MOLE PAD DOCS
A Solana launchpad on pump.fun where a new coin starts underground. Wallets dig its field for rights; a right is a seat in the one pooled first buy that creates the coin. Bots can only buy after.
- OVERVIEW
- LIFECYCLE
- THE DIG GAME
- RIGHTS
- SURFACING
- REFUNDS
- FEES + $DIG
- COMPROMISES
- TRUST
- VERIFY
- PARAMETERS
- ACCOUNTS
- INSTRUCTIONS
- ERRORS
- RISKS
- FAQ
OVERVIEW
A pump.fun coin is public from the transaction that creates it, so a coin cannot be hidden on pump. On Mole Pad it does not exist on pump at all for its first minutes. It is a burrow: the program stores only a salted hash of its name, ticker and metadata link, and a hash of the dig field's seed (the round code).
While the burrow is underground, wallets dig its field through the dig service. A dug cell shows how many buried treasures touch it. A dig that hits a treasure returns a right signed by the pad's attestor. The wallet funds the right: it locks up to the right's cap in the burrow's escrow.
At the timer, or as soon as every right is funded or the escrow is full, anyone sends surface: one instruction creates the coin on pump.fun and makes one pooled buy with the whole escrow (the diggers and the dev deposit, one price). Everybody then claims tokens in proportion to what they locked. A burrow that cannot surface refunds everybody in full.
The pad promises that diggers enter first, in one transaction. It does not promise that there are no bots: anyone can buy the coin on pump.fun right after the surfacing transaction.
LIFECYCLE
| STATE | WHAT HAPPENS | WHO MOVES IT |
|---|---|---|
| PREPARED | The creator sends name, ticker, picture link (IPFS), field size, treasures, caps and a dev deposit. The dig service draws a random field seed and a salt and co-signs the opening. | creator + dig service |
| UNDERGROUND | open_burrow: the escrow takes the dev deposit, the rent deposit and the launch fee. The timer runs 10 minutes. Wallets dig and fund rights. | diggers |
| READY | Every right funded, or the escrow full, or the timer over with at least 3 funded rights. | - |
| SURFACED | surface: create_v2 on pump.fun (mint = a PDA of the pad, creator = the coin's Fees PDA) + one buy of the whole escrow, alone in its transaction. Then reveal_field puts the seed on chain. | anyone (the keeper does it) |
| SETTLED | claim per right and claim_dev_share: tokens x deposit / budget, plus a share of any SOL the capped buy did not spend. sweep returns the leftover rents to the creator. | anyone; the keeper pushes after 30 min |
| CANCELLED | Too few diggers at the timer, nobody surfaced within 1 h after it, the creator before any right was funded, or a guardian veto. refund per right and refund_dev pay back 100 %. | anyone / creator / guardian |
THE DIG GAME
The field is a grid of 4-24 x 4-24 cells with at least four cells per treasure. Its layout is a pure function of the seed: treasure i sits at the first sha256("mole/cell/v1" || seed || i || generation || counter) mod cells that is free.
- Sign in: your wallet signs a plain text message (no transaction, no SOL moves) and you pass a Cloudflare Turnstile human check. The wallet must hold at least 0.01 SOL: it is only read, never spent. The session lasts 30 minutes.
- Digs per hour: a token bucket per wallet. Every new wallet starts with 6 digs. Holding $DIG raises how fast digs come back: 6 an hour for every wallet; 9 from 100K $DIG, 12 from 1M, 18 from 10M (balance read on chain). Moving one bag of $DIG from wallet to wallet gives nothing: each new wallet still starts at 6.
- Per network: at most 10 sign-ins and 60 digs an hour from one IP address, whatever the wallets.
- Hints: an empty cell shows how many buried treasures touch it (8 neighbours), like minesweeper.
- One right per wallet per burrow. The creator cannot dig his own burrow.
- Rights expire: a found treasure must be funded within 180 s. Unfunded, it is re-buried at a cell anyone can recompute from the seed after the reveal.
- Everything is public: every dig (wallet, cell, time, result) and every re-bury is in the burrow's dig log while it is underground.
RIGHTS AND THE ESCROW
A right is an Ed25519 signature of the attestor over "mole/right/v1" || program || burrow || index || wallet || cap || expiry. claim_right checks it, creates the Right account (one per wallet per burrow) and moves your deposit into the escrow: min(amount, cap, room left), at least 0.02 SOL. Deposits are final until the burrow surfaces or is cancelled.
Worked example. A 16 x 12 burrow, 20 treasures, 0.25 SOL per right, escrow cap 5 SOL, dev deposit 0.3 SOL. Four diggers fund 0.25 + 0.25 + 0.1 + 0.1 = 0.7 SOL. Budget = 0.3 + 0.7 = 1.0 SOL. At surfacing one buy of 1.0 SOL takes about 3.41 % of the supply at about 1.046 x the start price. A digger who locked 0.25 SOL claims tokens x 0.25 / 1.0 = a quarter of what the buy got.
SURFACING
One instruction, alone in its transaction (only compute budget next to it): it checks the metadata against the committed hash, creates the coin with create_v2 (mayhem, holder rewards and cashback off) and buys once with the budget. The buy never offers more than the lamports that buy 15 % of the supply on the fresh curve; what it did not spend goes back pro rata (SOL back). Measured: a full 5 SOL escrow is capped at about 4.875 SOL = 14.84 % of the supply at 1.175 x the start price. The program asserts the escrow holds at most 15 % of the supply after the buy.
It is permissionless: the keeper sends it with the metadata the dig service keeps, and the creator can send it from the receipt the site gives at launch (name, ticker, link, salt).
NO SHOW, NO LOSS
A burrow that cannot surface is cancelled and every lamport goes back: each right gets 100 % of its deposit plus the Right account's rent, the creator gets the dev deposit, the rent deposit and the launch fee. Measured cost of a cancelled burrow to its creator: transaction fees only.
FEES AND $DIG
- Launch fee 0.02 SOL to the treasury, taken at surfacing (refunded on cancel).
- Rent deposit 0.05 SOL pays pump.fun's create and first-buyer rents (about 0.0102 SOL); the rest comes back with the dev share.
- Creator fees of every surfaced coin are split on chain: dev 40 %, $DIG buyback 20 %, treasury 40 %.
- The $DIG share sits in the dig pot.
buy_digspends it on $DIG through a price guard (median of recent observations, max impact 1 %) and burns every token bought.
COMPROMISES, IN PLAIN WORDS
- "Hide the coin for 10 minutes on pump" is impossible. A pump coin is public from its create transaction. So the coin is not created at all until it surfaces; until then it is a hash.
- The first buy is one pooled buy, not a race. Diggers do not buy one by one before the public; they all sit in one buy in the creating instruction, at one price. Bots buy right after it.
- The dig game runs off chain. The field, the hints and the rights come from the dig service. The seed is committed before the first dig and revealed after, so every hint can be checked; it cannot be made impossible to cheat while the round runs.
- Rights are capped, not free. A cap per right, a cap per burrow (at most 5 SOL) and one right per wallet stop a whale from taking the launch.
- Bot farms are slowed, not stopped. A wallet signature, a human check, 0.01 SOL in the wallet and per-network limits make each extra digger cost something. A farm with many funded wallets, many IP addresses and solved checks can still dig, and one right per wallet does not stop it from collecting many rights.
TRUST POINTS
- The dig service (attestor) knows every seed while burrows are underground and decides who gets a right. It could tip a friend or sign a right without a dig. Checkable after the fact: the round code, the public log, the rights list and the on-chain reveal show any right without a matching treasure dig. The program bounds it: rights only up to the burrow's cap, one per wallet, the escrow cap, at most 15 % of the supply, only while underground.
- The keeper surfaces, reveals, pushes claims and refunds, and collects fees. Every one of these is permissionless; anyone can do them from the burrow page.
- The guardian can veto (cancel) an underground burrow, which refunds everybody. It cannot touch a surfaced coin.
ADMIN CAN
- Pause new burrows and new deposits (claims and refunds keep working).
- Change parameters, with a 1-day timelock the guardian can cancel; every burrow keeps the parameters it opened with.
- Rotate the attestor or the guardian (3-day timelock), set the $DIG mint once, upgrade the program (the upgrade authority is a trust point like every upgradeable program).
ADMIN CANNOT
- Move escrow, Fees or dig pot funds: no instruction lets it.
- Create a right, change a burrow's caps or seed, or stop a refund.
IF THE PAD CLOSES
The site shows a SUNSET banner and stops taking new burrows. Underground burrows either surface or are cancelled by the rules above; claims, refunds and the dev share stay open on chain forever.
VERIFY ON CHAIN
- The program id is
Dig3eAVxdv5Cd6Pek741FfMAB1Te3wcVYqghMRH3gTCK. Config PDA["config"]. - A burrow is the PDA
["burrow", round code]. Itsmeta_hash= sha256("mole/meta/v1" || len || name || len || ticker || len || uri || salt). - After surfacing,
field_seedis on the burrow account andsha256(seed) == round code(checked byreveal_field). - Open any surfaced burrow and press VERIFY FIELD: your browser recomputes the layout from the seed and replays every dig and re-bury of the public log.
- The surfacing transaction has one instruction of this program: create_v2 and the buy are its inner instructions. Open it from the burrow page.
- The coin's pump.fun creator is
["fees", mint]of this program; its curve is created in the same instruction as the buy.
PARAMETERS
Live from the config account (version -). Each burrow copies them when it opens.
| PARAMETER | VALUE | MEANS |
|---|---|---|
| Reading the config. | ||
ACCOUNTS AND SEEDS
| ACCOUNT | SEEDS | HOLDS |
|---|---|---|
| Config | ["config"] | admin, treasury, attestor, guardian, params (+ pending), $DIG mint, counters |
| Burrow | ["burrow", field_commit] | the burrow, then the coin's record: fee books, price ring |
| Escrow | ["escrow", burrow] | deposits; pump.fun payer and buyer of the pooled buy; holds the tokens until claimed |
| Mint | ["mint", burrow] | the coin's mint, created by pump.fun's create_v2 |
| Fees | ["fees", mint] | the pump creator of the coin: creator fees, dev / treasury books |
| Right | ["right", burrow, wallet] | seat index, cap, deposit; closed at claim / refund (rent back to the wallet) |
| Dig pot | ["digpot"] | the $DIG share of every coin's fees |
| Buyer | ["buyer"] | the pump user of $DIG buybacks (tokens burned at once) |
INSTRUCTIONS
| WHO | INSTRUCTIONS |
|---|---|
| creator | open_burrow (+ the attestor's Ed25519 co-sign), cancel_burrow before any right is funded |
| digger | claim_right (+ the attestor's Ed25519 right) |
| anyone | surface, reveal_field, cancel_burrow (too few diggers / past the deadline), claim, claim_dev_share, refund, refund_dev, close_burrow, sweep, collect, claim_dev, collect_treasury, sync_migration, observe, buy_dig |
| guardian | cancel_burrow (veto, underground only), cancel_params, cancel_attestor |
| admin | init_config, propose_params / accept_params, set_treasury, set_paused, key rotations, set_pad_mint (once) |
| dev | propose_dev / accept_dev (two-step handover of the fee share) |
ERRORS
What the program answers when it refuses, from its IDL.
| CODE | NAME | MEANS |
|---|---|---|
| Reading the IDL. | ||
RISKS
- The metadata becomes public at surfacing; a copycat can launch the same name after us (not before: it is hashed with a salt).
- Bots can buy in the same block right after the surfacing transaction. They pay a higher price than the diggers (about 1.36 x the start price after a full escrow).
- The dig service knows the seed during the round (see Trust points).
- A bot farm with many funded wallets and IP addresses can still win many rights; each one is capped.
- If pump.fun raises its create rents above the rent deposit, surfacing fails until the parameter is raised; the burrow is then cancelled with full refunds.
- Ticker $DIG is also used by another live coin. Check the CA posted here and on our X.
FAQ
DO I PAY TO DIG?
No. Signing in is a signed message, digging is off chain. The wallet needs 0.01 SOL in it to sign in, but nothing is taken. You pay only when you fund a right (your deposit + about 0.0016 SOL account rent, returned at claim).
WHY ONLY 6 DIGS WITH 10M $DIG?
A new wallet always starts with 6. $DIG makes digs come back faster (up to 18 an hour) and lets a wallet that keeps holding store up to its tier. That way one bag moved between wallets is worth nothing.
WHAT IF NOBODY SURFACES IT?
Anyone can cancel it after the window, and every right is refunded in full. The keeper does it on its rounds.
CAN I WITHDRAW A DEPOSIT?
No, deposits are final until the burrow surfaces or is cancelled. That stops a seat being parked and pulled at the last second.
WHY CAN'T I SEE THE COIN WHILE IT IS UNDERGROUND?
Because it does not exist yet. Only its hash is on chain; the name and picture appear when it surfaces.