Mainnet

Docs · Protocol

Security & verification

Check every claim yourself: the program, its authorities, a mint, a vault, and the instruction list.

The checklist

  1. Program EduE…6AMQ ↗ is deployed and executable.
  2. A launch’s mint shows no mint authority and no freeze authority, and a supply of exactly 1,000,000,000.
  3. The vault is the program address ["vault", launch] — only the program can sign for it, through the agent trades, wind_down and admin_withdraw_vault.
  4. The launch account’s terms hold the fee split and agent limits you backed under.
  5. The platform account’s admin is the only key that can call admin_withdraw_vault, and its fee_recipient is where withdrawals go (admin 6vUg…zBWF ↗, recipient 6vUg…zBWF ↗).
  6. Every withdrawal is a VaultWithdrawn event: it’s listed on the launch page and at /api/launches/:mint/activity?type=vault_withdrawn.
  • Program deployed

    Executable, upgradeable loader

    EduE…6AMQ
  • Upgrade authority

    Held by the platform admin key

    6vUg…zBWF
  • Mint authority revoked

    $HFLIVE: mint none · freeze none

    7cCC…Gaow
  • Vault PDA

    $HFLIVE’s vault, owned by its launch account · withdrawals by the admin only

    6Pok…jZNZ
  • Fees frozen per launch

    $HFLIVE: 1% fee · 50% / 30% / 20% split

    Chpz…NGD8
  • Agent authority

    Can only sign agent_buy and agent_sell

    Fvbd…tWKP
Read live from mainnet on the server; each tile links to the account.

Derive the accounts yourself

TypeScript · @holdfast/sdk
import { PublicKey } from "@solana/web3.js";
import { launchPda, vaultPda, curvePda } from "@holdfast/sdk";

const mint = new PublicKey("7cCCdB53uc76BgEQPZ8ojdSFPFBZHSEZ7X89qwaXGaow");
const launch = launchPda(mint);       // ["launch", mint]
const vault = vaultPda(launch);       // ["vault", launch]
const curve = curvePda(launch);       // ["curve", launch]

Every instruction

Launch lifecycle

  • create_launchAnyoneCreate fee → fee recipient; mints 1B tokens to the curve

    Creates the launch, mints the fixed 1,000,000,000 supply to the curve, revokes the mint authority in the same instruction, and freezes the fee split and agent limits into the launch.

  • depositAnyoneYour SOL → the launch (raise)

    Joins the raise as a backer. Deposits are clipped to the room left under the max raise and the per-wallet cap.

  • cancel_launchCreatorNothing — opens full refunds

    The creator can abort a raise before it launches. Every backer can then refund 100%.

  • refundBackerYour deposit → you

    Returns the full deposit when the raise missed its minimum by the deadline or was cancelled.

  • launchCreator, or anyone once readyRaise → bundle buy → vault; launch fee

    Opens trading. The bundle buy runs first, before any public trade can exist; the tokens and the SOL reserve go into the vault.

  • wind_downAnyone, once eligibleVault tokens → curve; curve + vault SOL → backers

    Ends a live launch that is at least 3 days old, no trade for 24 hours, and no tokens held outside the curve and vault. Returns the vault's tokens to the curve, credits the curve's and vault's SOL to backers pro-rata (claim_backer_fees) and stops trading for good.

Trading

  • buyAnyoneYour SOL → curve; tokens → you; trade fee

    Buys on the constant-product curve. The trade fee is split between backers, the creator and the platform.

  • sellAnyoneYour tokens → curve; SOL → you; trade fee

    Sells back into the Holdfast curve (legacy launches only; pump.fun launches trade on pump.fun). The curve's liquidity never migrates, so it is always there to sell into.

Vault agent

  • agent_buyAgent authorityVault SOL → curve; tokens → vault

    Only on dips at least the band under the EMA, at or below the vault's average cost (or a buy-back below the average sell), within the window budget and impact limit.

  • agent_sellAgent authorityVault tokens → curve; cost → vault; profit → backers

    Only into rallies at least the band over the EMA, at a fill of at least the vault's average cost plus the band, within the window budget and impact limit. The realized profit over average cost goes 100% to backers.

Fees

  • claim_backer_feesBackerYour accrued fees and profit share → you

    Pays the backer's pro-rata share of trade fees, vault-agent profit and any wind-down payout accrued so far. Claim any time.

  • claim_creator_feesCreatorCreator fees → creator

    Pays the creator's share of trade fees on their launch.

  • sweep_platform_feesAnyonePlatform fees → the fixed fee recipient

    Permissionless: it can only ever pay the platform's configured fee recipient.

Platform admin

  • admin_withdraw_vaultAdminVault SOL and tokens → fee recipient

    Withdraws any amount of a launch's vault SOL and tokens to the platform fee recipient. It can't touch the curve's liquidity. Every withdrawal emits VaultWithdrawn and is shown on the launch page.

  • initialize_platformAdminNothing — creates the platform config

    One-time setup by the program's upgrade authority: fee recipient, agent authority and default params.

  • update_platformAdminNothing — params for future launches

    Changes defaults for launches created afterwards. Existing launches keep the terms frozen at their creation.

  • set_fee_recipientAdminNothing — where platform fees and vault withdrawals go

    Points platform fee sweeps and vault withdrawals at a new recipient.

  • set_agent_authorityAdminNothing — which key may call the agent instructions

    Rotates the vault agent's key. Whoever holds it can still only call agent_buy and agent_sell.

  • propose_adminAdminNothing

    Starts a two-step admin handover.

  • accept_adminProposed adminNothing

    Completes the handover; the new key must sign.

Other

  • agent_buy_pumpagentWrites agent, launch, pump_authority, vault_tokens

    Signed by agent.

  • agent_sell_pumpagentWrites agent, launch, pump_authority, vault_tokens

    Signed by agent.

  • buyback_burncrankerWrites cranker, launch, pump_authority, buyback_mint, burn_tokens

    Signed by cranker.

  • collect_pump_feescrankerWrites cranker, launch, creator_vault

    Signed by cranker.

  • create_launch_pumpcreatorWrites creator, platform, fee_recipient, launch

    Signed by creator.

  • graduate_pumpAnyoneWrites launch

    Signed by anyone.

  • launch_pumpcrankerWrites cranker, launch, pump_authority, mint, bonding_curve, associated_bonding_curve, metadata, vault_tokens, fee_recipient, creator_vault, user_volume_accumulator, buyback_fee_recipient

    Signed by cranker.

  • migrate_launchadminWrites admin, launch

    Signed by admin.

  • migrate_platformadminWrites admin, platform

    Signed by admin.

  • wind_down_pumpcrankerWrites cranker, launch, pump_authority, vault_tokens

    Signed by cranker.

Vault exitsAgent trades on the launch’s own curve, wind_down (to backers) and admin_withdraw_vault (platform admin → fee recipient). Each one is on-chain and shown on the launch page.

What you still trust

  • The upgrade authority. The program is upgradeable by 6vUg…zBWF; an upgrade could change any rule.
  • The admin can withdraw any vault’s SOL and tokens to the fee recipient with admin_withdraw_vault(never the curve’s liquidity), pause new launches and deposits, pause the agent, and change defaults for future launches — not the terms of existing ones.
  • The agent operator decides when to trade within the rules; it can’t break them.
Indexer synced· slot 452,231,947· lag 31Agent online· tick 573Mainnet
RisksTermsPrivacy© 2026 Holdfast