VAULTHAUS
Documentation

How the vaults work

Everything on this page is what the contracts actually do. Numbers come from the deployed code, not from a pitch deck.

The collection

7777 pixel safes on Robinhood Chain. Every safe is drawn from the same parts library, and its tier decides what the safe costs to open and how likely it is to break. Supply thins out fast on the way up: 3400 Common safes against three True ones for the entire run.

Rarity is not written at mint. It is dealt after the mint sells out, by shuffling the run with the hash of the sold out block, and each token can be assigned exactly once. Until then a safe shows as sealed rather than pretending to be Common.

Opening a safe

Opening a Common costs the collection floor, never less than one dollar, and rarer tiers cost fixed multiples of that number (the ladder is in the next section). The floor is read from the order book by a daemon and written on chain once a day, so the price you pay is the price the market is asking for the same safe.

The payment is not a fee to anyone. It goes straight into the pool as a real swap: your ETH buys $VAULT, and that $VAULT is what lands in your wallet. The pool charges 1% on the swap, which is the same number as the 99% return the mechanic promises. There is no second fee hidden anywhere.

An open runs in two transactions on purpose:

  1. Commit. You pay, the swap happens, the tokens and the safes are parked in escrow, and the roll is pinned to a block that does not exist yet.
  2. Reveal. Once that block is mined, its hash decides the spread and whether the safe breaks. Anyone can call it, and whoever does keeps the reveal tip you already paid, five cents by default. A daemon does it in about ten seconds. If nobody shows up, the site offers you the button and the tip comes back to you.

If a commit sits unrevealed for more than 256 blocks the hash is gone. Nothing is lost: the commit re arms itself onto a fresh future block.

The payout is what your money bought, moved by a spread of plus or minus 12%. That is why two identical safes opened a minute apart rarely pay the same, and why nobody can promise a number in advance: it depends on the price in the pool at the moment you pay.

Tiers, price and the risk

No safe holds a fixed amount of $VAULT. What a tier decides is what the open costs and how likely the safe is to break. The money you pay buys tokens in the pool at whatever the price is at that second, and that is what you receive, give or take the spread. A rarer safe therefore buys more tokens because it pays more, not because something larger was put inside it.

Every price starts from the Common. Opening a Common costs the collection floor, and never less than one dollar: the engine takes whichever of the two is larger, so a floor of $0.95 still costs a dollar, and a floor of $4 costs four.

Every rarer tier is a fixed multiple of whatever the Common costs at that moment. If a Common costs $1.30, an Uncommon costs $1.65 (1.30 × 1.27) and a True costs $43.76 (1.30 × 33.67). The multiples themselves never change, so the whole ladder moves as one. They grow as the square root of rarity: supply falls 1133 times from Common to True, the price rises only 33.67.

TierSupplyCosts to open Breaks
Common3 400floor, min $15%
Uncommon2 100Common × 1.274%
Rare1 300Common × 1.623%
Epic600Common × 2.382%
Legendary260Common × 3.621%
Mythic90Common × 6.150.5%
Ultra24Common × 11.900.1%
True3Common × 33.67never

A safe can break when it is opened. A broken safe is burned and does not come back, and the tokens from that open are still paid out. True safes never break, which makes them the only ones that can be opened forever.

Up to 30 safes can be opened in one go: a single payment, a single roll transaction, and a separate outcome for every safe inside the batch.

Both columns live in the engine and are readable on chain at any time, and the table above shows what the contract says right now. Break odds can be lowered or raised for a campaign, never above 20% and never for True, and the odds are frozen the moment you pay: a change made afterwards cannot touch a batch already committed. The site quotes the real price of your exact safes before you sign.

$VAULT

A plain ERC-20 with a fixed supply of 100 000 000 and no mint function left in the contract. There is no transfer tax: a tax breaks concentrated liquidity, because the pool checks the balance before and after and reverts when less arrives than promised. The 1% lives in the pool instead.

50MLiquidity position Laid out across the price range. This is what every open buys from.
20MDepth reserve Sits on the engine and refills the position automatically. Nobody can withdraw it, the function does not exist.
20MTreasury Held by its own contract, not on a personal wallet.
10MTeam, vested 20% unlocks a week after launch, then 10% more every week. Nothing is claimable before that first week.

The pool and the gate

Liquidity is a single Uniswap v4 position owned by the engine. There is no withdraw path in the bytecode, so the position cannot be pulled. Fees collected on the position stay with it.

Trading is locked at launch by a hook contract. Before trading opens the hook reverts every swap that does not come from the engine, which means $VAULT cannot be bought or sold anywhere and the only way tokens enter circulation is by opening safes. The hook owns nothing and stores nothing, it only asks the engine whether trading is open.

The lock is one way. The owner can open trading at any moment, and anyone at all can open it 14 days after the presale starts. Once open, there is nothing in the code that closes it again.

The position is finite, and tokens leave it faster than money comes in. That is why the depth reserve exists: when price approaches the bottom of what is laid out, the engine puts down the next tranche by itself, one of four, each covering roughly a doubling in price. The refill happens before the swap in the same unlock, so a large open meets the depth that was just added.

What makes it checkable

  • The provenance hash of all 7777 images was published before the first mint, so the art cannot be swapped afterwards.
  • The roll cannot be replayed. It is decided by a block hash that did not exist when you paid, so a contract cannot peek at the result and revert the transaction to try again.
  • Anyone can reveal a commit, not just its owner, so an unlucky roll cannot be sat on.
  • Tiers can be written once per token and then locked forever.
  • The engine is set on the collection exactly once. A replaceable engine would mean the right to point at a contract that takes other people's safes.

Vault wallets

Every safe owns an ERC-6551 account through the canonical registry, so a vault can hold tokens and NFTs of its own, and whatever sits inside moves with the safe when it is sold.

A burned safe locks its wallet forever. Ownership of the account is read from the token, and a burned token has no owner, so anything left inside becomes unreachable. Empty a vault wallet before you open the safe.

ContractsRobinhood Chain
Collection—
Engine—
Token—
Trading gate—
Treasury—
Team vesting—
Minted—
Opens—