DDocs
How raids work
Every coin launched here is a vault with a keep of SOL. Holders of one coin raid another coin's keep; the target's holders defend. The loot moves from keep to keep and is only ever spent on buying the coin back and burning it. No wallet is ever paid loot.
- 01 · LaunchA coin becomes a vault70% of its creator fees fill its keep, forever.
- 02 · DeclareA holder declares a raidBond posted, the target is warned, prep runs.
- 03 · BattleCrews commit tokensAttack wins at 1.25x the defense. Loot moves keep to keep.
- 01Overview
- 02The keep
- 03A raid, step by step
- 04Power and the price feed
- 05Worked example
- 06Buyback and burn
- 07Launching a vault
- 08Transactions
- 09Parameters
- 10Program reference
- 11Verify on chain
- 12Admin powers
- 13Risks
- 14FAQ
01Overview
Heistpad is a Solana program (Heist46B2L5u4oDxcGwTRSRgy7dvoVDhTSmgLGvtSAjC) on top of pump.fun. A coin launched through it is a normal pump.fun coin whose creator is a program account (the coin's Fees account). The creator fees it earns are split on chain: 70% into the coin's keep, 20% to the dev, 10% to the treasury.
The keep has exactly two ways out: a buyback (the keep buys the coin on its own market and burns every token it bought) and loot taken by a winning raid, which goes into the attacker's keep. The program has no instruction that sends keep SOL or loot to a wallet.
The site reads everything from chain. The district's tower heights and lit floors are the keeps; the streams of points are running raids.
02The keep
| Fills from | Empties into |
|---|---|
| 70% of the coin's creator fees (pump.fun curve and, after migration, PumpSwap) | Buyback and burn: at most once per interval, a share of the keep, never into a pumped price |
| Loot from raids this coin won | Loot taken by a raid this coin lost |
| Bonds of raids on this coin that fizzled | (nothing else) |
| Donations (anyone, booked on chain) |
Every keep satisfies, at all times: keep = rent floor + from fees + loot in + bonds in + donated − loot out − bought back. The vault panel on the site shows exactly these lines. A raid can never take a keep below its rent floor plus 0.1 SOL.
03A raid, step by step
| Phase | Lasts | What happens |
|---|---|---|
| Declare | - | A holder of at least 0.1% of the attacking coin's supply posts a bond of 0.2 SOL, doubled for every raid the target repelled in a row (up to x32, the streak fades after a day without one). The target must hold at least 0.2 SOL, be out of its shield and not already under attack; the attacking coin must not be on another raid or resting. |
| Prep | 30 min | The warning period. Both sides see the raid coming. No commits yet. The target's keep is locked (no buyback) until settle. |
| Battle | 60 min | Holders of the attacking coin commit tokens to the attack, holders of the target coin to the defense. Each commit's power (in SOL) is fixed when it lands. |
| Soft close | +2 min each | A commit in the last 2 min pushes the end by 2 min, at most 30 min in total. No last-second sniping. |
| Settle | anyone | After the end anyone can settle: outcome, loot, burns, bond, shield and cooldown, in one transaction. |
| Withdraw | anyone | Every crew gets its tokens back minus the burn, to its own wallet. The keeper pushes these; you can also take them from Mine. |
Outcome
- Fizzled if the attack's power is below 0.25 SOL. The bond goes to the target's keep.
- Attack won if attack ≥ defense × 1.25. Loot moves from the target's keep to the attacker's keep.
- Defended otherwise. No loot moves.
Loot
loot = min( available × 20% × attack / (attack + defense), available − 0.1 SOL ), where available is the target keep above its rent floor at settle. A narrow win takes less than a crushing one.
Burns
Committed tokens sit in the raid's escrow until settle. The losing side's escrow is 20% burned, the winning side's 5% (a fizzle counts as a defense win). Every crew gets back exactly floor(amount × (1 − burn)).
After a raid
Only a target that lost a raid is shielded, for 24 h. A target that held (or saw the raid fizzle) gets no shield but a repel: the next raid on it costs twice the bond, and so on up to x32. The attacking coin rests for 6 h after every raid, fizzles included. Times count from the raid's end. The bond goes back to the declarer unless the raid fizzled.
04Power and the price feed
Power is measured in SOL at the moment a commit lands: what the tokens would sell for at the coin's 30-minute median price, and never more than they would sell for right now.
- Sell value is pump.fun's constant-product quote minus its 1.25% fee, stacked: as if the tokens already in this side's escrow were sold first. Splitting one bag into many commits gains nothing.
- Median price: the median of every price reading of the last 30 minutes. A commit needs at least 7 readings spanning at least 15 minutes (
StaleMedian/ShortPriceHistory); the vault panel shows the feed as 7 cells, says "warming up" while the span is short, and offers to add a reading. Anyone can add one (observe, at most one per minute per coin); the keeper adds one every minute during raids. - Readings are clamped: each reading is stored at most 10% away from the median of the 7 before it, so a pump bundled around a reading moves the series slowly.
- Pumping a coin right before committing buys nothing: the pool is valued as if it sat at the median price, and the lower of that and the live sale value counts.
- Every commit carries a minimum power (the site sets 97% of its estimate): if the price moves before it lands, it is refused instead of counting for less.
05Worked example
With the default parameters. The target's keep holds 10 SOL above its floor. The attack commits tokens worth 6 SOL of power, the defense 4 SOL.
| Win line | 4 × 1.25 = 5 SOL | 6 ≥ 5: attack won |
| Loot | 10 × 20% × 6 / 10 = 1.2 SOL | below the cap (10 − 0.1): 1.2 SOL moves keep to keep |
| Burns | attack 5%, defense 20% | of the tokens each side escrowed |
| Bond | 0.2 SOL | back to the declarer |
| After | shield 24 h / rest 6 h | target shielded, attacker resting |
Had the defense committed 5 SOL, the line would be 6.25 SOL and the attack (6) would have failed: nothing moves, the attackers lose 20% of their tokens, the defenders 5%.
06Buyback and burn
Anyone can trigger a coin's buyback once per 1 h. It spends 10% of the keep, never more than 0.5% of the market's SOL reserves (keeping 0.01 SOL of rent headroom, at least 0.01 SOL), buys the coin on pump.fun (or PumpSwap after migration) through a program account, and burns every token it bought in the same instruction. It refuses when the live price is more than 3% above the median of the last 7 readings (PriceAboveMedian), when those 7 readings disagree by more than twice that (PricesDisagree), and while the coin is under attack (KeepFrozen). The admin can only ever tighten a coin's buyback settings (tighten_buyback).
07Launching a vault
Name (up to 32 bytes), ticker (up to 10 characters), a picture and an optional first buy (none, 0.5, 1, 2 or 5 SOL on the site). The program creates the coin on pump.fun with its Fees account as the creator and makes your first buy in the same instruction. The launch fee is 2.5% of the first buy, on top, to the treasury; no first buy, no fee. You also fund the rent floors of the coin's Fees and keep accounts (about 0.002 SOL).
The program refuses a mint that has a freeze authority or any extension that could move escrowed tokens (UnsafeMint).
08Transactions
Every action on the site is one transaction you sign, simulated first so a failing one never reaches your wallet. launch, declare, commit and buyback must be alone in their transaction (only compute budget and SOL transfers may join), so no trade can be bundled next to them. The site resends the same signed transaction every 2 seconds until it lands and asks you to sign once more only if the network let it expire.
| Action | Instruction | Who |
|---|---|---|
| Launch a vault | launch + pump.fun create and buy | anyone (the dev signs) |
| Buy on the curve | pump.fun buy | anyone |
| Declare a raid | declare(max_bond) | a holder of ≥ 0.1% of the attacking coin |
| Join the attack / defend | commit(side, amount, min_power) | any holder of that side's coin, during the battle |
| Settle | settle | anyone, after the end |
| Take tokens back | withdraw | anyone, for a crew; tokens go to the crew's wallet only |
| Buy back and burn | buyback(max_spend) | anyone, when due |
| Add a price reading | observe | anyone, one per coin per minute |
| Donate to a keep | donate(amount) | anyone |
| Dev share | collect_fees, sync_fees, claim_dev | anyone; pays the coin's dev only |
09Parameters
Read from the program's config now (this network). A coin copies the parameters at launch, a raid at declare: changes only apply to coins launched and raids declared afterwards.
| Parameter | Now | Mainnet default | Allowed range |
|---|---|---|---|
10Program reference
Accounts
| Account | Seeds | Holds |
|---|---|---|
| Config | ["config"] | admin, pending admin, treasury, paused, parameters, counters |
| Coin | ["coin", mint] | name, ticker, uri, dev, a copy of the parameters, active raids, shield / cooldown, record, keep and fee ledgers |
| PriceObs | ["obs", mint] | the last 16 price readings |
| Fees | ["fees", mint] | the coin's creator on pump.fun and PumpSwap; fees land here |
| Keep | ["keep", mint] | the chest (SOL) |
| Buyer | ["buyer", mint] | signs the buyback's trade; holds only its rent floor between buybacks |
| Raid | ["raid", id u64 le] | both sides (tokens, power, crews, burns), times, outcome, loot; the bond rides in its lamports |
| Crew | ["crew", raid, side, wallet] | one wallet's commits on one side |
| Escrows | ATA(raid, mint), Token-2022 | the attack and defense tokens until settle |
Errors
The site shows these messages when the program refuses a transaction. Rendered from the program's IDL.
| Code | Name | Meaning |
|---|---|---|
11Verify on chain
- Open the program in an explorer: Heist46B2...AjC. The IDL the site uses is at /idl/heist.json.
- Pick any coin and read its
Coinaccount. Check the keep equation from section 02 against the keep account's balance. - Add up
loot_inandloot_outover every coin: the sums are equal, so loot only ever moved keep to keep. /stats does this sum live. - Open any
settletransaction: the only SOL movements are keep to keep (loot) and the bond (to the declarer or the target's keep). - Open any
buybacktransaction: the Buyer account buys, burns every token it bought, and returns what it did not spend to the keep.
12Admin powers
- pause new coins and new raids (running raids, withdrawals and fees keep working);
- change parameters within fixed bounds, for coins launched and raids declared afterwards;
- change the treasury;
- tighten (never loosen) an existing coin's buyback size and slippage;
- hand the role over (two steps: propose, then the new key accepts).
- move keep SOL, escrowed tokens, bonds or pending dev shares;
- change a running raid, or loosen an existing coin's parameters;
- send loot to any wallet (no instruction exists for it).
As with every program on this pad family, the program's upgrade authority can upgrade it. An upgrade is a public on-chain transaction.
13Risks
- Capital decides. Outcomes follow committed value. A whale can win a raid; the 1.25 defender bonus, burns on both sides and the loot cap are what keep it a game.
- Your tokens are at stake. Committed tokens are locked until settle, and the losing side loses 20% of them to the burn (the winning side 5%).
- Price manipulation. A bundle can bias a price reading, but each reading is clamped to 10% of the recent median, commits need 15 minutes of history and value tokens at the median, so a short pump buys nothing but its fees.
- Dumping the other coin. Selling the target coin before defenders commit lowers their sell value. The dumper pays for the dump; commits already made keep their power.
- Fizzle griefing. Anyone holding 0.1% of some coin can lock a target for prep plus battle with a raid nobody joins. It costs the bond (doubling with every repel in a row), which goes to the target's keep, and puts the attacking coin on rest.
- Stale feed. Without readings, commits and buybacks are refused until 7 exist; a raid on an unobserved coin can fizzle.
- pump.fun powers. pump.fun's own admin tools can redirect a coin's creator fees; the keep then stops filling. Nothing already in a keep or escrow is at risk.
- Loot reaches sellers over time. Keeps buy their coin on the market, so whoever sells into a buyback receives that SOL. Buybacks are capped, hourly and permissionless, so nobody has a privileged seat.
14FAQ
Can I win SOL by raiding?
Not directly. Loot goes into your coin's keep, which buys your coin back and burns it. If you hold the coin, that is what you win.
What do I lose if my side loses?
20% of the tokens you committed are burned; the other 80% come back after settle. The winning side loses 5%.
Can the dev take the keep?
No. The dev gets 20% of creator fees as they arrive, never anything from the keep.
Why did my commit fail with a stale feed?
The coin needs 7 price readings in the last 30 minutes. Add one from its vault panel (one per minute) or wait for the keeper.
Who settles a raid?
Anyone, once it is over. The keeper does it within seconds; the site shows a Settle button too.
Can a coin attack and defend at the same time?
Yes: one raid as attacker and one as target at once, never two of either.