The coin
Every Trove coin is a clone (EIP-1167) of one small contract, TroveCoin. It is an ordinary ERC-20 with 18 decimals and a fixed supply of 1,000,000,000, all of which starts inside the coin itself. The coin is also its own market: a constant-product curve between the coins it holds and a reserve of ETH that starts with a virtual 1 ETH. So a new coin has a price from its first block (a market cap of 1 ETH), and there is no other pool to route around its fee.
Buying sends ETH in; the fee is taken first, the rest goes to the curve, and you receive coinReserve × net ÷ (ethReserve + net) coins, rounded down. Selling is the mirror image, and the fee is taken from the ETH that comes out. The page computes both with the contract’s own integer formulas and sends a minimum 1% below its quote.
The fee
Chosen at launch, from 0.25% to 10% in steps of 0.25%, and stored in the coin. No function changes it — there is no owner and no admin, in the coin or in the factory. Every buy and every sell pays it, in ETH. None of it goes to the creator or to Trove.
The fair-price guard
Each fee is swapped inside the same transaction: ETH → USDG in Uniswap’s WETH/USDG 0.01% pool, then USDG → the stock in the pool chosen at launch. Before swapping, the coin reads both pools’ time-weighted average price (30 minutes; if a very busy pool has overwritten that much history, 10 minutes, then 2) and sets the swap’s minimum to what the averages say the ETH is worth, less both pools’ fees and 2%.
A price pushed inside the current block carries no weight in an average, so an attacker who moves a pool and then triggers a trove purchase gets nothing: the swap fails its minimum, the ETH stays in the coin as pendingEth, and the next trade — or anyone calling convert — tries again once the pool is back. The trade itself always goes through.
One refusal is deliberate: a transaction with too little gas left for the swap reverts with NeedsMoreGas instead of quietly deferring the fee. Wallets estimate the smallest gas at which a transaction does not revert; without that refusal, estimates would starve every purchase.
Burning for the trove
Anyone holding coins can burn them with redeem and receive exactly trove × coins ÷ totalSupply of the stock, plus the same share of any fee ETH still waiting. The share is taken over the whole supply, including coins still in the curve, so nobody can take more than their fraction — and every burn leaves each remaining coin backed by at least as much stock as before. The coin page shows whether burning or selling pays more for your amount.
The picture and links
The picture (cropped square and shrunk to under 16 KB in your browser), the description and up to three links are ABI-encoded and stored as the code of a tiny contract (SSTORE2) when the coin launches — 24 KB at most. meta() returns them byte for byte. Nothing depends on a server.
The contracts
| What | Address |
|---|---|
| TroveFactory | 0xEbD68174066CA22c7D37d6de73fC1A4c1aEC277B |
| TroveCoin implementation | 0x40d1aA4Fbf939795C140F0fD4aF0125c4b451E11 |
| CREATE2 deployer (Arachnid’s, deterministic) | 0x4e59b44847b379578588920ca78fbf26c0b4956c |
| Uniswap SwapRouter02 | 0xCaf681a66D020601342297493863E78C959E5cb2 |
| WETH / USDG 0.01% pool | 0x52e65B17fB6E5BA00Ed806f37Afcd2DaA50271Ca |
The factory’s address is keccak256(0xff ++ deployer ++ salt ++ keccak256(initCode)), with salt 0x1c01a4e22cd86ab78a7bc8379f28e6db67851eaedb95d6a2f07073c846cf8ede and init-code hash 0xa50f080f78ed876c3a475e990b91173392bb5abdd811a2fdbc8470391035a638. So the address is the code: anyone can deploy it, and whoever does puts exactly this code there. Source: TroveFactory.sol, TroveCoin.sol, and Uniswap’s TickMath.sol; solc 0.8.26, optimizer 1000 runs, via-IR, Cancun. Status right now: checking…
How it was tested
Every property below runs on a private fork of live Robinhood Chain (anvil, started fresh at the newest block for each property): the real CREATE2 deployer deploys the factory, coins launch on real stock tokens, and every trove purchase swaps through the real Uniswap pools, in the state they are in right now. Nothing is broadcast and nothing is mocked. Expected numbers are computed in the test from the formulas written out there, never by asking the contract.
The last run: 10/10 properties and 189 checks passed against live state (30 Sep 2026), for the factory at 0xEbD68174066CA22c7D37d6de73fC1A4c1aEC277B.
| # | Property | Checks |
|---|---|---|
| P1 | The factory lands at the address its code fixes, with the implementation beside it | 7 |
| P2 | Launch refuses every bad input with the error named for it, and accepts a good one | 20 |
| P3 | Buys and sells pay exactly the curve and the fee, and every fee reaches the trove | 62 |
| P4 | A round trip never makes money, and everyone can always sell back | 20 |
| P5 | The trove only buys near the average price; a pushed pool defers the buy until it is not | 15 |
| P6 | The price read is Uniswap's, in both token orders and every fee tier, and the swap matches the quoter NVDA through its 0.05% pool: 0.005 ETH bought 0.058475 NVDA, 20 bp above what the 30-minute average said (the floor allows 206 bp below) SPCX through its 0.05% pool: 0.005 ETH bought 0.088815 SPCX, 20 bp above what the 30-minute average said (the floor allows 206 bp below) TSLA through its 0.3% pool: 0.005 ETH bought 0.037679 TSLA, 11 bp below what the 30-minute average said (the floor allows 231 bp below) MSTR through its 1% pool: 0.005 ETH bought 0.086354 MSTR, 71 bp below what the 30-minute average said (the floor allows 301 bp below) | 17 |
| P7 | Redeeming pays exactly the holder's share of the trove and nothing more | 28 |
| P8 | Too little gas is refused outright rather than silently deferring the fee | 6 |
| P9 | A coin keeps its picture and links on chain, byte for byte | 6 |
| P10 | The coin is an ordinary ERC-20, refuses stray ETH, and cannot be re-initialised | 8 |
Then a sabotage sweep plants 12 bugs, one at a time, in copies of the contracts — the fair-price guard removed, the 30-minute average swapped for the spot price, a sale whose fee never reaches the trove, a burn that overpays, a buy that rounds one coin the wrong way, a price average off by one tick — and requires the property named for each one to fail. 12/12 were caught by the property named for them.
And in a real browser: headless Chrome drove these pages with a test wallet against a private copy of the live chain — deployed the factory from the launch page, launched a coin with a picture on TSLA at 3%, bought, sold and burned through the trade box, and read the board. 7/7 journeys, 28 checks, each outcome read back from the chain by the harness itself (30 Sep 2026).
Risks
- Unaudited. The contracts are small and tested, not audited.
- Coins can go to zero. The trove gives each coin a floor only as high as the stock it holds; a coin can trade far above it and fall back to it.
- Stocks fall, and Robinhood controls its stock tokens. Robinhood can pause, block or burn its tokenized stocks. A paused stock cannot be bought (fees wait) or paid out (burns revert until it resumes).
- Thin pools make the trove wait. If the stock’s pool is too thin for a fair fill, fees accumulate as ETH until it is not; burns still pay that ETH out pro rata.