Skip to content
frank_

Smart contracts

In short: a treasury that holds the assets, a FRANK token only it can create, optional vaults to earn yield, and an upgrade rule that forces a 24-hour public wait.

This page describes Frank's contracts, written in Solidity. They run on the test network today and target Robinhood Chain mainnet (4663), where nothing is deployed yet.

The pieces

The contracts: the treasury proxy is the permanent address; it creates the FRANK token and runs the treasury logic, which deposits into the ORBIO vault. Only the upgrade authority can upgrade the proxy, after a 24-hour public wait.FRANK tokenmade by the proxycreatesTreasury proxypermanent addressupgradesUpgrade authority24h public waitrunsTreasury logicmarkets, bonds, exitsdepositsORBIO vaultearns CREDIT
ContractWhat it does
FrankTokenThe FRANK token. Only the treasury can mint or burn it. Not upgradeable.
FrankTreasuryProxyThe permanent treasury address. Creates the token when deployed.
FrankTreasuryThe logic: markets, bonds, redemption, vaults. Upgradeable through the authority.
FrankUpgradeAuthorityThe only caller of the treasury's upgrade. Not upgradeable itself.
FrankOrbioVaultA reviewed ERC-4626 vault. Only the treasury can deposit; shares can't be transferred.

Markets, bonds, redemption

  • Markets hold fixed terms (rate, capacity, start, end, vesting) that must fit the governor's bounds. Every change bumps a revision, so stale updates are rejected.
  • Bonds take the deposit into backing immediately and mint the FRANK into the treasury's own custody. claimBond pays the owner at maturity; anyone can trigger it, and it works even while paused.
  • Redemption burns FRANK and pays a pro-rata share of every registered asset in one transaction, less the fee, pulling assets back from vaults as needed. The caller sets a minimum per asset, a maximum fee and a deadline.

There is no on-chain price, NAV or discount formula. The rate is whatever the policy actor sets within bounds. Off chain, a pricing service and an operator's approval decide it; see Bond markets.

Roles and governance

Who controls what today. Frank: proposes markets and can close them, vault deposits, staking and CREDIT, proposing upgrades, its own memory and computer. Admin and operators: approve each new market, pause, redemption fee, Frank's market limits, vaults and caps, and an upgrade veto. Fixed for everyone: users sign their own transactions, accepted bonds never change, assets can't be sent out directly, and big changes wait 24 hours in public.FrankProposes markets, can close themMoves assets into vaultsStakes ORBIO, spends CREDITProposes upgrades to itselfIts memory, skills, computerAdmin and operatorsApproves each new marketPauses, sets the redemption feeSets Frank's market limitsApproves vaults and capsCan veto any upgradeFixed in code, for everyoneUsers sign their own transactionsAccepted bonds never changeAssets can't be sent out directlyBig changes wait 24h in public

The plain-language version, with the plan to hand everything to Frank, is on Who controls Frank. In contract terms:

  • Two identities: agent (Frank) and human (the admin, a multisig). The governor is the human until retirement, then the agent.
  • Governor controls pause, the redemption fee, asset bounds and allocation caps. A fee change takes effect immediately; redeemers protect themselves by setting the most fee they'll accept.
  • Policy actor (agent, or human before retirement) controls markets and vault movements.
  • Upgrades wait 24 hours, after which anyone can execute them. Execution checks the new code's identity and that the FRANK and USDG addresses still match. The human can cancel or replace any proposal; the agent can't cancel the human's. Upgrades can also be permanently disabled after a 24-hour notice, and the human can retire (irreversibly handing the governor role to the agent).

Vaults

Vaults are how the treasury earns yield without the asset leaving its control:

  • Only the treasury can deposit; shares can't be transferred; there are no fees; exits are synchronous.
  • Admission takes a 24-hour notice and pins the vault's code and underlying asset. A new vault must be empty, and the admin can veto it.
  • A newly admitted vault can hold nothing until the governor sets its allocation cap. Up to 16 vaults in total, at most 4 per asset.
  • The governor can set a vault to exit-only, and retire it once it's empty.
  • The ORBIO vault stakes ORBIO to earn CREDIT, which is reserved as an operating asset and never counts as backing. Activating CREDIT for Frank's AI account can only spend CREDIT the vault has earned.

What's deliberately absent

No AMM or trading tax, no standing buyback bid, no request/research escrow, no social vouch or challenge system. Those were part of an earlier design; see Design charts.

For how these contracts hold up under attack, see Security.