NVDA Printer: rules, roles and contracts
The quick start says what to do. This page says what the contracts enforce, what is only our policy, and who could do what with which key. Where a number is a constant it is stated; where the owner can change it, the bound is stated and the live value is on the vault page.
What the vault is
One BrokerEpochVault holds NVDA tokens and issues non-transferable shares. Each week it sells one covered call on
all of its NVDA to a whitelisted buyer, through the Vault's own BrokerVaultQuotedDesk, against a quote signed by
a quote signer and approved by the buyer. The buyer's premium moves into the Vault in the same transaction. At
expiry the week settles at a price proven on chain, and the premium is distributed by shares.
| Contract | What it decides |
|---|---|
BrokerEpochVault | deposits, shares, the weekly phases, claims, the queue, pause |
BrokerVaultQuotedDesk | the signed-quote sale, the premium escrow, the fee, settlement and the 1-hour void |
BrokerVaultOracle | NVDA's price at lock and at expiry: Chainlink, or an attested official close inside a band |
BrokerVaultDeskOperator | the Vault's operator: forwards the signed weekly sale to the Desk, and nothing else |
BrokerVaultScheduler | each week's times, derived from the on-chain trading calendar; anyone can call it |
BrokerVaultZap | USDG deposits and opt-in reinvestment, swapped against the pool at an oracle-bounded price |
BrokerVaultExitPool | buys locked shares mid-week against a signed quote |
HedgeStakingGate | the HEDGE stake that allows deposits |
None of them is a proxy, none can be upgraded, and the Vault's ownership cannot be renounced or bypassed.
Roles
| Role | Holder | Can | Cannot |
|---|---|---|---|
| Owner | a 2-of-3 Safe | the parameters below, inside their bounds; pause; void a sale within 1 h | move depositors' NVDA, shares or premium |
| Operator | BrokerVaultDeskOperator, a contract with no key | submit the signed weekly sale | anything else; it has no other function |
| Keeper | Hedgehood's server | pay gas: freeze, submit the sale through the operator, run the queue, settle | anything a stranger could not do; every step it takes is open to anyone |
| Quote signer | Hedgehood key | sign the weekly sale terms | lock anything by itself |
| Option buyer | Hedgehood's account | approve a quote and pay the premium | pay less than the Desk floor |
| Close attester | Hedgehood key | sign the official close | move the price more than 0.75% from Chainlink |
| Exit signer | Hedgehood key | sign mid-week exit prices | pay out more than the pool's cap and inventory |
| Reinvest keeper | Hedgehood's keeper | reinvest rewards for accounts that opted in | send rewards anywhere but into that account's deposit |
The buyer is Hedgehood. The premium is the listed option's bid and is checked against an on-chain floor, but the counterparty to every call is us, and that is a conflict of interest stated here rather than hidden.
The week, precisely
Times are New York, from the trading calendar; holidays skip, and early closes move expiry earlier.
| Step | Rule |
|---|---|
| Schedule | the scheduler publishes each week at least 12 h before its cutoff; anyone can call it |
| Cutoff | Monday 09:30; deposits after it belong to the next week |
| Freeze | at the cutoff the NVDA in the Vault and the share count are snapshotted; anyone can trigger it |
| Sale | between 09:35 and 15:30 (the trade window); if nothing is sold by 15:30 the week is skipped and nothing changes |
| Expiry | Friday 15:59, at least 12 h and at most 9 days after the window |
| Settlement | from about 16:10, see below; permissionless |
Depositing
- The gate. An account may deposit while it stakes at least the threshold (1,000,000 HEDGE) in the gate. While it has principal in the Vault, min(stake, threshold) stays locked; only the excess can be unstaked. Unstaking is a request followed by a 7-day cooldown. The owner can change the threshold or block new deposits; it cannot touch a stake.
- USDG. The Zap swaps USDG to NVDA in the pool. The minimum NVDA out must be at least the oracle price less 1%, enforced on chain, so a deposit never fills worse than that.
- The queue. Deposits wait as a cohort for their week. While deposits are open, the keeper turns them into shares at most hourly, at the current NVDA per share; a deposit made during a locked week waits until that week settles. Until it becomes shares, or its own week's cutoff passes, it can be cancelled for the same NVDA back.
- The cap. Total NVDA is capped by the owner; the page shows what is left.
The sale
The contracts enforce:
| Rule | Value |
|---|---|
| Strike strictly out of the money by at least | minOtmBps: owner-set, never below 0.5%; currently 1% |
| Strike at most this far above the price | the week's deviation, 6.5%; contract maximum 10% |
| Premium at least | minPremiumBps of notional: owner-set, never below 0.1%; currently 0.2% |
| Premium at most | 10% of notional |
| Covered | all of the Vault's NVDA at the freeze |
| Quote | signed by the quote signer, approved by the buyer, at most 120 s old, for this week's expiry |
| Price used | the oracle, which refuses to answer while the market is closed or the feed is stale |
Our policy, which the contracts do not enforce: the listed Friday NVDA call nearest delta 0.15 inside that band, priced at its OPRA bid; if that strike's premium is below the floor plus 0.05%, the nearest-delta strike that clears it. That walks toward the money in a quiet week, never outside the band.
Fee. Hedgehood takes feeBps of the premium, currently 20%, at most 30%. After the first sale an increase
applies only to sales at least 7 days later, so it can never land between a cutoff and that week's sale; a
decrease applies at once. A sold week keeps the fee it was sold with.
Void. For one hour after a sale the owner can void it with a stated reason. The buyer gets 90% of the premium back and the other 10% stays with depositors; the NVDA is untouched. No mid-week exit is possible in that hour.
Settlement
The price. If a close attester was set when the week was sold, the week settles at NVDA's official close, signed by that key and accepted only within 0.75% of the last Chainlink round before expiry, from 10 minutes after expiry. Our signer publishes nothing unless two independent providers agree on the close to the cent, and the evidence is public. Otherwise, and as the fallback from 48 h after expiry, the price is the last Chainlink round before expiry, proven by the round after it. Which source a week uses is fixed at its sale; changing the attester later cannot switch it.
The payout, with P the settlement price, K the strike and N the NVDA covered:
P ≤ K: depositors keep allNNVDA and the premium net of the fee.P > K: the buyer receivesN × (P − K) / PNVDA, the value above the strike. Depositors keep the rest and the premium net of the fee.- No price within 7 days of expiry: the week settles as
P ≤ K.
Every step after expiry is permissionless: anyone can finalize the price and settle, so a missing keeper delays a week but cannot hold it.
Getting out
| Contract rule | |
|---|---|
| Cancel a deposit | until it becomes shares, or its week's cutoff |
| Withdraw at expiry | requestRedeem reserves shares; they are paid in NVDA at the next queue run while open, or at settlement while locked; cancellable until then; no fee |
| Exit now | the exit pool buys shares from 1 h after the sale to 1 h before expiry, at a signed quote valid 25 s and usable once, within the pool's cap and inventory |
The exit price takes over your part of the call at the market's cost of buying it back:
value per share = uncovered × S_bid + covered × (S_bid − C_ask) + (premium − fee) / shares at the sale
payout = shares × value per share × (1 − exit fee) in USDG, or ÷ S_ask in NVDA
S is NVDA's SIP quote, C_ask the OPRA ask of the week's own call. The exit fee is 1% and is shown in every
quote.
Reinvesting
An account that opts in has its claimable premium swapped to NVDA by the keeper after a week settles and before the next cutoff, while the market is open, at no worse than the oracle price less 1%, and queued as its deposit for the next week. The keeper can only do this for accounts that opted in, and only into their own deposit. Turning it off is immediate.
What the owner can change
Deposit cap · HEDGE threshold and gate · the operator · the exit pool list · pause · the quote signer, the buyer and its approval key · the fee (bounded and delayed) · the premium and out-of-the-money floors (bounded) · the close attester (bounded at 0.75%, fixed per week at the sale) · the reinvest keeper · the exit pool's own signer and its own inventory.
Pause stops new deposits, new sales and exit-pool purchases. Settlement, claims, cancellations and withdrawals continue, and a queue run while paused refunds pending deposits instead of activating them.
None of these moves a depositor's NVDA, shares or premium.
Why the operator is a contract
The Vault still contains the path it was first built for, in which the operator sells the call at a broker and reports the result: a locked week whose loss the operator states, up to the call's intrinsic value at the oracle price plus 0.5% of notional, taken from depositors' NVDA. A Desk week can never settle from a reported figure, but whoever is the operator could open such a week instead.
So the operator is not a key. It is BrokerVaultDeskOperator: a contract without an owner, storage or funds whose
only function forwards a signed sale to the Desk. The broker path checks msg.sender == operator, and nothing can
make that contract call it. The keeper submits the sale through it, and anyone else could too, because the quote
signer and the buyer have already signed and every bound still applies.
The one way back is an owner decision: the 2-of-3 Safe naming a key as operator again, a transaction anyone can see on chain. We will not do it, and it is listed here so that you can check.
What can go wrong
- NVDA falls. The vault is long NVDA. The premium is a cushion, not a hedge.
- NVDA rallies. Everything above the strike is sold every week.
- A wrong price. The settlement price depends on Chainlink and, for attested weeks, on our signer inside a 0.75% band. A stale feed stops sales and deposits rather than pricing them.
- The token is paused. NVDA tokens can be paused by their issuer; while they are, nothing moves.
- Keys. The quote, buyer and attester keys are operational keys, kept out of plain files on the server. Misused, they are bounded by the sale floors and the 0.75% band above; lost, they delay a week, which anyone can then settle. The keeper's own key only pays gas.
- The exit pool is empty. Exit now depends on its inventory; withdraw at expiry does not.
- No third-party audit. The contracts have been reviewed internally and are tested, including against a fork of the live chain. That is not an audit.
Contracts
Robinhood Chain (4663). Deployed from edd7f09 at block 84792706; the deployed code was checked against a fresh build of that commit.
| Vault contracts | Address |
|---|---|
| Vault | 0xe35B7D7bf1212b89478ddAba2946ADEd59BEC0a9 |
| Desk | 0x6d17d089663e50823e29ad34D6e4EB2448BE8B0b |
| Desk operator (the Vault operator) | 0xCfC05f30773c761F122B92B9b5fBDb02BEA5F232 |
| Oracle | 0x5A6bf55578E85b806910f0B6Ee8e683786fD62C6 |
| Zap | 0x5AfdcE7484031e579Ff44c6499AfB6dd76819245 |
| Exit pool | 0x8ac43fcc039612D40148f74f64835c23130029AF |
| HEDGE gate | 0x48ae41142bb0Ddd18DC49BD659b55207FAcE64d8 |
| Scheduler | 0x399D6c2c529531b9071B02522bd0Fbc90CcDb3Cb |
| Policy | 0x1bc4694aEdB4d844946d1B9e4021001cc83cb544 |
| Settlement | 0xa9D051749bBa8A49d00fCdc0e54476c1f6df7Ec4 |
They build on:
| Address | |
|---|---|
| NVDA token | 0xd0601CE157Db5bdC3162BbaC2a2C8aF5320D9EEC |
| USDG | 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168 |
| NVDA / USD Chainlink feed | 0x379EC4f7C378F34a1B47E4F3cbeBCbAC3E8E9F15 |
| Trading calendar | 0xFcD3129E596B3C4577fb4129D61A90db52306461 |
| NVDA / USDG pool | 0xd4EB21209C4D6093f80B5b84f5C45cc093EA14a3 |
| HEDGE | 0x3f9108a3bECa998C14c6dda822a7e8EaEb88E20D |
| Owner Safe (2 of 3) | 0xB5C9e27F50599687eD141ABe337414B79061489b |
| Option buyer | 0xFD3C304e2f51542D2c7CD038f43fba4b28301b8A |
Robinhood Chain testnet (46630). The same source, with test tokens and a test price feed:
| Address | |
|---|---|
| Vault | 0xB60Ca23C68747eFeDF63c3429081ED418add64aC |
| Desk | 0xa0AE14695C29f7Ec59D79E456d407D254333374D |
| Oracle | 0xaF7B8E25ff5f6b4C90740B5B06c16f4Ef8f4d24b |
| Zap | 0xC5939A6FADADc36b091F39546573609011BF028F |
| Exit pool | 0x4b26073384fe4317e85cB587EE646aD1c15E029A |
| HEDGE gate | 0x7473f13f1e20FC59eeed224D1EbEC1548bdeE76A |
| Scheduler | 0x8F44D16D898f16933E1A17f1743ab0cb1FbBF36a |
Source: github.com/0xHedgeHood/hedgehood-vaults. Live parameters and this week's times are on the vault page.