Capital fragmentation
Stablecoins on one DEX, spot on another chain, stocks at a broker, hedges on a derivatives venue. Capital in one place cannot support a position anywhere else, so everyone over-collateralizes.
Trade crypto, tokenized equities, ETFs, indices, commodities and FX through one unified onchain account. Professional order-book execution, self-custody, transparent risk and programmable liquidity in a single multi-asset protocol.

Rivora is an independent proposed protocol. It is not operated, endorsed, sponsored, guaranteed or affiliated with Robinhood Markets, Inc. or its affiliates.
Crypto traders use one platform for spot, another for perps and a third for yield. Equity investors sit in brokerage accounts with their own hours and settlement. Every platform keeps its own balance, margin, interface and liquidity.
Stablecoins on one DEX, spot on another chain, stocks at a broker, hedges on a derivatives venue. Capital in one place cannot support a position anywhere else, so everyone over-collateralizes.
Crypto, equities, ETFs, FX and commodities live behind different venues and infrastructure. Even tokenized, their liquidity and UX stay isolated.
Onchain trading asks you to choose: a simple but limited AMM, or a professional order book with unclear custody and settlement.
Centralized venues hide leverage and liabilities. Many DEXs are transparent at the contract level yet unreadable for users. Health, thresholds, oracle state and reserves should be visible in the interface.
Market closures, corporate actions, regional eligibility, issuer restrictions, delayed reference prices, dividends and session gaps. Rivora treats these as core requirements, not afterthoughts.
Rivora unifies these markets: one non-custodial account, one risk engine, professional execution, and risk rules you can read.
Robinhood Chain already has perpetual protocols. Rivora's defensible position is a chain-native cross-asset liquidity and portfolio-margin layer: the bridge between crypto-native liquidity and tokenized financial assets.
Leveraged long and short exposure
Direct asset exchange and collateral acquisition — Uniswap V2 pools on Robinhood Chain
Shared collateral across approved markets
Transparent automated strategies
APIs and contracts for external applications
Every group gets its own collateral factors, leverage ceiling, position limits, oracle requirements and liquidation rules. Long-tail markets never share the core insurance pool.
BTC, ETH
Deepest books, continuous reference pricing, cross-margin eligible after the isolated phase.
SOL, ARB, LINK
Established alts with real spot liquidity. Lower leverage, tighter OI caps, extra oracle-deviation checks.
tSPY, tNVDA, tTSLA
Only when issuer terms, oracle data and regional access permit. Corporate-action and stale-price protection.
XAU, EURUSD, NDX
Cash-settled synthetic exposure, multiple reference sources, session-aware funding and isolated insurance.
Anything with a bond
Isolated collateral and liquidity, strict caps, creator bond. Never touches the main cross-margin pool.
Illustrative launch parameters. Final values require quantitative risk testing and governance approval.
Any Robinhood Chain wallet. Nothing leaves your keys.
Optional ERC-4337 account: gas sponsorship, batching, session keys with expiry, notional caps and no withdrawal rights.
One approved settlement asset at launch. The interface shows available margin, equity, liquidation distance and max order size.
Spot or perpetual, tiered by risk. Session-aware markets show their state before you size up.
Isolated first. Cross and portfolio margin arrive as separate, proven upgrades.
Market, limit, stop, take-profit. Reduce-only, post-only, GTC or IOC.
The risk engine simulates the order. Rejected? Reduce size or add collateral, then retry.
A typed EIP-712 order: account, market, side, price, size, time-in-force, nonce, expiry.
Relayers find execution; contracts verify signature, nonce, balances and limits before updating your account onchain.
Monitor PnL, funding and health. Modify, close, realize PnL, reuse collateral or withdraw.
Then reuse the collateral anywhere in the account.
Matching runs on high-performance relayers; custody, margin, positions, settlement, liquidations and withdrawals are enforced by contracts. More feasible for a first EVM deployment than promising a fully onchain high-frequency order book before the infrastructure exists.
If an indexer fails, users can still verify state and withdraw through the contracts or a minimal recovery interface.
Rivora starts with isolated margin. Cross-margin and portfolio margin ship as separate upgrades, only after risk performance is proven. The formulas below run in the terminal and in the relayer.
Healthy. Equity ÷ maintenance margin.
Equity = Adjusted collateral + Σ uPnL − fees − accrued funding
Initial margin = Σ (notional × IM rate)
Maintenance = Σ (notional × MM rate × risk multiplier)
Health = Equity ÷ Maintenance margin
| Collateral type | Conceptual treatment | Main risks |
|---|---|---|
| Approved stablecoin | Lowest haircut | Depeg and issuer risk |
| ETH or BTC representation | Moderate haircut | Volatility and bridge risk |
| Tokenized ETF | Asset-specific haircut | Session gaps and issuer restrictions |
| Tokenized single stock | Higher haircut | Concentration and corporate actions |
| Long-tail token | Isolated or ineligible | Liquidity and manipulation |
One dollar of volatile collateral never buys one dollar of borrowing power. Correlation benefits in portfolio margin are capped because correlations break under stress.
Rivora prioritizes partial liquidation and orderly deleveraging over immediate full account closure. The risk engine recalculates health continuously; every step down the ladder is visible in the terminal before it happens.
Health above warning threshold
Account trades normally.
Health below 1.25×
Interface warns; risk-increasing orders restricted.
Equity below maintenance margin
Cancel open risk-increasing orders.
Attempt to restore health
Reduce a slice of the position at mark price. Restored? Back to active.
Partial reduction insufficient
Liquidation auction or backstop vault takes the remainder.
Residual loss
Market-specific insurance reserve absorbs the deficit.
Reserve insufficient
Documented auto-deleveraging rules apply — never silently.
Primary feed, secondary reference and venue data flow through an adapter that checks freshness and deviation. Pass: compute index and mark. Fail: protective state — reduce leverage, block new risk, or pause settlement. The protocol never silently continues liquidations on stale or contradictory data.
Loading oracle telemetry…
Tokenized assets need a dedicated state machine. The existence of a token on Robinhood Chain does not make it eligible: Rivora reviews token contracts, transfer restrictions, issuer terms, oracle licensing, jurisdiction and user eligibility before enabling any market.
Underlying market open. Normal trading parameters, continuous pricing and funding.
state · open
Scheduled close. Lower leverage, higher margins, smaller max order, wider protection bands, tighter OI caps.
state · after_hours
Halt or stale feed. Block new risk or pause the market; resume only after feed and risk validation.
state · protective
Adjustment review and public notice. Contract specification adjusted deterministically with an onchain record.
state · corporate_action
Every adjustment gets a public notice period when possible, deterministic calculation rules, and an auditable onchain record.
Funding keeps a perpetual near its index and is exchanged between longs and shorts — it is not protocol yield. It considers the premium, the index, time-weighted observations, bounded rates, market-specific intervals, open-interest imbalance and protective rules during oracle disruption. For RWA-linked markets the parameters differ between the underlying's open and closed sessions.
Professional market makers and community vaults feed the order book; cross-chain deposits feed collateral. Trading fees flow back to market-maker incentives, the insurance reserve, security and operations, and the treasury. Raw volume is a poor incentive metric — it invites wash trading.
Vault deposits are at risk. Never marketed as guaranteed yield.
Quotes both sides of approved markets.
Captures spot–perpetual basis.
Offsets direction while pursuing fees or funding.
Tracks a defined crypto or RWA basket.
Capital for discounted liquidations under strict limits.
Vault lifecycle: proposal → code, permissions and risk review → guarded deployment with deposit cap → public monitoring → limits scale only if performance and risk stay acceptable; otherwise freeze deposits and unwind.
Illustrative launch ranges — product assumptions, not commitments. Final fees depend on liquidity, market-maker agreements, infrastructure cost, risk and regional requirements.
| Activity | Range |
|---|---|
| Core crypto maker fee | rebate → 2 bp |
| Core crypto taker fee | 4 – 7 bp |
| RWA-linked taker fee | 6 – 12 bp |
| Liquidation penalty | 0.5% – 1.5% |
| Vault performance fee | 10% – 20% of positive performance |
No fixed revenue or guaranteed returns are promised to any token holder without appropriate legal analysis.
Rivora should prove product demand before a token becomes central. If introduced, it carries operational utility — never equity, ownership in Robinhood, guaranteed revenue or a guaranteed appreciation mechanism.
| Allocation | Share | Suggested release |
|---|---|---|
| Community & trading incentives | 35% | Multi-year, performance-based emissions |
| Ecosystem treasury & grants | 20% | Governance-controlled and transparent |
| Core contributors | 18% | 12-month cliff, then 36-month vesting |
| Liquidity & market-maker programs | 15% | Milestone and liquidity-quality based |
| Strategic partners & backers | 8% | 12-month cliff, then 24–36-month vesting |
| Security & insurance reserve | 4% | Restricted emergency or security use |
Volume is never rewarded without measuring whether it provides real market utility.
The MVP's objective is to validate execution quality, risk controls, market-maker demand and user retention — not to list every market as quickly as possible.
Governance decentralizes progressively: early multisig powers, signers, timelocks and upgrade paths are public; emergency actions expire unless confirmed. Success is measured on liquidity quality and account health, never raw volume alone.
Proposal → technical and economic review → public discussion → routine vote or risk-council recommendation → timelock → onchain execution → post-execution monitoring. Emergency actors may pause new risk, disable a compromised oracle or cap a market — never withdraw user assets.
The name reads as a trading terminal today and a market network later, and deliberately avoids putting “Robin” or “Hood” in the brand so nobody mistakes it for an official product. Name, domains, handles, ticker and trademarks still need a professional availability review before launch.

One locked reference sheet drives every pose, expression and banner on this site, so the guide is the same person wherever she appears. She reacts to real numbers rather than decorating them — the face beside the margin lab reads the health figure the reader is moving.
Dark mode re-steps these against the dark surface rather than inverting them, so blue stays the accent in both themes.

Same chrome, same risk engine, live data. Connect a wallet, sign a typed order, watch the account health meter move. Testnet collateral is credited automatically.