RIADeFi
Research files · Other

Ketju research: Robinhood Chain Bridge

RejectedPublished by Ketju Research

This file describes the economic claim, control, loss, and exit evidence. Client action and amount belong to the advisor. Not investment, legal, tax, or compliance advice.

Research summary

The contract-level facts support rejection, not a finding that disclosures are lacking. Robinhood Chain is an Arbitrum Orbit L2 Robinhood operates for tokenized stocks and other RWA products. Unlike the disclosure gaps that sink several entries in this batch, Robinhood Chain is unusually well documented at the contract level. That documentation shows why it fails review: fraud-proof validation is not yet permissionless; a transaction-filtering precompile can block even transactions submitted directly to L1 to bypass a censoring sequencer, defeating the force-inclusion backstop every other canonical bridge in this registry relies on as a last resort; and a specific externally-owned account retains direct contract-upgrade authority alongside the chain's multisig, which L2Beat itself flags as a critical risk. A governance restructuring four weeks before this review improved the standing multisig but did not close any of these three gaps.

Observable review triggers

  • Fraud-proof validation becomes permissionless, removing the whitelisted-validator requirement
  • The ArbFilteredTransactionsManager filtering capability is removed, or is demonstrated never to block a force-included L1 transaction
  • The externally-owned account currently holding direct upgrade or admin permission is removed from that role, leaving only the disclosed multisig path
  • Twelve consecutive months of the restructured multisig governance operating with no bypass-the-timelock upgrade executed without public justification

Facts on file

Verdict
Rejected
Type
Other
Chains examined
Ethereum
Reviewed
Last confirmed

← All published rejections