Hot Potato Pad

Docs

How the potato moves

Every coin launched here has one potato. It jumps to whoever buys through the pad. While you hold it you earn half of the coin's creator fees, for every second you hold it. The jackpot is split by weighted seconds: a second held late in the curve weighs far more than an early one, and the take that finishes the curve weighs nothing, so nobody wins it by buying last.

1 TAKE2 HOLD3 THE RAMP Buy at least the price:it jumps to you Earn 50% of the coin'sfees for every second Late seconds weigh morefor the jackpot

01Lifecycle of a coin

StateWhat is trueWhat anyone can do
On the plateJust launched. Nobody holds the potato. The jackpot bag (bought with the seed) sits in the Oven.Take it for the minimum take (0.1 SOL).
Cooking, heldSomeone holds it; the fuse (30 min) is burning. He earns the holder share of every fee that arrives while he holds it.Steal it by buying at least the ladder price. The holder can refresh.
Hold ran outThe holder's fuse burned out. He stops earning; his share of new fees goes to the jackpot.Take it for the minimum take again (he can too).
Jackpot ramp50% of the curve is sold. From here every second held weighs more for the jackpot, rising to 1,000,001 per second at the end.Keep taking and refreshing; the price to steal is capped at half of what is left on the curve.
Curve completeThe last token of the curve was bought. The potato stops.Serve it (the take that completes the curve serves it at once).
ServedThe jackpot divisor is frozen. The coin moved to PumpSwap; its fees keep flowing into the jackpot.Claim jackpot shares, release escrow after the cooldown, claim holder fees.

02The ladder

The price to get the potato is the SOL that reaches the curve in your take (pump's own fee, 1.25% today, is on top and does not count). The program reads it from pump's curve account before and after your buy, so nobody can fake it.

SituationYou must buy at least
Nobody holds it, or the hold ran out0.1 SOL (min_take)
Held, within 60 s after the last take2× the last take (grace)
Held, after the grace window1.1× the last take
AlwaysAt most half of the room left on the curve (the SOL that would buy every token left), so a steal that does not finish the curve is always possible
Your take completes the curveAnything: it always qualifies, and ends the game

Your hold lasts 30 minutes from your take. A refresh (only the live holder) buys at least 50% of the last take and restarts the fuse: 30 minutes from the refresh. A refresh never lowers the price for others: the last take becomes the larger of the two, and there is no new grace window.

Only takes through this pad move the potato. Buys on pump.fun or in terminals never touch it, although their creator fees still count for the holder.

03Where the fees go

The coin's pump creator is its Oven, a program address with no private key. Every lamport of creator fees the coin earns is split when it is booked (inside every take, refresh, stoke, claim and serve):

ShareToHow it is paid
50%The potato holderFor his live seconds of the booking window. Claimable any time from Mine (claim_fees).
35%The jackpotPaid after the serve, by weighted potato-seconds.
15%The pad's treasurycollect_treasury, only to the configured treasury.

When nobody live holds the potato (on the plate, or the hold ran out), the holder share of those fees goes to the jackpot. After the serve, the holder share goes to the jackpot too, forever. The dev earns nothing from fees; he only has his own dev buy. The launch fee is 2.5% of the jackpot seed plus the dev buy, to the treasury.

04Escrow: no take-and-dump

Tokens bought by a take or a refresh do not go to your wallet. They go to the Oven's token account, booked to your Seat. They stay locked while you hold the potato and for 10 minutes after the earlier of: the moment you lost it, or the moment your hold ran out. After that anyone can push release and the tokens go to your wallet only. So you cannot take the potato and sell the bag in the same breath.

05The weight ramp

Curve progress is the share of the tokens the curve had at launch that are sold. Below 50% sold, one second of holding weighs 1. Above it the weight rises in a straight line to 1,000,001 per second at 100%: at 75% sold a second weighs 500,001, at 90% it weighs 800,001.

The program cuts the holder's time into segments at every take, refresh, stoke and serve, and weighs each segment at the lower of the two curve readings at its ends. A take reads the curve before its own buy, so the buy that finishes the curve never counts for its buyer. A rise of the curve counts for the holder from the next reading; the keeper stokes every few seconds when the curve rises inside the ramp, and anyone can stoke from the coin card. Instructions that read the curve must be alone in their transaction, so nobody can move the curve and read it in one transaction.

0% sold50%100% weight 11,000,001

06The jackpot

The jackpot is the jackpot bag (tokens bought at launch with the seed) plus jackpot SOL (35% of every fee, the holder share whenever nobody live holds, and everything but the treasury share after the serve). At the serve the divisor W, the sum of everyone's weight, freezes. One rule for every coin: split by weight. Only if nobody ever held the potato for a live second does the jackpot go to the creator, who paid the seed.

Your share is floor(w × tokens / W) of the bag, once, and floor(w × SOL / W) of the jackpot SOL minus what you already took, cumulative: fees keep flowing in after the serve, so you can claim again later. The take that completes the curve holds the potato for zero seconds, so a sniper who buys the last token gets nothing from the jackpot.

07Launching a coin

  1. Name, ticker, picture. Name 1 to 32 bytes, ticker 1 to 10 bytes, no spaces or invisible characters. The picture goes to IPFS through pump.fun's uploader.
  2. Jackpot seed. 0.2, 0.6 or 1 SOL (the program accepts 0.2 to 1 SOL). It buys the jackpot bag at launch.
  3. Dev buy. None, 0.5, 1 or 2 SOL. Your tokens, same price as the jackpot bag, in the same single buy. Seed plus dev buy must fit on a fresh curve.
  4. One transaction. The program creates the coin on pump.fun with the Oven as creator, makes one buy, moves your part to your wallet and the launch fee to the treasury. Nobody holds the potato after launch: the first take gets it.

08A worked example

  1. Carla launches $BAO with a 0.6 SOL seed and a 1 SOL dev buy. She pays 1.6 SOL plus 0.04 SOL launch fee (2.5%) plus pump's fee. The 0.6 SOL of tokens sit in the Oven as the jackpot bag.
  2. Ana takes the potato for 0.1 SOL. Her fuse: 30 minutes. Her tokens go to escrow.
  3. 20 s later Ben wants it. Inside the grace window he needs 2× = 0.2 SOL. He waits; after 60 s he needs 1.1× = 0.11 SOL, buys 0.11 SOL and takes it. Ana held it for 80 s.
  4. During those 80 s trading on pump.fun paid 0.02 SOL of creator fees to the Oven. At Ben's take they are booked: 0.01 SOL to Ana, 0.007 SOL to the jackpot, 0.003 SOL to the treasury. Ana's tokens unlock 10 min after she lost the potato.
  5. Ben refreshes 20 min later with 0.06 SOL (at least 50% of 0.11): his fuse restarts at 30 min. The price for others stays 0.121 SOL.
  6. Everything so far happened below 50% sold: Ana's 80 s weigh 80, Ben's first 40 min weigh 2,400. Then the curve climbs. Dan steals it at 70% sold and holds 60 s: 60 × 400,001 ≈ 24.0M. Eve steals it at 90% and holds 30 s: 30 × 800,001 ≈ 24.0M. Finn's take completes the curve and serves the potato; he holds it for zero seconds.
  7. W ≈ 48.0M. Dan and Eve each get about half of the jackpot; Ana and Ben get a sliver (their seconds were early); Finn gets nothing.

09The transactions the site sends

ButtonInstructionWhat is in the transaction
Take the potatotake(sol_in, max_required, min_tokens_out)Compute budget + take, alone. sol_in = your size plus pump's fee; max_required = your size, so if someone took it first at a higher price you get PriceMoved and nothing is spent; min_tokens_out = 95% of the quote.
Refresh holdrefresh(sol_in, min_tokens_out)Compute budget + refresh, alone.
Stokestoke()Collects the coin's waiting pump fees into the Oven and books them.
Serve itserve()After the curve completed. The keeper does it within seconds.
Claim (Mine)release, claim_fees, claim_jackpot, claim_orphan_jackpotUp to four per transaction; Claim everything sends as many as needed.
Launchlaunch(name, symbol, uri, jackpot_seed, dev_buy, fee_bps, treasury_bps)Compute budget + launch, alone, signed by you and the new mint key.

Every transaction is simulated before your wallet sees it: if the program would refuse it, you get the program's reason and nothing is signed. After signing, the same signed transaction is resent every 2 s until it lands; if the network lets it expire you are asked to sign once more, and nothing was spent.

10Parameters

ParameterValueWhat it does
min_take0.1 SOLthe price when nobody holds the potato
step_bps1.1xsteal after the grace window
grace_bps2xsteal inside the grace window
grace_secs1 mingrace window
hold_secs30 minthe fuse
refresh_bps50%minimum refresh
cooldown_secs10 minescrow unlock after losing it
ramp_bps50% soldwhere the weight ramp starts
room_cap_bps50%the price never exceeds this share of the room left

Launch defaults.

11Program reference

Program id HotPeqmeyErto6PKfAZyVYCSajWRwWUbGno7McWGdihi. Anchor 0.31, built on pump.fun's bonding curve (Token-2022 coins). The IDL is at /idl/potato.json.

Accounts

AccountSeedsHolds
Config["config"]admin, pending admin, treasury, paused, coin count, parameters for new coins
Potato["potato", mint]one coin's game: its copy of the parameters, holder, taken_at, expires_at, last take, fee books, jackpot books, escrow total, the open weight segment and weight total, serve result
Seat["seat", mint, wallet]a wallet's history on one coin: escrowed tokens and unlock time, earned and claimed fees, seconds held, weight, takes, refreshes, jackpot paid
Oven["oven", mint]system-owned PDA: the coin's pump creator, holds the creator fees, owns the token account with the escrow and the jackpot bag

Instructions

InstructionWhoWhat
launchthe devcreates the coin (creator = Oven), one buy of seed + dev buy, dev part to the dev, fee to the treasury; alone in its tx
takeanyonecollect + book fees, credit the outgoing holder, close the outgoing holder's weight segment, pump buy into escrow, price check; alone in its tx
refreshthe live holderbuy ≥ 50% of the last take, fuse restarts; alone in its tx
stokeanyonecollect + book; while cooking also a curve reading that closes the holder's weight segment; alone in its tx
serveanyoneafter the curve completes: last seconds, freeze the jackpot divisor (total weight)
releaseanyone, to the seat's wallet onlyescrowed tokens after the lock
claim_feesanyone, to the seat's wallet onlycollects pump's waiting fees, books them, pays the earned holder fees
claim_jackpotanyone, to the seat's wallet onlyafter the serve, by weight
claim_orphan_jackpotanyone, to the creator onlywhen nobody ever held the potato
collect_treasuryanyone, to the treasury onlythe booked treasury share
unwrap_feesanyonecloses WSOL owned by the Oven into it (PumpSwap fees collected as WSOL)
init_config, update_config, set_treasury, set_paused, propose_admin, accept_adminadminsee Admin powers

12Errors

Rendered from the program's IDL. The site shows the message when the simulation refuses a transaction.

CodeNameMessage

13Verify on chain

  1. The coin is ours. Derive ["potato", mint] under the program id: the account must exist and name that mint.
  2. Nobody holds the creator key. Read pump's bonding curve of the mint: its creator must be ["oven", mint] of this program, a PDA with no private key.
  3. The escrow is real. The Oven's Token-2022 account for the mint holds the sum of all seats' escrowed tokens plus the unpaid jackpot bag.
  4. The holder is who the site says. potato.holder and potato.expires_at are public; the site's fuse is expires_at - now.
  5. Every take is in the logs. Each take emits Taken with the taker, the previous holder, the size that reached the curve, the price and what the outgoing holder was credited.

14Admin powers

The admin can

  • pause new launches (coins already launched keep playing)
  • change the parameters of coins launched from then on, inside hard bounds
  • change the treasury (the platform's own 15% only)
  • hand the admin role to another key in two steps

The admin cannot

  • touch any coin's SOL, escrow or jackpot bag
  • change the parameters of a coin already launched
  • move the potato or change who holds it
  • stop takes, claims or releases

The program is upgradeable by its upgrade authority. Pump.fun keeps its own admin powers over creators of coins on its curve.

15Risks

16FAQ

Can I lose the potato while I sleep?

Yes, that is the game. Anyone who buys at least 1.1× your take (2× in the first minute) gets it. You keep everything you earned while you held it.

Does buying on pump.fun give me the potato?

No. Only takes through this pad move it. Buys on pump.fun or in terminals do pay creator fees, and those go to whoever holds the potato.

Can the dev keep the potato?

No more than anyone else. Nobody holds it after launch; the dev must take it like everyone and can be outbid.

Why can't I sell my tokens right after a take?

So nobody takes the potato and dumps the bag. Your tokens unlock 10 minutes after you lose the potato or your hold runs out; then anyone, including the keeper, can release them to your wallet.

Who serves the potato?

Anyone. The take that completes the curve serves it in the same instruction; otherwise the keeper sends serve within seconds, and the site shows a Serve button.

What if nobody ever takes the potato?

The jackpot goes back to the creator, who paid the seed: claim_orphan_jackpot, only to the creator's wallet.