$ETHOSIS is officially live on Robinhood Chain.
0x06bbc2ca0843a19c90254f65f87f092ddd46ab44
Ethosis is a non-custodial, peer-to-peer lending protocol where borrowers post tokenized RWAs such as Robinhood Stock Tokens as collateral and borrow USDG from lenders at fixed, negotiated rates. Every loan settles on-chain, is publicly verifiable, and keeps risk isolated to the lender who priced it.
Standing offers on Ethosis work like limit orders for credit.
Sign once: up to 50k USDG against any Tier A Stock Token, 8.5% APR, 30 days, max 50% LTV. Costs nothing until it fills. Idle balance earns the Morpho pool rate meanwhile.
Set your terms. Let borrowers come to you.
Development update: PolicyController now rejects parameter sets that would leave the protocol unusable.
Every basis-point field in the setters was already bounded, but a handful of plain integers went in unchecked. A slice cap of zero makes every origination revert on its first slice. A zero auction window opens every collateral sale already at the floor. A zero rollover window jumps the refinance rate straight to the cap with no time for anyone to accept.
None of those is a setting anyone would choose on purpose, but after bootstrap a mistake like that costs a full timelock cycle to undo. The controller now refuses all three at the door with InvalidParams, and the test confirms a rejected call leaves the previous values in place: 32 slices, 45-minute auctions, 4-hour rollovers.
https://t.co/MigjdH1SN0
Borrow against your tokenized portfolio without selling it.
Post tokenized AAPL, NVDA or SPY as collateral on Ethosis, draw USDG at a fixed rate for a fixed term, keep the upside. Dividends keep accruing to tokens in escrow.
Repay any time. Collateral returns in the same tx.
Development update: repayment now stays open on a loan that defaulted in a rollover.
A failed refinance auction marks the loan Defaulted so a keeper can open a collateral auction without waiting for the health factor to cross 1.0. That is intended. What was not intended is that repay() and addCollateral() only accepted Active loans, so from the moment the rollover window closed short, the borrower's only way out was liquidation, even if no auction had opened and the loan had not matured.
Default is meant to remove the health-factor guard on liquidation, not the borrower's right to settle first.
Both entry points now accept Defaulted loans via a shared _repayable() check. The new test walks a loan through a failed rollover, a collateral top-up and a full repayment, then confirms the auction has nothing left to open on.
https://t.co/od03O1NyYT
Thank you to everyone who has supported $ETHOSIS so far.
The attention on the token has brought a lot of new eyes to what we are actually building: fixed-term P2P lending against tokenized RWAs on Robinhood Chain.
Updates coming. Keep watching the codebase.
The Ethosis GitHub organization is public!
Contracts, relayer, indexer, front-end, all open source.
Transparency is our second promise after solvency. Read it, fork it, break it.
https://t.co/7gAto1rBPi
Ethosis contracts are live on Robinhood Chain testnet.
The full v1 contract set is deployed to chain 46630 and is currently running live transactions: offers being settled, interest accruing, health factors moving with the Chainlink feeds, auctions kicking off when they should. This is the phase where the design meets real block times and real oracle behaviour, and where we want to find out what breaks before an auditor does.
Seven contracts make up the core. Three of them carry most of the weight, so here is what they do.
LoanDesk
The settlement singleton. A borrower submits a borrow request plus the set of EIP-712 lender offers that fill it, all in one transaction. LoanDesk verifies each signature (ECDSA for EOAs, EIP-1271 for smart accounts), checks eligibility against the AccessRegistry, confirms the resulting LTV sits inside the tier limit, escrows the Stock Token collateral, pulls USDG from each lender, and mints one SliceToken per lender slice. Interest accrues per second at each slice's fixed APR. Repayment releases collateral and pays lenders pro rata. There is no pooled deposit anywhere in this flow: funds move only at settlement.
https://t.co/fuHEyThvzh
PriceGate
Every health factor and every liquidation price passes through PriceGate. It reads Chainlink 24/5 feeds for the exact token posted as collateral, applies the ERC-8056 uiMultiplier so splits and reinvested dividends are reflected in share terms, and enforces the guards: staleness bounds, zero and negative price rejection, single-update move caps, a halt on oraclePaused, and a grace window after a sequencer outage via the Sequencer Uptime Feed. When marketStatus reports the underlying market closed, LTV ceilings take a haircut, because Friday's close is not Monday's open. Testnet is where we are tuning those bounds against real feed cadence.
https://t.co/Q0tHE3thqx
CollateralAuction
When a loan's health factor drops below 1.0, anyone can start a Dutch auction of the collateral. Price opens at oracle x 1.03 and declines linearly toward a bounded floor over roughly 45 minutes, so single-name tokens are never dumped into thin DEX pools. Proceeds go to the syndicate pro rata, surplus goes back to the borrower, and the liquidation penalty is split between the keeper who triggered it and the lenders who priced the loan. Lenders who actually want the stock can opt to receive collateral in kind at the oracle price instead of USDG. During closed markets the floor is bounded to prevent weekend predation.
https://t.co/wrkWDe5OTF
The remaining four (AccessRegistry, AttestationStore, PolicyController, SliceToken) handle eligibility, attestation storage, timelocked parameter changes and the ERC-721 loan positions. We will cover each of them in their own posts.
What happens next: invariant and fuzz suites continue to run against the deployed bytecode, partner lenders and borrowers begin structured testing, and once the suite is green we move to independent audits and a public contest. Contracts, relayer, indexer and keepers will be published under a permissive licence.
Everything is verifiable on the explorer. If you are building on Robinhood Chain and want to test against the book, reach out.
Liquidation on Ethosis is a Dutch auction, not a DEX dump.
HF = collateralValue x liquidationLtv / debt. Below 1.0, anyone can start the auction: oracle x 1.03, declining to a bounded floor over ~45 min. Lenders can opt to take collateral in kind at oracle price instead of USDG.
Ethosis prices the exact token you post as collateral. Chainlink 24/5 feeds with marketStatus and staleness checks, ERC-8056 uiMultiplier for splits and dividends, a halt on oraclePaused.
Closed market? LTV ceilings take a haircut, because Friday's close is not Monday's open.
How an Ethosis loan settles:
Lenders sign EIP-712 offers off-chain (ECDSA, or EIP-1271 for smart accounts). The borrower submits the matched set in one tx. LoanDesk verifies signatures and eligibility, escrows collateral, pulls USDG per lender, mints one SliceToken per slice.
Ethosis is non-custodial by design. No deposits held before a match. Overcollateralised loans only, priced by Chainlink 24/5 feeds, liquidated by Dutch auction rather than DEX dumps.
Contracts, relayer, indexer and keepers will be open source.