Poncho → Risk
What can go wrong
Most products in this category bury their risk warning in capital letters inside the terms, where nobody reads it. This is a separate page because the risks are the most useful thing we can tell you. Read it before you send anything. If one item here makes you close the tab, it has done its job.
You can lose everything you put in, and most people who buy newly launched tokens do. Nothing here is reversible. Nobody insures it, no deposit-protection scheme covers it, and there is no authority to appeal to when a transaction goes through and the token goes to zero. Poncho does not reduce that risk. It makes some of it visible before you commit.
The token itself
Total loss is the normal outcome. Newly launched tokens overwhelmingly end at or near zero. Pons's own front page showed roughly 167,000 tokens launched by early September 2026 and about 2,300 graduated from the bonding curve — on the order of one in seventy. Graduating is not the same as being worth something, and most of the other sixty-nine never got that far. Assume yours is one of them and you will be right most of the time.
You may not be able to sell. A price on a screen is not a buyer. On a thin curve or after liquidity is withdrawn there may be nothing on the other side of your trade at any price.
The contract may be built to trap you. Transfer taxes, blacklists, pausable transfers, mint functions and a hundred variations exist and are used. Poncho simulates the sell path before it sends a buy, and where that exit can be simulated and comes back bad, the buy is refused. That catches the crude versions. It is a heuristic and it can be defeated by a contract designed to defeat it, and a clean check means one specific failure was not present at one moment — it is not a verdict on the token.
Where the exit cannot be quoted at all, the buy still goes ahead. We are telling you this because it is the part you would otherwise assume the other way round. The check does not treat "no answer" as "bad answer" — on a pool minutes old there is frequently nothing to quote against — so a buy that sails through may simply be a buy nothing could be measured about. Read a silent check as no information, not as a pass.
A token can impersonate anything. Names and symbols are free text. A token can carry the name of a real company, a real ticker or a well-known project and have nothing to do with it. Check the contract address, not the name.
The contracts underneath
Poncho does not own most of the code your money passes through, and neither do you.
- Pons v2 — the launchpad. Its own material asks to be treated as unaudited, and its documentation is not published. Two of the settings a launch asks you to fix forever are not described anywhere by its authors; what we know about them was read off real launches on chain.
- Upgradeable contracts. Some contracts in this ecosystem sit behind proxies their owners can upgrade. The rules that applied when you bought are not guaranteed to be the rules that apply when you sell.
- Admin keys. Where a contract has an owner, that owner can usually do things you cannot. This is normal, it is public on the explorer, and it is worth looking at before a large position.
- Poncho's own contracts are new software written by a small team. New code that holds money is the riskiest kind there is, and being ours does not change that. Treat it the way you would treat any contract you have not read yourself.
Trading through any router means granting that router permission to move a token from your wallet. The permission does not expire when the trade finishes. If the router is ever compromised, every approval still standing is a way into every wallet that granted one. This is not theoretical: in October 2023 a flaw in Maestro's router let an attacker use exactly those standing approvals, and about 280 ETH left users' wallets in one transaction. Maestro refunded 610 ETH to affected users afterwards, which is more than most teams do and more than you should count on; we mention the case because the point is the mechanism, not the company.
The mitigations are real but partial: approve the amount you are trading rather than an unlimited amount, and revoke approvals you are not using. Poncho will tell you which approvals you are carrying and how to remove them. No bot can make this risk zero while it routes trades.
Execution — what happens between "confirm" and "done"
The quote is an estimate. Price, gas and the amount you receive are computed before the transaction is included. All three can move between the preview and the block. Slippage limits cap how far, at the cost of the trade failing instead.
A failed transaction still costs gas. This is the most common surprise on day one. If a trade reverts, the network has already done work and keeps the fee for it. Poncho's own launch fee is a separate transfer taken only on success, so a failed launch does not pay us — but the gas is gone.
Ordering is not the protection people think it is. Robinhood Chain sequences transactions first-come, first-served by arrival time at the sequencer, and its documentation says a higher fee cannot buy priority. That removes the classic public-mempool sandwich, because there is no public mempool to watch. It does not remove everything: the sequencer operator sees your transaction before anyone else, whoever runs the endpoint you send through sees it before that, races are decided by latency, and Arbitrum-style chains can enable a paid express lane at the chain owner's discretion. Treat "you cannot be front-run here" as false, whoever says it.
The chain you are on
Robinhood Chain is operated by Robinhood, not by us, and its terms are worth reading once. Three things in them matter to you directly.
- No uptime guarantee. The sequencer can stop. Robinhood's terms say plainly that it does not guarantee availability and is not liable for losses from downtime. When the sequencer is down, nothing settles — including your exit.
- Addresses can be blocked. Robinhood reserves the right to restrict or block specific wallet addresses, at any time, without notice. Poncho cannot undo that and neither can you.
- The service can change or end. Robinhood may modify, suspend or discontinue the chain's services at any time and without notice, and its terms cap its liability at a nominal amount. Read them yourself rather than taking our word for it.
We are naming this because we depend on it and so do you. We cannot promise you more availability than our own supplier promises us, and nobody in this category discloses that.
Poncho is an independent product and is not affiliated with, endorsed by, or officially connected with Robinhood Markets, Inc. Built on Robinhood Chain. Nothing here is investment advice.
The dollar leg
Trades on Robinhood Chain frequently route through USDG, a stablecoin issued by Paxos. Paxos's own terms are explicit that it can freeze the token wherever it is held, that it must comply with a legal directive to freeze with or without notice, that assets can be seized or made permanently unusable, and that it is not liable to you for any of it. A stablecoin is a claim on an issuer that has told you in writing what it can do.
Your key, your PIN, and what we hold
This is the section where honesty costs us the most, so read it carefully.
Poncho stores encrypted key material on its server. Your PIN is not stored; it is what the encryption key is derived from, together with a random value stored beside the ciphertext and a secret held outside the database. To sign a transaction, the material is decrypted in memory, used, and discarded.
- Forget the PIN and the wallet is gone. Permanently. There is no reset, no support path, and no recovery. That is the direct consequence of not storing it. Anyone who offers to recover it for you is stealing from you.
- A server compromise is the largest single risk in the product. Not the chain, not the token — the server. An attacker who takes the database and the separate secret can attempt PINs offline, at whatever rate their hardware allows. That is why the PIN is long, why attempts are limited, and why balances are capped while Poncho is new. We will not tell you the database alone is worthless to an attacker, because whether that is true depends on a design detail, and we would rather you assumed the worst case.
- Your Telegram account is the front door. If someone takes over your Telegram — a SIM swap, a hijacked session, a stolen laptop — they are inside your bot. Turn on Telegram's two-step verification. This is the most under-disclosed risk in the whole category and it is entirely in your hands.
- You can export your key. It is your exit if we are down, blocked, or gone. It is also the moment you are most exposed: a key shown in a chat exists on Telegram's servers and in every device's cache, and a message we delete after a minute is a courtesy, not a guarantee. Write it on paper.
People pretending to be us
Impersonation is the most reliable way to lose money in this category, and it does not require any flaw in the software. There will be clone bots, look-alike handles, fake "verification" portals and support accounts that message you first.
Nobody from Poncho will ever message you first, ask for your PIN, ask for your key, or send you a link to "verify" anything. There is no verification step. The official channels are listed in the "Official channels" panel on the home page and nowhere else. Anything not on that list is not us — including anything that looks exactly like this page.
Sending things to the wrong place
Chain, address and network are three ways to lose funds with no error message. ETH sent on the wrong network is gone. A token address bridged from another chain is a different address here. An exchange deposit address that does not support this network eats the deposit. Address poisoning — where an attacker dusts you from an address matching the first and last characters of one you have used — is common and works because people check four characters. Poncho shows full addresses and asks you to confirm; it cannot stop you.
If you launch a token
Launching makes you the issuer, not a user, and the responsibility moves with it. You choose the name, the symbol and the image, and you are answerable for them — including for trademark, for what you say about the token, and for whether you may offer it to the public where you and your buyers live. Some of those rules are securities rules, and a token that represents a claim on anything real is far more likely to be caught by them. The creator fee rate is fixed at creation and can never be changed by anyone, including us, and the supply is fixed too. Everything else — the payout wallet, Buyback & Lock, reinvest — can be changed afterwards, with the caveats on the creator fees page. Poncho does not market your token, does not vouch for it, and does not advise you on any of this.
Tax
Disposals of crypto-assets are usually taxable events, the rules differ by country and by holding period, and record-keeping is your responsibility. Poncho does not calculate, withhold or report tax for you, and nothing here is tax advice. If the amounts matter to you, they matter enough for an adviser.
Regulation, and the fact that this can end
The rules for crypto services have changed materially in several jurisdictions over the last two years, and how they apply to a product like this is not fully settled in all of them. The honest position is that the regulatory question is open, that we are taking advice on it, and that the outcome may change who can use Poncho, from where, or whether it operates at all. If Poncho has to stop, your key export is the thing that matters, which is why it exists before anything else does.
Poncho is built by a very small team. There is no continuity guarantee, no escrow, and no acquirer waiting. Treat the wallet inside Poncho as a hot wallet holding what you are actively trading, not as a place to keep anything you would miss.
Questions
Is Poncho safe?
No software that signs transactions is safe in the sense people usually mean. Poncho's contracts are new, the server holds encrypted key material, and the chain, the launchpad and the stablecoin underneath are other people's code. What we can offer is that everything on this page is written down before you use it rather than after something goes wrong.
Can Poncho move my funds without me?
The design is that signing requires your PIN, which is never stored. The honest caveat is that this is a property of an implementation, not a law of nature, and that an attacker who took both the database and a separate server-held secret could attempt PINs offline. That is why balances are capped while Poncho is new and why export exists.
What happens if I lose my PIN?
The wallet is unrecoverable. Not by you, not by us. Export your key while you still can.
Can I be front-run on Robinhood Chain?
The classic public-mempool sandwich is structurally difficult here, because the mempool is not public and ordering is first-come, first-served. Latency races, backrunning and the sequencer's own visibility remain. Anyone telling you front-running is impossible is overselling it.
Does the honeypot check mean a token is safe to buy?
No. It means one specific failure was not detected at one moment, on one path. It says nothing about the team, the liquidity, the admin keys, or whether the price will be lower in an hour.
Is my money insured?
No. There is no deposit protection, no investor-compensation scheme, and no insurance of any kind behind anything Poncho does.