Security

Security

What is really Robin Hook, how to spot a copy, and how to tell us about a problem.

Official identity

WhatOfficial value
Websiterobinhook.lol (and its docs subdomain)
X accountx.com/robinhooklol
ChainRobinhood Chain, chain id 4663
$HOOK token0x5b146A9257C837c2d24A87742DbdEa6459Fa540aTrade on Robin Hook
Launchpad0x9b1aE2b752E3322fF814Ee7c0D458634356Dc7F9
Hook0x088135D91532f16e93A744394415748d414FeAcC
Router0xFDE55FD62467A061Ee20634583eCaAfB2eBf8E08

Every other contract is listed on the Contracts page. A token's identity is its address plus its chain. Names, symbols and logos are chosen by whoever launches, so many tokens can share them.

Impersonation warning

Copies of Robin Hook and of $HOOK exist. Robin Hook never DMs you first, never runs a presale or private sale, never offers support in DMs and never asks for your seed phrase or private key. Any "$HOOK" with an address other than the one above is not ours, and any site other than robinhook.lol that asks you to connect a wallet as Robin Hook is a phishing site.

Check before you sign

  • The address bar says robinhook.lol.
  • Your wallet shows Robinhood Chain and a contract from the table above (or the token you meant to buy).
  • You never approve more than the trade needs, and you never sign a message you can't read.
  • The token page shows the token's hooks; read them before you buy. Some cap buys or lock sells for a while.

Report a problem

Found a bug in a contract, a vulnerability in the site, or an account pretending to be us? Send a DM to @robinhooklol with what you found and how to reproduce it. Please don't post an unfixed vulnerability in public, and don't test against other people's funds. The machine-readable contact is at /.well-known/security.txt.

Note

Every contract is source-verified on Etherscan and went through internal audit rounds; an external audit is planned. Admin rights sit with a multisig, and nobody can remove a pool's locked liquidity.