Docs · Protocol
Security & verification
Check every claim yourself: the program, its authorities, a mint, a vault, and the instruction list.
The checklist
- Program EduE…6AMQ ↗ is deployed and executable.
- A launch’s mint shows no mint authority and no freeze authority, and a supply of exactly 1,000,000,000.
- The vault is the program address
["vault", launch]— only the program can sign for it, through the agent trades,wind_downandadmin_withdraw_vault. - The launch account’s
termshold the fee split and agent limits you backed under. - The platform account’s
adminis the only key that can calladmin_withdraw_vault, and itsfee_recipientis where withdrawals go (admin 6vUg…zBWF ↗, recipient 6vUg…zBWF ↗). - Every withdrawal is a
VaultWithdrawnevent: it’s listed on the launch page and at/api/launches/:mint/activity?type=vault_withdrawn.
- EduE…6AMQ
Program deployed
Executable, upgradeable loader
- 6vUg…zBWF
Upgrade authority
Held by the platform admin key
- 7cCC…Gaow
Mint authority revoked
$HFLIVE: mint none · freeze none
- 6Pok…jZNZ
Vault PDA
$HFLIVE’s vault, owned by its launch account · withdrawals by the admin only
- Chpz…NGD8
Fees frozen per launch
$HFLIVE: 1% fee · 50% / 30% / 20% split
- Fvbd…tWKP
Agent authority
Can only sign agent_buy and agent_sell
Derive the accounts yourself
import { PublicKey } from "@solana/web3.js";
import { launchPda, vaultPda, curvePda } from "@holdfast/sdk";
const mint = new PublicKey("7cCCdB53uc76BgEQPZ8ojdSFPFBZHSEZ7X89qwaXGaow");
const launch = launchPda(mint); // ["launch", mint]
const vault = vaultPda(launch); // ["vault", launch]
const curve = curvePda(launch); // ["curve", launch]Every instruction
Launch lifecycle
- create_launchAnyoneCreate fee → fee recipient; mints 1B tokens to the curve
Creates the launch, mints the fixed 1,000,000,000 supply to the curve, revokes the mint authority in the same instruction, and freezes the fee split and agent limits into the launch.
- depositAnyoneYour SOL → the launch (raise)
Joins the raise as a backer. Deposits are clipped to the room left under the max raise and the per-wallet cap.
- cancel_launchCreatorNothing — opens full refunds
The creator can abort a raise before it launches. Every backer can then refund 100%.
- refundBackerYour deposit → you
Returns the full deposit when the raise missed its minimum by the deadline or was cancelled.
- launchCreator, or anyone once readyRaise → bundle buy → vault; launch fee
Opens trading. The bundle buy runs first, before any public trade can exist; the tokens and the SOL reserve go into the vault.
- wind_downAnyone, once eligibleVault tokens → curve; curve + vault SOL → backers
Ends a live launch that is at least 3 days old, no trade for 24 hours, and no tokens held outside the curve and vault. Returns the vault's tokens to the curve, credits the curve's and vault's SOL to backers pro-rata (claim_backer_fees) and stops trading for good.
Trading
- buyAnyoneYour SOL → curve; tokens → you; trade fee
Buys on the constant-product curve. The trade fee is split between backers, the creator and the platform.
- sellAnyoneYour tokens → curve; SOL → you; trade fee
Sells back into the Holdfast curve (legacy launches only; pump.fun launches trade on pump.fun). The curve's liquidity never migrates, so it is always there to sell into.
Vault agent
- agent_buyAgent authorityVault SOL → curve; tokens → vault
Only on dips at least the band under the EMA, at or below the vault's average cost (or a buy-back below the average sell), within the window budget and impact limit.
- agent_sellAgent authorityVault tokens → curve; cost → vault; profit → backers
Only into rallies at least the band over the EMA, at a fill of at least the vault's average cost plus the band, within the window budget and impact limit. The realized profit over average cost goes 100% to backers.
Fees
- claim_backer_feesBackerYour accrued fees and profit share → you
Pays the backer's pro-rata share of trade fees, vault-agent profit and any wind-down payout accrued so far. Claim any time.
- claim_creator_feesCreatorCreator fees → creator
Pays the creator's share of trade fees on their launch.
- sweep_platform_feesAnyonePlatform fees → the fixed fee recipient
Permissionless: it can only ever pay the platform's configured fee recipient.
Platform admin
- admin_withdraw_vaultAdminVault SOL and tokens → fee recipient
Withdraws any amount of a launch's vault SOL and tokens to the platform fee recipient. It can't touch the curve's liquidity. Every withdrawal emits VaultWithdrawn and is shown on the launch page.
- initialize_platformAdminNothing — creates the platform config
One-time setup by the program's upgrade authority: fee recipient, agent authority and default params.
- update_platformAdminNothing — params for future launches
Changes defaults for launches created afterwards. Existing launches keep the terms frozen at their creation.
- set_fee_recipientAdminNothing — where platform fees and vault withdrawals go
Points platform fee sweeps and vault withdrawals at a new recipient.
- set_agent_authorityAdminNothing — which key may call the agent instructions
Rotates the vault agent's key. Whoever holds it can still only call agent_buy and agent_sell.
- propose_adminAdminNothing
Starts a two-step admin handover.
- accept_adminProposed adminNothing
Completes the handover; the new key must sign.
Other
- agent_buy_pumpagentWrites agent, launch, pump_authority, vault_tokens
Signed by agent.
- agent_sell_pumpagentWrites agent, launch, pump_authority, vault_tokens
Signed by agent.
- buyback_burncrankerWrites cranker, launch, pump_authority, buyback_mint, burn_tokens
Signed by cranker.
- collect_pump_feescrankerWrites cranker, launch, creator_vault
Signed by cranker.
- create_launch_pumpcreatorWrites creator, platform, fee_recipient, launch
Signed by creator.
- graduate_pumpAnyoneWrites launch
Signed by anyone.
- launch_pumpcrankerWrites cranker, launch, pump_authority, mint, bonding_curve, associated_bonding_curve, metadata, vault_tokens, fee_recipient, creator_vault, user_volume_accumulator, buyback_fee_recipient
Signed by cranker.
- migrate_launchadminWrites admin, launch
Signed by admin.
- migrate_platformadminWrites admin, platform
Signed by admin.
- wind_down_pumpcrankerWrites cranker, launch, pump_authority, vault_tokens
Signed by cranker.
What you still trust
- The upgrade authority. The program is upgradeable by 6vUg…zBWF; an upgrade could change any rule.
- The admin can withdraw any vault’s SOL and tokens to the fee recipient with
admin_withdraw_vault(never the curve’s liquidity), pause new launches and deposits, pause the agent, and change defaults for future launches — not the terms of existing ones. - The agent operator decides when to trade within the rules; it can’t break them.