Protocol
What is actually running
The honesty box. The contracts, circuits and fork tests live in the repository; every number on every other page is read from the chain.
Verified against the real pump.fun factory
Solana forklaunchToken(params, 0, SOL, [pool]) from the launchpad, pool exempt from the snipe tax, opening batch settled in the same transaction: 368,421,052 tokens per SOL for the crowd, 2,365,464 for a sniper in the same slot.
A 10 SOL batch clamped at the reserved allocation, refunded the rest, auto-graduated, and createGraduatedPool minted a real locked PumpSwap position.
The fee vault is pump.fun's creator of record; after graduation the creator share is harvested from pump.fun's escrow into a shielded note.
the pool, one line each
- deposit
no proof: the pool computes cm = Poseidon5(asset, value, pk, rho, 3) and inserts it
MutePool.deposit
- intent
spend a quote note into the open batch; prove eligibility and the cap tally when gated; insert change, swap commitment, tally
intent.circom · 40,414 constraints
- settle
one pump.fun buy and one pump.fun sell per batch; the result (in, out, unfilled) is public
MutePool.settleBatch
- claim
prove the swap commitment is in the tree; mint out = ⌊amountout/in⌋ and the refund as notes
claim.circom · 14,896 constraints
- joinsplit
2-in 2-out with an optional public leg: transfer, withdraw, or deposit with proof
joinsplit.circom · 28,026 constraints
zcash → solana
- Orchard notes, nullifiers, one commitment treeSame shape: Poseidon commitment tree on Solana
- Halo2 (IPA, Pasta curves)Groth16 on BN254 today, verified in-program
- Full / incoming / outgoing viewing keysnk derived from sk; per-note viewing tags
- Zcash Shielded Assets asset idsOne asset id per SPL token mint
- Memo fieldThe mute-1 inscription record
- Tachyon oblivious sync / aggregated proofsDetection-key indexer, proofs batched per slot
derivations · shared by circuits, contracts and wallets
pk = Poseidon2(sk, 1) nk = Poseidon2(sk, 2) cm = Poseidon5(assetId, value, pk, rho, 3) nf = Poseidon2(nk, rho) scm = Poseidon5(launchId·2^33 + batchId·2 + side, amount, pkClaim, rhoSwap, 4) snf = Poseidon2(rhoSwap, 5) idk = Poseidon2(idSecret, 6) gnf = Poseidon2(Poseidon2(idSecret, launchId), 7) tcm = Poseidon5(launchId, idk, cumulative, rhoTally, 8) tnf = Poseidon2(Poseidon2(idSecret, rhoTally), 9)
What is public
batch totals and results, the cap, the eligibility root, nullifier counts, inscription records, the pump.fun curve itself
What is hidden
who deposited, who intended, how much any identity holds, which claim belongs to which intent, creator identities
What is trusted
a one-contributor dev ceremony; the pool owner until verifiers are locked; pump.fun governance over its own factory