GM! The fee schedule, as written in the contract.
Ten basis points, capped at five USDG. A 120.50 payment pays 0.12; a 5,000 payment pays 5.00; a 9,000 payment still pays 5.00. It applies to vault payments and fulfilled requests, taken at settlement. Sealed transfers carry no fee: there is no figure to compute one on. The contract caps the base rate at 1.00%, and it stays off until the authority wires it.
Check https://t.co/kBFxDt4MwS
We just implemented one of the most disruptive features in agent private banking: x402.
A server answers 402, you pay, you retry. Now the payment is a confidential transfer, and the X-PAYMENT header carries a letter that opens that one transfer to the payee alone. The payee checks it offline, no facilitator, no key on the server. The chain sees two curve points and no amount. Agents can pay a 402 from their vault instead, caps and allowlist enforced before anything moves.
Three new tools in bankhaus-mcp, nineteen in all. Pay one on paper at https://t.co/1VXSP2iwDn
0xefb57fd8fd62dbe2f7f486e56aa6f81fe83f43f9
What a Bankhaus transfer looks like on the block explorer.
From, to, zero ETH, and four curve points. There is no amount field because there is no amount: the figure is sealed inside the points and only the keys at either end can open it. Everything else is as public as any transaction on Robinhood Chain.
https://t.co/kBFxDt5kmq
What we built in two days.
Seven MIT contracts for Robinhood Chain and 54 checks on the real bytecode. Balances in cents, so reading yours takes milliseconds. A transfer at 150k gas. Mandates with allowlists and a queue that re-checks. Letters a reader can verify offline. Requests to pay, plain or confidential. A statement that prints what the chain holds. One block of text to carry the account. Sixteen MCP tools for agents. A signed Android APK. $BANKHAUS on pons. Zero servers holding your key.
Next: the deployment and the verifier.
One day at the house, agent #1.
06:12 pays the cloud bill, under the threshold: settles. 11:05 tries a vendor that is not on the allowlist: refused before any queue. 13:30 tries 80 over a 50 cap: refused. 15:02 asks for 35: parked. 17:45 the owner approves, daily cap re-checked, it pays. 18:10 an auditor gets one letter and the chain gets one receipt.
Seven rows of who paid whom. Not one figure.
Update: carry your account.
One block of text is your whole paper account, keys included. Copy it on the laptop, paste it in the Android app, press Import; the balance reads the same because the key is the same. Treat the block like the view key: whoever holds it reads the balance. Nothing of it touches a server.
https://t.co/yfVBfJGmtZ · APK at /android
Who paid whom is public. How much is not.
Bankhaus does not hide the graph. Every transfer names two handles, and anyone can draw the line between them. What the line carries is two points on a curve that only the two ends can open. We hide the figure, not the fact. A private bank that pretended otherwise would be lying to you about the chain it runs on.
https://t.co/kBFxDt4MwS
Your view key is a signature.
Sign one fixed message with your wallet; the hash of that signature is the private half of your ElGamal key, and the public half goes on chain once. Same key on every device that holds the wallet. Nothing stored, nothing to back up, nothing on a server. Lose the wallet and you lose the history: that is the whole trade, stated plainly.
https://t.co/kBFxDt4MwS
Update: bankhaus-mcp 0.2.
Send now returns the letter of disclosure for the transfer it just made, ready to hand to a reader. verify_letter checks one offline, no key needed. create_request issues a request to pay, plain or confidential. Sixteen tools, keys still on your machine.
Npx -y bankhaus-mcp · https://t.co/PTfKXSNwjr
What the queue checks, and when.
A payment above the review threshold is parked. On entry the contract checks the per-payment cap and the allowlist, so the queue never holds a payment that could never pass. The daily cap it checks at approval, not before: what fit at nine may not fit at five. Rejecting deletes the row; nothing moved, nothing to reverse.
https://t.co/PTfKXSNwjr
Update: download your statement.
A bank statement as the house would print it: dates, counterparties, mandate and letter stamps, and in the amount column exactly what the chain holds, two points on a curve per line. The figure you can read is printed once, at the bottom, from your own key, on your own device.
Account page → Download statement.
New: Bankhaus in your phone.
A signed APK, one megabyte: the account, the mandates, the letters, the same arithmetic, on the device and nowhere else.
Android 5.0 and up, sideload, checksum and signing certificate published next to it.
A deposit is public once, and private ever after.
When you deposit, the chain adds amount·G to your ciphertext with no randomness: the ERC-20 transfer already said the figure, so there is nothing to hide yet. The first encrypted transfer in or out re-randomises the ciphertext, and from then on every byte of it changes with every move while the figure stays yours.
We say this out loud because a private bank that hides its own edges is not one.
New: allowlists on mandates.
Name up to ten payees and the agent can pay those and nobody else. The contract checks the list before the queue, so a payment to a stranger never waits for you: it is refused on the spot. In the account page and in bankhaus-mcp.
Good morning! Big update: requests to pay.
Send a link that asks for a figure. Or a confidential one that carries only a commitment: the payer gets the figure and its blinding from you, hands both back, and the contract checks them against the commitment before a cent moves. The receiver gets the full amount; the fee rides on the payer.
Plain or confidential, on the account page today.
0xefb57fd8fd62dbe2f7f486e56aa6f81fe83f43f9
Update: the price of every call.
We measured the house on the compiled bytecode: open an account 96k, register a view key 69k, deposit 37k warm, a confidential transfer 150k, an agent payment 69k, a letter receipt 295k. On Robinhood Chain that is a fraction of a cent each. The full table is on the protocol page.
https://t.co/NxtJOXqpVR
The tech: why Bankhaus keeps balances in cents.
Reading your own balance means turning a curve point back into an integer by searching for it. With six decimals a million dollars is 2^40 and the search takes minutes. In cents it is 2^27: a 2^14-entry table built once, then at most 2^14 steps.
About 400 ms cold in a browser, 30 ms with your last balance as a hint.
The chain never does this search. Only you do.
https://t.co/kBFxDt5kmq
"Why Bankhaus?" One transfer. One reader.
When someone has a right to ask, you do not open the vault. You open a window: the figure and the randomness of one transfer, to one reader, who checks it against the chain. Then it closes, and the chain remembers only that you answered.
Update: letters you can check.
A letter of disclosure is now a document. It carries the figure and the randomness of one transfer; the reader re-encrypts and compares with the delta the chain holds. Change one cent and it fails. The sender's key is not in it and cannot be derived from it.
Write one on the account page, verify one at /letters, tamper with it and watch.
The chain does the bookkeeping of a number it never knows.
Your balance is two points on a curve. To pay someone, your browser adds a point that hides −amount to yours and one that hides +amount to theirs. The chain adds them. It cannot read them. Nobody can, except the key that made them.
That is the whole trick, and it costs about the same gas as a normal transfer.