Alma Bond / protocol v1
Held by you.Revealed on your terms.
Wrap supported assets into Alma Bonds. Hold, transfer, and redeem through a verifiable protocol, with disclosure defined by the capabilities of each bond.
Everything about a bond is public on chain. The secret is not.
Protocol / three moves
A bond does three things. You start each one.
- 01one transaction
Create
Deposit a supported ERC-20 token. Before the deposit, your browser makes the receipt: 32 random bytes that stay with you. The contract records your address, the token, the amount and a hash of those bytes.
createBond(token, amount, commitment)
- 02two transactions, two wallets
Hold
The bond is yours while your address owns it and you hold its receipt. To hand it over, you propose a recipient and they accept from their own wallet with a receipt of their own. From that block on, yours opens nothing.
proposeTransfer → acceptTransfer
- 03a signature, or one transaction
Reveal
What you disclose, and when, is your move. Sign an ownership attestation for one verifier, or redeem: that publishes the receipt secret, closes the bond and pays the exact amount to the address you name.
redeem(bondId, secret, payoutTo)
“Bond” here means an asset-backed position in this application: a deposit held by a contract for its owner. It is not a debt instrument and it pays no interest, no yield and no return. It gives back what was put in.
Bond / what it contains
Six parts. Five of them anyone can read.

One ERC-20 token from the escrow’s allowlist and the exact amount that arrived. The contract holds it and owes exactly that amount back, once.
In the artwork: the yellow circle
Boundaries / what it does and does not do
The bond is public. The secret is yours.
This release implements one mode, public escrow with receipt-gated redemption, and says exactly what it is. A hash on chain does not hide a deposit, an amount, an address or a transaction history, and this protocol does not claim that it does.
Public escrow bonds
Deposit an allowlisted ERC-20 token, get a bond, redeem the same amount once. Redemption needs the owner address and the receipt secret together.
Available
Recipient-accepted transfer
The owner proposes, the recipient accepts with a fresh receipt, ownership and receipt change in one transaction. Passing a receipt file around is not a transfer.
Available
Receipt rotation
Replace a bond’s receipt with a new one when the file may have been exposed. The old receipt stops working in the same transaction.
Available
Ownership Attestation
A signed answer to a verifier’s challenge, checked against the contract at one block. It is a signature, not a zero-knowledge proof: the signing address is visible.
Available
Private bonds
Hiding amounts or owners needs a complete, reviewed protocol: commitments, membership proofs, nullifiers and a verified proof system. None of that exists here, and nothing in this app stands in for it.
Not available
Who can see what
Three columns, one bond. The middle one is short because nearly everything is public; what it holds is the part that gates redemption.
| Public on chain | Stays on your device | Becomes visible when you redeem | |
|---|---|---|---|
| Token and amount | Public from the moment the bond is created. | Nothing to keep. | Already public. The payout is a public token transfer. |
| Owner address | Public. The address that deposited, and every address the bond is transferred to. | Nothing to keep. | Already public. The redeeming address is the owner. |
| Transfers | Every proposal, cancellation and acceptance is a public transaction with both addresses in it. | Nothing to keep. | Already public. |
| Receipt commitment | Public. A hash; it hides the secret and nothing else about the bond. | Also written in the receipt file. | Already public. |
| Receipt secret | Not on chain while the bond is held. | In the receipt file you download and, encrypted, in this browser. Never sent to a server by this app. | Published in the redemption transaction, and spent by it. Transferring or rotating publishes it the same way. |
| Payout address | Not known before redemption. | You choose it when you redeem. | Public, as part of the transaction you sign. |
| Ownership attestation | Not on chain. It is a signed message. | You hold it and decide who receives it. It shows your address and the bond number, which are public anyway. | A redeemed bond has no owner, so an attestation for it no longer verifies. |
The reasoning, the threat notes and the limits are in the privacy model.
Token / the project token
$ALMACHAIN
CA: Soon
ERC-20 · Robinhood Chain · chain id 4663
- The protocol
- $ALMACHAIN has no role in the Alma Bond protocol. The escrow contract, AlmaBondEscrow, does not reference it. Bonds do not require it, pay it or accrue it.
- The address
- Not published yet. When it is, it appears in this section. Until then, no contract is $ALMACHAIN, whatever name or symbol it carries.
- Copies
- Tokens on Robinhood Chain can take any name and symbol, ALMACHAIN included. An address is $ALMACHAIN only when this site shows it: compare every character before you use one.
App / enter
Make the first one.
Connect a wallet, choose a token and an amount, save the receipt, deposit. The app shows each transaction before you sign it and reports a result only once the chain has confirmed it.
This build, right now
- Network
- Robinhood Chain · chain 4663
- Environment
- production
- Escrow contract
- deployed
- Bonds created
- reading the chain
- Read at
- not read yet
- Audit
- none