Robinhood Chain testnet · block reading ArbOS 61 compliance filtering settles in USDG

Your transfer
didn't fail.
It never happened.

Robinhood Chain screens transactions at the sequencer. A screened transfer is never sequenced, so it leaves no revert, no receipt, no event and no gas. Nullfill is an escrow that stays correct when that happens, and a console that shows you which of the four fates your transaction met.

A static page with no key and no backend. Everything live on it is read from the chain in your browser.

Landsreceipt, event, gas
Revertsfailure receipt, gas spent
Screenednothing at all
24 hoursforce inclusion window

“Since a blocked transfer is never processed, it simply appears as though the event never occurred.”

Robinhood Chain developer documentation, Differences from Ethereum. Written as a reassurance for indexers. For anyone holding money in escrow, it's the bug.

01 The four fates of a transaction

Most chains give a transaction two outcomes. This one gives it four.

Watch what each one leaves behind. Two of them are ordinary. The third leaves nothing for any contract to see, and the fourth can arrive up to a day late and burn gas to tell you it was blocked.

sequencerblock

Executes

Sender sees
Success
Chain records
Receipt, events
Gas
Spent
sequencerblock

Reverts

Sender sees
Revert
Chain records
Failure receipt
Gas
Spent
sequencerblock

Screened

Sender sees
-32000 rejected by chain policy
Chain records
Nothing
Gas
None
delayed
inbox
block+24h

Force included, then failed

Sender sees
A late failure
Chain records
Failure receipt
Gas
Burned on purpose

02 What's at stake

672.9 million USDG sits on Robinhood Chain mainnet.

Read from the token contract at block 74,889,519 on 28 September 2026. Every escrow, loan and payout holding it assumes a transaction either lands or reverts.

1,355

transactions the compliance filter refused on Robinhood Chain mainnet between 30 June and 16 September 2026, counted from the chain's own registry at 0x74. Every one I sampled was included and failed. And those are only the ones that came in through the delayed inbox. A transaction refused at the sequencer's door leaves no count at all.

So I read the fund-holding contracts in this buildathon whose source I could find, one function at a time.

8contracts read
0handle a transaction rejected at the sequencer
3move money when a transaction misses a deadline
2let that deadline be shorter than 24 hours

No project is named. They're other builders' entries, not bugs to air in public. The point is the pattern: on this chain, "no transaction arrived" gets treated as a decision, and it isn't one.

03 Real USDG, through the live contract

Two orders, 50 USDG each. Read from the chain as you look.

From the Paxos testnet faucet, through the deployed escrow at 0x7102…83A1. The status on each card comes from the contract's own describe() when this page loads.

04 Classify a transaction

Paste any hash. Find out which fate it met.

Works against the live chain from your browser. When it can't tell, it says so instead of guessing.

Live Worked examples

05 The contract

Three rules. Each one is a line you can read.

No owner, no fee, OpenZeppelin SafeERC20 and ReentrancyGuard. 46 tests, four fuzzed, and a test that the bytecode on chain is exactly this source.

1

Anyone can unwind an expired escrow.

Getting money back never depends on one party being able to send a transaction.

function unwind(bytes32 ref) external nonReentrant {
    // ...no check on who the caller is
    if (block.timestamp < o.deadline) revert NotYetUnwindable(ref, o.deadline);
    o.status = Status.Unwound;
    o.token.safeTransfer(o.unwindTo, o.amount);
2

The refund address is named up front.

Set when the escrow opens, changeable while it's open, never discovered too late.

address recovery = unwindTo == address(0) ? msg.sender : unwindTo;
_orders[ref] = Order({ ..., unwindTo: recovery, ... });
3

No deadline inside the 24 hour window.

Acting on a missing transaction before the window closes is the bug. The contract refuses.

uint64 public constant FORCE_INCLUSION_WINDOW = 24 hours;
uint64 earliest = uint64(block.timestamp) + FORCE_INCLUSION_WINDOW;
if (deadline < earliest) revert DeadlineTooSoon(earliest);

Read the whole contract · I broke it 14 ways on purpose and the tests caught 13. The one they missed now has its own test. · Reproduce the screening on a local Nitro chain

06 A desk's day, replayed

Every row is an escrow. Pick one to see its story.

A recorded scenario, so you can read it without a wallet. The state column is what the chain would tell you.

07 The failure no contract can fix

ETH leaves Ethereum. It arrives nowhere.

Arbitrum's own notes: ETH enters the parent bridge before any filtering runs on the child chain, and if the credit is dropped it's locked there with no matching asset. Spotting these as they happen is what the watcher is for. This one is a recorded example.

08 Nullfill Watch, alpha

The chain keeps no record of a refusal. So the watcher does.

Watch sits between a wallet or script and the RPC. Every transaction that passes through gets a receipt signed with the watcher's key, whether it was accepted or refused. The one below is real: the live Robinhood Chain RPC refused it on 28 September. It was refused for a stale nonce, not screening, because nobody can make the live chain screen on demand. The capture path is the same.

Checked in your browser, just now

    Verify your own receipt
    # sit between your wallet and the RPC, and keep a signed record of every refusal
    node watch/nullfill-watch.mjs proxy --rpc https://rpc.testnet.chain.robinhood.com --port 8646
    # every escrow an address is party to, and when anyone may unwind it
    node watch/nullfill-watch.mjs escrows --address 0x…

    09 Settlement assets

    The cash leg is USDG. Every address is checked live.

    Robinhood Chain lists Paxos USDG under Stablecoin on its own ecosystem page. Each row below says what the chain said, and says so plainly when it couldn't check.

    10 What this won't claim

    Limits, stated before anyone finds them.

    The escrow is free. The watcher is the business.

    The Watch alpha is in the repo today: signed receipts for refused transactions, and every escrow's deadline for an address. The hosted version, with alerts and bridge-deposit matching, is $99 a month per desk.