The vault rules
The program has 52 instructions. This page lists every one, who is allowed to sign it and what it checks before anything moves — and then the complete list of ways SOL can leave a vault. If a path isn't on that list, it doesn't exist.
Instructions that move vault money by rule#
The instructions that can send a vault's SOL or tokens anywhere, each by a fixed rule. The admin's own instruction is below.
Floor and Diamond mode: spends ammo on the coin's venue, at or under the floor. Tokens go to the vault. Floor mode is 100% ammo: nothing else in the vault.
- When it is the only venue instruction in its transaction, samples the reference with the venue spot first; it never trades on its own sample.
- The venue spot is below the stored floor (the MC below the floor MC), and the floor is above zero.
- The program computes the spend itself: the SOL that lifts the spot to the floor, capped by
max_soland by the ammo minus 0.01 SOL. - Rationed: at most 15% of the ammo per 1 hour window (the window rolls on the first buy after it ends). No room left →
FloorBuyRationed; less room than the lift needs → a partial buy,FloorBought.rationed= true andwindow_roomsays what is left. - The spend after those caps is at least 0.001 SOL, or the buy fails before trading (
BuyTooSmall): at dust sizes the venue's rounded-up fees would break the fee bound. A dust gap to the floor can stay open until the next buy is big enough. - Measured fill: the average fill and the spot after are both at or under the floor, or the transaction fails.
- The venue keeps at most 3% of the fill as fee, so a fee change on pump.fun's side can't drain the ammo.
- The curve isn't complete (after migration,
graduatefirst).
Burn mode: spends the bucket buying the coin at or under the reference, and burns exactly the tokens bought.
- Alone in its transaction; the launch is in Burn mode (
ModeMismatch). - The agent signs, or anyone once no burn has happened for 1 day (
BurnNotOpen), with the same bounds and no reward. - Spot ≤ reference × (1 + 0%) (
BuyAboveReference), the reference at most 2 minutes old. - At most 20% of the bucket per 5 minutes, at most 10% price impact, and the bucket keeps 0.01 SOL.
- The venue keeps at most 3% of the fill as fee. No floor ratchet; the backing per token rises.
Pulse mode: a small buy into the vault's pulse bucket on a flat chart.
- Alone in its transaction; the launch is in Pulse mode; the signer is a registered agent key.
- Spot within 10% under to 1% over the reference (
PulseOutOfBand). - At least 0.005 SOL; at most 10% of the bucket per buy and 40% per day; at least 5 minutes after the last pulse and the last vault sale (
PulseTooSoon). - Pulse tokens sell only through
sell_strengthat ≥ 1.5× × max(their cost, the backing).
Sells vault tokens into strength. Proceeds run the waterfall below; only the sponsor leg leaves the vault.
- Alone in its transaction: no other top-level pump.fun or PumpSwap instruction, and no other vault trade of this launch. This doesn't stop a Jito bundle or a wrapper program that calls pump.fun; the two-sample reference is what bounds those.
- The signer is a key the admin registered with
set_agent_executors: the vault agent's wallet. - The reference (as settled before this slot, if the slot already sampled it) is at most 2 minutes old (
RefStale), and the spot is at most 5% below it (SaleBelowReference). How the reference works. - Average fill ≥ the launch's
sell_multiple_bps(1.3× by default for creator-funded coins, 2× for pool-funded) × max(floor, backing, the bucket's average cost); Pulse bucket ≥ 1.5×; Diamond mode: the defense bucket always, and the inventory once the sponsor is paid, ≥ 10×. - While the sponsor is unpaid, the defense and pulse buckets sell only where the inventory can't.
- Spot after ≥ floor × (1 + 10%): never sells into the vault's own bid.
- Price impact ≤ 10% per trade; ≤ 30% of the vault's tokens per 2 minutes window.
- Proceeds cover the sold tokens' backing, and are at least
min_sol_out.
Sells the sponsor's first-buy tokens back on a coin that never ran. Same waterfall as an inventory sale.
- Alone in its transaction, like
sell_strength. - Signer is the pool's operator key (pool-sponsored launch) or the creator (self-sponsored launch).
- At least 1 day after launch, the sponsor position isn't settled yet, and the creator didn't waive repayment (
SponsorWaived). - The same reference checks as
sell_strength, and the coin never ran: the reference is still below the inventory's sell threshold ( the launch'ssell_multiple_bps× max(floor, backing, cost)) plus a 3% venue-fee margin (CoinRan). A coin that ran sells its inventory throughsell_strengthinstead. - Counted over every inventory sale of the launch, strength sales included, SOL received ≥ the tokens' cost × (1 − 5%).
- Spot after ≥ floor × (1 + 10%), and the same impact and window caps as
sell_strength.
Burn, Pulse and Diamond: burns the holder's tokens and pays their share of backing SOL, minus a fee that stays in. Floor mode refuses: there is no backing.
- Floor mode:
NothingToRedeem. A Floor-mode vault holds ammo only (hard_share_bpsis forced to 0 at create). - Pays tokens × backing SOL ÷ circulating, minus 2% (rounded up, left in backing).
- The payout is at least 0.00001 SOL, so dust can't be used to game rounding.
- No pause flag, no delay, no allow-list: works in every state, any time. It pays the backing as it stands, after any admin withdrawal.
Sends the launch's pending fee shares out: AI share to the AI treasury, burn share to the $LOADED buyback pool, backers' share to the sponsor pool.
- The AI treasury is the one address stored in the platform account (
InvalidParamotherwise). - Moves exactly
ai_pending,burn_pendingandbackers_pending; nothing else on the vault is reachable.
Pays a self-sponsoring creator what their first-buy tokens earned back; on a pool launch, the creator's refunded bond.
- Signer is the launch's creator.
- Pays exactly
sponsor_claimable: inventory-sale repayments (self-sponsored) or the bond once the pool is repaid in full (pool). Nothing else is reachable.
Moves the launch's $LOADED share of profit into the $LOADED coin's vault, as an inflow there.
- The $LOADED launch is set, and this isn't it.
- Moves exactly
floor_token_pending, to the one address stored in the platform account.
$LOADED only: lends part of the $LOADED vault's ammo to the sponsor pool, owed back at 125%.
- Signer is the sponsor pool's operator; the launch is the $LOADED launch named in the platform account. No other vault can be drawn.
- Draws from ammo only, never backing. Outstanding credit stays ≤ 25% of ammo plus credit lent (
CreditLimit), and the ammo left stays ≥ 0.01 SOL. - $LOADED's reference (as read for this slot, at most 2 minutes old:
RefStale) and its current spot are at least 3× its stored floor (CreditBelowTrigger), and the reference has stayed there for 10 minutes (CreditTriggerNotHeld). - The pool is short: the SOL it may spend on launches can't fund one largest first buy (
CreditNotNeeded), and what it owes stays ≤ 20% of NAV (CreditNavLimit). With nothing owed, not before 7 days after the last draw (CreditCooldown). The premium is a pool loss at the draw. - Owed = principal × 125%, rounded up. The stored floor and the backing don't move; the bid at the floor is thinner until repaid.
Lends sponsor-pool SOL into a broken Floor-mode vault as ammo at once, owed back with the sponsor premium from the vault's sale proceeds.
- Signer is the sponsor pool's operator; the launch is in Floor mode (
NotFloorMode). Accounts: operator, sponsor pool, launch, mint, vault tokens. - At most the pool's launch room (idle minus what is queued, owed and reserved:
PoolReserved); this launch's outstanding reinforcement plus the new SOL ≤ 10% of NAV and the pool's total reinforced ≤ 25% of NAV (ReinforceCap). - Pool: idle down, reinforced up, booked as a loss until repaid. Vault: ammo up,
reinforce_owed+= lamports × 125%. The floor guard runs and may ratchet the floor up. Repayment is the waterfall's reinforcement leg (ReinforceRepaid).
$LOADED only: lends part of the $LOADED vault's ammo to an open launch queue whose loan the pool can't fund alone, owed back at 125%.
- Signer is the pool's operator; the queue is open; accounts: platform, sponsor pool, queue, queue authority, the $LOADED launch and its venue.
- Only the shortfall: loan − credit already drawn − the pool's reservation − its launch room (
CreditNotNeededat 0,CreditExceedsShortfallabove it). - The same $LOADED checks as
draw_floor_credit: fresh reference and spot ≥ 3× its floor, held 10 minutes, outstanding ≤ 25%, ammo left ≥ 0.01 SOL. - SOL moves from the $LOADED vault to the queue's authority; the queue records its credit and return. The queue.
Sweeps a launch's pending credit repayment (the waterfall's credit leg) back into the $LOADED vault: principal to ammo, premium as an inflow.
- Accounts: platform, the launch and its mint and vault tokens, the $LOADED launch and its mint and vault tokens.
- Moves exactly
credit_pending(NothingToClaimat 0): principal first, up to what is still owed on principal; the rest is premium. - An expired queue returns its unspent credit the same way, inside
expire(LaunchCreditRepaid.from_queue).
The admin withdrawals#
The three admin instructions: the platform admin key can withdraw a vault's SOL and tokens, the public pool's idle SOL, and the SOL queued for the $LOADED buyback. Every call emits a public event with running totals on chain.
Sends any vault's SOL (ammo first, then backing where there is any) and tokens to the admin key. Stays in the program; documented here, never promoted.
- Signer is the platform account's admin. Works in every state, including while launches are paused.
- SOL comes out of ammo first, then backing; at most ammo + backing (
VaultWithdrawTooLarge). A Floor-mode vault is all ammo, so the withdrawal lowers its strength and can break the floor. It never touches the sponsor's claimable repayment, a pool launch's bond, the pending $LOADED share, pending credit repayment or the pending fee shares. - Tokens come out of the floor-bought bucket first, then the pulse bucket, then the inventory, each with its share of cost, to the admin's token account.
- The only instruction exempt from the floor guards. The stored floor never changes; on Burn, Pulse and Diamond the backing per token can drop and is stored at its new value, so
redeempays less afterwards. - If it empties the inventory, the sponsor position settles: unrepaid principal is written off, and a pool launch's bond is refunded to the creator.
- Pair a SOL-only withdrawal with the inventory: once ammo is below 0.01 SOL,
recall_inventorymeasures the defended zone on the computed floor so the sponsor can still recall, but withdrawing the inventory too settles the position at once.
Sends idle sponsor-pool SOL to the admin key. Every share, queued or not, loses that value at once.
- Signer is the platform account's admin. Instant; works while launches and deposits are paused.
- At most idle SOL minus what the pool owes $LOADED (
PoolWithdrawTooLarge). Touches no position and no ticket. - Emits
PoolAdminWithdrawnwith NAV and share price before and after, and the running total and count.
Sends SOL waiting in the $LOADED buyback pool to the admin key, before it is spent on buybacks.
- Signer is the platform account's admin. At most the pending buyback SOL (
BuybackWithdrawTooLarge). - Emits
BuybackAdminWithdrawnwith the running total and count.
Instructions that only add to a vault or record its state#
These create a vault, bring SOL into it or record state. None can take value out.
Creates the coin on pump.fun with the vault as its creator, buys the vault's first tokens (less any pour, which would land in the floor; the site sends none), then the optional dev buy. Self-sponsored only: pool launches go through submit_launch → launch.
- New launches aren't paused; name ≤ 32, symbol ≤ 10, URI ≤ 200 bytes.
- Dev buy ≤ 5 SOL; a self-sponsored first buy between 10 SOL and 50 SOL; the mode is enabled in the platform account. The mode is frozen.
- The pour:
pour_bps≤ 50% of the first buy skips the inventory buy and becomes ammo, clamped so the floor it sets sits under the launch price. The site, SDK and CLI send 0: the whole first buy is tokens and the coin has no floor at launch. Floor mode freezeshard_share_bpsat 0. - The floor's tightness:
sell_multiple_bpsfrom 1.2× up to the platform's 2× (0 = the platform's; the site sends 1.3×). The sponsor return:sponsor_return_bps∈ {12500, 10000, 0} — 0 waives repayment, every inventory sale funds the floor andrecall_inventoryis refused (SponsorWaived). - The vault's buy is the curve's first trade, capped at 75% of supply and one token short of the curve's sellable reserve, so it never completes the curve; unspent SOL goes straight back to the sponsor. The dev buy runs after it.
Samples the coin's venue spot into the vault's slow reference price. Moves no SOL and no tokens.
- Must be top-level, with no pump.fun or PumpSwap instruction in its transaction (
ObserveNotAlone). That doesn't stop a Jito bundle or a wrapper program's CPI; the fold below does. - Each sample folds the previous and the current spot (each clamped to the drift band): the lower of the two when both are above the reference, the higher when both are below, no move when they straddle it. A manipulated spot counts only if two samples in a row see it. The reference follows by how long the spot stood (period 2 minutes).
Claims pump.fun / PumpSwap creator fees into the vault and splits them: AI, burn and backers' shares are set aside for sweep_fees, the vault's share is an inflow.
- Fees land on the vault account only; something must be collected (fees or a donation to absorb).
Records the PumpSwap pool once pump.fun migrated the curve, so the vault trades there.
- The curve is complete and the pool is the coin's canonical SOL pool.
Pays the $LOADED credit line back from idle sponsor-pool SOL into the $LOADED vault.
- Principal goes back to ammo first; then the 25% premium is an inflow (all ammo: $LOADED is a Floor launch) that can raise $LOADED's floor.
- Before 7 days after the last draw, only the pool's authority or operator may repay, and only everything owed (
CreditNotDue). From then on anyone may, leaving one largest first buy (45 SOL) idle while the pool is enabled.
The launch queue#
A pool-funded launch is a queue first: the creator submits it, the public commits SOL toward a credit target, and anyone launches it once filled. The queue's SOL sits on a system-owned PDA (queue_authority) until then. Launching through the queue · what the pool lends.
Opens a queue for a pool-funded launch: reserves the pool's loan and takes the creator's bond.
- Accounts: creator, platform, sponsor pool, creator record, a one-time
create_keysigner, the queue PDA, its authority. Same metadata, mode and pause checks ascreate_launch; the pool is enabled. - One active sponsorship per creator (1) and the creator cooldown; outstanding + reserved + the loan ≤ 300 SOL (
SponsorOutstandingCap). - Loan = 45 SOL; the bond (0.05 SOL or 3% of the loan, whichever is larger) moves to the queue authority; the pool reserves what its launch room covers. Deadline = now + 1 day.
Puts SOL behind an open queue; it buys the coin in the launch transaction and the tokens are claimable afterwards.
- Accounts: owner, queue, queue authority, the owner's commitment PDA. The queue is open (
QueueNotOpen). - A wallet's total between 0.05 SOL and 2 SOL (
CommitOutOfRange).
Takes the whole commitment back from an open queue and closes the commitment account.
- Accounts: owner, queue, queue authority, commitment (closed to the owner). Open queues only;
refundis the same move on an expired one.
Creates the coin with the pool's loan plus the queue's credit and bond as the first buy, then buys with the committers' SOL into the queue's token account.
- Accounts: cranker, platform, sponsor pool, creator record, queue, queue authority, the new launch and mint, every pump.fun create/buy account, the queue's token account and volume accumulator — about 36, so the transaction uses the platform's lookup table.
- Open, and committed + post credit ≥ 10 SOL (
QueueNotFilled). Post credit (X-vote credit) needs the attestor's ed25519 signature over(queue, committed, post_credit, expiry)in the same transaction (BadAttestation,AttestorUnset). - The pool's part (loan − credit) fits its launch room and idle SOL (
QueueUnfunded), the outstanding cap, utilization and daily budget. Queue launches pour 0%. Unspent pool SOL goes back to idle; unspent credit stays as pending repayment. - Emits
LaunchCreatedthenQueueLaunched; the queue records the launch, its mint, what the committers spent and the tokens bought.
Pays a committer its share of the tokens the queue bought (and any unspent dust SOL), then closes the commitment.
- Accounts: owner, queue, queue authority, commitment (closed), the mint, the queue's and the owner's token accounts. Launched queues only (
QueueNotLaunched). - Tokens = tokens bought × commitment ÷ total committed, rounded down; dust = unspent committed SOL in the same proportion.
Closes an unfilled queue past its deadline: bond back to the creator, credit back to the $LOADED vault, the pool's reservation released.
- Accounts: cranker, platform, sponsor pool, creator record, queue, queue authority, the creator; the $LOADED launch, mint and vault tokens when credit was drawn.
- Open and now ≥ deadline (
QueueNotExpired). Committers take their SOL back withrefund.
Closes a launched or expired queue once every commitment is claimed or refunded; leftover lamports and rent go to the creator.
- Not open; no commitments left (
QueueNotEmpty).
Sponsor pool and $LOADED buyback#
The pool is a public fund owned by depositors through shares. None of these instructions can reach a launch's account.
Creates the pool and the $LOADED buyback pool once.
- Per-launch amount ≥ 0.05 SOL.
Changes the per-launch range, bond, caps, budget, deposit limits, delay, vesting, on/off. Moves no SOL.
- Every field inside its hard bounds (delay ≤ 14 days, vesting ≤ 30 days).
Sets the hot key allowed to recall and draw credit.
Adds SOL to idle and mints shares at the current price.
- At least 0.05 SOL; NAV stays ≤ 500 SOL; the share price isn't impaired.
Opens a FIFO withdrawal ticket at the current price.
- Unlocks no sooner than 2 days later. No cancel. At least 0.01 SOL unless the whole position.
Pays due tickets in queue order from idle SOL, into each ticket account.
- Paid at min(the ticket's price, today's price); never past what the pool owes $LOADED.
- Waits while NAV is 0, even with idle SOL. The SOL sits in the ticket until its owner claims it.
Moves the SOL paid into a ticket to its owner; a fully paid ticket closes and its rent comes back too.
- Signer is the ticket's owner. Something must be there to take.
Closes an empty position; rent back to the owner.
- No shares, no open tickets.
Marks a stuck, underwater pool sponsorship down: a loss to NAV now, recoveries vest later.
- At least 3 days after launch; inventory × reference below what is still owed.
Buys $LOADED with pending buyback SOL and burns everything bought.
- Alone in its transaction; at most once per 60 seconds; at least 0.001 SOL.
- Spot ≤ $LOADED's reference × (1 + 5%); drip-paced over about a day; ≤ 1.5% of $LOADED's SOL liquidity.
Platform#
The admin's other powers. None of these moves a launch's SOL or tokens, and parameter changes only reach launches created afterwards.
Creates the platform account once.
- Every param inside its hard bounds.
Sets params for future launches.
- Every param inside its hard bounds; existing launches keep their frozen terms.
Starts an admin handover.
Completes the handover.
- Signer is the proposed admin.
Registers the keys that may call sell_strength, buy_burn, pulse_buy and buyback_burn.
- No duplicates.
Sets the wallet that receives the AI fee share.
- Not the default key. Emits PlatformUpdated.
Sets which modes new launches may pick.
- Floor is always on; existing launches keep their mode.
Sets the key whose ed25519 signature a queue launch accepts for post credit.
- Emits PlatformUpdated. A queue launch with post credit fails while it is unset.
Names the $LOADED launch.
- Only once; immutable afterwards.
- Credits the $LOADED launch's own pending $LOADED share to its floor, as an inflow. No SOL leaves it.
Stops create_launch. Nothing else is pausable.
Publishes the address lookup table clients build launch transactions with.
- Never read by the program.
Where a sale's proceeds go#
sell_strength and recall_inventory pay their proceeds out in a fixed order. Each leg takes from what the one before left, and the sponsor can only ever be paid from the sale of its own tokens.
- 01Backingsold tokens × backing per token · 0 in Floor mode→ backing SOL (Burn / Pulse / Diamond) — the sale must cover it or it fails
- 02Sponsor or costsponsor's tokens: up to what it is still owed · the vault's own tokens: what they cost→ sponsor pool · or back to ammo
- 03Reinforcement, then creditup to what the launch still owes the pool for SOL lent into its floor, then up to what it owes $LOADED for its queue credit→ the sponsor pool (with its premium) · $LOADED's vault, swept by repay_launch_credit
- 04Profiteverything left→ 5% to $LOADED, the rest is an inflow: all ammo in Floor mode; in the other modes 50% backing, 50% ammo
The reference price and the sale guards#
A vault sale is signed by a key: the vault agent's wallet, the pool's operator, or a self-sponsoring creator. A leaked key must not be able to pump the coin, sell the vault into its own pump in the same breath, and walk away. So every vault keeps a slow reference price, and every sale is checked against it. The program keeps it per token; every check below is a ratio, so it reads the same on market caps.
Each sample folds two spots: the previous sample's and this one's. When both sit above the reference the lower one counts, when both sit below the higher one counts, and when they straddle it nothing moves. So a spot moves the reference only if two samples in a row see it. A spot pushed and restored around one sample — a dump, an observe, a restore, even inside a Jito bundle — leaves the reference where it was; the next honest sample either straddles it or is the closer of the two. Moving it for real means holding the market cap at the pushed level, with real exposure, across samples. The reference starts at launch, seeded with the spot right after the vault's first buy.
Within a slot that has already been sampled, sales and credit draws read the settled reference, as it stood before the slot's first sample, so nothing earlier in the same slot can move what they check against. Before it trades, every sell_strength and recall_inventory must pass, in this order:
SaleNotAlone— the sale is top-level and the only pump.fun or PumpSwap instruction in its transaction, and no other vault trade of this launch rides along. Compute budget, token-account creation and other programs are fine.RefTooFresh/RefStale— a reference exists, and the one read was sampled within the last 2 minutes. A stale reference could miss a move the market made since.SaleBelowReference— the spot before the sale is at most 5% below the reference.CoinRan(recall only) — the reference is still below the inventory's sell threshold plus a 3% margin for the venue fee. A coin that ran sells its inventory throughsell_strengthat the full threshold, never through a recall at cost. (The margin exists because just above the threshold a strength sale's average fill can't reach it after the fee; without it a dead coin parked there could sell through neither.)
Then the sale samples the reference and trades. Anyone can keep a reference fresh with observe, which moves no money. It must be a top-level instruction with no pump.fun or PumpSwap instruction in its transaction (ObserveNotAlone); for the same reason buy_floor only samples when it is alone. That check reads only this transaction: it does not stop a Jito bundle or a wrapper program that calls pump.fun. The two-sample fold is what bounds those. The agent observes before planned sales.
Every way SOL can leave a vault#
A vault is its Launch account. These are all the code paths that lower its lamports — found by reading every debit in the program, not by listing the ones we like.
| Path | Instruction | Goes to | Bound |
|---|---|---|---|
| Floor buy | buy_floor | The coin's venue, for tokens | Floor / Diamond. Fill ≤ floor; ammo ≥ min vault SOL left; ≤ 15% of ammo per 1 hour |
| Burn buy | buy_burn | The coin's venue, for tokens burned at once | Burn. Spot ≤ reference + 0%; ≤ 20% of the bucket per window |
| Pulse buy | pulse_buy | The coin's venue, for pulse tokens | Pulse. Inside the band; ≤ 10% per buy, 40% per day |
| First buy | create_launch, launch | The venue, for the inventory | Only the sponsor's own principal, less any pour (pour_bps, kept as ammo; the site sends 0, so all of it buys tokens), in the launch transaction |
| Unspent first-buy SOL | create_launch, launch | Back to whoever sponsored it | Exactly principal − spent − pour; 0 for a first buy in the allowed range |
| Sponsor repayment | sell_strength, recall_inventory | The sponsor pool | From inventory sales only; ≤ owed |
| Sponsor claim | claim_sponsor | The creator | Self-sponsored: only what inventory sales credited. Pool: the creator's own bond, once the pool is repaid in full |
| Forfeited bond | sell_strength, recall_inventory | The sponsor pool | Only the creator's bond, only when principal is written off; never vault SOL |
| Fee split | sweep_fees | AI treasury, $LOADED buyback pool, sponsor pool | Exactly the pending 5% / 10% / 5% of collected fees |
| Redemption | redeem | The holder | Burn / Pulse / Diamond only: their share of backing SOL, − 2%. Floor mode: NothingToRedeem |
| Reinforcement repayment | sell_strength, recall_inventory | The sponsor pool | Only what the pool lent into this floor plus its premium (reinforce_floor); from the waterfall's reinforcement leg |
| $LOADED share | sweep_to_floor | The $LOADED coin's vault | Exactly the pending 5% of profit |
| Credit repayment | repay_launch_credit | The $LOADED coin's vault | Exactly the pending credit leg of the waterfall (queue launches funded with $LOADED's credit) |
| $LOADED credit line | draw_floor_credit, draw_launch_credit | The sponsor pool, or a launch queue, as a loan | $LOADED's vault only; ammo only; ≤ 25% of ammo + credit lent; owed back at 125% |
| Admin withdrawal | admin_withdraw_vault | The platform admin key | Any vault: up to all of its ammo, then its backing (Burn / Pulse / Diamond), and its tokens. Public VaultWithdrawn event |
| Temporary account rent | PumpSwap trades, collect_fees | Whoever fronted it in the same transaction | The exact rent of a wrapped-SOL account |
Tokens leave a vault in three instructions: sell_strength and recall_inventory, only into the coin's own market at the checked limits, and admin_withdraw_vault, to the admin key. buy_burn burns exactly the tokens it bought. Everything else that touches a vault adds to it.
admin_withdraw_vault is signed by the platform admin key and is checked only on its signer: it can take a vault's ammo, then its backing where there is any, and its tokens. It can't lower the stored floor or reach the sponsor's claimable, a bond, the $LOADED share, pending credit repayment or the pending fee shares. Every call is a public on-chain event and shows in the coin's vault log (admin powers). It stays as built. Still not in the program: no close_launch, no set_floor, no migration of vault funds. Check the list yourself.
What the program asserts#
Checked by the program inside the instructions, and by the test suite after every step:
- The stored floor never decreases, in every instruction. Whenever it steps up, the ammo at that step is recorded: strength is measured against it.
- On Burn, Pulse and Diamond, backing SOL per circulating token never decreases (checked by cross-multiplying, so rounding can't sneak a drop through) — except in
admin_withdraw_vault, the one instruction exempt from both floor guards. A Floor-mode vault holds no backing:hard_share_bpsis 0 for life. - Backing SOL decreases only in
redeem, by at most the redeemer's share, and inadmin_withdraw_vault. Ammo decreases only inbuy_floorat fills ≤ floor and inside its window ration,buy_burn,pulse_buy,draw_floor_credit/draw_launch_credit($LOADED only) andadmin_withdraw_vault. - What a vault owes the pool for reinforcement and $LOADED for credit is never more than it was lent plus the premium; repayments come only from the waterfall and only in that order.
- A vault's lamports cover its rent plus every tracked balance, including a pool launch's bond. Anything extra (a donation, fees pushed in by pump.fun) is absorbed as an inflow.
- The vault's tokens are exactly its inventory plus the tokens it bought at the floor or in pulses (burned tokens are gone).
- The sponsor is never paid more than it is owed, and only from inventory proceeds. The bond is never inflow and never floor money.
- The reference price is seeded at launch and moves only at the start of
sell_strength,recall_inventory,buy_burn,pulse_buy,observe,buyback_burnand a lonebuy_floor, at most halfway per sample and only by spots two samples in a row saw. Sales and draws in a sampled slot read the settled reference from before that slot.
The parameters#
Each launch copies these from the platform account when it is created and keeps them for life (its terms). The admin can change the platform values for future launches, but only inside the hard bounds compiled into the program.
Platform params
| Param | Value | Default | Hard bounds |
|---|---|---|---|
defense_ratio_bps Share of circulating supply the defense must be able to buy at the floor | 10% | 10% | 5% – 50% |
hard_share_bps Share of every inflow that becomes backing SOL | 50% | 50% | 0% – 80% |
sell_multiple_bps Strength sells fill at no less than this multiple of max(floor, backing, cost) | 2× | 2× | ≥ 1.2× |
floor_token_share_bps Share of realized profit swept to $LOADED | 5% | 5% | ≤ 20% |
redeem_fee_bps Redeem fee, left in backing SOL | 2% | 2% | 0.5% – 5% |
max_impact_bps Largest price move one vault sale may cause | 10% | 10% | 0.5% – 10% |
sell_window_secs Length of a sell window | 2 minutes | 2 minutes | ≥ 1 minute |
sell_bps_per_window Share of the vault's tokens it may sell per window | 30% | 30% | ≤ 50% |
ai_fee_bps Share of every collected creator fee sent to the AI treasury | 5% | 5% | ≤ 15% |
burn_fee_bps Share of every collected creator fee queued for the $LOADED buyback and burn | 10% | 10% | ≤ 25% |
backers_fee_bps Share of every collected creator fee paid to sponsor-pool depositors (vests) | 5% | 5% | ≤ 10% |
sponsor_return_bps What the sponsor is owed, as a share of the first buy's cost | 125% | 125% | 100% – 200% |
recall_after_secs Time after launch before the sponsor may recall | 1 day | 1 day | ≥ 1 day |
recall_tolerance_bps How far below cost the inventory may sell on a recall, counted over every inventory sale | 5% | 5% | ≤ 5% |
recall_floor_margin_bps Vault sales must leave price at least this far above the floor | 10% | 10% | ≥ 5% |
min_self_sponsor_lamports Smallest self-sponsored first buy | 10 SOL | 10 SOL | ≥ 0.05 SOL |
max_self_sponsor_lamports Largest self-sponsored first buy | 50 SOL | 50 SOL | — |
max_dev_buy_lamports Largest dev buy in the launch transaction | 5 SOL | 5 SOL | — |
max_inventory_supply_bps Largest share of supply the first buy may take (it never completes the curve) | 75% | 75% | ≤ 75% |
launch_fee_lamports Launch fee, paid by the creator to the sponsor pool | 0 SOL | 0 SOL | ≤ 0.1 SOL |
min_vault_lamports Defense SOL a floor buy always leaves in the vault | 0.01 SOL | 0.01 SOL | ≥ 0.005 SOL |
ref_period_secs How slowly the market reference price follows spot (EMA period) | 2 minutes | 2 minutes | 10 seconds – 1 hour |
max_sale_drift_bps How far below the reference the spot may be when a vault sale starts | 5% | 5% | 1% – 20% |
credit_trigger_bps $LOADED credit line: its reference must be at least this multiple of its floor to draw | 3× | 3× | ≥ 2× |
credit_max_bps $LOADED credit line: most of its ammo (plus credit lent) that can be out at once | 25% | 25% | ≤ 50% |
credit_return_bps $LOADED credit line: what the pool owes back per SOL drawn | 125% | 125% | 100% – 200% |
credit_trigger_hold_secs $LOADED credit line: how long its reference must have stayed at the trigger before a draw | 10 minutes | 10 minutes | 1 minute – 1 day |
credit_term_secs $LOADED credit line: after the pool's last draw, how long until anyone may push a repayment | 7 days | 7 days | 1 day – 90 days |
burn_bps_per_window Burn mode: most of the burn bucket spent per burn window | 20% | 20% | 1% – 50% |
burn_window_secs Burn mode: length of a burn window | 5 minutes | 5 minutes | 1 minute – 1 hour |
burn_max_premium_bps Burn mode: how far above the reference a burn may buy | 0% | 0% | ≤ 5% |
burn_open_after_secs Burn mode: idle time after which anyone may call buy_burn | 1 day | 1 day | 1 hour – 7 days |
pulse_clip_bps Pulse mode: most of the pulse bucket one pulse buy may spend | 10% | 10% | 1% – 25% |
pulse_spacing_secs Pulse mode: minimum gap after any pulse buy or vault sale | 5 minutes | 5 minutes | 2 minutes – 1 hour |
pulse_day_bps Pulse mode: most of the pulse bucket spent per rolling day | 40% | 40% | 5% – 50% |
pulse_band_bps Pulse mode: how far under the reference a pulse may still buy | 10% | 10% | 1% – 30% |
pulse_max_premium_bps Pulse mode: how far above the reference a pulse may buy | 1% | 1% | ≤ 5% |
pulse_take_profit_bps Pulse mode: pulse tokens sell at no less than this multiple of max(cost, backing) | 1.5× | 1.5× | 1.2× – 3× |
diamond_multiple_bps Diamond mode: defense sales, and inventory sales once the sponsor is paid, fill at no less than this multiple | 10× | 10× | 3× – 25× |
pool_pour_bps Share of a queued launch's pool loan poured straight into its floor (the rest buys inventory) | 0% | 0% | — |
floor_buy_bps_per_window Most of the ammo buy_floor may spend per window (rationing) | 15% | 15% | — |
floor_buy_window_secs Length of a floor-buy rationing window | 1 hour | 1 hour | — |