Anti-MEV bonding-curve launchpad on Solana, written in Anchor/Rust.
This repository is a devnet MVP. It can initialize a launch, route first-slot snipes into a vesting vault, let normal buyers buy and sell on the bonding curve, and mark a curve complete when an optional graduation target is reached.
🌐 Live site: safepump-core.com · 🚀 Devnet app: safepump-core.com/app.html
SafePump-Core is open source and actively looking for collaborators. If you know Rust + Anchor, TypeScript + Solana web3.js, Next.js + wallet-adapter, or just want to write docs and tests — there's a place for you.
- 🎯 Open good-first-issues — scoped, beginner-friendly tasks
- 📖 CONTRIBUTING.md — workflow, conventions, quick start
- 🔒 SECURITY.md — responsible disclosure
- 💬 Discussions — design questions, RFCs
Currently a solo project; aiming for 3-5 active contributors before mainnet. Contributors will be credited and may be eligible for token allocation if a mainnet launch happens (see CONTRIBUTING.md).
FMAhGG8ETyqnd4zan4HBdLRPEQvk7Cvc6kzWbsvnXj5q
Deployed on devnet with upgrade authority
9WPztx4YNSrLr1ZD61kKziwqryQhrrTPomx6HodyJCS9.
The matching local keypair is generated under target/deploy/ and is ignored by
git. Do not commit deploy keypairs.
The public token name is staged as SolPump with draft symbol SOLPUMP.
Mainnet token creation is prepared under mainnet-launch, but
no mainnet transaction is automated or executed by the repository scripts.
Generate the mainnet token plan:
npm run token:planThe investor-facing static site is under site. Open site/index.html directly in a browser, or publish it with the example GitHub Pages workflow in docs after Pages is configured for GitHub Actions.
site/app.html is a static trading console for the deployed devnet program. It lists live bonding curves, quotes buys and sells with the same math as the on-chain program, and supports the full user flow: connect a wallet (Phantom or Solflare set to devnet), create a launch, buy, sell, and claim vested tokens after the anti-snipe lock expires.
It has no build step: site/safepump-sdk.js encodes the
program instructions directly (Anchor discriminators and account layouts) on
top of a vendored @solana/web3.js browser bundle, so opening the page — or
serving site/ statically — is enough.
The same SDK is exercised end-to-end against devnet by the smoke test:
npm run smoke:devnet # optional: pass a funded keypair path as the first argIt creates a fresh curve with a throwaway wallet, verifies that a first-slot buy is locked in the vesting vault, that a post-window buy pays the wallet the exact quoted amount, that sells return the quoted SOL, and that claiming while locked is rejected.
Token launches on Solana get sniped in the first slots by bots that buy a large piece of supply, wait for organic buyers to move price, and dump. SafePump punishes that pattern by routing buys inside a tight post-launch window into a time-locked vesting vault.
- Snipe window: first
SNIPE_WINDOW_SLOTS = 10slots afterinitialize_curve. - Penalty: sniped tokens go to a
VestingVaultPDA instead of the buyer wallet. - Lock duration:
VESTING_DURATION_SECONDS = 48 * 3600. - Repeat sniping: every snipe by the same wallet resets the unlock timestamp.
Virtual constant-product curve:
tokens_out = vtok - ceil((vsol * vtok) / (vsol + sol_in))
sol_out = vsol - ceil((vsol * vtok) / (vtok + tokens_in))
virtual_sol_reserves and virtual_token_reserves set the starting price.
real_sol_reserves and real_token_reserves track actual liquidity held by the
program.
initialize_curve(virtual_sol_reserves, virtual_token_reserves, token_supply, graduation_sol_target)creates the mint, bonding curve PDA, token vault, and mints supply into the vault.graduation_sol_target = 0disables target-based completion.buy(sol_amount, min_tokens_out)buys tokens. Snipes are locked; normal buys go to the buyer ATA.sell(token_amount, min_sol_out)sells tokens back into the curve before graduation.claim_vested()lets a beneficiary claim locked tokens after the unlock time.
Install the Solana toolchain if solana --version or cargo build-sbf is not
available:
curl --proto '=https' --tlsv1.2 -sSfL https://solana-install.solana.workers.dev | bashInstall JS dependencies:
npm installBuild and test locally:
npm run build
npm testDeploy to devnet:
solana config set --url devnet
solana airdrop 2
npm run deploy:devnetIf the public faucet is rate-limited, fund the deploy wallet with another
devnet faucet or devnet-pow before running the deploy command. The deploy
script uses solana program deploy directly with extra sign attempts because
anchor deploy is deprecated and can fail under devnet RPC throttling.
Verify the devnet deployment:
solana program show FMAhGG8ETyqnd4zan4HBdLRPEQvk7Cvc6kzWbsvnXj5q --url devnet- Graduation currently marks the curve complete, but does not yet migrate liquidity to Raydium. Add Raydium LaunchLab/CPMM integration before mainnet.
- Token metadata is not created yet. Add Metaplex metadata for names, symbols, images, and explorer compatibility.
- There is no protocol fee, creator fee, moderation layer, indexer, or public API yet. The devnet web app in site covers the core user flow.
- The Anchor IDL is not published on-chain yet (the web app does not need it —
it encodes instructions directly via
site/safepump-sdk.js). - This is suitable for devnet iteration, not unaudited mainnet use.