STOCKBACK
Scan. Prove. Own.
ビデオ




テックスタック
説明
Quick Links:
Live Link: https://stockbacks.vercel.app/
WhitePaper:https://tinyurl.com/5wusp88e
Deployed Contract: https://explorer.testnet.chain.robinhood.com/address/0x4273b12cD4A65c2180d4e65Bcb4254825cE64120
Vedio: https://youtu.be//70fX_mN6MuE
Introduction
Every purchase leaves evidence behind: a receipt, a UPI reference, an order email. Reward programs turn that evidence into points that expire, get devalued, and sit in one of the 15 programs you joined and forgot.
STOCKBACK changes two things:
The trust origin. The merchant's till signs every receipt field with Ed25519. STOCKBACK verifies that signature, not a photo, and checks it on-chain in Rust on Arbitrum Stylus.
The reward. A verified purchase becomes shares of that brand's ERC-4626 vault, held in your wallet. The vault has no admin, no pause and no sweep, so no one can dilute, freeze or expire your shares.
One transaction does it all: the registry verifies the claim, burns a per-receipt nullifier, applies eligibility, caps and a sponsor budget, then deposits into the vault in your name.
Global protocol, rail-first launch. Nothing in STOCKBACK is tied to one country:
Every brand sets its own currency (an ISO-4217 code on-chain, so INR, SGD and USD all work) and its own amount bounds.
Geography goes through a pluggable
IJurisdictionPolicyadapter instead of hardcoded rules.Sponsors fund rewards in USDG, a dollar stablecoin.
We launch where every payment already carries a digital merchant trail, which is exactly where merchant-signed receipts plug in:
Singapore, through PayNow and SGQR
India, through UPI
The live demo is priced in INR for that reason.
The problem

A receipt photo is no longer evidence.
In a 2026 paired study, people picked an AI-edited receipt over its authentic twin 50.1% of the time, which is chance.
The best forensic detectors reached an AUC of only 0.53–0.60 (Wu et al., arXiv:2604.25213).
Digital document forgeries rose 244% year on year (Entrust 2025, cited there).
Any reward, refund or warranty flow that trusts pixels is paying out on fakes.

Points never feel like yours.
People belong to 14.8 loyalty programs and use 6.7.
73% find loyalty programs too complicated.
About 60% of coalition programs fail within ten years.
Operators can also expire or devalue balances at will (Bond Loyalty Report 2020, via arXiv:2512.00738).
The painkiller

Step | What happens | |
|---|---|---|
読 | Scan | The merchant's till signs the receipt. You scan its QR. No photo needs to be trusted. |
証 | Prove | The signature is checked, the receipt counts once, and Stylus verifies the claim on-chain. |
有 | Own | You receive shares of that brand's vault. No admin can dilute, freeze or expire them. |
What makes it different

Guarantee | How | Where |
|---|---|---|
Signature, not pixels | The till signs 8 fields (merchant, brand, receipt ID, amount, currency, issue, expiry). Change one digit and the claim fails. |
|
Counted once, for anyone |
|
|
Yours, no admin | One ERC-4626 vault per brand, with no owner, pause or sweep. |
|
9.2x cheaper to verify | Strict Ed25519 in Rust on Stylus, behind the same |
|
The vault is not the moat. The moat is the verification and eligibility pipeline that connects an off-chain purchase to an on-chain ownership allocation, with every key's authority bounded.
Product tour
Real screenshots of the live app at stockbacks.vercel.app, on Robinhood Chain testnet.
![]()
| ![]()
|
![]()
| ![]()
|
![]()
| ![]()
|
![]()
| |
Architecture

Layer | Component | Responsibility |
|---|---|---|
Evidence |
| Sign a receipt with the demo merchant Ed25519 key and print it as a QR |
Evidence |
| Verify the merchant signature (tier 1) or take user-confirmed fields (tier 2); hash identifiers with a secret salt; sign the EIP-712 claim |
Proof |
| Claimant binding, deadline, commitment, nullifier, orchestration, pause |
Proof |
| Yes or no: did an allowlisted attester sign exactly this claim? |
Eligibility |
| Brand active, currency, amount bounds (₹100–₹5,00,000), purchase within 30 days, optional KYC/region gate |
Eligibility |
|
|
Ownership |
| Sponsor-funded budget per brand; pays only what was deposited |
Ownership |
| One admin-less ERC-4626 vault per brand (CREATE2, salt = brandId) |
Funding |
| Optional: fund the budget in USDG, swapped to the brand asset with oracle-bounded slippage (SwapRouter02) |

Trust boundary:
The till holds the merchant private key.
The attester holds only the merchant public key plus its own key.
The chain holds no secrets.
No key ever reaches the browser;
npm run check:secretsverifies the client bundle.
More diagrams are in docs/ARCHITECTURE.md.
Workflows
1. From receipt to ownership

2. Inside the one claim transaction

Every check runs on-chain, in order. If any fails, nothing changes and the receipt is not burned. previewClaim returns exactly the status submitClaim would revert with, so the UI explains a rejection before the wallet opens.
3. The live demo, step by step

Open /merchant, pick a brand and amount, then Issue signed receipt.
Scan the QR with a phone, or press Claim in STOCKBACK.
Connect a wallet on Robinhood Chain testnet, then Verify signature: merchant signature ✓, attested ✓, new receipt ✓, eligible ✓.
Claim ownership. One transaction, verified by Stylus. View transaction shows it on the explorer.
Open the same QR again: "This receipt has already been claimed." Edit any field in the link: "The merchant signature doesn't match."
Evidence tiers

The on-chain path is identical for every claim. What differs is what the attester checked before signing, and the app labels it on every screen.
Tier | Evidence | Establishes | Status |
|---|---|---|---|
1 | Merchant-signed receipt | The receipt is unaltered since the merchant key signed it. Merchant simulated in the demo. | Live demo |
2 | Attested photo / OCR | Only that the attester signed what it was given; authenticity is not established | Live demo |
3 | Verified payment / order evidence (zkTLS) | Provenance from the payment or order source itself | Roadmap |
Stylus benchmark

Strict Ed25519 verification of attestation signatures, measured on Robinhood Chain testnet with eth_estimateGas and byte-identical calldata:
Batch | Solidity Ed25519 | Stylus Ed25519 | Solidity ÷ Stylus |
|---|---|---|---|
1 | 736,502 gas | 140,063 gas | 5.3× |
10 | 6,214,368 gas | 724,659 gas | 8.6× |
50 | 30,555,405 gas | 3,327,511 gas | 9.2× |
100 | exceeds the 32M per-tx cap | 6,583,441 gas | n/a |
Marginal cost: about 608k gas per signature in Solidity against about 65k in Stylus.
Capacity: 100 signatures fit in one transaction with Stylus; Solidity can't fit 53.
ECDSA through the EVM precompile is cheaper still, so Stylus earns its place for schemes the EVM lacks.
Methodology: benchmarks/results/BENCHMARKS.md. The fitted gas model is in the whitepaper.
Live on Robinhood Chain testnet (46630)
Contract | Address |
|---|---|
ReceiptCommitmentRegistry |
|
Stylus ReceiptProver (active verifier) |
|
ECDSAAttestationVerifier |
|
EligibilityPolicy |
|
RewardPolicy |
|
RewardPool |
|
BrandVaultFactory |
|
USDGRewardAdapter |
|
sbNKE / sbSBUX / sbAAPL vaults |
|
Real transactions:
Sponsor funds the Nike budget in USDG through the adapter:
0x3d8de149…6c6d(100 USDG → 10,000 mNKE)Merchant-signed receipt claimed on film, Stylus-verified:
0x1fc40e3e…7afa97(18.7425 sbNKE)Merchant-signed receipt, browser test:
0xabd3b62b…5388Apple ₹14,990 claim, Ed25519 verified in Stylus:
0x7fe2a51a…d9c4(74.95 mAAPL)Registry switched to the Stylus verifier:
0xdef1f321…c324
All brand assets and USDG here are mocks. Full list: deployments/46630.json.
FAQ
Is STOCKBACK India-only? It's for all.....
Currency is set per brand, jurisdiction is an adapter, and rewards are funded in USDG.
The demo uses INR because we launch on payment rails that already carry a merchant trail: Singapore (PayNow/SGQR) first, then India (UPI).
Launching a brand in SGD or USD is one
setBrandRulescall, not a redeploy.
License and attribution
MIT (see LICENSE). This repository started from Wield (MIT, © 2026 Wield).
Adapted from Wield:
Foundry setup and CI
the oracle freshness and slippage checks and chain-id guards (now in
USDGRewardAdapterand the deploy script)IAggregatorV3,ISwapRouter(corrected to SwapRouter02), andMockUSDG/MockAggregatorV3
Original STOCKBACK work: the claim model, registry, verifiers (Solidity and Stylus), policies, reward pool, brand vault and factory, attester, merchant receipts, web app, benchmark, whitepaper, brand and film.
Not included: Wield's vault, basket and P2P contracts; see docs/MIGRATION_AUDIT.md.
Vendored: the benchmark baseline uses chengwenxi/Ed25519 (Apache-2.0) under
benchmarks/solidity/src/vendor/.
ハッカソンの進行状況
Deployed on Testnet.
資金調達の状況
NA






