Corpus is in open beta. Start with small amounts.

PROTOCOL INFO

Protocol info

How Corpus works: deposit a Robinhood Stock Token, borrow USDG with no interest, and let harvested yield pay the debt down. Includes worked numbers, risk parameters, and the rules for stale prices and liquidation.

Updated 13 min read12 sections
On this page

Corpus is a lending protocol on Robinhood Chain (chain ID 4663). You deposit a Robinhood Stock Token as collateral, borrow USDG against it, and any yield the collateral produces is harvested, converted to USDG and applied to your debt. There is no interest, no schedule and no maturity date.

This page is the practical guide. The whitepaper covers the same mechanism with the formulas written out, and the risk page is a plain list of what can go wrong.

One thing belongs at the top, before anything else. Today the yield is zero. Every market at launch routes collateral into a 1:1 custody vault that holds tokens and earns nothing, because no earning vault for these tokens exists on Robinhood Chain yet. Everything else on this page works exactly as described, but until an earning vault is connected, your debt will not shrink on its own. See Why the yield is zero today.

The loop

There are four actions, and you can stop after any of them.

  1. Deposit. You send a supported Stock Token to Corpus. It is recorded as your collateral and forwarded to that market's yield source. It is still yours; nothing is sold.
  2. Borrow. You draw USDG from a treasury the protocol holds, up to the market's maximum loan-to-value ratio. The USDG comes from the protocol's own balance, not from other users, so there is no lender to pay and no rate to bid up.
  3. Harvest. Whenever the collateral has produced yield, anyone can call harvest for your position. The surplus is withdrawn, swapped to USDG, and the protocol keeps 10%. The rest is subtracted from your debt. If your debt reaches zero, the remainder becomes USDG credit you can claim.
  4. Repay and withdraw. You can repay in full or in part at any time, with no fee for repaying early. Once the debt is gone, the collateral comes back to you.

Your debt only ever moves in one direction after you borrow: down. It increases only when you choose to borrow more.

What it costs

Item Cost
Interest None
Origination fee None
Early repayment fee None
Ongoing account fee None
Protocol share of harvested yield 10%
Swap cost during harvest Pool fee plus up to 1% slippage against the oracle price
Liquidation bonus (only if your position becomes unhealthy) 5%, or 7.5% for TSLA
Gas Robinhood Chain transaction fees

Note what this means. The only recurring cost of carrying a Corpus loan is the 10% cut and the swap cost, and both come out of yield the collateral produced. Neither touches your principal. If the collateral produces nothing, the loan costs nothing to carry. It also does not repay itself.

A worked example

Suppose AAPL is quoted at $200.00 by the oracle and you deposit 10 AAPL.

  • Collateral value = 10 x $200.00 = 2,000.00 USDG.
  • AAPL's maximum LTV is 50%, so your borrowing capacity is 2,000.00 x 0.50 = 1,000.00 USDG.
  • You borrow 600.00 USDG. Your LTV is 600 / 2,000 = 30%.
  • AAPL's liquidation threshold is 60%, so your health factor is 2,000.00 x 0.60 / 600.00 = 2.00.
  • You become liquidatable once the health factor drops below 1.00, which takes a price under 600.00 / (10 x 0.60) = $100.00, a 50% fall. At exactly $100.00 the factor is 1.00 and the contract still refuses to liquidate.

Now suppose a harvest realises 100.00 USDG of yield for your position:

  • The protocol keeps 10% = 10.00 USDG.
  • The remaining 90.00 USDG is applied to your debt: 600.00 becomes 510.00 USDG.
  • Nothing else changes. Your collateral is untouched, your health factor improves because the debt is smaller, and no new debt was created by the repayment.

If instead your debt had been 50.00 USDG when that 90.00 USDG arrived, 50.00 would clear the debt and the leftover 40.00 USDG would sit as claimable credit, which you can withdraw at any time: the protocol reserves both credit and unsettled harvest out of what it will lend, so claiming is never blocked by other people's borrowing.

Risk parameters

Each market has three numbers. Maximum LTV is the most you can borrow against a given collateral value. Liquidation threshold is the point at which the position becomes unhealthy. Liquidation bonus is the discount a liquidator earns on the collateral they take.

Market Max LTV Liquidation threshold Liquidation bonus Price fall to liquidation from max LTV
AAPL, AMZN, GOOGL, META, MSFT, NVDA 50% 60% 5% 16.67%
QQQ, SPY 60% 70% 5% 14.29%
TSLA 40% 50% 7.5% 20.00%

The last column is 1 - maxLTV / liquidationThreshold: the fall in price that takes a position borrowed to the very limit down to a health factor of 1.00. It is a small buffer, and it is the worst case rather than your case. Borrow only half of your capacity on a 50/60 market and the fall you can absorb goes from 16.67% to 58.33%.

Supply caps are unlimited at launch. That is a decision about simplicity, not a statement that the markets are deep. It can be changed later.

Health factor

healthFactor = collateralValue x liquidationThreshold / debt

At or above 1.00 the position is healthy. Strictly below 1.00 it can be partially liquidated — at exactly 1.00 the contract refuses, so the boundary belongs to the borrower. With no debt the health factor is treated as infinite.

Two useful readings of the same number: the price fall you can absorb is 1 - 1 / healthFactor, and the amount you could still borrow is collateralValue x maxLTV - debt.

When prices go stale

Corpus reads prices from Chainlink feeds. Those feeds update while the underlying market is trading, which means they go quiet at every close, every weekend and every market holiday. Corpus accepts a price as fresh for 80 hours (288,000 seconds) after its last update.

When a market's price is older than that, the protocol refuses to act on it:

Action With a stale price
Deposit collateral Allowed
Repay Allowed
Harvest Allowed
Claim credit Allowed
Borrow Blocked
Withdraw collateral while you have debt Blocked
Liquidate Blocked

The split is deliberate. Everything that can only make a position safer stays open in every condition. Everything that depends on knowing what the collateral is worth stops until the feed speaks again. Withdrawing collateral when you have no debt is also always allowed, because no valuation is needed to permit it.

Two footnotes to that table. Harvest is allowed by the core at any age, but the yield source sells the harvested surplus against the same oracle price and will not use an answer older than 26 hours — so once a market has a surplus to sell, a harvest can be refused long before the 80-hour window runs out. Nothing is lost while it is: the yield stays where it is and the next harvest takes it. Deposit is allowed at any price age, but it is the one action refused on two other grounds. If the market has yield waiting and that sale cannot go through in the same transaction, the deposit is refused rather than let a new depositor share in yield earned before they arrived. And if the market's vault is behind the collateral the market records, deposits pause until it is whole again — see the next section.

When a market's vault falls behind

Collateral is held in an ERC-4626 vault, and a vault can lose value. Corpus records what you deposited as a claim on the market's vault position, not as a promise of assets, so if the vault can no longer return everything the market records, the difference is shared in proportion rather than paid in full to whoever withdraws first.

While that is true of a market, the app shows it: the market page carries an Impaired badge and states what the vault can return against what the market records, and your own position shows both numbers. Every risk figure — collateral value, LTV, health factor, borrowing capacity, the liquidation bound — is already net of the shortfall, so what you see is what the contract acts on. A withdrawal gives up recorded collateral and pays out the same share of it, which is why the withdraw Max is set to what would actually arrive.

Only deposits stop, because everything a market holds sits in one vault position and a deposit made into a shortfall would take a share of it the moment it landed. Repaying, withdrawing, harvesting, claiming credit and liquidation all keep working. Nothing is written down, so a vault that recovers lifts the haircut by itself.

A normal weekend is about 65.5 hours from the Friday close to the Monday open, which fits inside the window. A three-day holiday weekend is about 89.5 hours, which does not. Expect borrowing to be unavailable on those Mondays until the feed updates.

Liquidation

If your health factor falls below 1.00, anyone can repay part of your debt and take collateral at a discount. Corpus's liquidation is partial by design: the contract computes the smallest repayment that restores your health factor to within a rounding unit of 1.00, and reverts any attempt to repay more than that.

Before the calculation runs, pending yield is applied to your position. If the yield alone is enough to make you healthy again, the liquidation reverts.

The maximum repayment is

R = (D - V x LT) / (1 - LT x (1 + bonus))

where D is the debt, V the collateral value and LT the liquidation threshold. R is additionally capped at D and at V / (1 + bonus), so a liquidator can never be owed more collateral than the position holds.

A numeric example

Take the position from above, 10 AAPL with 600.00 USDG of debt, threshold 60%, bonus 5%, and let AAPL fall to $95.00.

  • Collateral value V = 10 x $95.00 = 950.00 USDG.
  • Health factor = 950.00 x 0.60 / 600.00 = 0.95. The position is liquidatable.
  • R = (600.00 - 950.00 x 0.60) / (1 - 0.60 x 1.05) = 30.00 / 0.37 = 81.081081...

The contract rounds in the protocol's favour and permits at most 81.081082 USDG. A liquidator repaying that amount receives collateral worth 81.081082 x 1.05 = 85.14 USDG, which at $95.00 is about 0.8962 AAPL.

Afterwards:

  • Debt = 600.00 - 81.08 = 518.92 USDG
  • Collateral = 10 - 0.8962 = 9.1038 AAPL, worth 9.1038 x $95.00 = 864.86 USDG
  • Health factor = 864.86 x 0.60 / 518.92 = 1.00 to the cent — 0.99999999961 in the contract's exact integer arithmetic

You keep 91% of your collateral and the position is back to within a rounding unit of a health factor of 1.00. Because the remaining collateral is re-valued with the rounding in the protocol's favour, it can land a hair under 1.00 rather than on it, leaving the position liquidatable for one more USDG unit — 0.000001 USDG — until the price moves. An attempt to repay 81.081083 USDG reverts. That is the point of the design: a liquidation costs you the bonus on a small slice, not half the position.

If the price keeps falling, another liquidation can follow. If collateral runs out while debt remains, the remainder stays recorded against the position and is a loss to the treasury.

Why the yield is zero today

Corpus's yield comes from an ERC-4626 vault. Yield is defined as the amount by which the vault shares held for your position are worth more than the principal recorded for it. At launch, every market points at a Corpus custody vault: it holds the deposited tokens one for one and earns nothing. So the surplus is zero, harvest has nothing to swap, and your debt does not shrink by itself.

We shipped it this way because there is no earning vault for Robinhood Stock Tokens on this chain yet, and because we would rather run the machinery with a zero in it than describe a yield that does not exist. When an earning vault is available, it can be connected to a market without touching anyone's position, and harvests start producing real repayments from that moment.

Until then, treat Corpus as what it currently is: a zero-interest loan against your stock tokens, with no schedule and no maturity. That is genuinely useful. It is just not yet self-repaying.

Using the app

  • Connect a wallet and switch it to Robinhood Chain. The app offers the switch if you are on another network.
  • Deposit from a market page. The first deposit of each token needs an approval transaction, then the deposit itself.
  • Borrow up to the capacity shown. The app mirrors the guards the contract enforces, so a disabled button means the contract would reject the transaction: a stale price, a closed market, not enough USDG in the treasury, or a market whose vault is behind its books.
  • Watch the health factor on the market page and in the portfolio. The gauge also shows how far the price can fall before liquidation.
  • Repay any amount at any time. Repaying is never blocked, not by a stale price and not by a pause.
  • Harvest is open to anyone, so you rarely need to press it yourself; a keeper batches harvests across positions. Pressing it yourself costs you gas and nothing else. The button is disabled when the price the surplus would be sold against is more than 26 hours old, because the yield source would refuse the sale.
  • Claim credit collects USDG left over after your debt reached zero. It can revert while the treasury is fully lent out; the credit stays recorded against your address until there is USDG to pay it.
  • Read-only view: append ?address=0x... to the portfolio URL to inspect any address without connecting a wallet.

Every number in the app is read directly from the chain on each refresh. None of them are hard-coded.

Parameters

Every value the protocol launched with. Deployed contract addresses are in the sidebar of the app and on the explorer.

Network

Parameter Value
Chain Robinhood Chain
Chain ID 4663
Borrow asset USDG (6 decimals)
Collateral assets AAPL, AMZN, GOOGL, META, MSFT, NVDA, TSLA, QQQ, SPY (18 decimals)

Markets

Market Max LTV Liquidation threshold Liquidation bonus Supply cap
AAPL 50% 60% 5% Unlimited
AMZN 50% 60% 5% Unlimited
GOOGL 50% 60% 5% Unlimited
META 50% 60% 5% Unlimited
MSFT 50% 60% 5% Unlimited
NVDA 50% 60% 5% Unlimited
TSLA 40% 50% 7.5% Unlimited
QQQ 60% 70% 5% Unlimited
SPY 60% 70% 5% Unlimited

Protocol

Parameter Value
Protocol share of harvested yield 10% (1000 bps)
Maximum share the owner can ever set 50% (5000 bps)
Price staleness window 80 hours (288,000 seconds)
Harvest slippage bound 1% (100 bps) against the oracle price
Oldest price a harvest may be sold against 26 hours (93,600 seconds), owner-settable up to 3 days
Hard ceiling on the slippage bound 10% (1000 bps)
Oracle Chainlink feeds, 8 decimals; per-feed price floor and ceiling supported, neither configured at launch
Yield source one ERC-4626 vault per market
Vault at launch Corpus custody vault, 1:1, yield = 0
Interest rate 0%, fixed by construction
Loan term None

Status

Corpus is in open beta and has not been audited. The contracts are not upgradeable, but the owner can change market parameters, replace the oracle or the swap router, pause the protocol and withdraw from the treasury. Repay and claim keep working in every state, including while paused.

Start with an amount you are willing to lose. Robinhood Stock Tokens are not available to US persons and are restricted in other jurisdictions; whether you may hold or use them is your responsibility, not ours.