Encrypted messaging for Robinhood Chain wallets

Protocol

Smart contract

One shared contract on Robinhood Chain that every HoodChat user talks through. It never sees plaintext and never holds funds.

Deployment

Network
Robinhood Chain (chain 4663)
Contract
0x81a0E8eb42256586a934E062047CD8cA0449B4dc
USDG
0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168
Wallets with keys
—
Messages sent
—

What it does

FunctionPurpose
registerKey(key)Publish or rotate your public encryption key
sendMessage(to, ciphertext, hash)Post an encrypted message (up to 4,096 bytes) as an event
sendMessageWithTip(…, amount)Message plus a USDG tip in one transaction
tip(to, amount)USDG tip without a message
encryptionKeys(wallet)Look up anyone’s public key
lastActivityBlock(wallet)Where a wallet’s history starts, so apps load it without an indexer

What the owner can — and can’t — do

  • Can set a per-message fee in USDG, between 0 and 1 USDG. It is 0 today. The ceiling is a constant in the code.
  • Can choose where that fee goes, and hand ownership to another wallet (two-step, so it can’t be sent to a typo).
  • Cannot read, edit, delete or censor messages.
  • Cannot freeze wallets, move anyone’s funds, or upgrade the code. There is no proxy; what’s deployed is final.

Where messages live

Messages are emitted as MessageSent events rather than written to contract storage. That keeps sending cheap and makes history readable by anyone with an RPC — but it also means messages are permanent.

Verify it yourself

The full source, tests and deploy script are in the HoodChat repository under packages/contracts. Read Encryption for what the ciphertext contains.