A coin launches only when its target is pledged. Everyone enters in the same transaction at the same price. A campaign that misses its target refunds every pledger in full.
This repository is the Solana program that holds the money. It is public so that the claims on pledgepad.app can be checked against the code rather than believed.
Pledged SOL sits in a vault PDA: an account whose address is derived from the program and the campaign, and for which no private key exists. Not held by the team, not held in a multisig, not held anywhere. Lamports leave it only when the program itself signs with the vault's seeds.
There are exactly two destinations in the code for pledged SOL: the launch buy, and the wallet that pledged it.
| Guarantee | Enforced by | Proven by |
|---|---|---|
| A missed target refunds everyone in full | withdraw |
missed_target_refunds_every_pledger_in_full |
| You can leave any time before the deadline | withdraw |
withdraw_is_open_before_the_deadline_even_when_target_is_met |
| Nobody can withdraw someone else's pledge | PDA seeds + has_one |
cannot_withdraw_another_wallet_pledge |
| The campaign creator has no power over the pool | no admin instruction exists | creator_cannot_touch_the_vault |
| A filled campaign commits to the launch | withdraw |
withdraw_locks_when_target_met_after_deadline |
| Pledged SOL is never stranded | GRACE_SECONDS |
grace_period_unlocks_withdrawals_if_launch_never_runs |
| Caps are enforced on-chain, not in the UI | pledge |
caps_are_enforced |
The last one matters more than it looks. If a campaign fills but the launch cannot execute, for any reason, withdrawals unlock one hour after the deadline and every pledger takes their SOL back. There is no state in which the pool is frozen.
campaign seeds ["campaign", creator, seed] campaign terms, immutable after creation
vault seeds ["vault", campaign] holds pledged SOL, system-owned, no key
pledge seeds ["pledge", campaign, wallet] one per wallet per campaign
Because the pledge PDA is derived from the pledger's own wallet, an instruction can only ever reach the caller's own pledge. That is the whole access-control model, and it is why there is no owner check to get wrong.
cargo build-sbf
cargo testThe tests run against a real Solana VM, not mocks. They fund wallets, pledge, warp past deadlines, and assert on actual lamport balances.
Built and tested:
create_campaignpledgewithdraw
Not yet written:
launch(pump.fun CPI: mint, then one buy with the whole pool)claim(pro-rata from the vault, floor division so the vault cannot run short)
The program has not been deployed to mainnet and has not been audited. Do not send it real money yet.
MIT.
