Security and roles
This page explains where the money is, who can do what, and what Robinhood controls.
Where the money is
- Employer deposits sit in the Work2OwnEscrow contract as USDG. work2own's admin cannot withdraw USDG from the escrow: the only admin rescue function refuses USDG.
- USDG leaves the escrow only as a worker payout, a refund to the employer who deposited it, or a pending refund withdrawn by its owner.
- The platform fee is sent to the treasury when a quest or gig is funded. It is not held in the escrow and is not refunded.
- Stock payouts are swapped and sent to the worker in one transaction. No contract of work2own keeps stock tokens.
- The contracts are deployed directly, without an upgrade proxy. Their code cannot be changed.
What the admin can do
The admin wallet (0x5Dd2…D562) holds the admin role of both contracts. It can:
- pause and unpause the escrow (see Pause);
- set the platform fee, up to a hard limit of 5%;
- set the maximum deposit per quest or gig;
- change the treasury address that receives fees;
- add, change or disable payout tokens, including each token's pool, price feed and maximum price age, and set the slippage allowance (hard limit 5%) and the per-payout cap for quote-protected tokens;
- grant and revoke all roles, including operator and arbiter;
- recover tokens other than USDG sent to the escrow by mistake.
The admin cannot withdraw USDG from the escrow directly, but it controls the settings that protect stock payouts and who holds the operator and arbiter roles.
Changing the fee or the maximum deposit only affects quests and gigs funded afterwards. Disabling a token does not change payouts already chosen in it, but a pending payout in a disabled token cannot run; after 3 days its worker can switch it to another token or USDG.
What the operator can do
The operator bot (0x0eF9…231c) can:
- complete or reject submissions of automatic quests;
- run pending payouts, supplying the price quote.
It cannot approve or reject manual quests, approve, reject or cancel gigs, settle disputes, change a payout's token, move refunds, or send any payout anywhere except to the worker it belongs to. Like anyone, it can release a manual quest or a gig after the 7-day review window, which it does automatically.
What this means for you:
- Automatic quests rely on the operator's checks, described in Automatic verification.
- If the operator stops, automatic quests stall: submissions stay waiting, and the quest cannot be closed and refunded until an operator acts again. The admin can appoint a new operator wallet. A time-based fallback is planned for the next escrow (see Roadmap).
- Most other things keep working without the operator: employers can approve, workers can release their payment after 7 days, employers can close ended quests, and workers can run their own payouts with Try now or switch tokens after 3 days. Try now uses a price quote from the work2own API. Expired reservations in a full quest are freed by the operator; the app has no button for that.
- For quote-protected tokens, the minimum price comes from the quote in the transaction (the operator's or the worker's), and the contract cannot check it against an oracle. This is why those payouts are capped at 25 USDG each.
A watchdog on the work2own server checks the operator, the API, the indexer, the RPC connection, the operator's gas balance and the database backup every 5 minutes and alerts work2own when a check fails. Because it runs on the same server, a full server outage is noticed only from outside.
What the arbiter can do
The arbiter (0xf4af…2Aeb) can only settle disputed gigs, by splitting the budget between the worker and the employer. Only the arbiter can settle a dispute, and the contract sets no deadline for it.
What Robinhood controls
Stock tokens are issued by Robinhood, and Robinhood keeps powers over them that work2own does not control:
- pausing a single token, its price oracle, or all stock token transfers;
- blocking addresses from holding or receiving stock tokens;
- upgrading the logic of all stock tokens;
- burning tokens from any address: the token contracts include an
adminBurnfunction.
work2own checks the pauses and the block list before every swap. If one of them applies, the payout stays pending in USDG instead of failing.
Pause
When the admin pauses the escrow:
- still possible: reserving slots, submitting quests and gigs, freeing expired slots, and rejecting within a review window. Time-limited actions keep working so that a pause never makes a worker miss a deadline or an employer miss a review window;
- waiting until unpause: creating quests and gigs, employer approvals, automatic verification, releases, closing quests, dispute settlements, cancellations, payouts, token switches and refund withdrawals.
The contract sets no maximum length for a pause. While paused, no USDG leaves the escrow.
The app shows a banner while paused.
Good to know
- Deposit cap. Each quest or gig is limited to 10,000 USDG of rewards or budget.
- Automatic verification only reads the transaction itself, not calls made through other contracts, token amounts or events. See what is not checked.
- Project verification proves control of a domain at the moment of the check; it is not re-checked later. It is not an endorsement.
- Country eligibility for stock tokens is applied by the app and the API when you choose a payout token. Robinhood's own terms and eligibility rules for stock tokens apply to you in any case.
- The indexer reads up to the latest block and does not handle chain reorganizations. If the app and the chain ever disagree, the contracts are the source of truth.
- Chain outages. Robinhood Chain runs a single sequencer. The 24-hour, 3-day and 7-day windows are measured in block time, so if the chain stops for a long time, that time still counts against a reservation or a review window once blocks resume.
Keys
The operator's key is kept in an encrypted keystore on the work2own server and loaded only by the operator service. The admin key is kept in an encrypted keystore, not in plain files. Neither key can take USDG out of the escrow directly. Because the admin can appoint operators, the trust you place in the operator for automatic quests is also trust in the admin.