HoodLend Paper

Protocol paper · September 2026 · Testnet live

Never sell your bags
to raise cash.

HoodLend is an isolated money market on Robinhood Chain. Post tokenized equity as collateral, borrow USDG against it, and keep the upside you would have surrendered by selling.

● Deployed · chain 46630 6 markets 96/96 tests passing Unaudited

01 — Thesis

Executive summary

  • The asset class is new and unlevered. Robinhood put tokenized US equities on-chain. Those tokens can be held and traded, but there is no venue that lets a holder borrow against them. Every tokenized share is idle collateral.
  • HoodLend is the credit layer for it. Supply TSLA, AMZN, PLTR, NFLX, AMD or WETH; borrow USDG at up to 65% LTV. An Aave-style health factor governs solvency; positions below 1.00 are liquidated by open competition.
  • Revenue is a spread, not a subsidy. The protocol keeps a 10% reserve factor on all borrow interest plus 10% of every liquidation bonus. No emissions are required to produce it.
  • The token earns its demand. Staking cuts borrow interest by up to 40%. That is a measurable cash saving for a borrower, so demand scales with real loan volume rather than with narrative.
  • It already runs. 17 contracts deployed on Robinhood Chain testnet, 96 unit tests green, six live oracle-priced markets, and a frontend in production. The discount is verified on-chain at 4000 bps.
Borrow APR floor 2.0%

Base rate at zero utilization, rising with demand.

Protocol take 10%

Reserve factor on interest, plus 10% of liquidation bonuses.

Max staker discount 40%

Verified live: 4000 bps at 100k staked.

02 — Thesis

The problem

A holder of tokenized equity who needs liquidity has exactly one option today: sell. Selling is the expensive choice in three separate ways, and all three are avoidable.

  • It ends the position. Upside after the sale belongs to someone else. For a holder with conviction this is the entire cost.
  • It realizes a taxable event. Borrowing against an asset is not a disposal. Selling to raise cash converts a paper gain into a tax bill.
  • It is one-directional. Re-entering costs spread and slippage twice, and the price rarely waits.

Traditional finance solved this a century ago with margin loans and securities-based lending. On-chain, the same primitive exists for ETH and stablecoins but not for tokenized stocks — the asset class is too new to have been listed anywhere.

The gap, stated plainly

Tokenized equity has price discovery and custody, but no credit market. HoodLend supplies the missing leg: a borrower keeps exposure, and a lender earns yield on an asset class that previously paid none.

03 — Thesis

Market & timing

Lending is the largest and most durable category in DeFi. It survived every cycle since 2020 because the demand is structural: leverage and yield are wanted in all market conditions.

  • Collateral drives borrow volume. Across major money markets, borrows typically run at a meaningful fraction of supplied collateral. Every new collateral type is additive to that base.
  • Tokenized equity is the growth asset class. Real-world assets moved from thesis to shipped product, and Robinhood — a retail broker with tens of millions of funded accounts — is the distribution.
  • The chain is new. Robinhood Chain has no incumbent money market. Lending is typically the first protocol to matter on a new chain, because every other application needs it.
  • First-mover advantage compounds here. Liquidity attracts borrowers, borrowers deepen liquidity, and the resulting rate curve is hard for a later entrant to beat.
Honest framing on size

Robinhood Chain is early and its on-chain equity float is small today. HoodLend is a bet on that float growing, positioned before it does — not a claim that the market already exists at scale.

04 — Mechanism

How it works

Four actions, one pool. Suppliers provide collateral, borrowers draw USDG against it, interest accrues per second, and liquidators keep the book solvent.

Lending pool Isolated market 6 collaterals · 1 borrow asset health factor ≥ 1.00 Supplier Stock tokens TSLA · AMZN · WETH… Borrower Draws USDG up to 65% LTV Liquidator Repays debt takes 8–10% bonus Interest 90% suppliers 10% reserves collateral USDG accrual repay below 1.00 → liquidatable
Figure 1 — Capital flow. Collateral is never rehypothecated: it sits in the pool as the borrower's own escrow. The only asset that leaves is USDG, and only against sufficient collateral.
MarketLTVLiq. thresholdBonusRole
AMZN65%72%8%Collateral
NFLX65%72%8%Collateral
TSLA50%60%10%Collateral
PLTR50%60%10%Collateral
AMD50%60%10%Collateral
WETH75%80%7.5%Collateral
USDGBorrow asset

Higher-volatility equities carry a lower LTV and a larger liquidation bonus. Parameters are per-asset, never a single blended constant.

05 — Mechanism

Risk engine

Solvency reduces to one number. The health factor is the ratio of risk-weighted collateral to debt, and it is computed per-asset then blended — a mixed portfolio is never scored against a single average.

Health factor
HF = Σᵢ ( collateralᵢ × priceᵢ × LTᵢ )total debt × priceUSDG
Where LTᵢ is asset i's liquidation threshold. Solvent at HF ≥ 1.00; liquidatable below. Debt rounds up and collateral rounds down, so rounding always favors the pool.

Worked example — a real position

A borrower supplies 100 AMZN at $200 and 5 TSLA at $90, then draws $9,000 USDG.

Step 1 · Risk-weighted collateral
AMZN 100 × $200 × 0.72 = $14,400 TSLA 5 × $90 × 0.60 = $270 ───────── weighted collateral $14,670
Step 2 · Health factor
HF = $14,670 / $9,000 = 1.63 → solvent
Step 3 · Distance to liquidation
collateral may fall to $9,000 before HF = 1.00 drawdown tolerated = 1 (9,000 / 14,670) = 38.6%
The borrower can absorb a 38.6% portfolio decline before facing liquidation. Borrowing power itself is set by the stricter LTV (65%/50%), not the threshold — the gap between the two is deliberate headroom.
liquidatable at risk healthy 0 1.00 1.50 2.50+ example · 1.63 HF = 1.00 · liquidation begins
Figure 2 — Health factor bands. The protocol enforces only the 1.00 boundary; the "at risk" band is guidance surfaced in the UI so borrowers act before a liquidator does.

Oracle design

  • Chainlink feeds, normalized to 8-decimal USD through a single router.
  • Staleness and round guards reject a feed that has stopped updating rather than pricing against a frozen quote.
  • A market whose feed is unconfigured ships disabled, never mispriced. Feed addresses are never guessed.
  • ERC-8056 uiMultiplier() is deliberately not re-applied — Chainlink equity feeds already include it, and double-multiplying would lie dormant until a stock split.
block.number is not a clock on this chain

Robinhood Chain runs Arbitrum Nitro, where block.number returns an L1-derived value that does not advance at a usable L2 cadence. All accrual is keyed to block.timestamp, enforced by a CI guard that scans the source and fails the build.

06 — Mechanism

Interest rate model

A two-slope jump-rate curve. Rates track utilization, so the pool prices its own scarcity: cheap when liquidity is abundant, punitive when withdrawals are at risk.

Utilization and borrow rate
U = borrowscash + borrows reserves if U 80% r = 2% + U × 8%80% if U > 80% r = 10% + (U 80%) × 100%20%
Base 2%, slope₁ 8% to the 80% kink, slope₂ 100% beyond it. The curve is continuous at the kink — both branches yield exactly 10% — which unit tests assert.
0% 10% 40% 80% 110% 0 25% 60% 80% 100% utilization kink · 80% 2% 10% 110% gentle · liquidity abundant steep
Figure 3 — The jump-rate curve. Past the kink the slope goes vertical by design: it pays suppliers to arrive and forces borrowers to repay, so the pool always retains withdrawable cash.

Suppliers receive the borrow interest net of the reserve factor, pro-rated across the whole pool:

Supply rate
rsupply = rborrow × U × (1 0.10)
At 60% utilization: borrow rate 8.0%, so supply rate = 8.0 × 0.60 × 0.90 = 4.32%, and the protocol keeps 0.48% of pool value annually as reserves.

07 — Mechanism

Liquidations

When a position falls below 1.00, anyone may repay part of its debt and seize collateral at a discount. The bonus is the incentive that makes third parties do the protocol's risk management for free.

  • Close factor 50%. A single liquidation may retire at most half the debt, so a small breach does not wipe out the whole position.
  • Bonus 7.5–10% by asset — larger where the collateral is more volatile, because the liquidator carries more price risk.
  • The protocol takes 10% of the bonus, in collateral. Not from the pool's cash, which would fund the cut out of supplier liquidity.
  • Liquidation cannot worsen a position. Health factor is re-read after state writes and the call reverts on regression.
Seize calculation · $9,000 debt, HF falls to 0.98
max repay = $9,000 × 50% = $4,500 collateral = $4,500 × 1.08 = $4,860 of which bonus = $360 protocol cut = $360 × 10% = $36 liquidator = $360 $36 = $324
The liquidator nets $324 on $4,500 deployed — a 7.2% return on a single transaction. That margin is what guarantees someone is watching every position at 3am.
$4,500 · debt repaid $324 92.6% liquidator $36 protocol
Figure 4 — Where seized collateral goes. The borrower pays the bonus in collateral; suppliers are made whole in cash. Total seized $4,860.

08 — Economics

Revenue model

Two streams, both mechanical. Neither depends on token emissions, inflation, or new deposits to pay old ones.

Stream 1 · Reserve factor 10%

Of all borrow interest. Scales with borrows × rate — the recurring line. Accrues per second into pool reserves.

Stream 2 · Liquidation cut 10%

Of every liquidation bonus, taken in collateral. Counter-cyclical: it pays most when markets are violent.

Annual protocol revenue
R = ( borrows × rborrow × 0.10 ) + ( liquidated × bonus × 0.10 ) └──── recurring ────┘ └──── episodic ────┘
Reserves are moved to the fee collector by collectReserves() — permissionless, so no privileged party gates the flow, but it is not automatic and must be called.

Why the fee is on interest, not deposits

A deposit fee taxes the side of the market that is hardest to attract. Taxing interest means the protocol earns only when it has actually provided credit — the incentive is aligned with the thing being sold.

09 — Economics

Token utility

Fixed supply of 100,000,000, capped in the contract and fully minted at deploy — no inflation is possible. The token does two things, both live on chain.

StakedDiscountSaving at 8% on $1M
1,00010%$8,000 / yr
10,00020%$16,000 / yr
100,00040%$32,000 / yr
  • 1 · Borrow-rate discount. Staking cuts the interest paid on every open borrow. A borrower compares the token's cost against a cash saving, which is a valuation anchor rather than a story.
  • 2 · Fee share. Staked tokens earn USDG from protocol revenue through a Synthetix-style vault. No lock-up.
The mechanism is self-limiting by design

As the token price rises, the payback period on the discount stretches until buying stops being rational. Demand is therefore capped by real borrowing volume — the token cannot inflate past the utility it delivers.

Verified on chain 46630
stake 100,000 discountBpsOf() = 0 4000 bps gross interest accrued = 58 interest actually charged = 35 effective reduction = 39.7%
The 0.3% gap against a nominal 40% is integer rounding at USDG's 6 decimals, not a modelling error. The discount is applied in debtOf() so the global borrow index stays uniform across all borrowers.

10 — Economics

Unit economics

The model has one input that matters: total value supplied. Everything else follows from the curve. Three scenarios at a constant 60% utilization, where the borrow rate is 8.0%.

Scenario Supplied Borrows Interest / yr Protocol / yr
Early $2M$1.2M $96,000$9,600
Traction $25M$15M $1.20M$120,000
Scale $150M$90M $7.20M$720,000
Traction case, derived
supplied = $25,000,000 borrows @ U=60% = $15,000,000 borrow rate @ U=60% = 2% + 60/80 × 8% = 8.0% gross interest = 15,000,000 × 0.080 = $1,200,000 ├─ to suppliers = × 0.90 = $1,080,000 └─ to protocol = × 0.10 = $120,000 supplier APY = 8.0% × 0.60 × 0.90 = 4.32%
Liquidation revenue is excluded — it is episodic and depends on volatility. In a sharp drawdown it can exceed a full year of interest revenue in a single week, which is why the two streams are complementary rather than additive in a base case.
scale traction early $150M tvl $25M tvl $2M tvl $720,000 $120,000 $9,600 protocol revenue per year · interest only · U = 60%
Figure 5 — Revenue scales linearly with borrows. Bar lengths are scaled for legibility, not proportionally; read the labelled figures. The protocol has no per-user cost, so this line is close to gross margin once contracts are deployed.
These are scenarios, not forecasts

The figures are the model's arithmetic at stated inputs. They assume a TVL the protocol does not have today and a utilization it has not yet demonstrated. Treat them as a sensitivity table, not a projection.

11 — Execution

What is live today

This is a deployed system, not a design document. Every claim below was verified against chain 46630.

Unit tests 96/96

12 suites, including fuzz tests on debt accounting.

Contracts deployed 17

All verifiable on Blockscout, non-zero codesize.

Live markets 6

Five equities plus WETH, all oracle-priced.

  • Core loop works end to end — supply, withdraw, borrow, repay, liquidate, all exercised on-chain.
  • Guards fire correctly. Over-borrowing reverts ExceedsBorrowPower; liquidating a solvent position reverts NotLiquidatable.
  • Staking discount confirmed at 4000 bps with a 39.7% measured interest reduction.
  • Oracles fresh across all seven assets, staleness guards passing.
  • Frontend in production — five routes, live health-factor preview, mobile responsive.
Contracts are unaudited

The code is open and verified on-chain, and it is not yet audited. A third-party audit is a precondition for mainnet, not a follow-up. Until then this is testnet software and the assets have no value.

12 — Execution

Roadmap

Ordered by dependency, not by date. Each phase gates the next; nothing here is parallelizable past the audit.

PhaseMilestoneGate
Now Testnet live, public frontend Complete
Next Third-party security audit Precondition for mainnet
Then Mainnet deploy on chain 4663 Real Chainlink feeds wired
Then Supply-side liquidity bootstrap Mainnet contracts live
Later Additional equity markets Feed availability per ticker

The mainnet script is written and compiles, but deliberately refuses to run until real feed addresses are populated. A market whose feed is unset ships disabled rather than mispriced — a guard, not an oversight.