The memo
REJECTED ON CONTRACT-LEVEL FACTS, NOT A DISCLOSURE GAP. Robinhood Chain is an Arbitrum Orbit L2 Robinhood operates for tokenized stocks and other RWA products. Unlike the disclosure gaps that sink several entries in this batch, Robinhood Chain is unusually well documented at the contract level, and what that documentation shows disqualifies it: fraud-proof validation is not yet permissionless, a transaction-filtering precompile can block even transactions submitted directly to L1 to bypass a censoring sequencer — defeating the force-inclusion backstop every other canonical bridge in this registry relies on as a last resort — and a specific externally-owned account retains direct contract-upgrade authority alongside the chain's multisig, which L2Beat itself flags as a critical risk. A governance restructuring four weeks before this review improved the standing multisig but did not close any of these three gaps.
What would reopen the file
- Fraud-proof validation becomes permissionless, removing the whitelisted-validator requirement
- The ArbFilteredTransactionsManager filtering capability is removed, or is demonstrated never to block a force-included L1 transaction
- The externally-owned account currently holding direct upgrade or admin permission is removed from that role, leaving only the disclosed multisig path
- Twelve consecutive months of the restructured multisig governance operating with no bypass-the-timelock upgrade executed without public justification
Facts on file
- Verdict
- Rejected
- Exposure
- other
- Chains examined
- Ethereum
- Memo version
- v1
- Reviewed
- Next review