on Robinhood Chain · testnet

ERC-4337 paymaster · on Robinhood Chain

Pay gas with work, not ETH.

Your browser solves a small proof-of-work puzzle and the paymaster covers the gas. A fresh address never needs a funding transaction, so it never links back to your main wallet.

Funding transaction that would be needed: 0.002 ETH from 0xA1f0…7e3B to the fresh address 0x9c4e…a041.

00/20Bits
Hash
searching, real hashes of this tab's work
Worker
Demo · throttled to 0.25 MH/s on 1 thread · starts in view
Demo

Valid proof. Found in this tab and never sent. A real transaction needs about 32× this work (~2 to the power of 25 hashes in 8 sub-solutions at the testnet floor), checked on-chain by the paymaster. Zero ETH. Zero link.

01 · The funding link

1 top-up. 1 public link. Permanently.

A fresh address can’t move until it holds ETH for gas. Send it 0.002 ETH from your main wallet and that funding transaction ties the two together on a public ledger.

Stealth addresses, new smart accounts and tokenized-stock positions all leak the same way.

LinkedAnyone can read the funding tx, forever.

UnlinkedThe funding tx never exists. Nothing to trace.

02 · The fix

2 to the power of 25 hashes replace the top-up.

Your browser finds nonces whose hashes fall under the paymaster’s target. The paymaster checks them on-chain and sponsors exactly that one UserOperation. Proof-of-work does the anti-spam job ETH used to do. Your main wallet stays public; it is simply never connected.

How it works

3 steps. 0 ETH. Seconds of work.

  1. Mine

    Your tab searches for valid nonces in Web Workers: about 3 s at the testnet floor on a laptop using all cores, longer on one core or at higher difficulty.

    ~2 to the power of 25 hashes · stops at 8 hits

  2. Sponsor

    The paymaster verifies hash ≤ target on-chain and pays for that UserOperation.

    validatePaymasterUserOp · 1 proof, 1 op

  3. Send

    Your fresh address transacts with 0 ETH. No funding transaction to trace.

    0 ETH · no funding tx

What the paymaster does. What it never does.

Six commitments, each one checkable in the contract source.

Limits, stated plainly

Testnet only for now. Proof-of-work is a rate limiter, not a security guarantee: the per-epoch budget is what bounds losses. The relay sees your IP address unless you connect through Tor.

  • Not a mixer

    We pay gas for one UserOperation. We never hold, pool or move your tokens.

  • Keys stay in your tab

    Your fresh account’s key is generated locally and never sent to us.

  • CPU capped

    Web Workers only, at the thread count you pick. Stops once the proof is done. The demo on this page uses one core and pauses when hidden.

  • Funded by donations and fees

    Donations and protocol fees sent to fund() refill the treasury. Each epoch gets a capped budget. You never pay per transaction.

  • Rate-limited by work

    Difficulty rises with load, so spam costs CPU time, not your identity.

  • Verified contracts

    Open source, not upgradeable, verified on the Robinhood Chain explorer at deployment. Audit linked when published.

Who sees what

Your fresh address and its ops
ClearPublic on-chain, like any account.
Your main wallet
ClearIts history stays public. It is simply never connected.
A funding tx between them
SealedNever sent, so there is nothing to trace.
Your fresh account’s key
SealedMade in your tab. Never sent to us or to the relay.
Addresses and amounts on your screen
MosaicThe app masks them from onlookers. Hold to read.
Your IP address and send time
Clear to the relayThe relay sees them. Tor Browser hides the IP.

Testnet demo data · Robinhood Chain testnet

Ops sponsored
12,408
Median solve · s
2.7
Work per op · bits
about 2 to the power of 25 hashes
Runway · days
41
Sponsored ops per day · 90 daysSponsored ops per day · last 45 daysDemo data

03 · For builders

Three lines between your dapp and gasless UserOps.

The SDK fetches the epoch, mines in Web Workers and attaches the proof to paymasterAndData. Built on viem, with EIP-7702 accounts and no wallet connection.

  1. Install the SDK. No API key, no signup.
  2. Create a fresh key in the browser and point it at the relay.
  3. Send the UserOperation. The proof rides along; the gas is sponsored.
$ npm i @unlinked/sdk @unlinked/miner viem

import { generatePrivateKey, privateKeyToAccount } from 'viem/accounts'
import { createRelayClient, sendPowUserOperation, startEpochPolling } from '@unlinked/sdk'

const owner = privateKeyToAccount(generatePrivateKey()) // never funded
const relay = createRelayClient(RELAY_URL)
const epochs = startEpochPolling(relay)   // at app start: reads on a fixed schedule
const { receipt } = await sendPowUserOperation({ relay, epochs, owner, call })

// call = claimCall(faucet, token) or transferCall(token, to, amount)
Matches @unlinked/sdk. The full 20-line example is in the quickstart.
One thread, in this tab, for a moment. Nothing is broadcast.

Zero ETH. Zero link.

A fresh account's first transaction takes seconds of mining: about 3 on a laptop at today's testnet floor. No email. No wallet connection.

Every fresh account gets a private mark computed from its key. Other people's marks stay mosaic: nobody can compute yours. Example shown.