Docs · Protocol
Security & verification
Check every claim yourself: the program, its authorities, a mint, a vault, and the instruction list.
The checklist
- Program C1c2…pTSW ↗ is deployed and executable.
- A launch’s mint shows no mint authority and no freeze authority, and a supply of exactly 1,000,000,000.
- The vault is the program address
["vault", launch]— only the program can move its tokens. - The launch account’s
termshold the fee split and agent limits you backed under. - The instruction list below has nothing that moves vault funds to a wallet.
- C1c2…pTSW
Program deployed
Executable, upgradeable loader
- FwYL…pnAs
Upgrade authority
Held by the platform admin key
- DRoH…HJNv
Mint authority revoked
$VOLT: mint none · freeze none
- BKtK…tdft
Vault PDA
$VOLT’s vault, owned by its launch account
- 62dt…n3Wg
Fees frozen per launch
$VOLT: 1% fee · 50% / 30% / 20% split
- 3qLL…Fj2t
Agent authority
Can only sign agent_buy and agent_sell
Derive the accounts yourself
import { PublicKey } from "@solana/web3.js";
import { launchPda, vaultPda, curvePda } from "@holdfast/sdk";
const mint = new PublicKey("DRoHKBY6hAszKSBm8fey8AZqMDzPexkgYPSNeyZdHJNv");
const launch = launchPda(mint); // ["launch", mint]
const vault = vaultPda(launch); // ["vault", launch]
const curve = curvePda(launch); // ["curve", launch]Every instruction
Launch lifecycle
- create_launchAnyoneCreate fee → fee recipient; mints 1B tokens to the curve
Creates the launch, mints the fixed 1,000,000,000 supply to the curve, revokes the mint authority in the same instruction, and freezes the fee split and agent limits into the launch.
- depositAnyoneYour SOL → the launch (raise)
Joins the raise as a backer. Deposits are clipped to the room left under the max raise and the per-wallet cap.
- cancel_launchCreatorNothing — opens full refunds
The creator can abort a raise before it launches. Every backer can then refund 100%.
- refundBackerYour deposit → you
Returns the full deposit when the raise missed its minimum by the deadline or was cancelled.
- launchCreator, or anyone once readyRaise → bundle buy → vault; launch fee
Opens trading. The bundle buy runs first, before any public trade can exist; the tokens and the SOL reserve go into the vault.
Trading
- buyAnyoneYour SOL → curve; tokens → you; trade fee
Buys on the constant-product curve. The trade fee is split between backers, the creator and the platform.
- sellAnyoneYour tokens → curve; SOL → you; trade fee
Sells back into the curve. Liquidity never migrates, so the curve is always there to sell into.
Vault agent
- agent_buyAgent authorityVault SOL → curve; tokens → vault
Only on dips at least the band under the EMA, at or below the vault's average cost (or a buy-back below the average sell), within the window budget and impact limit.
- agent_sellAgent authorityVault tokens → curve; SOL → vault
Only into rallies at least the band over the EMA, at a fill of at least the vault's average cost plus the band, within the window budget and impact limit.
Fees
- claim_backer_feesBackerYour accrued fees → you
Pays the backer's pro-rata share of every trade fee accrued so far. Claim any time.
- claim_creator_feesCreatorCreator fees → creator
Pays the creator's share of trade fees on their launch.
- sweep_platform_feesAnyonePlatform fees → the fixed fee recipient
Permissionless: it can only ever pay the platform's configured fee recipient.
Platform admin
- initialize_platformAdminNothing — creates the platform config
One-time setup by the program's upgrade authority: fee recipient, agent authority and default params.
- update_platformAdminNothing — params for future launches
Changes defaults for launches created afterwards. Existing launches keep the terms frozen at their creation.
- set_fee_recipientAdminNothing — where future platform fees go
Points platform fee sweeps at a new recipient.
- set_agent_authorityAdminNothing — which key may call the agent instructions
Rotates the vault agent's key. Whoever holds it can still only call agent_buy and agent_sell.
- propose_adminAdminNothing
Starts a two-step admin handover.
- accept_adminProposed adminNothing
Completes the handover; the new key must sign.
What you still trust
- The upgrade authority. The program is upgradeable by FwYL…pnAs; an upgrade could change any rule.
- The admin can pause new launches and deposits, pause the agent, and change defaults for future launches — not the terms of existing ones.
- The agent operator decides when to trade within the rules; it can’t break them.