On-chain architecture
Planned design, not implemented. The app currently runs on a read-only demo adapter; every write action is disabled. Full notes live in docs/ARCHITECTURE.md.
App boundary
UI ──▶ IcoChainAdapter (capabilities gate every action)
├─ DemoAdapter (today: sample data, writes refuse)
└─ SolanaAnchorAdapter (future: RPC gateway via server functions,
returns unsigned tx → user wallet signs)Accounts
- Offering
- Immutable sale parameters, running totals and state.
- SolVault (PDA)
- Program-owned account holding committed SOL. Never a founder wallet.
- TokenVault
- PDA-owned token account for participant allocations — exact role depends on the verified Pump.fun settlement design.
- BuyerPosition
- Per-participant commitment with claimed / refunded flags.
Invariants
- Sale parameters immutable after activation
- Floor rounding, u128 checked math, dust handled per terms
- Claim/refund flags prevent duplicates
- Authority + PDA checks on every privileged instruction
- Clock-based deadlines, no admin override
- FCFS hard cap or pro-rata, fixed before opening
Launch layers (V1 destination: Pump.fun)
Offering terms, commitments, escrow, success/failure finalization, refunds and participant allocation settlement.
Creating the coin and public trading on Pump.fun's bonding curve. Pump.fun's own rules, pricing and fees apply. ICO cannot change them.
When a coin reaches Pump.fun's protocol threshold it graduates to PumpSwap. This is handled by Pump.fun, not ICO.
Pump.fun integration status: planned, not implemented or verified end to end. Pump.fun is a third-party token launch and trading protocol. It is not affiliated with, endorsed by or partnered with ICO.
Pump.fun research findings
- A standard Pump.fun coin puts its entire fixed supply into the bonding curve at creation. No tokens exist outside the curve, so ICO cannot pre-allocate tokens to participants.
- Coins are tradable on the curve from the moment they are created. ICO cannot delay public trading or set a private price.
- Pump.fun's official tools allow a coin to be created and bought from in the same transaction. This is the only path for ICO participants to hold the coin: buying at the curve price at launch.
- Creator rewards go to the creator set at launch and continue after PumpSwap graduation. Reward sharing between wallets exists, but is configured once and then locked.
- Pump.fun's program is also deployed on Solana devnet, so testing can happen without real funds.
Model: first buyers at launch. A standard Pump.fun coin has no tokens outside its bonding curve, so nothing can be pre-allocated. If an offering succeeds, the agreed launch SOL makes the initial Pump.fun purchase in the same transaction that creates the coin, and participants claim a proportional share of the tokens actually bought. A proof of concept passed on a local copy of Solana devnet running Pump.fun's real devnet program; it has not been run on live devnet or audited, and nothing is live.
Sources and full analysis: docs/ICO_PUMPFUN_HANDOFF.md.
Proof of concept — local copy of Solana devnet (test only)
- A program-controlled vault (no human key) paid for and made the initial Pump.fun purchase, and a program-derived address was used as the coin's mint, all in one transaction.
- The bought tokens landed in an account owned by the program vault. The coin had no mint or freeze authority afterwards.
- Two test participants (25% / 75%) claimed exactly their rounded-down shares; 1 base unit of rounding dust stayed in the vault.
- Second claims, claims through someone else's position, a second launch, a launch with a different coin address, and launches before close or after failure were all rejected by the program.
- A launch whose purchase failed reverted completely: no coin was created, the vault balance was unchanged and the offering stayed closed-successful for retry.
- Failed offerings refunded in full once; a second refund was rejected.
Not run on live devnet, not audited, no mainnet. Code and logs: poc/pumpfun-settlement/.
Pump.fun integration checklist (unresolved)
- Repeat the program-vault create-and-buy test on live Solana devnet (done only on a local copy so far; the public test SOL faucet was rate-limited).
- Build the coin name, ticker, metadata link and creator on-chain from the offering record; the proof of concept accepted these from the caller, which is unsafe.
- Fit the launch transaction under Solana's 1,232-byte limit with lookup tables (the proof of concept only fit after shortening the coin details).
- Decide who receives leftover vault SOL and rounding dust, and how anyone else buying in the same block affects the result.
- Measure the largest launch buy the curve and transaction limits allow; define partial-fill and slippage handling.
- Confirm whether creator-reward sharing can be set at creation and whether it covers PumpSwap fees after graduation.
- Read supported pair assets and launch modes at execution time instead of hardcoding them.
- Prove idempotent launch on devnet: fixed mint per offering, on-chain launch flag, reconcile before any retry.
- Legal review of Pump.fun's terms and of pooled launch purchases before any real funds.
- Store mint address, Pump.fun URL, create signature, status, attempts, failure reason and settings snapshot once a real integration exists.
Instructions
- create_offering
- Validate allocations = 100%, limits, window. Params freeze at start.
- contribute
- Live only. Enforces per-participant caps and oversubscription mode. SOL → vault.
- finalize
- Permissionless after deadline. Successful if min met, else Failed.
- refund
- Failed only. Full SOL back. Single use per position.
- claim_tokens
- Deterministic floor-rounded allocation; excess pro-rata SOL returned.
- withdraw_project_funds
- Creator authority, after launch step, exact amount per terms.
- launch
- CPI: Pump create_v2 (program mint) + ATA + buy, vault PDA signs. Proven on a local devnet copy only.
Remaining before mainnet
- 01Anchor program + tests, rounding fuzzing
- 02Pump.fun launch integration (see checklist below)
- 03Devnet deploy and SolanaAnchorAdapter
- 04Server-side RPC gateway (keys never in browser)
- 05Wallet Standard adapter with tx simulation
- 06Indexer for activity and positions
- 07Independent audits, upgrade authority to multisig
- 08Legal review, geo-restrictions, creator verification