burrow.
Burrow's mole, wearing a headlamp
Proofs for Robinhood Chain tokens

Dig, don't trust.

Airdrops, burns, transfers and holder snapshots, proven from the chain's own roots. Burrow walks the Merkle tries down to the value and hands you a certificate anyone can re-check. No API to believe, no explorer to screenshot.

Live · this block, re-hashed by your browser
block
reading the chain…
connecting
10 m · topsoil

Every token runs on trust me.

A dev says the airdrop went out. A team says the supply was burned. A screenshot of an explorer says you held on snapshot day. You are asked to believe a sentence, an image, or a spreadsheet, and none of them can be checked by the people they affect.

dev · 2hAirdrop done. Every holder from the snapshot got paid, check your wallets.
team · 5hWe burned 40% of the supply tonight. Tx in bio.
holder · 1dI held since day one, here's my screenshot, where's my allocation?
launchpad · 3dSnapshot taken at block 79,069,447. List attached as CSV.
What Burrow hands back instead
  • A proof, not a picture. Each fact is cut out of the chain's state, receipts or transactions trie with every hash on the way down.
  • Checked where you are. The maths runs in your browser or your terminal. Burrow's servers are not in the loop, because there are none.
  • One file to share. A certificate carries its own evidence. Anyone can open it later and re-derive the same answer, or catch the lie.
55 m · rock

Three roots, three kinds of truth.

Inside the header sit three 32-byte roots. Each is the top of a Merkle Patricia trie, a tree where every node is named by the hash of its children. Burrow picks the root that holds the fact you care about and digs from there.

block headerkeccak256 → block hash
stateRoot

What is

Every account and every storage slot: balances, total supply, contract code. Read at one block.

holdingsnapshotburn
receiptsRoot

What happened

The outcome of each transaction, with every log it emitted. A Transfer event lives here, forever.

transferairdropburn
transactionsRoot

Who asked

The signed transactions themselves. Ties a transaction hash to its exact place in the block.

transferairdrop
80 m · deep · bring a light

Follow one balance all the way down.

Pick a token and a wallet. Burrow asks the public node for the proof, then walks it itself: state root, account, storage root, the balance slot. Every chamber below is a node whose hash must equal the pointer in the one above. Move your pointer to light the walls: there are fossils down there.

Dig a balance
fossil · nibbleA trie key is read four bits at a time. Sixty-four steps would reach the bottom; real proofs need about eight, because branches fork early.
fossil · inline nodeA node shorter than 32 bytes is not hashed. It is written straight into its parent, so a proof can be one node shorter than the path.
fossil · slot 0Solidity keeps balances[holder] at keccak256(holder ‖ slot). Burrow finds the slot by asking the contract, then never trusts that answer again.
fossil · 126 blocksThe public node forgets old state after about 126 blocks, half a minute. Live proofs are cut at the freshest block and kept forever in the certificate.
110 m · bedrock

What comes up is a certificate.

The certificate is a small JSON file: the claim, the block headers, and every trie node on the way down. It needs nothing else. Open it next year on a laptop with no internet and the same checks run; give it a connection and Burrow also confirms the blocks are still the chain's blocks.

burrow.certificate of transfer

loading a recorded certificate…

  1. Re-hash every header. The claimed block hash must come out.
  2. Walk every proof. Each node's keccak256 must match the pointer above it, from the root to the value.
  3. Re-derive the claim. Burrow ignores what the certificate says happened and rebuilds it from the proven logs and slots.
  4. Anchor, if online. Ask the chain whether those block hashes are still canonical.
One engine

Three ways in.

The app, the command line and the SDK run the same verification code, file for file. A certificate made in one is checked identically in the others.

Nothing to install. Every proof is walked in the page, against the public Robinhood Chain node, and the result can be downloaded or shared as a link.

Open the app
# prove every Transfer in a transaction
$ burrow transfer 0x1046…5432

# snapshot all holders, write a CSV next to the certificate
$ burrow snapshot 0xd219…b609 --csv holders.csv

# re-check a certificate someone sent you
$ burrow verify burrow-snapshot-79140912.json
See it run
import { createClient, proveHolding, verifyCertificate } from '@burrow/core';

const chain = createClient();          // Robinhood Chain public RPC
const cert  = await proveHolding(chain, token, wallet, { atLeast: 10n ** 21n });
const r     = await verifyCertificate(cert, { client: chain });

r.ok;            // every hash on the way down matched
r.facts.balance; // re-derived from storage, not from the claim
SDK reference
Honest ground

What Burrow will not pretend.

No balances in the past.

The public node keeps state for about 126 blocks. Balance proofs are cut now and stay valid forever; a balance at last month's block needs an archive node.

Standard tokens only.

Balances must live in a mapping Burrow can locate. Rebasing tokens, share based vaults and packed layouts are refused, not guessed.

Completeness needs the supply.

A snapshot is called complete only when its proven balances add up to the proven total supply slot. Otherwise it says so.

Anchoring trusts a node.

Offline, a certificate proves internal consistency. "Canonical block" is confirmed by asking an RPC; Burrow says which one it asked.

Questions from the surface

Before you pick up a shovel.

Isn't this what an explorer shows?

An explorer shows you its database. Burrow shows you why the chain itself agrees, with the hashes that link the answer to a block header. If an explorer, an API or the RPC lied, the proof would fail to connect.

Tokens on launchpads are standard. Why verify anything?

The contract can be perfectly standard while the story around it is not: who received the airdrop, whether the burn happened, who held at snapshot time. Burrow verifies the events and balances, not the contract code.

Do I need a wallet?

No. Burrow only reads. It never asks to connect a wallet or sign anything.

Which chain?

Robinhood Chain (chain id 4663), an Arbitrum Nitro chain. The engine handles its system transaction types, so transaction hashes can be bound to blocks, not just events.

How big is a certificate?

A transfer is around 15 KB and fits in a share link. A snapshot of a few hundred holders is a few hundred KB and travels as a file.

Is the code open?

Yes, MIT. The engine has no dependencies: keccak256, RLP and the trie walk are written out in plain JavaScript so you can read every line that decides "verified".