Prices for the 159 Robinhood stock tokens Chainlink doesn't cover. Applies the split multiplier in force when each price was observed, and refuses rather than guesses. Live on mainnet.




On Robinhood Chain mainnet, 45 of the 194 stock tokens carry a multiplier other than 1, and 32 of those have no Chainlink feed. Price one by its share price and you are wrong: 75% low on CRWD (a 4:1 split), up to 2.1% low on the rest, and 36 of those multipliers changed in the last 30 days (all read on-chain at block 79,510,181).
Slate is a price feed built for those tokens. It applies each token's multiplier as it stood when the price was observed, refuses to answer around a split instead of guessing, and is live on mainnet for 20 tokens with no Chainlink feed (8 of the 32 so far, CRWD first), with a USDG lender that values CRWD and all 29 contracts verified on Sourcify.
Paxos USDG: CRWD and AAPL are quoted in USDG by live mainnet feeds (CRWD/USDG 1,079.75, AAPL/USDG 333.78 at block 79,366,648), StockLender on mainnet lends USDG against CRWD, and in a fork test pinned to mainnet block 78,690,791 Slate's router bought AAPL with real USDG through the live AAPL/USDG pool, paying 33.36 against 33.38 fair.
THE PROBLEM, MEASURED
Robinhood Chain lists 194 stock tokens; Chainlink publishes feeds for 35. Robinhood's own docs say every stock token has a live Chainlink feed; the chain shows 159 don't. Without a price a token can't be borrowed against, held in an index or used as collateral, and pricing one yourself is a trap: each is an ERC-8056 token whose uiMultiplier() changes at a set time. Our census reads every token's multiplier from the chain: 45 are not 1 (one split, CRWD ×4; 44 smaller adjustments up to CCL ×1.0215), 32 of them have no Chainlink feed, and 36 changed in the last 30 days, 7 in the last week. It is live at app.slate.0xo.in/census and rebuildable with one script. We also reproduced the split failure: in our Corporate Action Lab (testnet) a lender on a naive feed lent 742.47 against a token worth $372.94, while the same lender on Slate paused until the post-split price landed.
WHAT SLATE DOES
SlateFeed = a share price signed by 2 of 3 signers (EIP-712) × the multiplier in force at the moment of observation, served through Chainlink's AggregatorV3Interface, so any protocol that reads Chainlink reads Slate unchanged. It fails closed with a named status: market closed (an on-chain NYSE calendar with holidays and New York daylight saving), stale, oracle paused, a split straddling the price, or a corporate action inside its grace window. On mainnet, CRWD's first signed price was $268.105 × 4.000 = $1,072.42 (tx 0x0d8a2bde…ccda); at block 79,360,405 it reads $1,079.90, Friday's close, marked market-closed. On testnet, SLATE-5 is a basket of five stock tokens created and redeemed in kind whose NAV is itself an AggregatorV3 feed, and SlateRouter refuses any purchase leg more than 3% from Slate's price.
WHO IT IS FOR, AND THE HONEST STATE OF DEMAND
No outside protocol has integrated Slate yet, and no one has borrowed from the mainnet lender, which holds no USDG. Here is why we expect them to come.
The users: lending markets and vaults on Robinhood Chain that want stock tokens as collateral (today they can list only the 35 Chainlink covers), index and basket builders, and Robinhood itself, whose docs promise a feed for every token.
Why they would come: no new integration, since a Slate feed is a Chainlink feed to their code; protection from the split mispricing that would otherwise liquidate users or drain a market; and a fail-closed status that tells them why there is no price.
Evidence of need today: the census (45 tokens with a multiplier, 32 with no feed, 36 changes in 30 days); the 159-token gap; the issuer's own documentation promising feeds that don't exist; CRWD already trades on-chain in a live Uniswap v4 USDG pool with no feed any lender could use; and the 4× failure reproduced live.
Trying it costs ten seconds: app.slate.0xo.in/price/CRWD returns the feed as JSON, the dashboard playground reads any feed address and hands over the Solidity, and npm install @slate-protocol/contracts gives a five-line fail-closed reader. The first outside integration is the test we have not passed yet.
EVIDENCE, INCLUDING OUR WORST CASE
For the 35 tokens Chainlink does price, the accuracy board puts Slate's signed price beside Chainlink's and verifies every signature in the browser: at Friday's close, median gap 0.11%, worst 0.41%. Charted over 1–2 Oct for TSLA, AMD, AMZN and PLTR (testnet signed prices against Chainlink mainnet): like for like across 73 Chainlink updates, median 0.035%, worst 0.53%. Across all 2,057 reports the worst gap, 1.42%, was ours: one overnight AMD report 1.7% off its neighbours that the publisher did not refuse. The page says so, and the docs describe the guard we plan to add. The full 35-token history is stored hourly from Monday's open.
A GAP OUR OWN TESTS FOUND, NOT FIXED ON MAINNET
On 4 Oct our stateful invariant tests found a real gap in the deployed SlateFeed. A token reports only its latest multiplier change. If a price was observed before change A, A takes effect, and the token then schedules change B before a newer price arrives, the feed can no longer see A and applies A's multiplier to the older price. What it could cost: the size of A on that one price until the next one lands, up to 2.1% for the adjustments on mainnet today, 4× for a split. While the market is open a newer price replaces it within 30 minutes on CRWD and 4 hours on the other feeds; over a weekend, Friday's price is served until Monday. No mainnet feed is exposed today: all 21 hold a price observed after their token's latest change (block 79,525,398). The fix: the feed records each change it sees and refuses a price older than the last one recorded. It is not deployed because it changes the feed contract, which means new feeds and a redeploy we cannot fund during the event. A unit test pins the behaviour, and docs.slate.0xo.in/security states all of this.
ARBITRUM
Robinhood Chain is an Arbitrum Orbit chain. We built Slate's signature verifier in Stylus and benchmarked it: Rust cost 32.7% more gas than Solidity at three signers (98,989 vs 74,576), so we shipped Solidity and published the numbers. A fork test reads Chainlink's raw TSLA feed on Arbitrum One through the same multiplier logic.
Open source: github.com/Slate-Protocol/slate · docs.slate.0xo.in · Unaudited.
CONTRACT QUALITY, MEASURED (all built 1–4 Oct)
- 180 tests, 0 failing: 156 unit and fuzz tests (fuzzing at 1,024 runs, 4,096 in CI), 8 stateful invariants (256 runs × 64 calls each) and 16 fork tests against live Robinhood Chain mainnet, Robinhood Chain testnet and Arbitrum One, all passing on 4 Oct.
- SignedSource invariants, at mainnet's parameters: it accepts exactly the reports its rules allow, checked against an independent model of those rules (about 4,000 reports per campaign); it stores the accepted median; observation times only move forward; only the owner rotates signers, and quorum stays a majority.
- SlateFeed invariants, in CRWD's mainnet configuration: every price it serves equals share price × the multiplier in force when that price was observed, checked against a full multiplier history across splits, small adjustments and overwritten schedules; it never serves while paused, stale with the market open, or under a refusing status. They found one real gap, disclosed in the Description and the docs, not fixed on mainnet.
- StockLender invariants: cash matches the books, totals equal their parts, no risk without a price.
- Mutation testing (Gambit): of 505 mutants of SlateFeed, SignedSource, its signature verifier and the multiplier reader, the suite kills 492 (97.4%). The first run killed 89.1%; its survivors were real gaps (the verifier's sort of signer timestamps was never exercised), now covered by 10 new tests. The 13 survivors are equivalent, each explained in contracts/mutation.
- All 29 mainnet contracts verified on Sourcify.
- Adversarial limits enforced on-chain: signers must agree within 0.5%, a move over 10% needs all three signers, timestamps must strictly increase; the factory refuses a feed whose answer disagrees with an independent reference (a wrongly declared multiplier kind never ships); the mainnet deploy refuses unless the deployer's nonce is 0, so SignedSource lands on its presigned address.
- Governance: SignedSource is owned by a 48-hour TimelockController; signer rotation and the calendar handover are rehearsed in fork tests.
- Findings we published: two statements in Robinhood's official docs that the chain contradicts (Disclosures page), and our own worst report (one AMD price 1.7% off), with the guard we plan to add. Unaudited.
TIMELINE
1 Oct: contracts (SlateFeed, SignedSource, market calendar, SLATE-5 basket and NAV feed, SlateRouter, Lab); testnet deploy; publisher on Railway signing 24/5; Stylus verifier built and benchmarked.
2 Oct: dashboard, landing and docs live; the Lab's live 4:1 split filmed; StockLender with a live testnet loan (19.57 TESTUSD against 0.58 NFLX); the Slate-vs-Chainlink accuracy board; timelocked signer rotation and a co-signer.
3 Oct: Robinhood Chain mainnet deployed during Friday's US session: SignedSource, timelock, calendar, 20 feeds for tokens without Chainlink plus AAPL, CRWD/USDG and AAPL/USDG feeds, StockLender; CRWD live from its first signed price, $1,072.42. Then WalletConnect wallet connection, the price API, the integration playground, the arithmetic page, hourly accuracy history in Postgres, and @slate-protocol/contracts 0.1.0 published on npm.
4 Oct: the multiplier census (every mainnet token's multiplier read on-chain: 45 of 194 not 1, 32 with no Chainlink feed, 36 changed in 30 days), live at app.slate.0xo.in/census with a rebuild script. Stateful invariants for SignedSource and SlateFeed, which found the multiplier gap we disclose; mutation testing of both, 97.4% of mutants killed.
No outside funding raised. Open to ecosystem grants and support.