What is running, and what we actually know about it
Three groups: the watchtower, the relay that funds it, and the upstream services neither of us controls. A pill is green here only when a payload said so. Where we have no signal it reads unknown, because a status page that guesses is a status page that lies.
live
api process uptime0d 01h 11mthis process, since its last restart
clean-day rateno datano complete day is on record yet
days with no record89of 90drawn grey below, never green
last feed frame1,244ms agosocket open
Ninety days
One bar per UTC day. The only durable per-day record we publish is the daily attestation root, so that is what this is drawn from — a filled day is a day whose root exists and can be checked on-chain by anyone. We do not yet have ninety days of it, and the missing days are left empty rather than filled in.
2026-04-302026-07-28
root committed, nothing deniedroot committed, an assertion did not reproducea component reporting an outageno data recorded
An amber day is not our downtime. It means the watchtower ran and at least one of Robinhood’s assertions failed to reproduce against an independent replay — the service working exactly as intended, on a bad day for the chain. Those same days appear in deny on the roots ledger, where the subject is the chain rather than us.
Components
Watchtowerlayer one · the part that cannot be behind a paywalldegraded
L1 log indexer
scans Ethereum for AssertionCreated and AssertionConfirmed
scanned to 25,634,428 of 25,634,428 · 0 L1 blocks behind head
operational
Assertion verifier
re-derives each claimed state root against an independent node
316 affirmed · 0 denied · 0 awaiting · median verdict lag 300168.70s
operational
Attestation signer
EIP-712 signature over every decided verdict
no attester key configured — verdicts are recorded and published, but nothing is counter-signable by a third party
read-only
Daily root publisher
commits one Merkle root per complete day, then mirrors it to Ethereum
no daily root exists yet — roots are only built for complete UTC days
nothing committed
Relaylayer two · the part that pays for layer one4/4 operational
Ingress
authenticates the caller, applies the tier rate limit, admits the bundle
0 accepted · 0 rejected before submission
operational
Simulator
eth_simulateV1 against the freshest state we hold, then derives the preconditions
0 bundles failed preflight and were never sent
operational
Submitter
eth_sendRawTransactionConditional to the sequencer
0 included · 0 awaiting · 0 dropped at zero gas by a precondition
operational
Feed listener
matches submitted hashes against the sequencer feed to time inclusion
inclusion timings below are measured against feed frames, not against the public RPC
watching
Relay component states are self-reported by the relay process. There is no synthetic probe hitting these four in production, so treat them as "the service believes it is up", not as an independent measurement. The upstream group below is different: those states are derived from data that actually arrived.
Upstreamthird-party dependencies · we do not operate any of these3/3 operational
Robinhood sequencer feed
the only push channel this chain has — there is no eth_subscribe and no mempool
sequenceNumber 21,966,034 · last frame 1,244 ms ago · 0 reconnects · 43,362 frames this process
operational
Robinhood public RPC
chain head, gas price and the submission path everyone else also uses
head 21,965,794 · observed block interval 100 ms · 0.028578 gwei
operational
Ethereum L1 RPC
assertion discovery, every rollup contract read, and the CheckpointAnchor write
head 25,634,428 · latestConfirmed assertion 0x26e987aced94…
operational
None of these are ours. When one of them is red the correct reading is that Robinhood or the parent chain is having a bad minute, not that Verderer is. We publish them anyway because a watchtower that hides its own blind spots is running the same trick it exists to catch.
Upstream endpoints we depend on
Read live from the running process rather than typed into this page. The feed is public and unauthenticated, which is the single reason an independent watchtower on this chain is possible at all.
no assertion discovery and no anchoring to Ethereum
How to read this page adversarially
Nothing here is a service-level agreement, and the clean-day rate is not a ninety-day uptime figure — we print the denominator next to it precisely so it cannot be quoted as one. The bar covers 1 of 90 days.
The one number on this page you can verify without us is the daily root: it is write-once on two chains, and the roots ledger shows how to check it yourself. Everything else is our own process reporting on itself, and you should weight it accordingly.