# RAILHOOD — full documentation (llms-full.txt) > Complete docs in one file, generated from https://railhood.gitbook.io/railhood-docs. Canonical per-page URLs are noted on each section. Index: https://railhood.com/llms.txt --- # The off-market layer for Robinhood Chain. Robinhood Chain runs on a public tape. Every balance, every position, every counterparty — printed for anyone, forever. RAILHOOD is where you trade when you don't want to broadcast: take your balance off-market, move value privately, settle back onto the tape with a clean receipt. ## TL;DR You move funds off-market into a pool of sealed notes. Off-market, your balance is encrypted — only your key can spend it, and the public tape shows nothing about size, ownership, or history. When you're ready, you settle back to any address through a settlement agent that pays the gas, so your wallet never even appears as the sender. Point an AI agent at it over MCP and the agent gets the same cover: **an agent can't leak what it can't see, and an attacker can't price what it can't see.** ## Positions on the product - **Non-custodial.** RAILHOOD never holds your keys or your funds. You sign everything. There is no desk to call and no desk to freeze you. - **Not a mixer.** Your deposit stays your individually-owned note the whole way through — nothing gets pooled and dealt back out. The full breakdown is in [Inside the pool](https://railhood.gitbook.io/railhood-docs/inside-the-pool). - **Compliance is architecture, not paperwork.** The design screens the door, keeps the middle private, and issues clean-provenance receipts at exit. Details in [Standards & policy](https://railhood.gitbook.io/railhood-docs/standards-and-policy). - **Built for machine flow.** Every capability is callable by an AI agent over MCP, no account, no API key. See [Quickstart](https://railhood.gitbook.io/railhood-docs/quickstart-mcp). ## Where to go from here | You are | Start with | | --- | --- | | New to all of this | [Why markets go off-market](https://railhood.gitbook.io/railhood-docs/why-markets-go-off-market) — the 300-year backstory in five minutes. | | Running agents | [Agents on glass](https://railhood.gitbook.io/railhood-docs/agents-on-glass), then [Quickstart](https://railhood.gitbook.io/railhood-docs/quickstart-mcp). | | Technical | [Inside the pool](https://railhood.gitbook.io/railhood-docs/inside-the-pool) → [Execution & settlement](https://railhood.gitbook.io/railhood-docs/execution-and-settlement) → [Privacy quality](https://railhood.gitbook.io/railhood-docs/privacy-quality). | | Here for the token | [Tokenomics](https://railhood.gitbook.io/railhood-docs/tokenomics). 75% fair launch; the chart speaks for itself. | > **INDEPENDENT** — RAILHOOD is an independent protocol on the permissionless Robinhood Chain network. Not affiliated with, endorsed by, or sponsored by Robinhood Markets, Inc. --- # Wire it up in one minute RAILHOOD speaks MCP — the open standard AI agents use to discover and call tools. Tools are free to call; the protocol takes its cut inside the transaction, like any venue. No accounts. No API keys. ## Connect ``` npx -y railhood-privacy ``` Local stdio mode runs the full 10 tools with proof generation in-process. A remote HTTP mode with the 6 read-only tools is served at your facilitator's `/mcp` endpoint; set `RAILHOOD_API_URL` to point at it. No MCP client? Same actions from the command line. If your agent has shell access, it has RAILHOOD. ## Current release | Spec | v1 | | --- | --- | | Asset | ETH | | Standard sizes | 0.001 · 0.01 · 0.1 · 1 · 10 · 100 ETH | | Protocol fee | 0.25% in · 0.25% out | | Exit gas | Paid by the settlement agent — your wallet never appears as the sender | | Custody | None. You sign your own transactions. | ## The tools | API verb | What it does | | --- | --- | | railhood_get_pool_info | Reads the crowd: pool depth per standard size, live. Bigger crowd, stronger privacy — check it before you commit. How to read it: [Privacy quality](https://railhood.gitbook.io/railhood-docs/privacy-quality). | | railhood_shield_eth | Takes a position off-market — deposits ETH into the pool as a sealed note, in a standard size. | | railhood_unshield | Settles back on-market — exits to any address through the gasless settlement agent. | The API verbs keep the crypto-native names; the docs use market language because that's what the actions are. More tools land per the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap). ## Your first pass, end to end - **1 — Read the crowd.** Call `railhood_get_pool_info`. You want depth in your size: a 1 ETH position in a deep 1-ETH pool is a face in a crowd; in a shallow one it's a face in a hallway. - **2 — Go off-market.** Call `railhood_shield_eth` with a standard size. Your funds become a sealed note; the tape records only that *someone* entered at that size. - **3 — Sit.** Time is camouflage. Entering and exiting in the same breath telegraphs the link — treat the pool like a position, not a corridor. More in [Privacy quality](https://railhood.gitbook.io/railhood-docs/privacy-quality). - **4 — Settle out.** Call `railhood_unshield` to any address — a fresh one, an exchange deposit, a counterparty. The settlement agent submits and pays gas; the tape never prints your original wallet. - **5 — Back up the note.** It's a bearer instrument. Lose it, lose the funds. Treat it exactly like a private key, because it is one. ## Why standard sizes Deposits come in a fixed menu on purpose. If everyone entered random amounts, an observer could match a 12.4073-ETH entry to a 12.4073-ETH exit and the privacy is toast. Standard sizes make every entry look identical. TradFi solved the same problem the same way a century ago — it's why shares trade in round lots and cash comes in denominations. Uniformity is what makes a crowd a crowd. --- # Every serious market runs an off-market This isn't a crypto idea. It's the oldest structural fact in finance: shown size gets traded against. Wall Street engineered around it decades ago. Public chains shipped a tape with no off-market — RAILHOOD is that missing layer. ## The number that explains everything *(Figure: FIG 1 · WHERE US EQUITY VOLUME ACTUALLY EXECUTES)* Over 40% of US stock volume never touches a lit exchange. It executes off-exchange — in dark pools, on internalizers, at the desks Wall Street politely calls "the upstairs market." Robinhood's 28 million customers trade inside this structure every day, whether they think about it or not. ## Why the street built it Because showing your order costs money. Post a $200M buy on a lit book and the price runs before you fill — that's market impact, and against fast counterparties it's a tax with no upper bound. So institutions built venues with no pre-trade transparency: work the order quietly, print the trade after. Dark pools aren't shady. They're what rational size does when the alternative is feeding the market a map of your intentions. The pattern is older than electronics. Blocks got crossed upstairs by phone before they got crossed by servers. Bearer bonds, numbered accounts, the specialist's book only the specialist could read — finance has always kept a private layer, because markets stop working when every participant's hand is face-up. ## Even the banks' blockchain is private When Wall Street finally built its own chain, look what it chose. Canton — the settlement network used by Goldman, HSBC, Société Générale, Broadridge, with JPMorgan bringing its deposit token and DTCC tokenizing Treasuries on it — moves trillions in tokenized securities monthly. Its defining feature is need-to-know privacy. Six hundred–plus institutions voted with their infrastructure: no confidentiality, no size. ## Then crypto printed everything Public chains inverted the structure completely: one tape, fully lit, no off-market, history permanent. Radical transparency verifies the ledger — and hands every observer your balance, your flow, your counterparties, and your pattern, free of charge. The bill for that shows up as front-running and sandwiching: over a billion dollars extracted by bots reordering transactions they could see coming. On a transparent chain, everyone trades face-up against players who don't. ## RAILHOOD is the off-market for this chain Robinhood Chain brought equities culture on-chain — 200+ stock tokens, 120+ countries, 24/7. RAILHOOD brings the other half of equities market structure: the place you go when you don't want to print your hand. One line of precision, because words matter here: RAILHOOD is not a dark pool or an ATS — it doesn't match orders or run a book. It's the settlement-privacy layer: the tape stays public, your position doesn't. ## The crosswalk | TradFi | RAILHOOD | | --- | --- | | Off-exchange execution | Off-market balances in the pool | | Round lots | Standard sizes (0.001 – 100 ETH) | | The consolidated tape | The public ledger | | Market impact | Getting sandwiched / front-run | | Settlement agent | The relayer — submits your exit, pays the gas | | Books & records for your auditor | Viewing keys | | Clean settlement confirm | Clean-provenance receipt (attestation) | --- # Your agent is doxxing you People are wiring AI agents to real money — Robinhood's agentic accounts crossed 70,000 in six weeks. Put those agents on a public tape and four things break immediately. ## A public balance is a bounty poster Anyone can read the balance behind your agent, which means anyone can price the attack before running it. May 2026: a prompt injection drained ~$175,000 from a live AI trading wallet — Morse code hidden in a feed, a gifted NFT to widen permissions, funds gone in minutes. It's logged in the OECD AI Incident Monitor. The attacker knew the prize before lifting a finger, because the tape told them. ## Agents print their strategy every block An agent trades the same way every time — that's what makes it an agent. On a public tape, a week of watching its wallet gets an observer most of the way to the algorithm. Then they copy it, front-run it, or trade straight into it. In TradFi terms: your agent is a fund publishing its blotter in real time. ## The tape connects the agent to you The agent's wallet got funded from somewhere. Clustering — the standard chain-analysis toolkit — links the funder to the agent's entire public life in one query. A pseudonym isn't privacy when every action points home. ## And nobody is supervising Robinhood's own disclosure says it flat: it does not control, supervise, monitor, or audit third-party agents, and once your data reaches an AI provider "it leaves Robinhood's security environment." Maximum autonomy, zero oversight. That combination is the attack surface. ## What going off-market changes - **Caps the blast radius.** A hijacked agent can only reach the balance it holds. Your treasury sits off-market, unlinked — not one hop away on a block explorer. - **Kills the bounty.** No visible balance, nothing to price. - **Hides the pattern.** Off-market there's nothing to watch, so there's no strategy to reverse. - **Cuts the trail home.** The public link from agent to funder to you: broken at the pool boundary. Straight up: nothing stops an agent from getting fooled. Going off-market caps what fooling it pays. ## The fleet pattern The end state: one off-market treasury funding a fleet of single-purpose agents, each holding only its working float, each observable by you through its own viewing key, none linkable to each other or to you on the public tape. The treasury and per-agent controls land per the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap); the primitive that makes it possible — the pool — is live now. --- # Inside the pool Four moves in the life of off-market value: Screen, Enter, Hold, Settle. Enter and Hold are live; Screen and full Settle receipts ship per the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap). No math degree required — but the mechanics are all here. *(Figure: FIG 2 · THE LIFECYCLE OF OFF-MARKET VALUE)* ## Screen — the door Entries get checked against public sanctions and illicit-flow data before they can join the pool. Dirty funds bounce at the door. That's how the crowd stays clean without anyone surveilling the inside — the venue checks IDs at entry instead of bugging the room. ## Enter — value becomes a sealed note Your deposit becomes a **sealed note**: "this much value, owned by this key," encrypted. Only your key can spend it. The chain stores a fingerprint of the note — a [commitment](https://railhood.gitbook.io/railhood-docs/glossary) — in a shared tree next to everyone else's fingerprints. Nobody can read yours. Not us, not anyone. *(Figure: FIG 3 · A TREE OF SEALED NOTES — NOT A POT OF MIXED COINS)* ### Why the tree matters The tree is a compact way to prove membership: any single note can prove "I'm in here" against the root without pointing to its own leaf. Every entry rebuilds the root, so the whole pool vouches for every note while learning nothing about any of them. That's the trick that makes a crowd cryptographic. ### Standard sizes, again Entries happen in the six standard sizes (0.001 – 100 ETH). Inside the tree, a 1-ETH note is indistinguishable from every other 1-ETH note — which is precisely the point. Uniform units are what let one participant vanish into many; it's the round-lot principle doing privacy work. ## Hold — spending without pointing To spend, your device builds a [zero-knowledge proof](https://railhood.gitbook.io/railhood-docs/glossary): a real note exists in the tree, it's never been spent, and you own it — proven without revealing *which* note. Spending also publishes a [nullifier](https://railhood.gitbook.io/railhood-docs/glossary), a one-way stamp that burns the note so it can't be spent twice. The tape learns "a valid note was spent." It never learns which. Your secret never leaves your device. ## Settle — back on the tape, clean Exit goes through the settlement agent (covered fully in [Execution & settlement](https://railhood.gitbook.io/railhood-docs/execution-and-settlement)) to any address you choose. On the roadmap, exits carry a zero-knowledge receipt — proof the funds trace to screened, clean entries — so counterparties and venues get their assurance while the public still gets nothing. ## "So it's a mixer?" No. A mixer throws everyone's coins in a pot and deals them back out. RAILHOOD never pools ownership — your note is yours the whole way through, sealed and individually owned. And the architecture ships with a front door and an exit receipt, which is the opposite of a laundromat. | | Mixer | RAILHOOD | | --- | --- | --- | | Ownership | Pools everyone's coins | Each note sealed, individually owned | | Payout | Deals you coins from the pot | You spend your own value | | History | Erased | Provable on demand — viewing keys, receipts | | Entry | Anything in | Screened at the door | --- # Execution & settlement Getting off-market is easy. Getting back on-market without undoing the whole exercise is where the engineering lives. This page is the exit path, the fees, and the timing. ## The settlement agent Here's the trap naive designs fall into: you exit to a fresh wallet, but that wallet has to pay gas — and funding it links it straight back to you. One transaction and the privacy you bought is gone. RAILHOOD routes exits through a **settlement agent** (the relayer). It takes your proof, submits the exit transaction, and pays the gas itself, deducting a small cut from the amount. Your wallet never appears on the tape as the sender. Not once. The receiving address starts life with no visible past. ### What the agent can and can't do - It **can** submit your exit and collect its fee — that's the job. - It **can't** steal, redirect, or alter your exit: the zero-knowledge proof pins the destination and amount, so a tampered submission simply fails on-chain. - It **can't** see inside your history — it handles a proof, not your books. ## The full bill | Line item | Cost | | --- | --- | | Entry (protocol fee) | 0.25% | | Exit (protocol fee) | 0.25% | | Settlement agent | Small cut of the exit, in exchange for paying your gas | | MCP tool calls | Free | That's everything. For scale: analysts peg the invisible markup from getting sandwiched on lit venues at a meaningful slice of every sizable trade — and that one repeats every time you show your hand. The off-market fee is paid once per round trip, on purpose, for a defined service. ## Timing and finality Entries and exits confirm at Robinhood Chain block speed — this is on-chain settlement, not a batch window. The strategic timing question isn't the chain's, it's yours: exiting seconds after entering telegraphs the link between the two prints. Treat time in the pool as part of the trade. The full playbook is in [Privacy quality](https://railhood.gitbook.io/railhood-docs/privacy-quality). ## Settlement receipts The roadmap's exit receipt is a zero-knowledge attestation: portable proof that your funds trace to screened, clean entries, produced without exposing a line of your history. Hand it to an exchange, a counterparty, an auditor — they verify the math, not your life. It's the clearing confirm of the off-market world: settlement finality plus provenance, minus the disclosure. ## Failure modes, plainly - **Agent offline?** Your funds don't move without you — the note stays yours; exit resumes when a settlement agent does. - **Chain congestion?** Exits queue like any transaction. Nothing about the wait leaks anything about you. - **Lost note?** Bearer instrument rules: no note, no funds, no recovery desk. Back it up like a private key, because it is one. --- # Privacy quality Privacy isn't a switch, it's a crowd. This page is how to measure the crowd, how to stand in it properly, and what weakens it. Most protocols won't write this page. That's exactly why we do — a user who understands the crowd makes it stronger for everyone. ## The crowd is the product When you exit the pool, an observer knows one thing: some entry became this exit. The question is how many entries it could plausibly have been. That count is the **anonymity set** — your crowd. Ten notes in your size: you're one of ten. Ten thousand: good luck. Every additional participant makes every existing participant harder to trace. Depth is a shared asset, which is why the whole protocol is tuned to grow it. *(Figure: FIG 4 · SAME NOTE, DIFFERENT CROWD, DIFFERENT PRIVACY)* ## Read the crowd before you join it `railhood_get_pool_info` publishes live depth per standard size. We put the number on the table so you can size the crowd before committing a wei — and so agents can make the same judgment programmatically. An agent that checks depth before entering is a well-built agent; the tool exists so that's one call. ## Standing in the crowd properly - **Give it time.** Enter-and-exit in the same block is a signed confession — the two prints bracket you. Let other entries and exits land between yours. Time between prints is camouflage you get for free. - **Don't mirror yourself.** Exiting the exact pattern you entered (three 10s in, three 10s out, same order, same hour) rebuilds the link you paid to break. Vary size combinations and timing. - **Exit to fresh ground.** Settling out to a wallet already linked to you hands the observer the answer. Fresh address, or straight to a deposit address that was getting your funds anyway. - **Mind the outside world.** The pool hides on-chain links. It can't hide you tweeting "just moved 100 ETH" at exit time. The tape isn't the only tape. ## What strengthens the crowd Depth (more notes per size), churn (steady unrelated entries and exits), and uniformity (standard sizes doing their job). The roadmap is sequenced around exactly this — every feature that grows or thickens the crowd ships before features that don't. Machine flow helps too: agents entering and exiting around the clock are crowd, and they don't sleep. ## The honest ceiling No system makes you untraceable against every adversary forever, and anyone who claims otherwise is selling something. What a deep pool plus good habits buys you: no public balance, no public counterparties, no public pattern, and an exit that could be any of thousands of entries. That's the product. Check the number, stand in the crowd properly, and it's a very strong product. --- # Books and records, on your terms Off-market doesn't mean off the books. Every regulated desk keeps records its auditor can inspect — the street never confused confidentiality with lawlessness. Viewing keys are that discipline, rebuilt in cryptography. ## Two keys, two powers Your spending key moves money. Your **viewing key** only reveals. Hand a viewing key to your accountant: they read your full off-market history — every entry, every exit, every amount — and they cannot move a wei. Grant it to exactly who needs it: an auditor, a tax authority, a fund's compliance officer, a co-founder. The public never enters the equation; they never had access to revoke. ## Who sees what Tap a column. See the world from that seat. | Data | You | Your auditor | The public | | --- | --- | --- | --- | | Your off-market balance | ✓ | ✓ | ✕ | | Amounts you move | ✓ | ✓ | ✕ | | Who you transact with | ✓ | ✓ | ✕ | | Your full history | ✓ | ✓ | ✕ | | Proof funds are clean | ✓ | ✓ | ✓ | | That the pool exists & its depth | ✓ | ✓ | ✓ | *(✓ = visible to that party · ✕ = hidden. Interactive version on the docs page.)* ## Scope is the feature Disclosure that can't be scoped isn't disclosure, it's surrender. The design principle: reveal to a chosen party, for a chosen purpose, and nothing propagates to anyone else. Your auditor seeing your books doesn't put your books on the tape — that's the entire difference between reporting and broadcasting, and it's the difference public chains forgot. ## Per-agent keys and the fleet The fleet pattern from [Agents on glass](https://railhood.gitbook.io/railhood-docs/agents-on-glass) completes here: one off-market treasury, a viewing key per agent. You watch every agent's activity in full. Agents can't see each other. The world sees none of it. Full observability for the owner, zero for everyone else — which is what "supervised autonomy" should have meant all along. Viewing keys and per-agent scoping ship per the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap). --- # Compliance without surveillance Keep illicit funds out at the door. Give lawful users real privacy in between. Make clean provenance provable on the way out. That's the architecture — and policy is moving toward it, on the record. ## The receipts March 2026: the U.S. Treasury tells Congress, in a report under the GENIUS Act, that lawful users may use privacy tools "to protect sensitive information on personal wealth, business payments or charitable donations from appearing on a public blockchain." Financial privacy, on the federal record. They wrote it about mixers; the point is bigger than mixers. The 2023 U.S. national strategy made privacy-enhancing technologies — the exact family RAILHOOD's zero-knowledge design belongs to — a research and adoption priority. EU data-protection law runs on data minimisation: expose only what's necessary. Publishing every citizen's full financial history by default fails that test. Selective disclosure passes it. ## Where RAILHOOD maps | Framework | What it wants | RAILHOOD | | --- | --- | --- | | NIST Privacy Framework | Control data exposure, enable disclosure choices, communicate clearly. | Off-market by default; viewing keys as user-directed disclosure; these docs. | | PETs strategy | Get utility from data without exposing it. | Zero-knowledge proofs: verify validity and provenance, reveal nothing else. | | Sanctions compliance | Don't transact with sanctioned parties. | Screening at the door; clean-provenance receipts on exit. | | Auditability | Regulated entities must evidence their activity. | Viewing keys; exportable settlement receipts. | One precision worth having: NIST publishes standards and frameworks — it doesn't certify DeFi protocols, for anyone. "Maps to the frameworks" is the strongest claim that exists, and the table above is RAILHOOD making it. ## The market-structure argument Regulators have overseen confidential execution for decades — 40%+ of equity volume runs off-exchange inside a fully regulated system, because the rules distinguish *confidentiality from the market* from *concealment from the law*. Dark pools report to regulators; they just don't broadcast to competitors. RAILHOOD is built on the same distinction: private against the crowd, provable to the parties who have a right to ask. That's not a loophole; it's how mature markets already work. ## The direction of travel Yes, privacy tech has had its court battles — sanctions fights, developer-liability debates, the lot. The law is in motion. But the destination is visible: not privacy *or* compliance, both. Viewing keys give honest users accountability on their own terms. Association sets — proving your funds aren't tied to known illicit sources without giving up privacy — are the research frontier we build toward. Tools that fight compliance get banned; surveillance rails get abandoned. RAILHOOD holds the middle, which is where the volume ends up. Context, not legal advice — rules differ by jurisdiction. See [Disclaimers](https://railhood.gitbook.io/railhood-docs/disclaimers). --- # Tokenomics 75% to the community at fair launch. No presale, no VC unlock hanging over your head. The other 25% — team, foundation, exchange reserve — vests on-chain where anyone can watch it. *(Figure: FIG 5 · SUPPLY ALLOCATION)* ## Unlock schedule *(Figure: FIG 6 · UNLOCKED SUPPLY OVER 24 MONTHS)* ## The schedule, precisely | Allocation | Share | Cliff | Vesting | Fully unlocked | | --- | --- | --- | --- | --- | | Fair launch | 75% | — | Unlocked at TGE | TGE | | Team | 10% | 12 months | Linear over 12 months | Month 24 | | Foundation | 10% | 6 months | Linear over 12 months | Month 18 | | Exchange reserve | 5% | — | Unlocked at TGE · held on contract until listings need it | TGE | ## Why fair launch The pool gets stronger with every participant — the crowd *is* the product, so the crowd gets the supply. The team waits a full year before seeing a single token, then drips for a year. Foundation waits six months, drips for twelve. All enforced by contract, all watchable on-chain, exactly like the rest of the protocol: don't trust the desk, read the tape. Final parameters publish at TGE; see [Disclaimers](https://railhood.gitbook.io/railhood-docs/disclaimers). --- # Roadmap One rule sets the order: crowd depth first. Every participant makes every other participant harder to trace, so anything that grows the pool ships before anything that doesn't. ## Now (LIVE) - The ETH pool on Robinhood Chain — off-market entries and exits in six standard sizes (0.001 – 100 ETH), 0.25% fee each side. - MCP server + command-line tool for agents: `railhood-privacy` (10 tools: query, notes, `railhood_shield_eth`, `railhood_unshield`). - Gasless exits through the settlement agent — your wallet never appears as the sender. ## Next - Stablecoin pools and in-pool private transfers — pay counterparties without surfacing on the tape at all. - Screening at the door — sanctions checks on every entry. - Settlement receipts — zero-knowledge proof of clean provenance on exit. - Viewing keys and selective disclosure, including off-market balance reads and fee quoting for agents. - Agent SDK & policy engine — per-agent spend caps, so an injected agent can't spend past its allowance. - x402 pay-per-call extras: priority settlement lane, receipt exports. ## Later - Off-market treasuries — fund a fleet of agents from one pool balance, viewing key per agent. - Agent trust infrastructure on Robinhood Chain (ERC-8004 registries). - Private cross-chain settlement. - Post-quantum migration as NIST-standardized components mature. Live means live. Next means being built. Later means designed, not scheduled. --- # FAQ ## Is it a mixer? No. Mixers pool coins and deal them back out. RAILHOOD seals each entry as a note only you can spend — ownership never pools, entries get screened, history stays provable on demand. Full mechanics in [Inside the pool](https://railhood.gitbook.io/railhood-docs/inside-the-pool). ## Is it a dark pool? Also no — and the distinction matters. Dark pools are regulated trading venues that match orders. RAILHOOD doesn't match anything; it's the settlement-privacy layer. Same instinct as the off-exchange world — don't print your hand — different machine entirely. ## Affiliated with Robinhood? No. Independent protocol on the permissionless Robinhood Chain network. Not affiliated with, endorsed by, or sponsored by Robinhood Markets, Inc. ## What can I take off-market? ETH, in six standard sizes from 0.001 to 100. Stablecoins are next on the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap). ## What's the all-in cost? 0.25% in, 0.25% out, plus a small settlement-agent cut on exit in exchange for it paying your gas. MCP tools are free. That's the whole bill. ## Is it audited? Audit details will be published here when available. ## How private am I, really? As private as the crowd you're standing in. Run `railhood_get_pool_info`, read the depth in your size, and stand in the crowd properly — the playbook is [Privacy quality](https://railhood.gitbook.io/railhood-docs/privacy-quality). We publish the number precisely so you can judge. ## What if I lose my note? Bearer instrument rules: lose it, lose the funds — and anyone who can read it can spend it. No recovery desk; that's what non-custodial means. Back it up like a private key, because it is one. ## What if my agent gets prompt-injected? Nothing stops the trick. Going off-market caps what the trick pays: the agent only reaches the float it holds, and the public trail from agent to treasury to you doesn't exist. Per-agent spend caps on the [Roadmap](https://railhood.gitbook.io/railhood-docs/roadmap) tighten it further. ## Do regulators hate this? Less than the timeline thinks. The U.S. Treasury told Congress in 2026 that lawful users have legitimate privacy needs on public blockchains, PETs are a national research priority, and regulators have overseen confidential execution in equities for decades. Receipts on [Standards & policy](https://railhood.gitbook.io/railhood-docs/standards-and-policy). ## Why would an institution touch this? Same reason they built the upstairs market: shown size gets traded against. The version they need — confidential against the crowd, provable to auditors — is exactly the viewing-keys-plus-receipts architecture. When the banks built their own chain, they built it private; the demand isn't hypothetical. --- # Glossary Every term in these docs — the market words and the cryptography words, one or two sentences each. ## Market terms | Term | Meaning | | --- | --- | | The tape | The public record of transactions. In TradFi, the consolidated tape; here, the public ledger. Same word, same job. | | Off-market | Held or moved outside public view. In equities, 40%+ of volume executes off-exchange; RAILHOOD is the on-chain equivalent for balances and settlement. | | Market impact | The price moving against you because your order was visible. The reason off-market exists. | | Round lot / standard size | A standard trade unit. Uniform units make participants interchangeable — the foundation of crowd privacy. | | Upstairs market | Wall Street's historical name for trading negotiated away from the exchange floor. The instinct RAILHOOD inherits. | | Settlement agent | The relayer: submits your exit and pays the gas so your wallet never appears on the tape as the sender. | | Settlement receipt | The exit attestation — portable zero-knowledge proof your funds trace to clean, screened entries. | | Front-running / sandwiching | Bots trading around your visible order to extract value. The on-chain version of market impact, industrialized. | | Fair launch | Everyone gets access at the same time on the same terms. No presale. | | TGE | Token Generation Event — the moment the token goes live. | | Cliff | A period where an allocation is fully locked. Nothing moves until it ends. | | Linear vesting | After the cliff, tokens unlock in equal slices over time. A slope, not a dump. | ## Cryptography terms | Term | Meaning | | --- | --- | | The pool | A shared vault of sealed, encrypted notes — the off-market layer itself. The cryptography literature calls this design a shielded pool. | | Note | An encrypted record of value: "this much, owned by this key." A bearer instrument — a sealed envelope only your key opens. | | Commitment | The on-chain fingerprint of a note. Proves it exists without showing what's inside. | | Nullifier | The one-way stamp published when a note is spent. Kills double-spending without revealing which note died. | | Zero-knowledge proof | Prove a statement is true ("I own an unspent note") while revealing nothing else ("which one"). | | Anonymity set | The crowd your note hides in. Bigger crowd, stronger privacy. Published live via `railhood_get_pool_info`. | | Viewing key | A read-only key. Holders see your activity; they can never move your funds. Books and records, on your terms. | | Clustering | Chain analysis that links addresses to each other — and usually to a person. | | MCP | Model Context Protocol — the open standard AI agents use to discover and call tools. | | x402 | An open standard letting software pay for an API call in stablecoins, instantly, no account. | --- # Disclaimers **Independence.** RAILHOOD is an independent protocol on the permissionless Robinhood Chain network. It is not affiliated with, endorsed by, or sponsored by Robinhood Markets, Inc. "Robinhood" is a trademark of its respective owner. **Not a regulated venue.** RAILHOOD is not a dark pool, alternative trading system, exchange, broker-dealer, or custodian, and does not match orders or execute trades. References to traditional market structure describe analogous concepts, not a regulatory status. **Not advice.** Nothing in this documentation is investment, tax, or legal advice. Digital assets and privacy technology carry significant risk, including total loss of funds. **Forward-looking statements.** Roadmap items and token details describe current intentions and may change. Final token parameters publish at TGE. **No privacy guarantee.** Privacy quality depends on pool depth and correct use. No system guarantees anonymity. **Use responsibly.** RAILHOOD supports legitimate financial privacy with accountability. Users are responsible for complying with the laws that apply to them.