Weekend-gap protection for Robinhood Chain Stock Tokens. Fully collateralized puts, priced onchain by a Stylus (Rust) engine from the feed's own history, settled on the first Monday print.




AT A GLANCE — Live on Robinhood Chain testnet: v2.1 market 0x91107801a88baCeC879554e4F0529BF015fA5A03 (the v2 market submitted with the form, 0x605dF7bFc5E17fF57A8F9a586Bc5032B797D4fd7, also stays live). Quotes come from real mainnet Chainlink round history mirrored on chain, not mock feeds. Premiums are computed onchain by an Arbitrum Stylus (Rust) pricing engine: realized vol from the feed's own rounds plus a closed-market surcharge for the 49 h/week the feeds are dark. Settlement uses the first valid print at or after expiry; positions are fully collateralized ERC-1155s; writers earn via ERC-4626 vaults with settlement escrow, premiums that accrue over a series' life, and mark-to-market gating. Two adversarial audit rounds (90 and 94 agents, three independent reviewers per finding); every confirmed finding fixed. 117 Foundry tests (6 invariants) + 28 pricer tests; keeper on a public GitHub Actions cron. Demo works with a built-in wallet at bchuazw.github.io/afterhours.
The gap nobody prices. Robinhood Chain brings US equities onchain as ERC-20 Stock Tokens, and their Uniswap pools never close. But the Chainlink tokenized-equity feeds that value them are 24/5: they go quiet from Friday 20:00 ET to Sunday 20:00 ET. For ~52 hours a week, every holder of tokenized TSLA, NVDA or AMZN carries gap risk that nothing on the chain can hedge. Perps are leverage, not insurance. Lending markets liquidate; they don't protect. Listed options don't exist for the tokens.
AfterHours is the missing primitive. A holder picks a stock, a strike (say 90% of spot) and an expiry ("Monday open", "Friday close", 7 or 30 days) and pays a stablecoin premium. They receive an ERC-1155 position that pays max(strike − settle, 0) per token in stablecoins. Writers deposit stablecoins into a per-stock ERC-4626 vault; premiums accrue to the vault over the life of each series. Every position is fully collateralized at the moment of sale: no liquidation engine, no leverage, no oracle-manipulation-to-liquidate surface.
Priced onchain, in Rust. The premium is computed by an Arbitrum Stylus contract. It walks the underlying's Chainlink round history with getRoundData, derives annualized realized volatility over open-market seconds (so weekend freezes don't dilute it), measures variance from the last print rather than "now", splits the tenor into open and closed seconds, charges closed time at a configurable multiple of vol (σ_eff²·T = σ²·(T_open + m²·T_closed)) and returns a Black-Scholes put premium plus the writer spread. The market cross-checks the pricer's spot against the feed and enforces a premium floor of intrinsic value plus 5 bps. The same math in Solidity would be a gas-hungry mess; in Rust it is ~200 lines of fixed-point i128 with native unit tests.
Settled on the first print after expiry. A "Monday open" put settles on the first valid feed print at or after expiry, not whatever price is convenient hours later: settle() walks back the round history to the earliest post-expiry round, and settleAt() takes a verified round hint when the walk is long. Expiries sit on a 30-minute grid and can never fall in the dark window (Friday 20:00 UTC to Monday 01:00 UTC), so no series is priced for a weekday and settled on the Monday reopen. If the Stock Token is paused for a corporate action, settlement waits; after a per-series grace period the last valid price is used so collateral never strands. At settlement, any payout moves into escrow and the rest of the collateral returns to writers immediately; out-of-the-money positions need no claim.
Writer protection. Protocol fees come only from time value, never intrinsic. Premiums accrue linearly, so a deposit made just before expiry earns only its own risk period. The vault marks open puts to market and closes entries and exits while the feeds are dark with exposure or while an expired series awaits settlement, so nobody can trade ahead of a loss that is already known. Every risk-increasing admin change (pricer, pricing parameters, config) is scheduled with a two-day open-market delay; writers can always exit first.
Built for Robinhood Chain. Stock Tokens, Chainlink equity feeds and Stylus only exist together on Robinhood Chain. The testnet deployment mirrors the real mainnet Chainlink rounds (same roundIds, answers and timestamps) onto Chainlink-compatible FeedMirror contracts, so the demo runs on live market data with the real weekend freeze. On mainnet the market points straight at the Chainlink proxies and settles in USDG.
In the repo (github.com/bchuazw/afterhours): AfterHoursMarket (ERC-1155 series, quote/buy/settle/settleAt/claim, scheduled admin changes), ProtectionVault (ERC-4626 with collateral locking, premium accrual, mark-to-market and a utilization cap), FeedMirror, the Stylus pricer, 117 Foundry tests including invariants, a keeper (feed relayer + settlement bot on a GitHub Actions cron) and a Next.js app with Protect / Earn / Positions views.
How to verify onchain in two minutes. Call quote(1, 31900000000, <any expiry on a 30-minute grid, ≥ 1 h out, before Friday 20:00 UTC>, 1e18) on the v2.1 market and the premium you get back was computed by the Stylus pricer 0x0006FC22254403d08D0Cdf1b005CD3906Cfc6fE8 from mirrored mainnet Chainlink history; the TSLA mirror 0x8492cad02fD0bF9358B2988e43039e013D56FfBA replays the real mainnet round ids, answers and timestamps. Buy, settle and claim events are on the explorer; each vault exposes locked collateral, unearned premium and mark-to-market liability. The keeper that relays mainnet rounds and settles expired series runs in public on GitHub Actions (repo → Actions → keeper). Gas for the demo wallet comes from faucet.testnet.chain.robinhood.com; test tUSD from the in-app mint.
Everything was designed and built during the buildathon, starting 14 Sep 2026; commit history is public at github.com/bchuazw/afterhours.
Week 1: market + ERC-4626 writer vault + feed mirror in Solidity with Foundry tests; the Stylus (Rust) pricing engine with native unit tests, passing cargo stylus check on Robinhood Chain testnet; a keeper that replays real Robinhood Chain mainnet Chainlink rounds; the Next.js app (Protect / Earn / Positions / How it works).
Week 2: full lifecycle verified end to end on an Arbitrum Nitro node with Stylus (onchain quote from live TSLA/AMZN/NVDA feed history, buy, settle at the first post-expiry mainnet print, claim); pitch video.
Week 3: a 90-agent adversarial audit (three independent reviewers per finding) confirmed 27 defects in v1, including collateral behind out-of-the-money series never being released, the vault share price ignoring payouts already owed, variance measured from "now" instead of the last feed print, weekend expiries settling days after they were priced, and the corporate-action pause flag living on the Stock Token rather than the feed. v2 fixes all of them: per-series accounting with settlement escrow, premiums unearned until settlement, mark-to-market vault gating while feeds are dark, sales blocked in the dark window, feed-spot cross-check and premium floor against the pricer, a 2-day pricer timelock, bounded settle walk-back with a verified settleAt hint, and invalid genesis rounds rejected instead of rescaled. 97 Foundry tests (incl. invariants) and 28 pricer tests. v2 is live on Robinhood Chain testnet with real mainnet feed history mirrored on chain; the keeper runs on a GitHub Actions cron.
Not currently fundraising. Prototype stage; seeking Founder House feedback on writer-side economics and a path to mainnet with USDG collateral and native Chainlink feeds.