PAWN is a community token with no claim on fees and no promise of return. The only official contract address is the one on this site, pinned on our X and Telegram.

Security review

Before launch the contracts went through an internal adversarial review: we attacked our own code the way a thief would, with working exploits against real Robinhood Chain pools. It found one high-severity issue (a pool price could be pushed and held to inflate loans), three medium and several low ones. Each was fixed, and each original exploit is kept as a test that must now fail:

  • Held manipulation → the 6-hour anchor, the second guard, manipulation-priced caps and the speed limit.
  • Window pricing → the window uses the seller-side price with the same guards; no buying in the same block.
  • Pool checks → every pool must be the Uniswap factory's own; hard limits on caps and loan size; 72-hour timelock for new stocks and pools.
  • Lender fairness → fees and window recoveries vest over 7 days, losses are provisioned when a ticket enters the window and eat unvested income first.
  • A second pass → a smaller speed limit (an eighth of the cap per 6 hours), a 25,000 USDG shared limit for new listings in their first 30 days, a guardian key that can only pause or disable (driven by an off-chain watchdog comparing pool and reference prices), and pool-history monitoring.
  • Smaller fixes → the 31-day extension limit, stricter punch card rules, the house paid by pull, and Collect for issuer-paused shares.

This is not a third-party audit. The contracts are still unaudited by an outside firm. Use amounts you can afford to lose.

Contract addresses

Robinhood Chain mainnet (chain id 4663). Click through to the explorer and check the verified source.

Loading…

FAQ

Will my shares be sold if the price drops?

Not before the due date plus grace. Nothing in the contract reacts to price during the term. Only an unredeemed ticket after grace goes to the window.

Can I repay early?

Yes, any time. You repay the loan amount; the fee was for the term and is not refunded.

Can I repay part of the loan?

Yes, by extending with a paydown: you pay part of the loan plus the fee for a new term on what's left.

I sold or sent my ticket. Who gets the shares?

Whoever holds the ticket when it is redeemed. The punch card hole still goes to the wallet that pawned.

Someone else redeemed my ticket?

Anyone may pay a ticket's loan, but the shares always go to the ticket holder. Paying someone's ticket is a gift to them.

Why did the counter refuse my pawn?

The counter shows the reason under the quote. The usual ones: spot is more than about 2% from the 30-minute average, or the 30-minute average is more than about 5% from the 6-hour anchor (wait for prices to settle), the stock hit its 6-hour speed limit or its cap, the till is at its 85% lending limit, or the loan is under the minimum.

My redemption went through but the shares didn't arrive?

The stock's issuer probably paused transfers. Your loan is closed and the shares are safe in the counter; press Collect on My tickets once transfers reopen.

Why is my loan smaller on Saturday?

The weekend rate: LTV is 5% lower while the stock market is closed, because pool prices can drift with no market to follow.

Is the till APR guaranteed?

No. It's last week's fees divided by the average till size, annualised. It changes with demand and falls with losses.

What if nobody buys in the window?

The price stops at its floor (60% of the lower of the window value and today's 30-minute value, or 60% of the window value while the price guards fail) and waits for a buyer. The ticket holder's surplus right stays until it sells.

What do I need to start?

An EVM wallet (MetaMask, Rabby…), tokenized shares on Robinhood Chain, and a little ETH on Robinhood Chain for gas.