hens.farm
Live protocol mechanism · Robinhood Chain

show the machinery.

A source-aligned explanation of how Hens, HEGG and GLD interact—from snapshot and mint through emissions, weighted redemption, revenue routing, liquidity and floor support.

x² Σ ½ √x + = Thinking Hen
01 Claim a Hen
02 Earn HEGG
03 Burn into Hen
04 Receive GLD

1. system overview.

A Hen earns HEGG. HEGG can be traded or permanently burned through the redemption vault. Burning HEGG claims GLD at the current daily base rate and increases that Hen’s permanent weight. Existing weight earns a separately reserved GLD bonus.

  • HEGG emissions reward Hen ownership over time.
  • Base GLD backing supports ordinary redemption without requiring weight.
  • Bonus GLD backing rewards historical weight without diluting the base calculation.
  • Protocol revenue replenishes GLD, HEGG liquidity and rule-bound floor support.
HEN NFT earns HEGG
→
USER burns HEGG into Hen
→
VAULT pays base + bonus GLD

2. contract map.

Responsibilities are split so minting, accounting, trading and revenue operations can be checked independently.

Contract Responsibility Boundary
HenNFT ERC-721, origin and cumulative HEGG burned. System roles mint and add weight.
HenClaimController OG proofs, batch claims, public mint and trust allocation. Committed Merkle roots.
HenEmissionController Time-based HEGG accrual and multi-Hen claims. Current ownership required.
GldRateController Daily rates, budgets and bonus reservations. Deterministic permissionless epochs.
HenRedemptionVault Burns HEGG, pays GLD and records weight. Owner or approved operator.
HenMarketplace Non-custodial fixed-price settlement. Exact nonce, price and approval.
ProtocolRevenueSplitter Immutable 70/10/10/10 distribution. Immutable recipients.
QuorumHenFloorOracle Two-of-three hourly floor consensus. Locked reporter set.
Hen holding a claim ticket
One proof per eligible Chikn. One transaction can carry every proof in a wallet.

3. launch and claims.

The controller enforces three non-overlapping phases. OG claims begin 1 October 2026 at 00:00 UTC, last exactly twelve days, and are followed by an exact 24-hour pause. Public mint begins 14 October 2026 at 00:00 UTC.

  1. Snapshot. Each eligible claimant, Chikn ID and matching Hen ID becomes a Merkle leaf.
  2. OG claim. A wallet may claim every eligible Hen in one atomic transaction.
  3. Final shuffle. Remaining IDs are committed 80% public and 20% trust.
  4. Public free mint. One Hen per wallet while supply remains.

// Every tuple is proven independently; one bad proof reverts all.
function claimAll(uint256[] calldata chiknIds,
                  uint256[] calldata henIds,
                  bytes32[][] calldata proofs) external {
    for (uint256 i; i < chiknIds.length; ++i) {
        bytes32 leaf = keccak256(bytes.concat(
            keccak256(abi.encode(msg.sender, chiknIds[i], henIds[i]))
        ));
        if (!MerkleProof.verifyCalldata(proofs[i], ogSnapshotRoot, leaf))
            revert InvalidProof();
        // mark used, mint matching Hen, emit OgHenClaimed
    }
}

4. HEGG emissions.

HEGG has an immutable maximum supply of 11,000,000 tokens, minted once at deployment. The emission controller received 10,000,000 HEGG for the fixed emission schedule, while 1,000,000 HEGG seeded initial DEX liquidity. There is no team, ecosystem or discretionary token allocation, and the contract has no function to mint additional HEGG.

11mMaximum supply
10mEmission reserve
1mInitial liquidity
0Additional minting

The emission controller holds the unearned reserve. Each Hen accrues from its mint time. The initial per-Hen rate halves every 90 days for eight epochs, then remains at the final plateau rate. Accrual integrates across epoch boundaries.

rate(timestamp) initialRate ÷ 2min(epoch, 8)
uint256 epoch = (timestamp - emissionStart) / 90 days;
if (epoch > HALVING_EPOCHS) epoch = HALVING_EPOCHS;
return initialRatePerHenPerSecond >> epoch;
Unearned HEGG cannot dilute holders. Eligible supply is totalSupply - unearnedHegg.

5. HEGG trade tax.

HEGG is a standard fixed-supply ERC-20. Official-pool fees are enforced by the Uniswap v4 hook, so claims, transfers and burns are not treated as trades.

1% Official-pool buy
2% Official-pool sell
0% Burn into Hen

Collected HEGG reaches the fee collector. Bounded batches are swapped through the approved adapter and native proceeds reach the immutable revenue splitter. There is no team-wallet exemption list; non-swap actions are outside the hook because they are not trades.

6. burning HEGG into a Hen.

GLD is not a Hens-issued token

The Hens ecosystem did not create GLD, control its issuance or reuse the ticker for an internal reward point. Redemptions use the official Robinhood Stock Token:

SPDR Gold Shares • Robinhood Stock Token (GLD) 0xC9a981FEE1F9DEc688bb123ccDeCc63D0deBFC4e ↗

burnIntoHenAndClaimGLD verifies ownership or approval, calculates GLD, consumes budget, burns HEGG, transfers GLD and records the new weight—all atomically. minimumGldOut protects the user; if output is lower, everything reverts.

uint256 baseGld = Math.mulDiv(
    heggAmount, rateController.currentRate(), 1 ether
);
rateController.consumeBase(baseGld);
uint256 bonusGld = _claimableReservedBonus(henId, baseGld);
gldOut = baseGld + bonusGld;
if (gldOut < minimumGldOut) revert InsufficientOutput(gldOut, minimumGldOut);

hegg.burnFrom(msg.sender, heggAmount);
gld.safeTransfer(msg.sender, gldOut);
hen.addBurnedHegg(henId, heggAmount);
display weight cumulative HEGG burned ÷ 1,000 HEGG

7. daily GLD base rate.

Anyone can roll a one-day epoch. If nobody does, the first redemption rolls it automatically. New GLD entering the vault is assigned 90% to base backing and 10% to bonus backing. A 20% buffer stays undeployed; the daily base-spend budget is 4% of deployable base.

eligible HEGG total supply − unearned reserve
deployable base base backing × 80%
GLD per HEGG deployable base ÷ eligible HEGG
daily base budget deployable base × 4%
uint256 deployableBase = projectedBase * 8_000 / 10_000;
uint256 rate = Math.mulDiv(deployableBase, 1 ether, eligibleSupply);
uint256 baseBudget = deployableBase * 400 / 10_000;

Once rolled, an epoch’s terms cannot be rewritten. The budget limits aggregate daily outflow; it does not move the rate inside a user transaction.

8. reserved weight bonus.

Weight never increases the base rate. Available bonus backing is divided pro rata across existing total weight at each epoch roll. The current burn is added only after that snapshot, preventing retroactive participation.

bonus per weight deployable unallocated bonus ÷ historical weight
Hen earned bonus old weight × accumulator − bonus debt
lifetime bonus ceiling 200% of that Hen’s lifetime base GLD
uint256 newlyEarned =
    Math.mulDiv(oldWeight, cumulativeBonusPerWeight, 1 ether)
    - bonusDebt[henId];
uint256 bonusCap =
    (lifetimeBasePaid[henId] + baseGld) * 20_000 / 10_000
    - lifetimeBonusPaid[henId];
bonusGld = Math.min(reservedBonus[henId] + newlyEarned, bonusCap);
Why it is payable. bonusAllocatedOutstanding tracks GLD promised by completed snapshots. Later epochs allocate only unreserved backing.
Hen operating a transparent raffle drum
Rates, reservations and caps are mechanical and visible onchain.

9. protocol revenue routing.

Marketplace fees, processed HEGG fees and supported royalty proceeds reach the splitter. Distribution is permissionless; recipients are immutable.

70% GLD acquisition
10% HEGG liquidity
10% Floor support
10% Creator
liquidityShare = total * 1_000 / 10_000;
floorShare     = total * 1_000 / 10_000;
creatorShare   = total * 1_000 / 10_000;
// Rounding dust benefits GLD acquisition.
gldShare = total - liquidityShare - floorShare - creatorShare;

The GLD acquisition manager converts its share and deposits GLD into the redemption vault. The liquidity manager adds its share to the canonical HEGG/native position held by protocol custody.

Royalty limitation. ERC-2981 announces 2.5%, but third-party marketplaces may ignore it. The official marketplace enforces a 2.5% settlement fee; vault funding does not depend only on voluntary royalties.

10. official marketplace.

Listings are non-custodial and record seller, price, expiry and a monotonically increasing nonce. Ownership, approval and expiry are rechecked at purchase. The buyer supplies the expected nonce, preventing a stale listing from filling after cancellation and relisting.

uint256 fee = paid * 250 / 10_000; // 2.5%
pendingProceeds[seller] += paid - fee;
hen.safeTransferFrom(seller, recipient, henId);
_sendNative(revenueSplitter, fee);

Seller proceeds use pull-payment accounting and are withdrawn separately, reducing settlement reentrancy risk.

11. constrained floor support.

Three public reporters observe the official marketplace hourly. At least two permitted reporters must agree before a round finalises. The reserve checks oracle age, maximum premium, per-purchase cap, rolling spend limit and purchase interval. It buys only through the approved marketplace adapter and receives the NFT into protocol custody.

uint256 oracleCap = floor * (10_000 + maximumPremiumBps) / 10_000;
if (price > oracleCap || price > maximumPurchaseAmount)
    revert PurchaseOutsideLimits();
adapter.buyHen{value: price}(address(hen), henId, address(this), orderData);

12. the unclaimed 20%.

The trust receives 20% of Hens remaining after the OG window—not 20% of original supply unless no OG claims occur. Every trust mint needs an unused index and proof in the final shuffled root.

uint256 remaining = hen.MAX_SUPPLY() - ogClaimedCount;
uint256 expectedTrust = remaining * 20 / 100;
uint256 expectedPublic = remaining - expectedTrust;

Trust Hens use the same NFT and emission rules. Their unearned HEGG remains excluded from eligible HEGG supply until earned.

13. roles and upgrades.

Upgradeable modules use UUPS proxies with a dedicated upgrader role. Ownership modules use two-step transfer: stage one nominates governance; governance explicitly accepts in stage two. Configuration locks bind critical adapters, reporters, receivers and limits after deployment validation.

Governance Upgrade roles and timelocked emergency control over future epochs.
Anyone Roll epochs, distribute revenue and invalidate stale listings.
Reporters Submit floors; two of three are required.
Creator Receives fixed 10%; cannot withdraw vault or floor funds.

Pausing future epochs cannot rewrite an existing epoch, historical weight or completed transfers.

14. events and indexing.

The frontend may cache indexed events for speed, but onchain state remains authoritative before signing.

OgHenClaimed(account, chiknId, henId) EmissionsClaimed(owner, henId, amount) HeggBurnedIntoHen(account, henId, heggBurned, gldPaid, previousWeightUnits, newWeightUnits) EpochRolled(epoch, gldPerHegg, baseBudget, bonusBudget, eligibleSupply, baseBacking, bonusBacking) HenListed(henId, seller, price, expiry, nonce) HenPurchased(henId, seller, buyer, recipient, price, fee, nonce) LiquidityAdded(nativeIn, heggAdded, nativeAdded, lpOut)

15. worked examples.

Batch claim

A wallet eligible for four Chikns submits four IDs, matching Hen IDs and proofs. Any invalid or reused entry reverts the transaction; otherwise all four mint together.

Base redemption

With 800 GLD deployable base and 10,000 eligible HEGG, the rate is 0.08 GLD per HEGG. Burning 100 HEGG returns 8 GLD base output, subject to daily capacity and minimum output.

Weighted bonus

A Hen entering a snapshot with 5,000 historical HEGG weight and an award of 0.002 GLD per weight reserves 10 GLD before cap accounting. A new burn participates only in future epochs.

One ETH sale

The official marketplace keeps 0.025 ETH from a 1 ETH sale; the seller accrues 0.975 ETH. Distribution routes about 0.0175 ETH to GLD acquisition and 0.0025 ETH each to liquidity, floor support and creator.

16. security notes.

  • Contract risk: testing cannot prove the absence of defects; independent review remains required.
  • Market risk: GLD and native-asset prices move; token-unit backing is not stable fiat value.
  • Liquidity risk: budgets and buffers intentionally limit concentrated redemption.
  • Oracle risk: quorum and limits contain but cannot eliminate bad-report risk.
  • External royalty risk: only fees actually collected can be routed.
  • Governance risk: upgrades can change future implementation within the disclosed role system.
Verify before signing. Use the live Robinhood Chain contract links in the footer and never trust an address received by direct message.

Choose wallet