Skip to content

Repository files navigation

Pledge

Pledge

A coin launches only when its target is pledged. Everyone enters in the same transaction at the same price. A campaign that misses its target refunds every pledger in full.

This repository is the Solana program that holds the money. It is public so that the claims on pledgepad.app can be checked against the code rather than believed.


What the program guarantees

Pledged SOL sits in a vault PDA: an account whose address is derived from the program and the campaign, and for which no private key exists. Not held by the team, not held in a multisig, not held anywhere. Lamports leave it only when the program itself signs with the vault's seeds.

There are exactly two destinations in the code for pledged SOL: the launch buy, and the wallet that pledged it.

Guarantee Enforced by Proven by
A missed target refunds everyone in full withdraw missed_target_refunds_every_pledger_in_full
You can leave any time before the deadline withdraw withdraw_is_open_before_the_deadline_even_when_target_is_met
Nobody can withdraw someone else's pledge PDA seeds + has_one cannot_withdraw_another_wallet_pledge
The campaign creator has no power over the pool no admin instruction exists creator_cannot_touch_the_vault
A filled campaign commits to the launch withdraw withdraw_locks_when_target_met_after_deadline
Pledged SOL is never stranded GRACE_SECONDS grace_period_unlocks_withdrawals_if_launch_never_runs
Caps are enforced on-chain, not in the UI pledge caps_are_enforced

The last one matters more than it looks. If a campaign fills but the launch cannot execute, for any reason, withdrawals unlock one hour after the deadline and every pledger takes their SOL back. There is no state in which the pool is frozen.

Accounts

campaign  seeds ["campaign", creator, seed]   campaign terms, immutable after creation
vault     seeds ["vault", campaign]           holds pledged SOL, system-owned, no key
pledge    seeds ["pledge", campaign, wallet]  one per wallet per campaign

Because the pledge PDA is derived from the pledger's own wallet, an instruction can only ever reach the caller's own pledge. That is the whole access-control model, and it is why there is no owner check to get wrong.

Verify it yourself

cargo build-sbf
cargo test

The tests run against a real Solana VM, not mocks. They fund wallets, pledge, warp past deadlines, and assert on actual lamport balances.

Status

Built and tested:

  • create_campaign
  • pledge
  • withdraw

Not yet written:

  • launch (pump.fun CPI: mint, then one buy with the whole pool)
  • claim (pro-rata from the vault, floor division so the vault cannot run short)

The program has not been deployed to mainnet and has not been audited. Do not send it real money yet.

Licence

MIT.

About

Pledge: a coin launches only when its target is pledged. Solana escrow program.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages