Octopus Pad mark

DOCS

How the Kraken works

Octopus Pad is a Solana launchpad on pump.fun. Eight promoted arms pay into $INK burns, the weakest arm is cut every day and auctioned for $INK, and a crash is met with ink: a slow buyback instead of a pause. Every number on this page is the program's.

Overview

Every coin is launched through the pad on pump.fun with its creator set to the coin's own program account. pump.fun's creator fees (0.30 % on the curve, the PumpSwap creator tier after migration) flow into that account, and the program splits them on chain. Nobody holds the creator fees by hand.

Eight coins hold the eight arms of the Kraken. A coin on an arm is shown first and pays more: 40 % of its fees buy $INK and burn it. At the end of every day the arm that earned the least is cut. The cut coin gets one support buy, burned. The free arm goes to an auction paid in $INK, and the winning $INK is burned.

The rules in one place

  1. Arms. Eight slots. Before $INK existed the admin seeded the first eight once (seed_slot); after that, arms are only won at auction.
  2. The day. At the bell the arms are measured: fees since the last measurement divided by the seconds, in SOL per day. The lowest rate among arms that served the whole day and are not inked is cut. Ties: the arm that joined first. No cut while fewer than 5 arms are held.
  3. Grace. A coin that takes an arm today can be cut from tomorrow on.
  4. Support. The cut coin gets one buy budget, once in its life: the smallest of 0.5 SOL, 5 % of the support reserve and what the coin itself paid into $INK buybacks, spent within 6 h. Tokens bought are burned.
  5. Leaving. A coin's dev can take it off its arm at any time. There is no support for leaving; the arm goes to auction.
  6. Auction. The first bid of at least 100,000 $INK starts a 6 h round. Each new top bid beats the last by 5 %. A bid in the last 5 min moves the end to that long after it. The winning $INK is burned; every other bid goes back to its bidder.
  7. Ink. When an arm's price falls at least 30 % below its highest 3-observation median of the last 10 min, anyone can open ink: a buyback in 15 chunks at least 60 s apart, bought tokens burned, only below 80 % of the pre-crash price. That arm cannot be cut that day; one event protects one day, never two. Cooldown 24 h.

The day: measure, then cut

The day closes in two steps so that no fee is counted twice or missed. First every held arm is measured: its parked fees are swept in (PumpSwap fees, then pump.fun fees), booked, and its rate is recorded as fees since its last measurement over the seconds since then. Then cut picks the lowest rate among eligible arms. A late or early measurement changes nobody's rank, because it is a rate, not a total.

For the first 10 min after the bell only the keeper may measure, so it can first recover fees someone parked out of reach (see Risks). After that anyone can close the day from the home page.

Where the fees go

DEV$INK BUY + BURNINK RESERVESUPPORT RESERVETREASURY
Off an arm50 %-14 %6 %30 %
On an arm30 %40 %7 %3 %20 %

Worked example. A coin on an arm earns 1 SOL of creator fees: 0.30 SOL is booked for its dev, 0.40 SOL goes to the $INK buyback pot, 0.07 SOL to the ink reserve, 0.03 SOL to the support reserve and 0.20 SOL to the treasury (it also takes the rounding dust). Off an arm the same 1 SOL is 0.50 / 0.14 / 0.06 / 0.30. The split is copied into each coin at launch. The dev share on an arm is capped at 30 % so that sending your own coin SOL to look busy costs at least 70 % of it.

The auction

A free arm waits for its first bid; the first bid starts the round. You bid for any pad coin that is not on an arm, is not $INK, and does not already lead another arm's auction. A second bid from you is a top-up for the same coin. Example: the top bid is 100,000 $INK; the next bid must reach at least 105,000. The round ends with no bid in its last minutes; settle then burns exactly the winning amount and puts the coin on the arm. Outbid bids can be pushed back by anyone, always to the bidder's own $INK account. With no bids, the arm stays empty.

Support

The cut coin's support budget is fixed at the cut: min(0.5 SOL, 5 % of the support reserve, what the coin paid into $INK buybacks). A coin that never paid into $INK gets no support. It is spent in depth-capped buys at least 60 s apart within 6 h; whatever is left returns to the reserve with end_support. A coin is supported once in its life.

Ink, not a pause

pump.fun coins have no pause and no tax, so the pad cannot stop a crash. It answers it. The program keeps its own clamped price observations for every arm. A crash is: the median of the newest 3 observations and the live price are both at or below 70 % of the reference, where the reference is the highest median of 3 consecutive observations in the last 10 min, with at least 5 observations in that window.

Budget = the smallest of 10 % of the ink reserve, 2 SOL, what is left of today's 4 SOL pad-wide cap, and 20 times what this coin itself has paid into the pool over its life, minus what its earlier ink events drew. Each chunk spends what is left divided by the chunks left, at most 0.5 % of the curve's SOL (0.25 % of a PumpSwap pool's), and only while the price stays below 80 % of the reference: the reserve buys the discount, never the recovery. After the deadline end_ink returns the unspent budget. One event protects the arm for one day only: a second event the same or the next day still buys, but adds no protection.

Observations are the program's own. For a few seconds after it is taken, the newest observation can still be replaced by a reading closer to the median before it; only settled observations count for a crash or a program buy, so one bundled trade cannot fake a fall.

Worked example. The ink reserve holds 7.80 SOL. A coin on an arm falls 31 % in ten minutes. Budget: min(0.78, 2, 4, 20 x its payments) = 0.78 SOL, in 15 chunks of 0.052 SOL a minute apart. Every token bought is burned and the arm is safe from today's cut.

Lifecycle

STATEHOW IT GETS THEREWHAT HAPPENS
Off the armslaunchTrades on pump.fun; fees split 50 / 20 / 30.
Biddingbid on a free armIts $INK sits in the escrow; it leads or is outbid.
On an arm (grace)settle (or seed_slot before $INK)Fees split 30 / 40 / 10 / 20; cannot be cut today.
On an arma day servedMeasured at every bell; the lowest rate is cut.
Inkedink after a crash15-chunk buyback, burned; safe from today's cut.
CutcutOff the arm; one support buy, burned; the arm goes to auction.
Leftleave by its devOff the arm, no support; the arm goes to auction.
Migratedcurve complete, sync_migrationTrades on PumpSwap; fees swept from PumpSwap on every collect.

The transactions

  1. Launch. launch(name, symbol, uri, dev_buy, expected_seq) alone in its transaction: pays the 0.02 SOL launch fee, pre-funds the creator vault, creates the coin on pump.fun with the coin's own account as creator, and makes your optional first buy.
  2. Bid. bid(slot, round, amount) moves your $INK into the escrow. You need $INK first; the site buys it on pump.fun from your wallet.
  3. Settle. collect + settle(slot) after the round: burns the winning bid, the coin takes the arm.
  4. Close the day. measure(slots) (four arms per transaction) then collect of the victim + cut.
  5. Ink. ink opens the cloud; ink_buy buys one chunk; end_ink closes it.
  6. Support. support buys one chunk of the cut coin; end_support closes it.
  7. $INK buy + burn. buy_ink spends at most 0.5 SOL of the pot per call, at least 60 s apart.

Every program buy is alone in its transaction (only compute-budget and SOL transfers may sit next to it), at most one per coin per slot, and its minimum output is computed on chain from the median of fresh observations, never from the caller.

Parameters (live from the chain)

Reading the config.

Program reference

Program ink9y8FhksdSUnyn8SbJrrDDLKQ2Kpmrh8sBTweaarY (Anchor 0.31.1).

ACCOUNTSEEDSHOLDS
Config["config"]admin, treasury, keeper, paused, params, $INK mint, counters
Kraken["kraken"]the day, 8 arms, 8 auctions, the pool's books, totals
Coin["coin", mint]the pump.fun creator of the coin; its split, fees, dev share, ink and support state
Obs["obs", mint]24 clamped price observations
Bid["bid", slot, round, bidder]one bidder's escrowed $INK in one round
Pool["pool"]all pooled SOL: ink + support reserves, buyback pot, locked budgets
Buyer["buyer"]the account that makes every program buy, for one buy at a time
Escrow["escrow"]authority of the $INK escrow account
INSTRUCTIONWHOWHAT
launchdevcreate the coin on pump.fun + optional first buy
observe, collect, sync_migration, unwrap_feesanyoneprices and fee booking
claim_dev, flush_treasuryanyonepay only the dev / the treasury what is booked
measurekeeper first, then anyonerecord each arm's fee rate of the day
cutanyoneclose the day
leavethe coin's devtake the coin off its arm (no support)
bid, refund_bid, settle$INK holder / anyone / anyonethe auction
ink, ink_buy, end_inkanyonethe crash shield
support, end_supportanyonethe cut coin's one buy
buy_ink, sweep, burn_escrow_surplusanyone$INK buy + burn, gifts to the pool, stray $INK burned
update_config, set_paused, set_hidden, set_treasury, set_keeper, propose_adminadminsee Admin
set_pad_mint, seed_slotadmin, once / before $INKset $INK; seed the first arms

Errors

Reading the program's error list.

Verify on chain

  1. Each coin's pump.fun creator is its ["coin", mint] account of this program, not a wallet.
  2. The Kraken's eight arms, their measured fees and seconds, and the cut it would make are public; the home page shows them.
  3. Every cut, bid, settle, ink chunk, support and burn emits an event; each row in the soundings links to its transaction.
  4. $INK supply only falls: auction wins, buybacks and stray escrow $INK are burned with Token-2022 burns.
  5. The pool always holds at least its books: ink reserve + support reserve + buyback pot + locked budgets.

Admin: can and cannot

CANCANNOT
Pause new launches and bids (settle, refunds, claims keep working).Move anyone's SOL or tokens, or the pool's.
Change parameters within their bounds for future coins, rounds, ink events and supports, including the day length and the minimum arms to cut (it can slow or stop cuts).Change the split of an existing coin, or a running round.
Hide a coin from bidding (moderation).Take an arm from a coin or give one, after $INK exists.
Set $INK once; seed arms before $INK exists.Change $INK after it is set.
Change treasury or keeper; hand over admin in two steps.Pick the cut, the ink trigger or any buy amount.

Winding down. If the pad is ever closed, the admin pauses launches and bids; bids stay refundable, booked fees stay claimable, and the site shows a closing banner with the transaction.

Risks and the compromise

Compromise. "Weakest volume" is the weakest creator-fee rate: exact between coins on the curve (a flat 0.30 %), tiered after migration, because PumpSwap's creator fee falls as market cap grows (0.95 % to 0.05 %). A big migrated coin pays less per SOL of volume.

FAQ

Can a crash be stopped?
No. pump.fun coins cannot be paused or taxed. Ink buys slowly below the crash price and burns what it buys.
Why is $INK burned instead of kept?
Burned tokens can never be sold back into the market.
What do I need to bid?
$INK in your wallet and a pad coin that is off the arms. You can launch one first.
I was outbid. Where is my $INK?
Still in the escrow, refundable by anyone to your own account. Mine shows a button for it, and the keeper pushes refunds.
Is this mainnet?
This preview runs the real program on a local Solana validator with test SOL.