DOCS
How the Kraken works
Octopus Pad is a Solana launchpad on pump.fun. Eight promoted arms pay into $INK burns, the weakest arm is cut every day and auctioned for $INK, and a crash is met with ink: a slow buyback instead of a pause. Every number on this page is the program's.
Overview
Every coin is launched through the pad on pump.fun with its creator set to the coin's own program account. pump.fun's creator fees (0.30 % on the curve, the PumpSwap creator tier after migration) flow into that account, and the program splits them on chain. Nobody holds the creator fees by hand.
Eight coins hold the eight arms of the Kraken. A coin on an arm is shown first and pays more: 40 % of its fees buy $INK and burn it. At the end of every day the arm that earned the least is cut. The cut coin gets one support buy, burned. The free arm goes to an auction paid in $INK, and the winning $INK is burned.
The rules in one place
- Arms. Eight slots. Before $INK existed the admin seeded the first eight once (
seed_slot); after that, arms are only won at auction. - The day. At the bell the arms are measured: fees since the last measurement divided by the seconds, in SOL per day. The lowest rate among arms that served the whole day and are not inked is cut. Ties: the arm that joined first. No cut while fewer than 5 arms are held.
- Grace. A coin that takes an arm today can be cut from tomorrow on.
- Support. The cut coin gets one buy budget, once in its life: the smallest of 0.5 SOL, 5 % of the support reserve and what the coin itself paid into $INK buybacks, spent within 6 h. Tokens bought are burned.
- Leaving. A coin's dev can take it off its arm at any time. There is no support for leaving; the arm goes to auction.
- Auction. The first bid of at least 100,000 $INK starts a 6 h round. Each new top bid beats the last by 5 %. A bid in the last 5 min moves the end to that long after it. The winning $INK is burned; every other bid goes back to its bidder.
- Ink. When an arm's price falls at least 30 % below its highest 3-observation median of the last 10 min, anyone can open ink: a buyback in 15 chunks at least 60 s apart, bought tokens burned, only below 80 % of the pre-crash price. That arm cannot be cut that day; one event protects one day, never two. Cooldown 24 h.
The day: measure, then cut
The day closes in two steps so that no fee is counted twice or missed. First every held arm is measured: its parked fees are swept in (PumpSwap fees, then pump.fun fees), booked, and its rate is recorded as fees since its last measurement over the seconds since then. Then cut picks the lowest rate among eligible arms. A late or early measurement changes nobody's rank, because it is a rate, not a total.
For the first 10 min after the bell only the keeper may measure, so it can first recover fees someone parked out of reach (see Risks). After that anyone can close the day from the home page.
Where the fees go
| DEV | $INK BUY + BURN | INK RESERVE | SUPPORT RESERVE | TREASURY | |
|---|---|---|---|---|---|
| Off an arm | 50 % | - | 14 % | 6 % | 30 % |
| On an arm | 30 % | 40 % | 7 % | 3 % | 20 % |
Worked example. A coin on an arm earns 1 SOL of creator fees: 0.30 SOL is booked for its dev, 0.40 SOL goes to the $INK buyback pot, 0.07 SOL to the ink reserve, 0.03 SOL to the support reserve and 0.20 SOL to the treasury (it also takes the rounding dust). Off an arm the same 1 SOL is 0.50 / 0.14 / 0.06 / 0.30. The split is copied into each coin at launch. The dev share on an arm is capped at 30 % so that sending your own coin SOL to look busy costs at least 70 % of it.
The auction
A free arm waits for its first bid; the first bid starts the round. You bid for any pad coin that is not on an arm, is not $INK, and does not already lead another arm's auction. A second bid from you is a top-up for the same coin. Example: the top bid is 100,000 $INK; the next bid must reach at least 105,000. The round ends with no bid in its last minutes; settle then burns exactly the winning amount and puts the coin on the arm. Outbid bids can be pushed back by anyone, always to the bidder's own $INK account. With no bids, the arm stays empty.
Support
The cut coin's support budget is fixed at the cut: min(0.5 SOL, 5 % of the support reserve, what the coin paid into $INK buybacks). A coin that never paid into $INK gets no support. It is spent in depth-capped buys at least 60 s apart within 6 h; whatever is left returns to the reserve with end_support. A coin is supported once in its life.
Ink, not a pause
pump.fun coins have no pause and no tax, so the pad cannot stop a crash. It answers it. The program keeps its own clamped price observations for every arm. A crash is: the median of the newest 3 observations and the live price are both at or below 70 % of the reference, where the reference is the highest median of 3 consecutive observations in the last 10 min, with at least 5 observations in that window.
Budget = the smallest of 10 % of the ink reserve, 2 SOL, what is left of today's 4 SOL pad-wide cap, and 20 times what this coin itself has paid into the pool over its life, minus what its earlier ink events drew. Each chunk spends what is left divided by the chunks left, at most 0.5 % of the curve's SOL (0.25 % of a PumpSwap pool's), and only while the price stays below 80 % of the reference: the reserve buys the discount, never the recovery. After the deadline end_ink returns the unspent budget. One event protects the arm for one day only: a second event the same or the next day still buys, but adds no protection.
Observations are the program's own. For a few seconds after it is taken, the newest observation can still be replaced by a reading closer to the median before it; only settled observations count for a crash or a program buy, so one bundled trade cannot fake a fall.
Worked example. The ink reserve holds 7.80 SOL. A coin on an arm falls 31 % in ten minutes. Budget: min(0.78, 2, 4, 20 x its payments) = 0.78 SOL, in 15 chunks of 0.052 SOL a minute apart. Every token bought is burned and the arm is safe from today's cut.
Lifecycle
| STATE | HOW IT GETS THERE | WHAT HAPPENS |
|---|---|---|
| Off the arms | launch | Trades on pump.fun; fees split 50 / 20 / 30. |
| Bidding | bid on a free arm | Its $INK sits in the escrow; it leads or is outbid. |
| On an arm (grace) | settle (or seed_slot before $INK) | Fees split 30 / 40 / 10 / 20; cannot be cut today. |
| On an arm | a day served | Measured at every bell; the lowest rate is cut. |
| Inked | ink after a crash | 15-chunk buyback, burned; safe from today's cut. |
| Cut | cut | Off the arm; one support buy, burned; the arm goes to auction. |
| Left | leave by its dev | Off the arm, no support; the arm goes to auction. |
| Migrated | curve complete, sync_migration | Trades on PumpSwap; fees swept from PumpSwap on every collect. |
The transactions
- Launch.
launch(name, symbol, uri, dev_buy, expected_seq)alone in its transaction: pays the 0.02 SOL launch fee, pre-funds the creator vault, creates the coin on pump.fun with the coin's own account as creator, and makes your optional first buy. - Bid.
bid(slot, round, amount)moves your $INK into the escrow. You need $INK first; the site buys it on pump.fun from your wallet. - Settle.
collect+settle(slot)after the round: burns the winning bid, the coin takes the arm. - Close the day.
measure(slots)(four arms per transaction) thencollectof the victim +cut. - Ink.
inkopens the cloud;ink_buybuys one chunk;end_inkcloses it. - Support.
supportbuys one chunk of the cut coin;end_supportcloses it. - $INK buy + burn.
buy_inkspends at most 0.5 SOL of the pot per call, at least 60 s apart.
Every program buy is alone in its transaction (only compute-budget and SOL transfers may sit next to it), at most one per coin per slot, and its minimum output is computed on chain from the median of fresh observations, never from the caller.
Parameters (live from the chain)
| Reading the config. |
Program reference
Program ink9y8FhksdSUnyn8SbJrrDDLKQ2Kpmrh8sBTweaarY (Anchor 0.31.1).
| ACCOUNT | SEEDS | HOLDS |
|---|---|---|
| Config | ["config"] | admin, treasury, keeper, paused, params, $INK mint, counters |
| Kraken | ["kraken"] | the day, 8 arms, 8 auctions, the pool's books, totals |
| Coin | ["coin", mint] | the pump.fun creator of the coin; its split, fees, dev share, ink and support state |
| Obs | ["obs", mint] | 24 clamped price observations |
| Bid | ["bid", slot, round, bidder] | one bidder's escrowed $INK in one round |
| Pool | ["pool"] | all pooled SOL: ink + support reserves, buyback pot, locked budgets |
| Buyer | ["buyer"] | the account that makes every program buy, for one buy at a time |
| Escrow | ["escrow"] | authority of the $INK escrow account |
| INSTRUCTION | WHO | WHAT |
|---|---|---|
launch | dev | create the coin on pump.fun + optional first buy |
observe, collect, sync_migration, unwrap_fees | anyone | prices and fee booking |
claim_dev, flush_treasury | anyone | pay only the dev / the treasury what is booked |
measure | keeper first, then anyone | record each arm's fee rate of the day |
cut | anyone | close the day |
leave | the coin's dev | take the coin off its arm (no support) |
bid, refund_bid, settle | $INK holder / anyone / anyone | the auction |
ink, ink_buy, end_ink | anyone | the crash shield |
support, end_support | anyone | the cut coin's one buy |
buy_ink, sweep, burn_escrow_surplus | anyone | $INK buy + burn, gifts to the pool, stray $INK burned |
update_config, set_paused, set_hidden, set_treasury, set_keeper, propose_admin | admin | see Admin |
set_pad_mint, seed_slot | admin, once / before $INK | set $INK; seed the first arms |
Errors
| Reading the program's error list. |
Verify on chain
- Each coin's pump.fun creator is its
["coin", mint]account of this program, not a wallet. - The Kraken's eight arms, their measured fees and seconds, and the cut it would make are public; the home page shows them.
- Every cut, bid, settle, ink chunk, support and burn emits an event; each row in the soundings links to its transaction.
- $INK supply only falls: auction wins, buybacks and stray escrow $INK are burned with Token-2022 burns.
- The pool always holds at least its books: ink reserve + support reserve + buyback pot + locked budgets.
Admin: can and cannot
| CAN | CANNOT |
|---|---|
| Pause new launches and bids (settle, refunds, claims keep working). | Move anyone's SOL or tokens, or the pool's. |
| Change parameters within their bounds for future coins, rounds, ink events and supports, including the day length and the minimum arms to cut (it can slow or stop cuts). | Change the split of an existing coin, or a running round. |
| Hide a coin from bidding (moderation). | Take an arm from a coin or give one, after $INK exists. |
| Set $INK once; seed arms before $INK exists. | Change $INK after it is set. |
| Change treasury or keeper; hand over admin in two steps. | Pick the cut, the ink trigger or any buy amount. |
Winding down. If the pad is ever closed, the admin pauses launches and bids; bids stay refundable, booked fees stay claimable, and the site shows a closing banner with the transaction.
Risks and the compromise
Compromise. "Weakest volume" is the weakest creator-fee rate: exact between coins on the curve (a flat 0.30 %), tiered after migration, because PumpSwap's creator fee falls as market cap grows (0.95 % to 0.05 %). A big migrated coin pays less per SOL of volume.
- Fees parked out of reach. PumpSwap lets anyone park a coin's creator fees in a separate account the coin owns; the measure does not see them until someone unwraps it. The keeper scans and unwraps before measuring; the money is never lost, it is counted later.
- Paying to look busy. SOL sent to a coin counts as fees. On an arm it costs the sender at least 70 %, and that 70 % funds $INK burns and the reserves.
- Crashing your own coin for ink. Bounded: the budget is at most 20 times what the coin paid into the pool over its life, at most 2 SOL, 4 SOL a day pad-wide, buys only below 80 % of the reference, a 24 h cooldown, and the tokens are burned.
- Keeper down. If nobody closes the day, the day does not close; nothing is lost and anyone can close it.
- pump.fun changes. pump.fun keeps its own admin powers; if it changes its account lists, program buys fail until an upgrade. The program is upgradeable.
FAQ
- Can a crash be stopped?
- No. pump.fun coins cannot be paused or taxed. Ink buys slowly below the crash price and burns what it buys.
- Why is $INK burned instead of kept?
- Burned tokens can never be sold back into the market.
- What do I need to bid?
- $INK in your wallet and a pad coin that is off the arms. You can launch one first.
- I was outbid. Where is my $INK?
- Still in the escrow, refundable by anyone to your own account. Mine shows a button for it, and the keeper pushes refunds.
- Is this mainnet?
- This preview runs the real program on a local Solana validator with test SOL.