Penguin Pad markPenguin Pad

Huddle map · docs

Docs

A launchpad on pump.fun. The coins that migrate form a huddle; once a voyage the pot buys and burns the coldest coins at its edge and a fixed share of $HUDDLE. The weather decides how much is spent.

Flow

StageWhat happensFee split of the creator fees
LaunchYou launch through the pad: create_v2 on pump.fun with the creator set to the coin's own Fees PDA of our program, plus your dev buy, in one instruction alone in its transaction. Launch fee SOL to the treasury.-
CurveNormal pump.fun trading. Creator fees (0.30% on the curve) pile up in pump's creator vault of the Fees PDA; anyone calls collect to split them.dev / treasury
Migrationpump.fun migrates the coin to its canonical PumpSwap pool. Anyone calls sync_migration: the coin joins the huddle.dev / pot / treasury
EmperorThe biggest migrated coin by median market cap wears the crown.dev / pot / treasury
VoyageOnce per epoch () anyone opens the voyage. The pot's budget is set by the weather; buys and burns $HUDDLE, the rest feeds the coldest coins of the edge report; everything bought is burned.-

Everything above runs on chain except one input: which coins are frozen (wallet-level data). That list is attested by the keeper and published, see Frozen.

Weather

r = fees(last epoch) / average(fees of the 7 epochs before), from the pad's fee ring on chain (every lamport collect books).

spend = clamp(125% - 75% × r, 20%, 100%) → r ≤ 0.33 spends 100% (Blizzard), r = 1 spends 50%, r ≥ 1.4 spends 20% (Warm).

LabelSpendHeat rings on the mapSnow
Blizzard100%core onlyheavy
Coldabove 62.5%core + ring 1light
Mildabove 35%+ ring 2a few flakes
Warm20-35%all ringsnone

History shorter than 8 epochs: the average uses the epochs the pad existed in. No history and a silent last epoch: Blizzard. No history but fees: Warm (r = 100x). Wash trading makes the weather warmer, so it only delays spending, and its fees land in the pot.

Frozen

Frozen = fewer than different wallets bought or sold the coin on its canonical PumpSwap pool in the last , counting only trades of SOL or more. A wallet that bought and sold inside one transaction is ignored; the pad's own pot is not a trader.

Edge order: frozen first, then fewer wallets, then older last trade, then the older launch. The report lists at most 5 coins. Eligible (checked again by the program): a Penguin coin, migrated at least ago, not the Emperor, not $HUDDLE. A coin whose trade history could not be read completely is excluded, never reported cold.

Compromise. Frozen needs wallet-level data, so the keeper publishes it as a signed report anyone can recompute (/report/<epoch>.json, its sha256 is in the epoch's Feed account). The amounts are enforced on chain: the attestor can only choose which eligible coins are fed, never how much.

Why wallets and not volume: volume is cheap to fake, wallets cost real people. Fake wallets on a coin only make it look warmer and keep it off the feed. They can be used against a competitor, though: sybil trades on another cold coin push it out of the 5 coldest (about 0.003 SOL per coin at the 0.01 SOL minimum). Raising the minimum trade is a timelocked parameter. Making a coin look frozen means its traders really stop trading.

Emperor

Market cap = median of the newest 7 price observations (each clamped to ±10% of the previous, at least apart, all within 30 min and spanning at least ) × the live mint supply.

A challenger takes the crown with crown when its median beats the Emperor's by and both medians are fresh. A coin gains or loses the crown at most once per . An Emperor without an observation for is replaced without comparison. The Emperor pays of its creator fees into the pot (others ) and is never fed at the edge.

Voyage

  1. open_feed(epoch) (anyone): closes the previous voyage, books stray lamports in the pot as donations, computes the weather, budget = pot × spend, $HUDDLE share = budget × , edge share = the rest.
  2. post_edge (anyone carrying the attestor's Ed25519 signature): 1-5 coins, coldest first. Each gets min(edge / n, edge × ). The report becomes final after unless the guardian vetoes it (then a new report, at most 3 per voyage).
  3. feed_edge / huddle_buy (anyone, alone in the transaction): one buy by the pot per call, then the whole token balance is burned and the temporary accounts are closed. Each buy is capped at price impact and 1% of the pool's SOL, must meet the median of 7 observations minus slippage, at most one per coin per . The caller lends 0.02 SOL headroom and gets it back, minus up to ~0.002 SOL of PumpSwap rent.
  4. Unspent budget stays in the pot. The next open_feed closes the voyage; close_feed returns the account's rent after 7 days.

Worked example

The pot holds 10 SOL. Last epoch the pad booked 2 SOL of fees, the 7 before averaged 4 SOL: r = 0.5, spend = 125% - 37.5% = 87.5% (Cold).

Budget 8.75 SOL: 2.625 SOL buys and burns $HUDDLE, 6.125 SOL is the edge share. The report lists 4 coins: each may get min(6.125 / 4, 6.125 × 25%) = 1.531 SOL, bought in chunks of at most 1% price impact, all burned. Whatever cannot be spent inside the voyage stays in the pot.

Launch

Name 1-32 characters (no invisible characters, no spaces at the ends), ticker 1-10 letters or digits, picture on IPFS, optional dev buy up to SOL bought in the same instruction. The site shows the launch fee and split it read; if they changed before you sign, the program refuses with ParamsChanged and nothing is charged.

Parameters

Read live from the Config account. Every change is timelocked () and the guardian can cancel it; accepted params apply to new coins only.

ParameterValue nowBounds

Program

Program - · Anchor 0.31 · localnet. IDL: penguin.json

AccountSeedsHolds
Config["config"]admin, treasury, attestor, guardian (each with a timelocked pending key), paused, $HUDDLE mint, params
Huddle["huddle"]epoch length, the Emperor, the pad's fee ring (weather), the pot's books
pot["pot"]the pot's SOL; the buyer of every program buy
Coin["coin", mint]dev, split, state, fee ring, dev / treasury pending, pot paid, feeds
Fees["fees", mint]the coin's pump.fun creator; holds the dev and treasury shares until paid
Obs["obs", mint]16 clamped price observations
Feed["feed", epoch u64 LE]one voyage: weather, budget, report, coins, allocations, spends, burns
InstructionWhoWhat
launchdevcreate_v2 (creator = Fees PDA) + dev buy, alone in its transaction
collectanyonepump creator fees in, split dev / pot / treasury, fee rings booked
claim_dev / collect_treasuryanyonepays only the dev / only the treasury
sync_migrationanyonecurve complete + canonical pool exists: the coin joins the huddle
observeanyoneone price observation, alone in its transaction
crownanyonemedian challenge, see Emperor
open_feed / close_feedanyoneopen a voyage / return a closed voyage's rent to its opener
post_edgeanyone with the attestor's signaturethe edge report; eligibility and amounts checked by the program
veto_edgeguardianbefore the report is final
revoke_attestorguardianinstant off switch for a leaked attestor key: no report can be posted until a new key passes the timelock
feed_edge / huddle_buyanyoneone price-guarded buy by the pot, then burn
set_paused, propose_* / accept_* / cancel_*, set_pad_mintadmin (accept after the timelock: anyone; cancel: guardian)see Admin powers

Errors

CodeNameMessage
Reading the IDL.

Verify on chain

  1. The pot: -. Its lamports equal rent + paid in + donated − spent (Huddle account, exact after every instruction).
  2. Any coin's pump.fun creator is its Fees PDA ["fees", mint] of this program: nobody else can collect its creator fees.
  3. Every feed burns: the fed coin's supply equals 1015 minus everything the pot bought (Coin.fed_burned), and the pot never holds a token account after a buy.
  4. Each voyage's report hash in its Feed account equals sha256 of /report/<epoch>.json; recount the wallets from the listed signatures.
  5. The Emperor's median: read its Obs ring, take the newest 7 within 30 min, sort, middle value × supply.

Admin powers

Can

  • Pause new launches (nothing else stops).
  • Propose params, attestor, guardian, admin: each timelocked , the guardian can cancel.
  • The guardian can revoke the attestor at once (a leaked key), veto a pending report, cancel any pending change.
  • Set the treasury, and set $HUDDLE once.

Cannot

  • Move the pot, a fee bucket or any token.
  • Change a coin's split after launch.
  • Pick how much a coin is fed, or feed an ineligible coin.

Wind-down: the site has a SUNSET switch (a banner, launches off). The pot keeps being spent by the rules above; dev shares stay claimable. The attestor can be rotated (timelocked) or simply stop posting: then no edge coin is fed and the pot only buys $HUDDLE.

Risks

FAQ

Why would my coin want to be frozen?
It would not. Being fed means the pot buys and burns some of it, but freezing means nobody trades it. The feed keeps the edge from dying; it is not a reward.
What are the penguins on the map?
One penguin = one different wallet that traded the coin in the last (at most 5 are drawn). Fewer than and the stack frosts over.
How tall is a stack?
1 floor + 2 floors per doubling of the median market cap above 120 SOL, at most 9. A drawing rule of this site, not a program rule.
Who runs the keeper?
The team runs one, and every crank is a button on the site. If it stops, anyone can open the voyage, feed the edge and buy $HUDDLE.
Where is $HUDDLE?
Its contract address appears in the map legend when it is live. 30% of every voyage's budget buys and burns it.