flipper

Docs

How flipper works

Flip majors, Robinhood stock tokens and a curated set of Robinhood Chain tokens against a house bankroll held in $FLIPPER, the protocol's own token. Every flip happens onchain and settles in one transaction.

Building on flipper? Integrate the SDK and widget →

Overview

Pick a token and an amount, then flip. Heads (the dolphin) doubles your stake in the same token. Tails (the fluke) loses it to the house. The house prices each flip from real pools, draws verifiable randomness and settles through Uniswap v4 in the randomness callback, with no offchain matching or IOUs.

The team's $FLIPPER is staked in the bankroll, and its principal can never be withdrawn (see Launch and team stake).

The odds improve as the protocol grows. The house edge starts at 10% and only moves down, to 5%, as the house builds a track record (see How the edge comes down).

Win chance
45% → 47.5%
Token payout
2×
$FLIPPER payout
2.05× → 2×
Max bet
Kelly-sized, per flip

How a flip works

  1. 1

    Priced onchain

    The house simulates both swaps for your stake: selling it yields S in $FLIPPER, and buying the same amount costs B. The route cost h = (B − S) / (B + S) covers LP fees, hook fees and price impact.

  2. 2

    Set the odds

    Win chance is p = min(base, (1 − h − 2%) / 2). The base is 45% at launch, rising to 47.5% as the edge comes down. Normal route costs get the full base (see the chance fee).

  3. 3

    Reserve and escrow

    The house reserves its worst-case liability L = 1.05 × B if it fits the flip's max bet, escrows your stake and requests randomness. You pay the randomness fee with the transaction, and any excess is refunded.

  4. 4

    Draw and settle

    When the randomness arrives, its callback settles the flip in that transaction. A win buys your token and pays you; a loss sells the stake into the bankroll.

Odds and payouts

$FLIPPER flipsToken flips
Win chance45% at launch, rising to 47.5%Same base while the route cost allows (up to 8% at launch), then (1 − h − 2%)/2, never below 40%
Payout2.05× in $FLIPPER at launch, easing to 2×2× in the token you flipped
House expected profit7.75% at launch, down to 5%10% − h at launch, down to 5% − h; never below 2% after swap costs
To $FLIPPER holdersHalf of itHalf of it

$FLIPPER flips need no swaps, so at launch they pay a little more. As the edge comes down the win chance rises instead, until both pay 2× at 47.5%. Winnings are always paid in the staked token, which keeps pricing safe from manipulation (see Protections).

How the edge comes down

flipper opens with a 10% house edge, the margin a young bankroll needs to stay steady while taking useful bets. It steps down to 5% as lost flips pay real value into the house.

House net buybacksWin chance$FLIPPER payoutEdge, token flipsEdge, $FLIPPER flips
Below 10 ETH (launch)45%2.05×10%7.75%
180 ETH (halfway)46.25%2.025×7.5%6.34%
350 ETH and above47.5%2×5%5%

Between those points it moves in a straight line, rounded in the house's favour.

  • What it counts. Settling a token flip trades through the $FLIPPER/ETH pool: selling a lost stake pushes ETH in, buying a win takes ETH out. The running total is the house's net buybacks. $FLIPPER flips don't trade, so they don't count.
  • It only steps down. The edge follows the highest total so far, so a run of player wins never raises it. Cold streaks are handled by bet size instead (see Liability and max bet).
  • It can't be gamed. Only real losses paid into the house raise the total. A flash loan can't settle a flip, and pushing the price around a settlement either lowers the count or hands the house the difference, so it costs about as much as it moves the count. Nobody can buy better odds for one big flip.
  • Terms are fixed when you flip. A flip keeps the odds and payout it was made at, with the chance fee, partner discounts and the 2% minimum edge applied on top.

Anyone can check it with the house's edgeProgress(), which returns net buybacks, the highest so far, the schedule's thresholds and the current terms.

The chance fee

For most tokens the house absorbs the swap costs within its margin, and you get the full base win chance. When a route is costly enough (thin pools, fee-taking hooks, a big stake) to push the house's expected profit below its 2% floor, the house lowers the odds, not the payout. You still win 2×, a little less often.

Expected profit per flip is V × (1 − h − 2p), or 10% − h at the launch odds of 45%. So odds only shift once h > 8% at launch, or h > 3% at the final 5% edge. A flip is rejected if h > 10% or the odds would fall below 40%.

The bet card flags it before you sign, showing only the gap to the usual odds (for example “Odds 1.3 pts below usual”). Smaller stakes move the pool less, so they're trimmed less.

Liability and max bet

Each flip is sized to its own edge and to how the bankroll is doing, using drawdown-scaled Kelly. A flip may use a share of its Kelly fraction (the part of the bankroll that maximises long-run growth on that exact flip), capped at 5% of the free bankroll. Flips that earn the house more can be larger.

  • Half Kelly while the bankroll's value per unit is at its all-time high.
  • Down to quarter Kelly at 50% below the high, where the circuit breaker locks, easing in a straight line in between. Bets shrink as a cold streak deepens, slowing the slide, and grow back as the bankroll recovers.
Flip, at launch oddsAt the high (half Kelly)Near the breaker (quarter Kelly)
Token flip, route cost about 02.75%1.38%
Token flip, route cost about 5%1.45%0.72%
Token flip, route cost about 10%0.62%0.31%
$FLIPPER flip2.08%1.04%

These are max liability per flip, as a share of the free bankroll. Kelly fractions shrink as the edge comes down: at the final 5% edge, a free-route token flip or a $FLIPPER flip tops out at about 1.31% at the high. The bet card's max is the largest stake that fits, computed onchain.

How it's computed

Each flip reserves L = 1.05 × B, enough to buy your winnings with 5% headroom, and is accepted only while L ≤ min(5%, k × f*) × (treasury − reserved). k is the Kelly share in force (50% at the high, 25% at a 50% drawdown). f* = q − p × W / G is the exact Kelly fraction for this flip, computed onchain from its terms at flip time:

  • p is your win chance after the chance fee and any partner discount, and q = 1 − p.
  • W is what the bankroll pays on a win: the buy B on a token flip, or the payout minus the stake on a $FLIPPER flip (1.05× the stake at launch).
  • G is what it keeps on a loss: the sale proceeds, minus the holders' share and any partner's share.

Costly routes, partner discounts and partner shares shrink the cap on their own. A flip that leaves the house no edge is rejected.

All pending flips together can reserve at most 30% of the treasury, so a burst of flips can't tie up the bankroll. Only treasury − reserved can be withdrawn, never reserved funds, escrowed stakes or inventory.

Randomness

Flips draw from Dice Protocol's DiceEntropy, a Pyth Entropy-style commit-reveal provider native to Robinhood Chain, via the house's Entropy adapter. You pay its request fee in the flip transaction: a flat 0.000025 ETH today, whatever the callback's gas budget, since Dice's per-gas provider fee is 0. Your wallet shows it as the transaction value, plus a small refunded buffer.

All in, a flip costs that fee plus its own gas; Dice's provider pays for the reveal and settlement. Measured on a Robinhood Chain fork at the current base fee (about 0.035 gwei) and ETH near $2,687, that's about $0.10 for a $FLIPPER flip (about 355k gas) and $0.12 for a token flip (about 554k gas). Both move with gas and ETH prices.

A prompt first delivery settles through the markets as usual; a later, retried or recovered one settles in safe mode. Refunds for unanswered requests, and how the randomness stays honest, are under Protections.

Settlement

Everything settles inside the randomness callback, in one transaction:

  • Win. The house buys exactly your stake's amount of the token for at most L and pays out 2× your stake.
  • Win, but the buy fails. You get your stake back, plus the winnings in $FLIPPER at the quote +5%: min(B, S_settle × B / S) × 1.05. The settle-time quote can't be flash-manipulated.
  • Win, pool unusable both ways. Your stake is returned and the winnings are reserved, then paid by upkeep once the pool works again (“settling winnings…”).
  • Loss. The stake is sold for $FLIPPER into the bankroll, with a floor of 95% of the flip-time quote. If the sale can't clear the floor, the house keeps the tokens as inventory. The loss stands either way.
  • $FLIPPER flips need no swaps: the flip's payout (2.05× at launch) or nothing.

Nothing on an outcome-dependent path can revert: every swap, quote and transfer is gas-capped and wrapped. Safe mode (no swaps, no pushes) covers two kinds of delivery: one whose timing could have been picked by someone who knew the outcome, and one nested inside the house's own call. In safe mode a loss becomes inventory, and a win returns the stake with the winnings paid later by upkeep.

Protections

These fixed onchain rules work without anyone watching.

The drawdown circuit breaker

  • What it watches. The bankroll's value per unit, in $FLIPPER. Stakes and withdrawals move units at the current value, so only flip results and income change it. It reads no prices, pools or oracles, so nothing can push it around.
  • The line. Below 50% of its all-time high, the protocol locks. The check runs after every settlement, and anyone can run it.
  • While locked, new flips, listings, vault deposits and withdrawals, claims and upkeep pause. Plain $FLIPPER transfers still work, and the site shows a banner.
  • Flips in progress are kept. A result that arrives during the lock is recorded and settles market-free after reopening. Our worker settles them right away, and anyone can.
  • Reopening. Only the unlocker, an operator key the team holds, can unlock. The guardian can't. The owner can only name a new unlocker, so a lost key never leaves the protocol locked.
  • Lowering the reference. During a genuine cold streak (ordinary flips, no sign of an exploit or broken pool), the unlocker can lower the high the 50% line is measured from (resetNavAth), anywhere down to today's value. It can never raise it; new highs raise it as usual.

Pauses and cancellations

  • Guardian pause. The guardian can briefly pause new flips and listings. Flips in progress still settle, and everything else keeps working.
  • Cancellations. A flip whose randomness never arrives can be cancelled for a refund (by you after 7 days, by the guardian after a day), but only while the result is provably unrevealed, so nobody can void an outcome once it's out. The one exception is an emergency: after 30 days the guardian can cancel a flip that is still pending.

Randomness safety

  • Mixed with the block. A flip's result mixes Dice's number with the hash of the flip's own block. No transaction can read its own block's hash, so even someone who knew Dice's number in advance couldn't tell whether a flip wins before making it.
  • Nobody can hold back a result. Dice's values form a hash chain, so once any later value is public, anyone can settle a withheld request against Dice's stored commitment. It settles market-free, since whoever picks the moment may know the outcome.
  • A stall stops new flips. If a request goes unanswered too long and can't be worked out from public values, new flips are refused until it's resolved.
  • Block hashes are kept. Hashes are only readable for 256 blocks, so our upkeep worker and every new request snapshot them for slower deliveries.

Settlement and custody

  • Pool shut off mid-flip. A loss still stands, with the tokens kept as inventory, so there's no free void. A win returns the stake and reserves the winnings until upkeep can pay them.
  • Price manipulation. Payouts are in the staked token, so pumping or dumping between request and callback doesn't help, and a manipulated flip-time quote only worsens your own outcome. The cost cap, loss floor and win-chance cap bound what anyone can extract, even knowing the outcome.
  • Hostile tokens. Tokens that block transfers, tax them or forge quotes can't extract a fallback or touch other players' escrow.
  • Custody. Revenue can only flow to the house or the rewards contract. The contracts are upgradeable proxies, and production upgrades sit behind a timelock or multisig.

Upkeep

Some jobs run after settlement: paying a pending win once its pool works again, settling flips that waited out a lock, snapshotting block hashes, selling inventory, and moving revenue into the bankroll and rewards. There's no privileged keeper. Each job is a public function with fixed onchain rules (what it may do, minimum outputs, when it's due), so anyone can call it. Our worker calls them within moments.

Holder rewards

Every $FLIPPER holder earns rewards in $FLIPPER, with nothing to stake or sign up for. The token contract does the accounting itself, with no epochs, snapshots or keeper.

  • Where it comes from. Half of every flip's expected profit goes to holders, half to the bankroll. Only losses pay the house, so the holders' share is set aside on losses and scaled up to match.
  • Protocol liquidity fees. Swap fees from the protocol's own $FLIPPER/ETH liquidity (held for good by the LiquidityKeeper) also go to holders. Anyone can call harvest() to collect them. The $FLIPPER side streams directly; the ETH side is sold for $FLIPPER by Dutch auction.
  • Streamed, not dropped. New rewards pay out continuously over a rolling 7-day window, pro rata to balance × time held. Buying just before a big result earns only from then on, selling stops your share, and a flash loan earns nothing.
  • Claim any time from your profile.
  • Staked $FLIPPER earns too, plus 20% of its share of the bankroll's gains. Stakes lock for 7 days (see staking).

What doesn't earn

  • Protocol-owned vault shares.
  • $FLIPPER in the official v4 pool. Liquidity providers earn the pool's swap fees instead.
  • $FLIPPER in other contracts (lending markets, vaults, multisigs) accrues to that contract like any holder. If the contract can't claim, its rewards stay locked for good, which works like a burn.

The stream right now

Holder rewards aren't live on this network yet.

Staking the bankroll

Anyone can stake $FLIPPER into the house bankroll through the TreasuryVault for sFLIPPER, a share of the whole bankroll. Stakes go straight into the bankroll the house bets with; the vault itself holds no tokens. sFLIPPER can't be transferred or approved, only minted on stake and burned on withdrawal, so the lock can't be sidestepped.

Staking locks for 7 days. Every stake locks all your sFLIPPER, so staking again restarts the lock for your whole position. You can't request a withdrawal until it ends. After that, a withdrawal takes a 2-day cooldown, so the earliest your $FLIPPER can be back in your wallet is 9 days after your latest stake.

The share price is the bankroll divided by all shares. Lost flips, the router's bankroll share of revenue and donations raise it; won flips lower it. Stakers bear their pro-rata share of drawdowns.

The 20/80 split

Of your pro-rata share of the bankroll's growth, 20% is yours and 80% becomes protocol-owned liquidity (POL). While the share price is above its high-water mark, the vault mints protocol shares until you keep exactly 20% of your gain above the mark, then moves the mark up to the new price. Say the vault holds 10 $FLIPPER, 1 of them yours, and the bankroll earns 1:

Before+1 inflow, no feeAfter the fee
You (1 of 10 shares)1.001.101.02: +0.02, 20% of your 0.10
Protocol (9 of 10 shares)9.009.909.98: +0.98
Price per share1.001.101.02, the new mark

The high-water mark

Nothing is charged at or below the mark. After a drawdown you bear your full share of the loss, and recovering to the previous high is fee-free. So you keep about 20% of your share of net growth, not 20% of the gains while bearing all the losses.

  • Fees are taken as they happen. A fee taken at a peak isn't refunded if the bankroll then falls, so on a path ending below its peak you can keep a little less than 20% of your net growth. Never more.
  • The mark is shared. Staking during a drawdown buys in at the lower price (existing stakers are unaffected) and also recovers fee-free up to the mark.

Lock, cooldown and withdrawal

  1. 1

    Stake: locked for 7 days

    Your position unlocks at the later of its current unlock time and 7 days from now (1 day on dev deployments). No withdrawal requests until then.

  2. 2

    Request a withdrawal

    Queue any amount of sFLIPPER. That (re)starts the cooldown for everything queued: 2 days by default (10 minutes on dev deployments). Queued shares stay staked, still earning, bearing losses and counting for holder rewards. You can cancel any time.

  3. 3

    Withdraw

    Withdrawing burns all your queued shares at that moment's share price, pending flips included, and sends the $FLIPPER to your wallet.

Free-bankroll limit. Withdrawals are paid only from the free bankroll, the treasury minus what pending flips reserve. If pending flips reserve too much, the vault reverts with InsufficientFreeBankroll until they settle.

Protocol-owned growth

The protocol's share grows from the bootstrap (the seeded bankroll and any donations start protocol-owned), 80% of stakers' gains above the mark, and its own pro-rata share of every result. Exits never touch it, and if every staker leaves, the bankroll is wholly protocol-owned and keeps growing. Nothing can withdraw it: the vault has no function that takes protocol-owned shares out.

  • Stakers earn holder rewards too. Your sFLIPPER counts at its $FLIPPER value (shares × price per share), queued withdrawals included. Protocol-owned shares don't earn.
  • Admin limits. The vault owner can set the fee (up to 95%), the lock (up to 365 days) and the cooldown (up to 30 days). Lock changes apply to new stakes, cooldown changes to new requests, and fee changes never touch gains already made. The owner can't move or burn stakers' shares. Once the vault is set, only the vault can take bankroll out of the house.

Stake $FLIPPER →

Launch and team stake

$FLIPPER launches with its whole supply in its own Uniswap v4 pool, at a $5k starting market cap. Nothing is minted on the side.

The team makes the opening buy as the pool's first trade, inside the launch transaction: 12.5% of the supply (125M $FLIPPER).

The pool's liquidity is permanent. The Uniswap v4 position is held by the LiquidityKeeper, an immutable contract with no owner, admin or upgrade path. Nothing can withdraw, move or shrink it; the keeper can only collect the pool's swap fees for holders.

The team stake

All of it is staked into the treasury through the PrincipalLock, an immutable contract with no admin or upgrade path, which enforces onchain that the team never withdraws this principal.

  • Only earnings on top can be claimed: the stake's share of treasury gains, plus its staking and holder rewards. They fund development.
  • Nothing is withdrawable while the stake is below its principal. It bears drawdowns like any stake, and only value above the principal can ever leave.
  • Anyone can verify it. On the lock, principal() is the locked amount, value() the stake's current worth and withdrawableExcess() the earnings claimable now.
  • What it relies on. The lock can't change, but its stake sits in the treasury vault, which is upgradeable. Vault upgrades are governed by [governance to be announced before launch].

Team stake

The team's stake is locked for good. Only what it earns can leave, and only to the dev address below.

The team-stake lock isn't deployed on this network yet. Its address is published here at launch.

The lock's address and the vault it stakes in are published here and in the contracts table at launch: [PrincipalLock address], staking through [TreasuryVault address].

Which tokens flip

At launch on Robinhood Chain, flipper flips the majors (ETH, USDG and cbBTC), Robinhood stock tokens, and a curated set of Robinhood Chain tokens: PONS, ORBIO, INDEX, SHROOM and DICE (Dice is an ecosystem partner).

Anyone can list a qualifying token in one transaction from the picker's “List on flipper” row, with the checks run onchain. Other tokens can't be listed permissionlessly. A token qualifies through:

  • The whitelist: specific pools and allowlisted tokens (majors, trusted tokens), added by the protocol's owner multisig.
  • A launchpad integration: a launchpad can attach its own onchain verifier to the listing policy, so tokens it vouches for can be listed. If you run a launchpad, get in touch.

The route must also be liquid. A listing runs a test trade whose round trip must cost ≤ 4% (listingMaxRouteCostBps). After that, every flip re-checks the route cost at the actual stake, so a pool that thins out gets shifted odds or a rejection. This checks the pool, not the token contract. In the picker, a checkmark marks tokens flipper whitelisted, or a launchpad's verified launches.

Free streak game

Tap the coin on the home screen to flip for free. The server draws heads or tails 50/50. Heads extends your streak, and tails ends it. From x5 the controls slide away, and the indicator gets wilder up to a legendary x50.

It's offchain and just for fun, with no stakes, tokens or transactions, and unrelated to the house's odds. Runs are ranked on the Longest streaks board. You can play signed out and sign in afterwards to claim your spot.

Contracts and chains

flipper launches on Robinhood Chain (chain id 4663, explorer robinhoodchain.blockscout.com) for its deeper liquidity and more eligible tokens. This deployment is on Robinhood Chain (chain id 4663). Most contracts are TransparentUpgradeableProxys (OpenZeppelin v5), each with its own ProxyAdmin, and the address below is the proxy. The listing policy, its verifiers and the v3 bridge hook are plain contracts.

Contract addresses on Robinhood Chain
ContractAddress
FlipperHouseEscrow, pricing, bankroll, randomness callback and settlementUpgradeable proxypublished at launch
FlipperLensBatched reads and flip previews for the app and SDKUpgradeable proxypublished at launch
TreasuryVaultStaking: $FLIPPER into the bankroll for non-transferable sFLIPPER (also the sFLIPPER token)Upgradeable proxypublished at launch
RevenueRouterLaunched $FLIPPER on its v4 pool; collects fees, funds bankroll and rewardsUpgradeable proxypublished at launch
Randomness adapterEntropy adapter: Dice Protocol's DiceEntropy on Robinhood ChainUpgradeable proxypublished at launch
V4RouteAdapterRoutes for whitelisted Uniswap v4 tokens and poolsUpgradeable proxypublished at launch
$FLIPPERHouse token (bankroll, 2.05× flips), with holder rewards built inTokenpublished at launch
Uniswap v4 PoolManagerEvery swap the house makes settles hereExternalclick to copyexplorer ↗