Docs

How a flock walks: one pool, one price, the flock sells first, and the leader pays for jumping early. Everything below is what the program enforces.

Overview

A flock is the leader's pool. The leader opens one vault with two ledgers: his own SOL and the followers' pooled SOL. When he buys, both ledgers spend the same share of their free SOL in one buy, so everyone gets one price. When he sells, the flock's tokens are sold first and his own second, in the same instruction. Selling before the minimum hold, or at a deep loss, is a cliff jump: 20 % of the leader's proceeds of that sale go to the flock. Followers unplug any time and take their slice of the cash and of every coin. The leader's cut is a share of a follower's profit above his high-water mark, taken only when the follower leaves, and only on profit.

The walk in 6 levels

LEVEL 1Join

Send SOL to a flock. You get shares at the flock's value per share. Shares are a ledger entry, not a token, and cannot be transferred.

LEVEL 2One price

A leader buy spends the same share of his SOL and of the flock's SOL in one buy. Tokens split by what each side put in. Rounding favours the flock.

LEVEL 3Flock sells first

A leader sale sells the flock's slice first and the same share of his own second. If the sale moves the price, he eats the worse half.

LEVEL 4The jump

Sold before 30 min since the last buy of that coin, or with the flock losing more than 30 % on the slice: 20 % of the leader's proceeds go to the flock.

LEVEL 5Leader's cut

When you unplug, the leader takes his fee (picked at creation, at most 20 %) of your profit above what you put in. No profit, no fee.

LEVEL 6Guard rails

Only coins launched here, no fresh coins, no buying into a pump above the median price, at most 3 % price impact, the leader keeps skin in every buy, caps per follower and per flock.

Lifecycle of a flock

StepInstructionWhoWhat happens
Opencreate_flockleaderFlock account with his first deposit in the leader ledger. The pad's current flock rules are copied in and frozen. The leader picks his fee.
FollowfollowfollowerSOL goes into the flock ledger, shares are minted at the flock's value. Refused while any open coin has no fresh median price.
Lead buylead_buyleaderOne buy for both ledgers, same share of each one's free SOL, tokens split pro rata.
Lead selllead_sellleaderFlock slice sold first, then the same share of the leader's tokens. Proceeds to each ledger.
Cliff jumpinside lead_sellautomaticEarly or deep-loss sale: 20 % of the leader's proceeds move to the flock ledger.
Unplugunfollow → exit_sell per slice → exit_payfollower (anyone cranks after 2 min)Your shares become an exit: your cash slice plus your slice of every coin. You sell each slice with your own limit, then the exit pays you, minus the leader's fee on profit.
Sunsetsunset, sunset_sellanyoneNo leader instruction for 30 days: the flock stops buying and following, its coins are sold in small chunks (flock first), and anyone can unplug the followers. The money goes to them.
Closeclose_flockleader (anyone in sunset)Only when empty: no followers, no coins, no pending exits. Everything left goes to the leader.

Worked example

Round numbers, pump fees left out so the arithmetic is visible. The program does the same in lamports.

The buy

Leader ledger: 2 SOL. Flock ledger: 8 SOL (Alice put in 2 SOL, others 6 SOL). The leader buys 10 %.

leader spends
0.2 SOL
flock spends
0.8 SOL
one buy of
1.0 SOL
tokens out
1,000,000
leader gets
200,000 (20 %)
flock gets
800,000 (80 %)

Both paid 0.000001 SOL per token. Free SOL after: leader 1.8, flock 7.2. Leader skin check: 0.2 ≥ 5 % × 0.8 = 0.04, passes.

The early sale

10 min later the leader sells everything. The flock's 800,000 go first and fetch 1.62 SOL. His 200,000 go second, at the lower price, and fetch 0.38 SOL. The sale is younger than 30 min: cliff jump.

penalty
0.38 × 20 % = 0.076
leader keeps
0.304 SOL
flock gets
1.62 + 0.076 = 1.696
leader free SOL
1.8 + 0.304 = 2.104
flock free SOL
7.2 + 1.696 = 8.896

Alice unplugs

Alice holds 25 % of the shares (2 of 8). The flock is all cash now.

her slice
8.896 × 25 % = 2.224
her basis
2.000 SOL
profit above HWM
0.224 SOL
leader fee 10 %
0.0224 SOL
Alice receives
2.2016 SOL

Plus the rent of her follower and exit accounts back. The 0.0224 goes to the leader ledger. Had her slice been worth 1.9 SOL, the fee would be 0.

Parameters

Each value below is read live from the program's Config account (showing defaults). A flock copies the flock rules when it is created and keeps them for life. A coin copies its fee split at launch.

Coins

ParamValueBoundsMeaning
launch_fee0.02 SOL≤ 0.1 SOLpaid by the dev at launch, to the treasury
dev_bps40 %≤ 50 %dev share of creator fees
pad_bps20 %5..30 %share of creator fees that buys $CLIFF and burns it
treasury40 %≥ 5 %the rest

$CLIFF buyback

ParamValueBoundsMeaning
buy_max0.5 SOL0.01..5 SOLlargest single buyback
buy_impact_bps1 %0.1..3 %largest price move of one buyback
buy_slip_bps2 %0.2..10 %how far the live quote may sit from the median
buy_gap_secs5 min60 s..1 daypause between buybacks

Flocks

ParamValueBoundsMeaning
min_hold_secs30 min5 min..1 daya sale younger than this since the coin's last buy is a cliff jump
cliff_bps20 %5..50 %share of the leader's proceeds of a cliff-jump sale that goes to the flock
cliff_loss_bps30 %0..90 %the flock slice fetching less than cost minus this is a cliff jump too
max_leader_fee_bps20 %0..30 %ceiling of the fee a leader may pick (suggested 10 %)
max_trade_bps50 %5..100 %one buy spends at most this share of each ledger's book value
follower_cap5 SOL0.1..100 SOLmost one follower can have in (by cost basis); never above the flock cap
flock_cap100 SOL1..1000 SOLlargest flock value after a follow
min_leader_stake0.5 SOL0.05..100 SOLleader ledger book value needed to buy
min_leader_bps5 %1..50 %in every buy the leader's SOL is at least this share of the flock's SOL
min_follow0.05 SOL0.01..1 SOLsmallest follow
max_impact_bps3 %0.5..5 %a flock buy moves the price at most this; bigger buys are cut, both ledgers by the same factor
buy_slip_bps2 %0.5..10 %the live quote must be within this of the median price
sell_slip_bps5 %1..15 %floor of the flock slice in a sale
min_coin_age10 min60 s..7 daysno flock buys into a coin younger than this
stale_secs30 days7..365 daysno leader instruction for this long: sunset
max_positions31..3open coins per flock
min_trade0.01 SOL0.001..1 SOLsmallest flock buy

Fixed in the program

observation gap
60 s
fresh median
≥ 5 of last 7
median window
15 min, span ≥ 4 min
buy dispersion
≤ 20 %
obs clamp
±10 % of median
virtual shares / assets
1000 / 1
small sale (curve / pool)
1.25 % / 0.25 %
exit crank grace
2 min

The math

Exact integers. SOL in lamports, prices per raw token.

Follow

NAV = f_sol + Σ f_tok × max(median, spot) / 1e9

shares = floor(lamports × (S + 1000) / (NAV + 1))

Coins are valued at the higher of the median and the live price. A dump right before your follow cannot make shares cheap, and a pump the median has not seen yet is charged at the live price. SOL sent straight to the flock account is not in the ledgers, so it never enters the NAV.

Lead buy sizing

eff = req_bps × 1e5 (parts per billion), then clamped by max_trade × book_L / l_sol, max_trade × book_F / f_sol and 1e9, then by the impact cap isqrt(L² × 1.03) − L on l_sol + f_sol.

l_spend = l_sol × eff / 1e9, f_spend = f_sol × eff / 1e9. One buy of the sum, with min_out = net(spend) / median × (1 − buy_slip).

Split: f_tok = ceil(tokens × f_spend / spend), f_used = floor(sol_used × f_spend / spend), the leader gets the rest. The flock's price per token is never worse than the leader's.

Lead sell slices

f_amt = ceil(f_tok × bps / 1e4), l_amt = floor(l_tok × bps / 1e4). Flock slice first, leader slice second. A small sale (worth up to the small-sale size of the pool) sells at the live price with floor liq × (1 − slip). A bigger one must fetch f_amt × median × (1 − 1.25 %) × (1 − slip) for the flock slice, or it is refused.

Sales against the median (audit fixes)

Every flock sale (lead sell, sunset sell) and every exit crank needs a fresh median; anyone may push an observation, and the site does it for you. A leader sale bigger than the sandwich-proof size also needs spot ≥ median × (1 − 2 %) before it, so a bundle in front of it has the same ~2 % of room a flock buy has. Sandwich-proof sizes are measured on the reserves at max(spot, median), which a push in front cannot move. When the band refuses a big sale, sell in smaller chunks: the console shows the largest one that goes through at the live price.

A slice worth less than 10,000 lamports (0.00001 SOL) is written off instead of sold: no swap, its cost leaves the books, the tokens stay in the vault until burn_strays. On the site it reads "dust written off". It is never a cliff jump.

Cliff rule

If the flock sold something and the leader got more than 0:

early = now − last_buy_at < min_hold · loss = f_got × 1e4 < f_cost_sold × (1e4 − cliff_loss)

If either: penalty = l_got × cliff_bps / 1e4 moves to f_sol. Cost basis leaves pro rata, so the average entry stays the same.

Unplug

Fraction s / S: cash f_sol × s / S, and of each coin tokens × s / S and cost × s / S (floor; the last follower takes exactly everything). Basis leaves pro rata.

fee = leader_fee_bps × max(0, total − basis) / 1e4 at exit_pay. The high-water mark is settled on the part you take out only. Profit you had and lost is never charged.

Accounts and seeds

AccountSeedsHoldsClosed
Config["config"]admin, pending admin, treasury, $CLIFF mint, paused, coin / buyback / flock rules, versionnever
Pad["pad"]$CLIFF buyback bucket + treasury share waiting to be paidnever
Burner["burner"]nothing between instructions; the buyer of $CLIFF buybacksnever
Coin["coin", mint]dev, fee split, dev balance, price observations, migration, statsnever
Fees["fees", mint]the coin's pump.fun creator; creator fees land here until collectnever
Flock["flock", leader]frozen rules, leader fee, leader / flock / exit SOL (all the vault's SOL), total shares, up to 3 coinsclose_flock
Purse["purse", flock]nothing between instructions; trades on pump.fun for the flock and owns its token accountswith the flock
Follower["follow", flock, wallet]shares, basis (HWM), deposited / received / fees paidexit_pay at 0 shares, rent to you
Exit["exit", flock, wallet]an unplug in progress: shares, basis, cash, slice of each coinexit_pay, rent to its payer

Instructions

InstructionWho can callWhat
init_configdeploy key, oncecreates Config and Pad with checked rules
set_paramsadminrules for future coins and flocks only, within bounds
set_treasury, set_paused, propose_admin / accept_adminadmin / proposed keypause blocks only launches, new flocks, follows and flock buys
set_pad_mint / register_pad_mintadmin, oncesets $CLIFF (launched here, or elsewhere as a fee-less record)
launchdevcreates the coin on pump.fun with the Fees PDA as creator, optional dev buy, launch fee to the treasury
collectanyonepulls creator fees and splits dev / $CLIFF / treasury
claim_dev, pay_treasuryanyonepays only the dev / only the treasury
observeanyonerecords a price, clamped to ±10 % of the median, one per 60 s
sync_migrationanyonemarks a graduated coin, prepares its pool fee account (caller pays)
prepare_burneranyoneone-time accounts for the $CLIFF buyer
buy_cliffanyonethe bucket buys $CLIFF in a program-sized chunk and burns it
create_flockleaderopens a flock with his deposit and fee
leader_deposit / leader_withdrawleaderonly his own ledger's free SOL
followfollowershares at NAV, with your own minimum
lead_buyleaderone buy for both ledgers
lead_sellleaderflock slice first, then his; cliff rules
unfollowfollower (anyone in sunset, paid to the follower)opens an exit with cash and coin slices
exit_sellfollower, any size, own limit; anyone after 2 min, program-sized chunksells one slice of an exit
exit_payanyonepays a finished exit to the follower, minus the fee on profit
sunsetanyonestale flock goes to sunset
sunset_sellanyonesells a sunset flock's coin in small chunks, flock first
burn_straysanyoneburns tokens sent to a purse account that is not a position
close_flockleader (anyone in sunset)empty flock closed, everything to the leader

Trades are top-level only and cannot share a transaction with a pump.fun instruction, so nobody can wrap a flock trade in their own buy and sell.

Errors

Read from the program's IDL. The number is what a wallet shows as a custom program error.

CodeNameMessageWhat to do

Honest limits

Trust points

Keeper

A bot that does the chores: records prices, collects creator fees, pushes dev and treasury payouts, runs $CLIFF buybacks, marks graduated coins, finishes unplugs a follower left half done (after the grace), puts stale flocks in sunset, sells their coins, unplugs their followers and closes them when empty.

Every one of those is an instruction anyone can call. If the keeper stops, nothing is stuck: you finish your own exit, anyone can observe a price or collect fees. It can steal nothing: every crank pays only fixed recipients (the follower, the dev, the treasury, the leader ledger), and its chunks are sized by the program.

Admin

can
pause launches, new flocks, follows, flock buys
can
change rules for future coins and flocks only
can
set the treasury; set $CLIFF once
cannot
touch any flock or its rules
cannot
withdraw anyone's SOL or tokens
cannot
block an unplug or a withdraw

While paused, unplugs, sales, leader withdrawals and claims still work. There is no attestor and no off-chain service: the page reads the chain directly.

Creator fees split

Every coin launched here has the pad's Fees PDA as its pump.fun creator. Creator fees are split at collect:

dev
40 %
$CLIFF buy + burn
20 %
treasury
40 %

The split is copied into the coin at launch and does not change later. A flock can only trade coins launched here.

Verify on chain

Program id: LemmhtCwJ4WPn2a3yCdn3z3k7Unguxvj7NcMHeuhrSX

IDL: /idl/lemming.json

To read a flock: derive findProgramAddress(["flock", leader], program), fetch the account and decode it with the IDL type Flock. Your position is ["follow", flock, wallet], a pending unplug ["exit", flock, wallet], the flock's trading account ["purse", flock]. A healthy flock holds at least l_sol + f_sol + exit_sol above its rent, and the purse's token account holds at least both ledgers' tokens of each coin.

FAQ

Can I leave any time?
Yes. Unplug takes your slice of the cash and of every coin. You sell the coin slices with your own limit, then get paid. No lockup, and pause does not block it.
What if the leader disappears?
After 30 days without a leader instruction anyone can put the flock in sunset. Its coins are sold in small chunks, flock first, and anyone can unplug you. The money is paid to you, not to whoever pressed the button. You can also unplug yourself before that.
What is the leader's cut?
The fee he picked when opening the flock (at most 20 %) of your profit above your high-water mark, taken when you unplug. No profit, no fee. Plus the cliff penalty goes the other way: from him to the flock.
Can the leader rug the vault?
No. He can only trade coins launched here through the program, with the flock selling first, and withdraw only the free SOL of his own ledger.
Why can't I follow with a min hold of my own?
One pool, one set of rules. The rules are copied into the flock at creation and are the same for everyone in it, otherwise one sale would be early for some and late for others. If you disagree with a sale, unplug.
What does "one price" mean?
The leader's SOL and the flock's SOL go into the same buy, and the tokens are split by what each put in. Same price per token, rounding in the flock's favour.
What is $CLIFF?
The pad's coin. 20 % of the creator fees of every coin launched here buy $CLIFF on the market and burn it.
Why was my buy or follow refused?
Usually a guard: the price ran above the median, the coin is too fresh, a cap is hit. See the error table above for what each one means.