Systematic liquidity provision against reference-price dislocations in tokenized equities
Arbitrage Ape is an autonomous market-making desk on Robinhood Chain. It prices every venue against the primary market, holds inventory where dislocations happen, sells into verified dislocations under strict profit rules, and pays 75% of realized profit to holders every 15 minutes once at least $300 is owed, keeping 25% as a desk reserve that absorbs pool losses. This document states the method, including the parts that are usually left vague, and every number below is read from the same configuration the running desk uses.
1The market microstructure premise
Tokenized equities on Robinhood Chain trade across a fragmented set of venues: Uniswap v3 pools at four fee tiers and Uniswap v4 pools at standard keys, quoted in USDG, in ETH, or in other stock tokens. Fragmentation plus thin depth produces a recurring phenomenon: a single aggressive order in a shallow pool moves its marginal price far from the value of the underlying share. That is a dislocation. With no resident market maker, it persists for minutes to days.
A dislocated pool is not an anomaly to be lamented; it is an inventory-constrained profit opportunity. Whoever already holds the asset when the dislocation appears is the counterparty of record. The desk's entire design reduces to one sentence: be the standing inventory in every instrument where dislocations occur, and be the fastest disciplined seller when they do.
2Reference pricing
For each instrument i the desk maintains a reference price P̂ᵢ(t) from the issuer's consolidated primary-market quote (bid/ask midpoint, multiplied by the token's corporate-action multiplier), refreshed every 15 seconds, with Chainlink tokenized-equity feeds as the fallback and a live Chainlink ETH/USD conversion for ETH-quoted venues. For a pool p holding instrument i, the instantaneous deviation is
Outside the primary session (09:30–16:00 New York, weekdays) P̂ is stale by construction; the desk widens every actionable threshold by a session premium θ rather than pretending the reference is live. Deviations in the parking band (below -95% or above +5,000%) are classified as structural artifacts (pools initialized at boundary prices) and discarded before they consume analysis.
3Fillability: the anti-mirage test
Displayed price is not evidence. Many pools advertise spectacular deviations against which no trade can execute. The desk therefore admits a dislocation only after a fillability probe: a quoted liquidation of a fixed notional q₀ (at reference) through the pool's own execution engine (Uniswap's QuoterV2 or the v4 Quoter), fees and impact included. Defining the probe yield
a pool qualifies as a real dislocation iff δₚ ≥ δ* and Φₚ ≥ φ_min. The economic logic is exact: a genuine pump deposits the aggressor's own quote asset into the pool, so a genuine pump is always fillable; a mirage quotes nothing. Probe results are cached per pool and invalidated on a ±2% deviation movement, so the fleet of static artifacts is paid for once.
4The liquidity survey and the eligible set
Daily, every instrument is classified by its impact function, the premium over reference paid by simulated aggressions of increasing notional through its best venue:
Instruments where I(10⁴) ≤ 0.25% are deep: dislocations there are arbitraged away before inventory can monetize, so they are excluded from the program entirely. Instruments where I(10³) exceeds 0.5% (or where a $1k order cannot fill at all) are the eligible set: markets where a four-figure order visibly moves price, which is precisely where five-figure dislocations are born. Tokenized ETFs are excluded categorically, as are operator-blocked symbols; the operator may also pin instruments into the set on discretionary information. Classification is re-estimated every 24 hours because thinness is a state, not a property.
5Inventory construction
Capital enters as protocol fee flow. $AA launches on Pons v2 quoted in USDG; the vault is the launch's creator-fee recipient, so the creator share of every trade on the bonding curve and, after graduation, on the locked Uniswap v4 pool accrues in USDG to the Pons fee escrow, and the keeper sweeps and claims it into the vault every five minutes. Deployment is a capacity-weighted round robin: given deployable budget C (cash less profit already owed to holders) and a minimum viable clip c_min, a pass executes
rotating through the eligible set with a persistent cursor, so every instrument receives inventory before any receives twice. Each purchase routes through the best of all venues for that instrument and executes only at P_eff ≤ P̂ · (1 + α). The desk never pays a premium to acquire what it intends to sell at one. Entries run on a fixed cadence (T+5m, T+15m, then every 30 minutes) so fee flow converts to standing inventory within the hour it arrives.
6Execution against a dislocation
When a held instrument prints a real dislocation, the desk sizes the maximum liquidation S* whose effective price, after pool fee and self-impact as quoted by the venue itself, clears the floor:
where B̄ is the position's average cost basis. The desk sells strength; it does not realize losses into noise. Each order additionally requires an absolute profit increment π ≥ π_min over max(reference value, basis), carries a slippage-bounded minimum output (1%) so a moved market reverts rather than fills badly, and settles against the vault's wallet delta: the quote predicts, the balance decides.
Exits are distributed, not slammed: at most a fraction τ of S* per order, one order per instrument per cooldown window Δt. A persistent dislocation is harvested across hours, each tranche re-sized against the pool's remaining depth, so extraction decelerates as the pool drains and the market is left visibly bid. A fading dislocation simply stops qualifying, and the remaining inventory is kept for the next event.
Where a pool carries real volume at a persistent premium, the desk also stands as passive liquidity: several Uniswap v3 bands, one per configured pool (AMC/USDG at $500), each managed on its own whichever side of the pool the stock sorts to. A USDG-only band is placed entirely below the pool price,
so it fills only as the premium unwinds, never buys above spot, and earns the pool fee on every fill in either direction. Fees are collected every 15 minutes into the vault as realized profit, so they enter the same payout pot as sales. If the pool falls through the band the position has become all stock: it is closed and the shares join inventory at cost, where the exit desk sells them into the next spike. If the pool runs 10% above the band the position is idle USDG: it is closed and re-placed under the new spot. Exposure is capped per pool, not per position: stock from earlier bands still in inventory plus a new band's deposit never exceeds $750 for AMC, so the desk can never buy the premium down a band at a time.
A band can instead run two-sided (LP_MODE=two-sided): a band centred on the pool price, ±5%, funded half in USDG and half in the stock drawn from the desk's own inventory, so it earns the pool fee on flow in both directions and is closed and re-centred once the pool has sat outside it for 5 minutes. On close the stock rejoins inventory at the cost basis it left with; whatever the band net-sold on the way is realized against that basis and whatever it net-bought joins inventory at what the band paid.
A third shape, above, is a ladder of asks: stock the desk already holds, placed alone from a little over the pool price up to a ceiling, so every tick up sells a slice at a higher price and earns the pool fee on the fill, and a falling price fills nothing and buys nothing. It has no max-loss guard (the desk owned the stock already) and does not chase the price down unless told to; once the pool has sold through the top the USDG comes back as cash, the stock's result against its cost is booked on the fund's own line (not the holder pot), and a new ladder is placed from the new price while inventory still holds any of the stock.
The desk also watches who else provides liquidity on the hot pools. Every liquidity add and remove on those pools is attributed to the wallet behind it and valued at the pool price of that moment, and every swap credits the positions in range with their share of the fee. A wallet's score over the last seven days is what it withdrew minus what it deposited, plus its open positions at the current price, plus the fees credited to it; only positions opened and closed inside the window count as wins or losses, so a wallet that merely sits in a pool is followed but not judged. A wallet is marked smart when it is a consistent winner over the window, not a lucky one. Contracts are tagged as bots and the desk's own wallet as desk, so the tracker never scores itself. The pools board shows, per band, how many smart wallets sit in the pool right now and what they hold, and how many entered or left in the last hour; the hot pairs table carries the same count. A pool the smart money is sitting in is worth a look; a pool it just left is a warning.
From the same hot-pool index and smart-LP tracker the desk raises opportunity alerts: pools where a $6k band looks like the most profitable place to be right now. A pool qualifies when it is hook-free with a real LP fee, has traded at least the configured hour of volume, holds liquidity within ±5% of the price under the cap, still trades above 60% of its 24 h peak, is at least 20 minutes old, and the smart-LP tracker shows liquidity providers winning in it. The alerts table at the top of the hot page carries each pool's share and fee estimate at $6k, why it qualified, and the band line the operator would add. A pool that stops qualifying fades on the board rather than vanishing and stays there for 24 hours, so a spike that has passed is still readable. The desk never opens a band from an alert on its own: every one is a decision for the operator.
The desk also reads Brew, the creator-token launchpad on BNB Smart Chain, where every launch is a PancakeSwap v3 pool at a 1% fee with its launch liquidity locked in a single position from the opening price upward. The desk holds nothing on BSC and places no band there; the Brew board is read-only, and it gives each launch the same read the hot page gives Robinhood Chain pools. For every pool the scanner takes the liquidity within ±5% of the price from the pool's active liquidity on-chain and works out the share a $6k band would take of it,
and from that share what the band would have earned in each window: volume × 1% × share, over the last 5 minutes, hour, 6 hours and 24 hours. Prices, volume and liquidity are read from the pools' own market data; the share and the fee estimates are what a band would have faced, not what the desk earned. A launch whose fee estimate holds up across windows, on liquidity that is not about to unlock, is a candidate for the first band the desk places there.
7Profit accounting and the distribution
Profit is a ledger identity, not an estimate. Every liquidation realizes proceeds minus the average cost basis of the size sold; lifetime realized profit Π(t) accumulates monotonically. With D(t) the cumulative amount already distributed, holders are owed
This balance carries forward and never resets. Of each increase in realized profit, 25% is moved to the desk reserve R (it absorbs losses on the pools and is never paid out); O is realized profit less R less what has been paid. Every 15 minutes the desk pays min(O, cash) in USDG, pro-rata over an eligibility-filtered holder snapshot: for holder h with balance bₕ,
The snapshot is reconstructed from the token's complete Transfer history maintained locally, never an indexer, and spot-verified against chain state before any value moves. AMM reserves, protocol machinery and desk addresses are excluded from the eligible supply; sub-dust allocations remain in the pot.
8Custody and the execution agent
All capital (fee inflow, cash, inventory) is custodied by a single on-chain fund contract, publicly auditable in real time. An autonomous execution agent (the keeper) runs the entire operation against that contract: it surveys venues, routes orders, and triggers the distribution, while the contract constrains every action it can take. The agent itself holds nothing; every balance lives at the fund address. Properties, stated as held:
| Invariant | Mechanism |
|---|---|
| All balances live at one address | Inventory, cash and fee inflow settle at the fund; the agent's wallet carries only gas |
| The agent trades only sanctioned venues | exec() reverts on any target outside the allowlist |
| Approvals cannot leak | Token approvals are spender-gated to the same allowlist |
| Distribution is rate-limited | Per-asset rolling 24h cap, contract-enforced |
| The agent is replaceable in one transaction | Rotation is a single transaction; custody is unaffected |
| The owner can withdraw | The vault owner (the deployer wallet) may withdraw any asset at any time with no timelock; the keeper cannot. This is stated here rather than discovered on the explorer |
9Operating parameters
| Symbol | Meaning | Setting |
|---|---|---|
| δ* | Minimum actionable deviation | +25%, unbounded above |
| θ | Closed-session threshold widening | +10% |
| δ_h | Exit threshold for instruments the desk holds | +8%, if depth clears the floor |
| d_min | Sellable depth for a dislocation to count as real | $100 above the floor |
| q₀ , φ_min | Fillability probe notional / minimum yield | $50 / $25 |
| ε | Execution edge over reference | 5% |
| π_min | Minimum profit per order | $2 |
| τ , Δt | Tranche fraction / cooldown | 20% / 2 min |
| c_min , κ | Minimum clip / per-instrument cap | $100 / $250 |
| α | Maximum acquisition premium | 2% |
| δ_ref , δ_spot | LP band margins over reference / under spot | 1% / 1% |
- Venue sweep cadence every 15 seconds, full set ≈ 5 min
- Distribution cycle every 15 minutes
- Liquidity survey every 24 hours; venue rediscovery every 6 hours
Parameters are operating policy, not physical constants; the desk publishes them so its behavior is predictable to the market it serves.