X
πŸ“„ πŸ¦† 🎲 ✦ 🧾 ✦ 🎲 πŸ¦† πŸ“„

ducs

~ * ~ The company is the document ~ * ~
no offices · no staff · no officers · owner status: NONE
*** THIS COMPANY HAS NO EMPLOYEES *** NOBODY OWNS IT *** NOBODY CAN CHANGE IT *** IT SELLS ITS OWN SHARES *** IT PAYS ITS OWN DIVIDENDS *** THE FOUNDER HOLDS ZERO *** THE PAPER IS THE WHOLE COMPANY ***
πŸ–¨ now printing: nothing The press is idle. Nobody has asked it for anything.
🧾 the press LIVE printing at block ...... on Robinhood Chain

πŸ“„ the front desk

there is nobody at it. there never was. that is the product.
ducs
fig. I. the company.
(the tail is the paperwork.)

ducs takes itself public. Anyone sends it money and gets shares back at net asset value, and those proceeds are the only capital it will ever have. There is no round, no allocation, and nothing minted at deploy. The founder buys in at the same price as the tenth buyer, or does not buy at all.

With that capital it runs one business, a dice house with the edge written into the charter. What it earns above the money put in stops being the company's and becomes the shareholders', continuously, without anyone deciding to declare it.

There is no owner, no admin, no pause and no upgrade path. Once it is deployed, what you read in the charter is what the company is for as long as the chain runs.

πŸ“Œ the short version

A company you can read in one sitting.

Most companies are a building full of people and a promise that they will behave. This one is a page of arithmetic. You do not have to trust it, because there is nothing in it that could decide to betray you.

🎲 want to see it work?

The house is not deployed yet, and the dice still roll. Open THE HOUSE in the menu and take a hand against the real chain.

🎲 the house

the one business the company runs, and the only place its money comes from.

A player picks the odds they want. The house pays a fair game minus two percent, every time, at every price. On a 49% bet that is 2.00x. On a 1% bet that is 98x. The two percent never moves, because it is a constant in the code and there is nobody who could move it.

πŸ–¨ take a hand, for nothing LIVE

This is not a picture of the game. Your secret is sealed the moment you press the button, the die is the hash of a Robinhood Chain block that does not exist yet, and the roll is computed the way the contract computes it. The chain decides, about a second from now.

Stake0.01 ETH
Pays2.00x
House edge2.00%

> ready

🏦 the window

where you buy a piece of the company, take it back, or collect what it owes you.

The window is shut until deploy day.

Nothing here is live yet, because the company does not exist on the chain yet. On the day it is deployed this panel starts reading the real books and the buttons start sending real transactions. Until then you can still take a hand in THE HOUSE: those dice are already real.

πŸ“œ the charter

constants in the code. this is what the company is, permanently.
House edge, every bet2.00%
Longest odds it will write98x
Most one bet may risk1% of the book
Most the whole table may risk5% of the book
Smallest stake0.01 ETH
Dividends pay out over1 hour, continuously
Price of the first share0.0001 ETH
Shares held back for the founder0
Ways to change any of the above0

why those numbers

Two percent, and not more.

A real casino takes between one and fifteen. Two is low enough that playing is not obviously foolish, and high enough that a thousand hands leave the company clearly ahead. It is the same two percent at 90% odds and at 1% odds, so there is no corner of the table where the house quietly takes more.

One percent on a bet, five on the table.

These two are what make ruin impossible rather than unlikely. A single hand can never take more than a hundredth of the company, and everything in play at once can never take more than a twentieth. The house can have a terrible night. It cannot have a fatal one.

Ten blocks, then twenty seconds.

Ten blocks is about one second on this chain: long enough that the die does not exist when you commit, short enough that you are not waiting. Twenty seconds is the window to reveal, and it is the chain's limit rather than a choice, because that is roughly how long Robinhood Chain keeps a block hash reachable.

An hour of dividends.

Profit is paid down over an hour rather than all at once, which is what stops anyone buying in the second before a win and leaving the second after. Hold for an hour and you get the whole of your share.

Zero founder shares.

Not a small number. Zero. There is no allocation, no vesting cliff and no treasury, because there is no mechanism in the contract that could mint a share to anyone who did not pay net asset value for it.

πŸ—‘ the attacks

two rounds of adversarial audit, forty-seven agents, eight confirmed ways to rob this company. Every one is dead, and every one has a test standing over its grave.

1. Buy the company for a fraction of its backing.

Bets used to take their money out of the book, and the book set the share price. So an attacker stacked bets until the price collapsed, bought the company cheap, then let the bets settle and the money come back. Measured: twenty ETH in, ninety-two out, and the victim's hundred ETH worth twenty-seven. Killed by making a bet a lien on the book rather than a withdrawal from it. The mint price no longer moves when the table fills up.

2. Arrive one second before the good news.

A die is public a moment before anyone settles it. If profit landed on shareholders instantly, you could read the result, buy the company, settle, take the dividend and leave in one transaction, and long-term holders would earn nothing forever. Killed by retaining profit and paying it down continuously. Arriving one second early is now worth one second of dividends.

3. Duck out before the bad news.

The mirror of the same trick: see the house about to lose, redeem first, leave the loss with everyone else. Killed by pricing exits net of every bet still on the table, so the loss is already in your exit price.

4. Never settle a loser.

A refund on an expired bet made losing free: you would settle your winners and let your losers rot for a two percent fee. The house edge went from plus two percent to hugely negative. Killed by making an unrevealed bet forfeit the whole stake, exactly what losing costs.

5. Open a hundred small bets at once.

A cap of one percent per bet bounds one bet and nothing else. Killed by capping every open bet together at five percent of the book.

6. Grind the block until the die says what you want.

A block hash is chosen by whoever assembles the block. On a chain with one sequencer, an operator who could also bet would need about a hundred candidate blocks to force a 98x win. Killed by splitting the die in two: half a future block hash, half a secret only the player holds. Grinding the block is now grinding blind.

7. Show up late and take a cut of money you did not earn.

The entry price ignored profit already earned and waiting to be paid out, so a newcomer minted a free claim on it and diluted the people who made it. Killed by putting that pot into the price you pay to come in.

8. Brick the company forever, for the price of gas.

The sharpest find. Redeem down to a single unit of a share, and one wei of dividend released against a supply of one inflates a counter by 2^128. It never comes down, and the very next ordinary transfer overflows on it. The company would be dead, unfixably, and the attacker walks away whole. Killed by making every position a whole share or nothing, on buying, selling and transferring alike, so the first step never lands.

πŸ”¬ the proof

forty-seven tests. these are the ones that matter, and what each one actually shows.

the mechanism is a real dice house

test_HouseEdgeConvergence

One thousand hands of one ETH at 49% are played and settled. The company's realised margin has to land on turnover times two percent, minus the settlement fees, inside the noise you would expect from a thousand coin flips. A dice house has one honest test, and this is it.

the money is all there, always

invariant_BooksBalanceToTheWei

Random sequences of buys, redeems, transfers, bets, settlements, forfeits, claims, waits, gifts and skims. After every single step, what the contract holds must equal its book plus staked bets plus retained profit plus declared dividends plus held payments. To the wei. Thousands of random paths, no exceptions.

invariant_ReservedIsCovered · invariant_OthersMoneyIsHeld

Every bet the house has accepted is still funded, and money that belongs to other people is really in the contract rather than an accounting fiction.

the attacks stay dead

test_JitSniperCannotCaptureProfit

An attacker reads a die that already landed in the company's favour, buys ninety-nine percent of the company, settles, claims and redeems, all in one transaction. They finish with less than they started.

test_SequencerCannotGrindTheDie

An operator is handed two hundred candidate blocks and every public input to the roll. Their best play still lands on the honest one percent, because the half of the die they cannot see is the half that decides.

test_TheDustSupplyBrickCannotBeBuilt

The audit's sharpest attack, reproduced step by step, blocked at the first move.

test_ForfeitIsNotAFreeOption · test_BountyFarmingLosesMoney

Walking away from a losing hand costs the stake. Betting to collect your own settlement fee costs money. Neither is a way in.

nothing gets stuck or stolen

test_HostileWinnerCannotWedge

A player contract that refuses to accept ETH still gets settled. The payout waits under its own name and the settler is still paid, so nobody can jam the house by being difficult.

test_NobodyCanConfiscateAnotherHoldersDividend

A stranger can push your dividend to you, but can never turn it into something other than a dividend.

test_LastShareholderOutTakesTheRetainedEarnings

The last holder out takes the unpaid profit with them, so nobody inherits a windfall by incorporating an empty shell afterwards.

it runs on the real chain

test_LifecycleOnLiveChainState

Incorporation, an IPO, a hand of dice, the dividend stream and a redemption, all on a fork of live Robinhood Chain. That is where the gas numbers in the ledger come from.

🧱 the walls

why the till cannot be raided, including by the person who wrote it.

Every risk is funded before it exists.

When a bet is accepted, the whole payout it could ever owe is placed under a lien on the book. The house can lose a hand. It cannot fail to pay one.

The die has two halves, and nobody holds both.

One half is the hash of a block ten blocks in the future, so the player cannot see it. The other is a secret only the player knows, sealed when the bet is placed. Whoever assembles that block is grinding blind.

Profit streams, so nobody can arrive for the good part.

Earnings are retained and paid down continuously rather than landing in a lump. Arriving one second early is worth one second of dividends, and the entry price already includes what is in the pot.

Money leaves through four doors and no others.

Winnings, settlement fees, dividends, redemptions. Each is a number the contract computes itself. You can take your slice back at any time, with no lockup and no permission. There is no fifth door.

🧾 the ledger

measured, not claimed. every line here is a number something printed.
Tests passing47
Adversarial audit rounds2
Attacks found and buried8
Margin over 1,000 handsthe charter edge
Books balance, after every stepto the wei
Gas to buy in131,290
Gas to settle a hand41,935
Owner functions in the bytecode0
Kept by the company0%
Paid to shareholders100%

where each number came from

The gas figures are from the real chain.

Not an estimate and not a testnet. The contract was deployed to a fork of live Robinhood Chain, taken through incorporation, an IPO, a hand of dice and a redemption, and those are the numbers it actually burned. At current fees a buy costs well under a cent.

The margin is measured, not asserted.

A thousand hands are played and settled in the suite, and the realised margin has to land on the charter edge within the noise of a thousand coin flips. If the mechanism drifted, that test would fail rather than quietly lie.

"Balances to the wei" is a property, not a spot check.

Random sequences of every action the contract offers are thrown at it, and after every step the money it holds must equal the money it says it holds, exactly. Not close. Exactly.

Zero owner functions is a fact about the bytecode.

Not a promise in a document and not a multisig that is currently behaving. There is no function in the deployed code that lets anyone move money, change a number or stop the company, which you can confirm yourself in CHECK IT YOURSELF.

The audits were adversarial, and they found real things.

Forty-seven agents across two rounds, each told to break the contract rather than approve it, and each finding attacked again by a separate agent trying to prove it wrong. Eight survived that and all eight are now closed. They are written up in THE ATTACKS, including the one that could have bricked the company forever for the price of gas.

πŸ” the seal

a charter is authenticated by a seal: proof it was not altered after issue.

0xe3f5c8ce93ac1e344ecf3c4c7f2de933a0db8e7877cdd5bbf8f6754a379e6a35

That is the fingerprint of the code that will be deployed. On the day it goes up, hash the bytecode at the address yourself. It has to come out to exactly this, or you are not looking at this company.

how to check it in one line

Ask the chain for the code living at the address, hash it, and compare:

cast keccak $(cast code <address> --rpc-url https://rpc.mainnet.chain.robinhood.com)

If that prints the fingerprint above, the company you are looking at is the one described on this page, and it can never become anything else. There is no upgrade path to change it later, which is the whole reason a fingerprint is worth taking.

what a seal cannot tell you

It proves the code is the code. It does not prove the code is good: that is what the tests and the audits are for, and both of them are things you can run yourself. A seal is only the promise that what you audited is what you are using.

πŸ”Ž check it yourself

nothing on this page asks to be believed.

the dice

Roll a hand in THE HOUSE, then take the block number it prints and ask the chain for that block yourself. The hash it returns is the die the page used. The roll is keccak(die, secret, id, player) % 10000, the contract's own line, and this page computes it with a keccak-256 checked against the standard vectors.

the code

Every number in the charter and the ledger comes out of the contract or its test suite, not out of a marketing document. The seal lets you confirm the deployed bytecode is the same code those numbers came from.

the company

Look for an owner function in the bytecode. There is not one. That is the entire security model, and it is checkable in a minute.

run the whole thing yourself

Clone the repository and run the suite. It needs nothing but Foundry.

forge test

Then run the last one against the live chain, which replays a full corporate lifetime on a fork of Robinhood Chain rather than on a made-up network:

forge test --match-contract Fork --fork-url https://rpc.mainnet.chain.robinhood.com -vv

read the charter in the source

Every number on this site is a constant near the top of one file. There is no configuration, no deployment script that sets values, and no admin call that changes them later. What the file says is what the company is.