Skip to main content

NVDA Printer: rules, roles and contracts

The quick start says what to do. This page says what the contracts enforce, what is only our policy, and who could do what with which key. Where a number is a constant it is stated; where the owner can change it, the bound is stated and the live value is on the vault page.

What the vault is​

One BrokerEpochVault holds NVDA tokens and issues non-transferable shares. Each week it sells one covered call on all of its NVDA to a whitelisted buyer, through the Vault's own BrokerVaultQuotedDesk, against a quote signed by a quote signer and approved by the buyer. The buyer's premium moves into the Vault in the same transaction. At expiry the week settles at a price proven on chain, and the premium is distributed by shares.

ContractWhat it decides
BrokerEpochVaultdeposits, shares, the weekly phases, claims, the queue, pause
BrokerVaultQuotedDeskthe signed-quote sale, the premium escrow, the fee, settlement and the 1-hour void
BrokerVaultOracleNVDA's price at lock and at expiry: Chainlink, or an attested official close inside a band
BrokerVaultDeskOperatorthe Vault's operator: forwards the signed weekly sale to the Desk, and nothing else
BrokerVaultSchedulereach week's times, derived from the on-chain trading calendar; anyone can call it
BrokerVaultZapUSDG deposits and opt-in reinvestment, swapped against the pool at an oracle-bounded price
BrokerVaultExitPoolbuys locked shares mid-week against a signed quote
HedgeStakingGatethe HEDGE stake that allows deposits

None of them is a proxy, none can be upgraded, and the Vault's ownership cannot be renounced or bypassed.

Roles​

RoleHolderCanCannot
Ownera 2-of-3 Safethe parameters below, inside their bounds; pause; void a sale within 1 hmove depositors' NVDA, shares or premium
OperatorBrokerVaultDeskOperator, a contract with no keysubmit the signed weekly saleanything else; it has no other function
KeeperHedgehood's serverpay gas: freeze, submit the sale through the operator, run the queue, settleanything a stranger could not do; every step it takes is open to anyone
Quote signerHedgehood keysign the weekly sale termslock anything by itself
Option buyerHedgehood's accountapprove a quote and pay the premiumpay less than the Desk floor
Close attesterHedgehood keysign the official closemove the price more than 0.75% from Chainlink
Exit signerHedgehood keysign mid-week exit pricespay out more than the pool's cap and inventory
Reinvest keeperHedgehood's keeperreinvest rewards for accounts that opted insend rewards anywhere but into that account's deposit

The buyer is Hedgehood. The premium is the listed option's bid and is checked against an on-chain floor, but the counterparty to every call is us, and that is a conflict of interest stated here rather than hidden.

The week, precisely​

Times are New York, from the trading calendar; holidays skip, and early closes move expiry earlier.

StepRule
Schedulethe scheduler publishes each week at least 12 h before its cutoff; anyone can call it
CutoffMonday 09:30; deposits after it belong to the next week
Freezeat the cutoff the NVDA in the Vault and the share count are snapshotted; anyone can trigger it
Salebetween 09:35 and 15:30 (the trade window); if nothing is sold by 15:30 the week is skipped and nothing changes
ExpiryFriday 15:59, at least 12 h and at most 9 days after the window
Settlementfrom about 16:10, see below; permissionless

Depositing​

  • The gate. An account may deposit while it stakes at least the threshold (1,000,000 HEDGE) in the gate. While it has principal in the Vault, min(stake, threshold) stays locked; only the excess can be unstaked. Unstaking is a request followed by a 7-day cooldown. The owner can change the threshold or block new deposits; it cannot touch a stake.
  • USDG. The Zap swaps USDG to NVDA in the pool. The minimum NVDA out must be at least the oracle price less 1%, enforced on chain, so a deposit never fills worse than that.
  • The queue. Deposits wait as a cohort for their week. While deposits are open, the keeper turns them into shares at most hourly, at the current NVDA per share; a deposit made during a locked week waits until that week settles. Until it becomes shares, or its own week's cutoff passes, it can be cancelled for the same NVDA back.
  • The cap. Total NVDA is capped by the owner; the page shows what is left.

The sale​

The contracts enforce:

RuleValue
Strike strictly out of the money by at leastminOtmBps: owner-set, never below 0.5%; currently 1%
Strike at most this far above the pricethe week's deviation, 6.5%; contract maximum 10%
Premium at leastminPremiumBps of notional: owner-set, never below 0.1%; currently 0.2%
Premium at most10% of notional
Coveredall of the Vault's NVDA at the freeze
Quotesigned by the quote signer, approved by the buyer, at most 120 s old, for this week's expiry
Price usedthe oracle, which refuses to answer while the market is closed or the feed is stale

Our policy, which the contracts do not enforce: the listed Friday NVDA call nearest delta 0.15 inside that band, priced at its OPRA bid; if that strike's premium is below the floor plus 0.05%, the nearest-delta strike that clears it. That walks toward the money in a quiet week, never outside the band.

Fee. Hedgehood takes feeBps of the premium, currently 20%, at most 30%. After the first sale an increase applies only to sales at least 7 days later, so it can never land between a cutoff and that week's sale; a decrease applies at once. A sold week keeps the fee it was sold with.

Void. For one hour after a sale the owner can void it with a stated reason. The buyer gets 90% of the premium back and the other 10% stays with depositors; the NVDA is untouched. No mid-week exit is possible in that hour.

Settlement​

The price. If a close attester was set when the week was sold, the week settles at NVDA's official close, signed by that key and accepted only within 0.75% of the last Chainlink round before expiry, from 10 minutes after expiry. Our signer publishes nothing unless two independent providers agree on the close to the cent, and the evidence is public. Otherwise, and as the fallback from 48 h after expiry, the price is the last Chainlink round before expiry, proven by the round after it. Which source a week uses is fixed at its sale; changing the attester later cannot switch it.

The payout, with P the settlement price, K the strike and N the NVDA covered:

  • P ≤ K: depositors keep all N NVDA and the premium net of the fee.
  • P > K: the buyer receives N × (P − K) / P NVDA, the value above the strike. Depositors keep the rest and the premium net of the fee.
  • No price within 7 days of expiry: the week settles as P ≤ K.

Every step after expiry is permissionless: anyone can finalize the price and settle, so a missing keeper delays a week but cannot hold it.

Getting out​

Contract rule
Cancel a deposituntil it becomes shares, or its week's cutoff
Withdraw at expiryrequestRedeem reserves shares; they are paid in NVDA at the next queue run while open, or at settlement while locked; cancellable until then; no fee
Exit nowthe exit pool buys shares from 1 h after the sale to 1 h before expiry, at a signed quote valid 25 s and usable once, within the pool's cap and inventory

The exit price takes over your part of the call at the market's cost of buying it back:

value per share = uncovered × S_bid + covered × (S_bid − C_ask) + (premium − fee) / shares at the sale
payout = shares × value per share × (1 − exit fee) in USDG, or ÷ S_ask in NVDA

S is NVDA's SIP quote, C_ask the OPRA ask of the week's own call. The exit fee is 1% and is shown in every quote.

Reinvesting​

An account that opts in has its claimable premium swapped to NVDA by the keeper after a week settles and before the next cutoff, while the market is open, at no worse than the oracle price less 1%, and queued as its deposit for the next week. The keeper can only do this for accounts that opted in, and only into their own deposit. Turning it off is immediate.

What the owner can change​

Deposit cap · HEDGE threshold and gate · the operator · the exit pool list · pause · the quote signer, the buyer and its approval key · the fee (bounded and delayed) · the premium and out-of-the-money floors (bounded) · the close attester (bounded at 0.75%, fixed per week at the sale) · the reinvest keeper · the exit pool's own signer and its own inventory.

Pause stops new deposits, new sales and exit-pool purchases. Settlement, claims, cancellations and withdrawals continue, and a queue run while paused refunds pending deposits instead of activating them.

None of these moves a depositor's NVDA, shares or premium.

Why the operator is a contract​

The Vault still contains the path it was first built for, in which the operator sells the call at a broker and reports the result: a locked week whose loss the operator states, up to the call's intrinsic value at the oracle price plus 0.5% of notional, taken from depositors' NVDA. A Desk week can never settle from a reported figure, but whoever is the operator could open such a week instead.

So the operator is not a key. It is BrokerVaultDeskOperator: a contract without an owner, storage or funds whose only function forwards a signed sale to the Desk. The broker path checks msg.sender == operator, and nothing can make that contract call it. The keeper submits the sale through it, and anyone else could too, because the quote signer and the buyer have already signed and every bound still applies.

The one way back is an owner decision: the 2-of-3 Safe naming a key as operator again, a transaction anyone can see on chain. We will not do it, and it is listed here so that you can check.

What can go wrong​

  • NVDA falls. The vault is long NVDA. The premium is a cushion, not a hedge.
  • NVDA rallies. Everything above the strike is sold every week.
  • A wrong price. The settlement price depends on Chainlink and, for attested weeks, on our signer inside a 0.75% band. A stale feed stops sales and deposits rather than pricing them.
  • The token is paused. NVDA tokens can be paused by their issuer; while they are, nothing moves.
  • Keys. The quote, buyer and attester keys are operational keys, kept out of plain files on the server. Misused, they are bounded by the sale floors and the 0.75% band above; lost, they delay a week, which anyone can then settle. The keeper's own key only pays gas.
  • The exit pool is empty. Exit now depends on its inventory; withdraw at expiry does not.
  • No third-party audit. The contracts have been reviewed internally and are tested, including against a fork of the live chain. That is not an audit.

Contracts​

Robinhood Chain (4663). Deployed from edd7f09 at block 84792706; the deployed code was checked against a fresh build of that commit.

Vault contractsAddress
Vault0xe35B7D7bf1212b89478ddAba2946ADEd59BEC0a9
Desk0x6d17d089663e50823e29ad34D6e4EB2448BE8B0b
Desk operator (the Vault operator)0xCfC05f30773c761F122B92B9b5fBDb02BEA5F232
Oracle0x5A6bf55578E85b806910f0B6Ee8e683786fD62C6
Zap0x5AfdcE7484031e579Ff44c6499AfB6dd76819245
Exit pool0x8ac43fcc039612D40148f74f64835c23130029AF
HEDGE gate0x48ae41142bb0Ddd18DC49BD659b55207FAcE64d8
Scheduler0x399D6c2c529531b9071B02522bd0Fbc90CcDb3Cb
Policy0x1bc4694aEdB4d844946d1B9e4021001cc83cb544
Settlement0xa9D051749bBa8A49d00fCdc0e54476c1f6df7Ec4

They build on:

Address
NVDA token0xd0601CE157Db5bdC3162BbaC2a2C8aF5320D9EEC
USDG0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168
NVDA / USD Chainlink feed0x379EC4f7C378F34a1B47E4F3cbeBCbAC3E8E9F15
Trading calendar0xFcD3129E596B3C4577fb4129D61A90db52306461
NVDA / USDG pool0xd4EB21209C4D6093f80B5b84f5C45cc093EA14a3
HEDGE0x3f9108a3bECa998C14c6dda822a7e8EaEb88E20D
Owner Safe (2 of 3)0xB5C9e27F50599687eD141ABe337414B79061489b
Option buyer0xFD3C304e2f51542D2c7CD038f43fba4b28301b8A

Robinhood Chain testnet (46630). The same source, with test tokens and a test price feed:

Address
Vault0xB60Ca23C68747eFeDF63c3429081ED418add64aC
Desk0xa0AE14695C29f7Ec59D79E456d407D254333374D
Oracle0xaF7B8E25ff5f6b4C90740B5B06c16f4Ef8f4d24b
Zap0xC5939A6FADADc36b091F39546573609011BF028F
Exit pool0x4b26073384fe4317e85cB587EE646aD1c15E029A
HEDGE gate0x7473f13f1e20FC59eeed224D1EbEC1548bdeE76A
Scheduler0x8F44D16D898f16933E1A17f1743ab0cb1FbBF36a

Source: github.com/0xHedgeHood/hedgehood-vaults. Live parameters and this week's times are on the vault page.