Skip to main content

Security & guarantees

pools.fun separates per-pool guarantees from settings that apply only to future launches. Contract generations are also kept distinct: legacy pools continue to use the contracts and fee split they launched with.

Enforced by immutable bytecode​

These cannot be changed by anyone — not the team, not a multisig, not a compromised key:

  • Liquidity is locked forever. The locker has no function that withdraws an LP position, and no sweep or rescue of pool assets. Rug-proof by construction, not by promise.
  • The new-pool creator share is at least 90% of each collected fee, on both sides of the pool, credited to a pull-based ledger.
  • Your launch-time fee split. Every token snapshots its split at launch; no later governance change can touch it.
  • Direct in-kind allocation. New-pool fee collection does not depend on a liquidation venue: the creator, the Bankr treasury, and the $BNKR buyback wallet are credited in the assets the pool collected.
  • Fee collection is permissionless. Anyone can trigger collection; claims are initiated by the recipient. A paired asset's own transfer restrictions can still delay delivery, in which case the credited balance remains claimable.
  • Fixed supply. 1 billion, no mint, no owner. A plain launch has no transfer hooks; a fees-to-holders token has exactly one, fixed at launch, that reports each balance change to its distributor so rewards stay in step with balances.

Fees to holders​

A launch that opts into fees to holders replaces the creator's payout address with a per-token distributor contract. The bytecode rules above still apply, and a few are specific to it:

  • No admin, no redirection. The distributor has no owner and no setters. It is registered as the pool's fee recipient at launch and never rotates. The locker also rejects the fees-to-holders sentinel, the token's own address, and another token's distributor as fee recipients — at launch and on rotation — because fees sent to any of them could never be claimed.
  • Fixed exclusion set. The launch pool, the locker, the factory, the token, the distributor, and the burn address never earn. Nothing can add to or remove from that set after launch.
  • Solvent by construction. Rewards stream from the distributor's own token balance. What it owes holders plus what is still streaming never exceeds what it holds; that invariant is fuzz-tested.

The buyback that converts paired-asset fees into the token is the one part of this design that touches a live market, so it is deliberately boring. It is permissionless and takes no inputs from the caller. Each fill is bounded two ways. It may move the price at most about 1% (100 ticks) above the tick the pool was at when the current second began — recovered from the pool's own observations if a swap already moved the tick this second — so a same-second push cannot move the reference. And it may spend at most what would move the locker's own liquidity from the current price up to that limit, so liquidity added just in time at a pushed price can only improve the fill, never enlarge it. On top of that, the reference is clamped to the floor of the locker's band, a fill of meaningful size closes buybacks for the next five minutes, a fill that buys nothing reverts instead of spending dust, and buybacks on Stock Token pairs pause during corporate actions and issuer oracle pauses, using the same check the factory applies to launches. If the price is already above the cap when the buyback is called, the call does nothing and waits for the next second.

What this does not eliminate, stated plainly:

  • Front-running across seconds. Someone who pushes the price up ahead of a buyback can extract at most about 1% of one capped slice per five-minute interval, and pays the pool's 1% fee in each direction to do it. The notional cap bounds it; it is not zero.
  • Wash trading is cheap for a dominant holder. Because 90% of both fee legs flow back to holders, a wallet holding most of the supply recovers most of the fees it pays trading against itself. Volume on a fees-to-holders token is not comparable to volume on a plain launch, and ranked surfaces have to treat it accordingly.
  • Contract holders. Any contract other than the launch pool that holds the token earns a share it may never claim. There is no admin exclusion, by design.
  • Dividend timing. Streaming over 24 hours makes capturing a distribution a matter of holding through it rather than timing a block. That bounds sniping; it does not remove it.

Governed with public timelocks​

  • Default splits for future launches can change only through an on-chain action with a 48-hour public timelock. The creator share cannot fall below 90%, and the remaining protocol share must stay evenly divided between the treasury and the $BNKR buyback wallet.
  • Dead-token takeovers (CTO) exist in the locker's bytecode as a 7-day public on-chain notice path that reassigns future fees only. The new launch suite is deployed with that capability permanently disabled: no key, the contract owner included, can ever reassign a fee recipient. Only a recipient can rotate itself.

Policy (we'll tune it, and we'll say so)​

  • How and when the $BNKR buyback wallet's assets are used to buy and burn $BNKR. A wallet allocation is not an executed buyback.
  • Temporary Stock Token launch availability during trading halts, corporate actions, or failed safety checks.
  • The allowlist of paired assets (which tokenized stocks can be launched against).
  • Launch access rules — Bankr wallet age, minimum native balance, and signed-in launch limits. Current requirements are listed under For creators.
  • Points, leaderboards, and other programs.

We ship fast and we'll modify things when the platform needs it — but only in the policy layer. The bytecode layer is forever.

Process​

Contract releases are verified with unit, invariant, integration, and Robinhood Chain fork tests. The new fee path allocates both legs in kind, so a creator claim does not wait for a keeper to liquidate a Stock Token or launch token first. Published deployments and vaults are listed on the contract-address page.