Robinhood Chain / EIP-7702
Sign it with a promise.
Pango wraps your transaction in a promise about what you must own when it ends. If the promise breaks, the chain refuses the whole thing, as if you had never sent it. No scanner, no guess: the outcome is part of what you sign.
Side by side
The same transaction, twice.
Left: a plain transaction. Right: the same one with a promise. Both run the rules of the real contract.
The gap
What it says. What it does.
A wallet shows you what a transaction says it will do. The chain only cares what it did. Everything you lose in a single click lives in that gap.
The claim that costs ten times more
"Pay 0.05, receive 2,000." It takes 0.5 and sends nothing.
The buy that pays someone else
The ETH leaves. The tokens go to a stranger. The screen said "success".
The approval you did not read
A swap plus "approve everything, forever". It is still open next month.
The idea
Check the end, not the promise on screen.
You send your calls together with a list of checks. Pango runs the calls, reads your balances and allowances, and compares them with what you said you would accept.
- Your wallet borrows Pango once (EIP-7702).
- You send the batch and the promise to your own address.
- One check fails, the whole transaction reverts.
The lab
Try to get past it.
Pick a trap, make the site behave badly or honestly, edit the promise, turn the guard off. Every verdict comes from the same rules as the contract, checked against the real one.
Even when you forget
Four rules you do not have to write.
What you did not name cannot go down
ETH and every token on your watchlist must end at least where they started, unless a check says otherwise. A forgotten token cannot be swept in silence.
Approvals need a cap
An approval is refused unless the same batch says how much can still be spent at the end. "Approve 100, use 100, leave 0" passes. "Unlimited" does not.
No permit signatures inside
Permits grant spending from a signature. They are blocked inside a guarded batch.
Nothing reaches back in
A call that targets your own account is refused, and only you can call the guard. No owner, no fee, no upgrade.
Proof, not promises
Run on the real chain.
Nothing is deployed and no transaction is sent. The script signs a real EIP-7702 authorization with a fresh wallet and asks Robinhood Chain what would happen: one good buy on a live Pons curve, then nine traps. Each trap is refused by the chain itself.
Versus the usual ways
Why not a warning screen?
| Warning screens and simulations | Slippage setting | Pango | |
|---|---|---|---|
| Method | predicts, then hopes | one number on one swap | checks the final state |
| Tokens sent to another wallet | often missed | not covered | refused |
| Hidden approval | shown, easy to skip | not covered | refused unless capped |
| Token that blocks sales | guess from history | not covered | refused by a test sale |
| Can a site still fool it? | yes, it is a prediction | yes | not past your numbers |
| Where your funds are | in your wallet | in your wallet | in your wallet |
One minute
See it first.
The idea, the traps, and the chain saying no.
Read this part
What it is not.
Not audited, not deployed by us yet. The contract is written, tested and run against the real chain. Start small.
Only as strong as your promise. Pango enforces the numbers you write and guards what you name or watch. It does not guess what a good number is.
Not a hiding place. It does not hide your transaction or reorder anyone. It caps the damage.