Documentation
How the vaults work
Everything on this page is what the contracts actually do. Numbers
come from the deployed code, not from a pitch deck.
Vaults
Opening
Odds
$VAULT
Pool
Fairness
Vault wallets
The collection
7777 pixel safes on Robinhood Chain. Every safe is drawn from the same
parts library, and its tier decides what the safe costs to open and
how likely it is to break. Supply thins out fast on the way up: 3400
Common safes against three True ones for the entire run.
Rarity is not written at mint. It is dealt after the mint sells out,
by shuffling the run with the hash of the sold out block, and each
token can be assigned exactly once. Until then a safe shows as sealed
rather than pretending to be Common.
Opening a safe
Opening a Common costs the collection floor, never less than one
dollar, and rarer tiers cost fixed multiples of that number (the
ladder is in the next section). The floor is read from the order book
by a daemon and written on chain once a day, so the price you pay
is the price the market is asking for the same safe.
The payment is not a fee to anyone. It goes straight into the pool as
a real swap: your ETH buys $VAULT, and that $VAULT is what lands in
your wallet. The pool charges 1% on the swap, which is the same number
as the 99% return the mechanic promises. There is no second fee
hidden anywhere.
An open runs in two transactions on purpose:
Commit. You pay, the swap happens, the tokens and the safes
are parked in escrow, and the roll is pinned to a block that does not
exist yet.
Reveal. Once that block is mined, its hash decides the
spread and whether the safe breaks. Anyone can call it, and whoever
does keeps the reveal tip you already paid, five cents by default.
A daemon does it in about ten seconds. If nobody shows up, the site
offers you the button and the tip comes back to you.
If a commit sits unrevealed for more than 256 blocks the hash is gone.
Nothing is lost: the commit re arms itself onto a fresh future block.
The payout is what your money bought, moved by a spread of plus or
minus 12%. That is why two identical safes opened a minute apart
rarely pay the same, and why nobody can promise a number in advance:
it depends on the price in the pool at the moment you pay.
Tiers, price and the risk
No safe holds a fixed amount of $VAULT. What a tier decides is what
the open costs and how likely the safe is to break. The money you pay
buys tokens in the pool at whatever the price is at that second, and
that is what you receive, give or take the spread. A rarer safe
therefore buys more tokens because it pays more, not because something
larger was put inside it.
Every price starts from the Common. Opening a Common costs the
collection floor, and never less than one dollar : the engine takes
whichever of the two is larger, so a floor of $0.95 still costs a
dollar, and a floor of $4 costs four.
Every rarer tier is a fixed multiple of whatever the Common costs at
that moment. If a Common costs $1.30, an Uncommon costs $1.65
(1.30 × 1.27) and a True costs $43.76 (1.30 × 33.67). The multiples
themselves never change, so the whole ladder moves as one. They grow
as the square root of rarity: supply falls 1133 times from Common to
True, the price rises only 33.67.
Tier Supply Costs to open
Breaks
Common3 400 floor, min $1 5%
Uncommon2 100 Common × 1.27 4%
Rare1 300 Common × 1.62 3%
Epic600 Common × 2.38 2%
Legendary260 Common × 3.62 1%
Mythic90 Common × 6.15 0.5%
Ultra24 Common × 11.90 0.1%
True3 Common × 33.67 never
A safe can break when it is opened. A broken safe is burned and does
not come back, and the tokens from that open are still paid out. True
safes never break, which makes them the only ones that can be opened
forever.
Up to 30 safes can be opened in one go: a single payment,
a single roll transaction, and a separate outcome for every safe
inside the batch.
Both columns live in the engine and are readable on
chain at any time, and the table above shows what the contract says
right now. Break odds can be lowered or raised for a campaign, never
above 20% and never for True, and the odds are frozen the moment you
pay: a change made afterwards cannot touch a batch already committed.
The site quotes the real price of your exact safes before you sign.
$VAULT
A plain ERC-20 with a fixed supply of 100 000 000 and no mint function
left in the contract. There is no transfer tax: a tax breaks
concentrated liquidity, because the pool checks the balance before and
after and reverts when less arrives than promised. The 1% lives in the
pool instead.
50M Liquidity position
Laid out across the price range. This is what every open buys
from.
20M Depth reserve
Sits on the engine and refills the position automatically.
Nobody can withdraw it, the function does not exist.
20M Treasury
Held by its own contract, not on a personal wallet.
10M Team, vested
20% unlocks a week after launch, then 10% more every week.
Nothing is claimable before that first week.
The pool and the gate
Liquidity is a single Uniswap v4 position owned by the engine. There
is no withdraw path in the bytecode, so the position cannot be pulled.
Fees collected on the position stay with it.
Trading is locked at launch by a hook contract. Before trading opens
the hook reverts every swap that does not come from the engine, which
means $VAULT cannot be bought or sold anywhere and the only way tokens
enter circulation is by opening safes. The hook owns nothing and stores
nothing, it only asks the engine whether trading is open.
The lock is one way. The owner can open trading at any moment, and
anyone at all can open it 14 days after the presale starts. Once open,
there is nothing in the code that closes it again.
The position is finite, and tokens leave it faster than money comes
in. That is why the depth reserve exists: when price approaches the
bottom of what is laid out, the engine puts down the next tranche by
itself, one of four, each covering roughly a doubling in price. The
refill happens before the swap in the same unlock, so a large open
meets the depth that was just added.
What makes it checkable
The provenance hash of all 7777 images was published before the
first mint, so the art cannot be swapped afterwards.
The roll cannot be replayed. It is decided by a block hash that did
not exist when you paid, so a contract cannot peek at the result and
revert the transaction to try again.
Anyone can reveal a commit, not just its owner, so an unlucky roll
cannot be sat on.
Tiers can be written once per token and then locked forever.
The engine is set on the collection exactly once. A replaceable
engine would mean the right to point at a contract that takes
other people's safes.
Vault wallets
Every safe owns an ERC-6551 account through the canonical registry,
so a vault can hold tokens and NFTs of its own, and whatever sits
inside moves with the safe when it is sold.
A burned safe locks its wallet forever. Ownership of
the account is read from the token, and a burned token has no owner,
so anything left inside becomes unreachable. Empty a vault wallet
before you open the safe.