On Robinhood Chain

Private payments.
Non-custodial.

Hold and send USDG and native ETH with a signing key split into three independent shards. Any two can sign — no single party, including us, can move your funds.

CAToken launching soon
Runs in your browserNothing to downloadNo seed phrase
Threshold quorum2 of 3 ready
A
Device shardEncrypted in this browser · AES-256-GCM
signed
B
Co-signer shardReleased only after policy check
policy passed
C
Recovery codeOffline · held by you
standby
Send 250.00 USDGQuorum reached ✓
NetworkRobinhood Chain
Chain ID4663
Overview

Why threshold custody for private payments?

Hot wallets keep one key in one place. Hardware wallets add cost and friction. Arcane splits authority across three shards and enforces your limits before anything is signed.

Browser wallet
Signing keyexposed
Stored onthis device
Spend limitsnone
Compromisedrains all

Single-key hot wallet

The full private key lives in one browser. One phishing page or malicious extension can authorize every transaction.

Offline signer
1 · Connect deviceUSB
2 · Verify addressscreen
3 · Sign manuallybutton
Backupseed phrase

Hardware wallet

Better key isolation, but adds hardware cost, firmware trust, shipping, and a 24-word seed you must never lose.

Threshold quorum
A · Devicesigned
B · Co-signerpolicy passed
C · Recoveryoffline
Result2 of 3 ✓

2-of-3 threshold quorum

Shard A on your device, Shard B with a policy co-signer, Shard C as your recovery code. Two are required — one alone is useless.

Architecture

The 5-step signing pipeline

Every transfer passes your device, the co-signer's policy engine, and an in-memory quorum before it reaches Robinhood Chain.

1

Build

Browser

Prepares an EIP-1559 transfer of USDG or native ETH and checks balance and gas.

unsigned tx · chain 4663
2

Authenticate

Device key (P-256)

The request is signed by a non-exportable device key with a timestamp, so it can't be forged or replayed.

sig_device(intent, ts)
3

Co-sign

Policy engine (Shard B)

Per-transaction cap, daily limit, velocity and freeze state are checked. Only then is Shard B released for this one signature.

policy ✓ → shard B
4

Quorum sign

Browser memory

Shards A + B reconstruct the key in memory, sign once, and are wiped. The key is never stored whole.

A ⊕ B → secp256k1 sig
5

Settle

Robinhood Chain

The signed transaction is broadcast and confirmed. Receipt and status are logged to your activity.

eth_sendRawTransaction
Recovery quorum (Shard C + Shard B): if your device is lost, your recovery code combines with the co-signer shard to restore the wallet on a new device. The old device key is revoked automatically — no seed phrase involved.
Protocol

Technical specifications

Standard primitives, verifiable on-chain. Nothing exotic, nothing hidden.

NetworkRobinhood Chain
Chain ID4663
StackArbitrum Orbit L2
AssetsUSDG · ETH
Threshold2-of-3 Shamir
TransactionsEIP-1559 (type 2)
Signing curvesecp256k1
Local vaultPBKDF2 600k · AES-GCM
Device authECDSA P-256
ComponentInterfaceDescription
USDG token0x5fc5…d168ERC-20 stablecoin balances and transfers on Robinhood Chain.
Co-signerPOST /api/cosignVerifies device signature and policy, then releases Shard B for exactly one signature.
Policy enginePOST /api/policyPer-tx cap, daily limit, velocity. Tightening is instant; loosening waits 24 h.
RecoveryPOST /api/recoverRecovery shard proof rebinds a new device and revokes the old one.
Stealth registryGET /api/stealth/announcementsPublic announcements for one-time addresses; scanned locally with your view key.
RPCrpc.mainnet.chain.robinhood.comAllow-listed JSON-RPC proxy for balances, gas and broadcast.
Product

Built for everyday private payments

Everything a payments wallet needs, without handing anyone custody.

Private Send

Send USDG or ETH to any address — or in stealth mode to a fresh one-time address that can't be linked on-chain to the recipient's main wallet.

Stealth Inbox

Your view key scans public announcements locally. Found payments can be swept into your main wallet in one click.

Spending Policies

Set per-transaction and daily limits plus a hourly velocity cap. Freeze the wallet instantly if something looks wrong.

Seedless Recovery

Lost your device? Your recovery code plus the co-signer restore access on a new one, with the old device revoked.

Open the wallet

Nothing to download.

Arcane runs entirely in your browser tab. Keys are generated locally with WebCrypto and never leave the device whole.

Setup time~30 seconds
Extension requiredNo
Seed phraseNo
NetworkRobinhood Chain · 4663
Launch Wallet →
Compatibility

Works where you are.

Any modern browser with WebCrypto support, on desktop or mobile.

Chrome / Bravev100+
SafarimacOS & iOS 16+
Firefoxv110+
Edgev100+
Create a wallet
FAQ

Questions, answered.

Is Arcane custodial?

No. The co-signer holds only one of three shards, which can't sign anything alone. It can refuse a transfer that breaks your policy — it can never initiate one.

Do I need to download anything?

No. There's no app, extension or installer. Open the wallet in your browser, set a password, save your recovery code, and you're ready.

What happens if I lose my device?

Use your recovery code on any browser. Combined with the co-signer shard, it restores the same address and revokes the lost device.

What are stealth payments?

The sender derives a one-time address from your public stealth keys. Only you can detect and spend it, so observers can't link the payment to your main address.

What does it cost?

You only pay Robinhood Chain network fees in ETH. Stealth USDG payments include a small ETH drip so the recipient can sweep the funds.

Has it been audited?

Not yet. Treat it as early software and keep balances small until an independent audit is published.