1. Launch
One transaction creates a pump.fun coin with you as its creator and pairs it with a vision + tools model from the OpenRouter catalog. The model is fixed for the coin's life. You keep 100 % of the pump.fun creator fee; the pad never touches it. The seed is split: 30 % to the coin's milestone pot, the rest to compute (the model's calls) up to a cap of 3 SOL. The launch fee is 0.02 SOL.
2. The emulator
The model plays in a deterministic emulator on our box. A coin wakes when it has $1 of compute and sleeps below $0.25; at most a fixed number of players are awake at once, longest-waiting first. A run is at most 24 turns, 4 minutes or $0.50. Each turn the model gets the screen and a short memory summary (map, position, party, badges) and answers with up to 3 tool calls: press buttons, walk, wait, or write a note to itself. Everything it does is public: thoughts, the input log, the frames.
If the model errors twice, the run continues with a fallback model and says so in the feed. Nobody resets a bad run: whiteouts and wrong turns stay on the stream.
3. Milestones
After every input the service reads fixed memory flags. A flag counts only if it is still set in the save re-loaded from disk after the run. Each new one is posted on chain with its evidence (address, before, after), the frame, the run's input-log hash and the end-of-run state hash, signed by the attestor key. It then sits in a public veto window of 30 min before anyone can settle it.
| Milestone | How many | Share of the pot |
|---|---|---|
| Badge | 8 | 15 % |
| Key item | 7 | 5 % |
| New town | 10 | 3 % |
| Every 10 caught | 15 | 3 % |
| Champion | 1 | 100 % |
4. Buyback + burn
A settled milestone moves its share of the pot (computed at settle time) into the coin's buyback bucket. A permissionless keeper then buys the coin on its bonding curve or its PumpSwap pool in chunks (at most 1 % price impact each, against a median price guard) and burns every token it bought. After the Champion, every later pot inflow goes to buyback too.
5. Money in, money out
- In: the seed, feeds from anyone (0.001 SOL minimum), and the router fee: trades through the pad pay 0.5 %, of which 20 % goes to the pad and the rest to the coin (split like a feed).
- Out: compute charges to the ops wallet that pays OpenRouter (posted per run, each with its request rows, settled after a 2 h veto window), and buybacks that burn the coin. Nothing else can move a coin's SOL; the admin has no path to it.
6. Replay
The emulator is deterministic. Every run publishes its input log (one row per action, with the frames and the request id that produced it) and the start and end state hashes; each run starts where the last one ended. With your own copy of the game file, replay.py rebuilds any coin's save from the public logs and prints the same state hash after each run and the frame of each milestone flip. Savestates stay private; the game file is never served.
7. Parameters (live from the program)
8. Trust points
- Attestor key (the emulator service) posts milestones and charges. A stolen key could at worst move a pot into buyback early (the SOL still only buys and burns that coin) or charge up to the daily cap to the pad's own ops wallet.
- Guardian watches every post during its window: it checks the run records, the hash chain, the input-log hash and the evidence, and replays the log with its own game file. A mismatch is vetoed and the attestor key revoked on the spot. The guardian cannot move money.
- Admin can change bounded parameters (24 h delay), pause, set the treasury and rotate keys (3 days). No admin path to coin balances.
- Platform: pump.fun and PumpSwap, OpenRouter availability (fallback model), Pyth SOL/USD for charges. The program is upgradeable and not externally audited.