Programs

Backer pools


Copied from the Tender programs' own docs on 2026-09-28: current; stake funding for the first launches is platform mode (D7).

Built and tested: commit d330cc3 (2026-09-28). Program id 7wVGSf1UVztxGsEtsVceyP6qqq6Jbed3ss28hSMBfpsx. A port of the EVM BackstopPool.sol and BackstopDistributor.sol (commits 7eaa1f7 and a323611; 17 fork tests in contracts/test/v2/Backstop.fork.t.sol) to lamports, wired into tender_vault through hooks in launch, buy, collect_fees, unwind_stake, burn_leftover and a new write_off.

Source: programs/tender_backstop/src/lib.rs and programs/tender_vault/src/lib.rs at d330cc3; review/0dte/SPEC-SOLANA.md section 5 "As built"; review/0dte/SPEC-BACKSTOP.md.

Model

Backers are senior lenders, not co-owners. Making them co-owners would give them the token and option exposure they asked to avoid, and pricing entry and exit would need a price for the inventory. They lend to one launch vault, are repaid first from its SOL income, earn a share of its creator fees, and hold tokens only after a write-off.

Source: SPEC-BACKSTOP.md "Why a lender, not a co-owner"; tender_backstop module docs.

Accounts and seeds

AccountSeedsHolds
Pool["pool", mint], one per launchcap, stake mode, distributor, registered and closed flags, shares, idle and lent SOL, last draw or repayment time, tokens taken on write-off, reward accumulator. Its only borrower is the launch vault's creator PDA ["creator", mint], fixed at creation
Backer["backer", pool, owner]shares, unlock time, reward debt
Distributor["distributor", registrar]the registrar, fixed when the registrar signs its creation
Epoch["epoch", distributor, day]one UTC day's platform SOL and total points
Points["points", pool, day]one pool's reported fees that day; closed when the pool is paid

Accounting is explicit (idle, lent, rewards held, token balance), never the account's lamports, so a donation cannot move the share price.

Source: tender_backstop lib.rs (seeds, Pool) at d330cc3; SPEC-SOLANA section 5 "As built" (Accounts).

Stake modes (fixed per pool, read by launch)

  • Platform-funded (mode a, MODE_PLATFORM = 0). The launcher pays the 10% stake, as in M3. Backers lend only shortfalls: when a sale's cover exceeds the inventory, the vault buys the missing tokens on PumpSwap in the same swap as the premium-funded buy, paying with its own SOL first (above rent, less 0.004 SOL kept for PumpSwap's per-user accounts) and drawing the rest from the pool. If the pool cannot lend it, the sale fails NotCovered. No cover buys after the leftover stake was burned.
  • Backer-funded (mode b, MODE_BACKERS = 1). launch draws max_sol_cost from the pool, buys the stake and repays the unspent part at once, so the debt is exactly the stake's cost. The launcher pays rent only. Refused if the pool's idle SOL is short. SPEC-SOLANA 5 names it the recommended default for the SDK.

The pool must exist before launch: init_pool(cap, mode, distributor) is signed by the coin's mint keypair, so only the launcher sets the terms and a backer-funded pool can fill before the coin exists.

Source: tender_backstop init_pool and tender_vault launch and cover_shortfall (AMM_USER_RENT = 4,000,000 lamports) at d330cc3; SPEC-SOLANA section 5 "As built".

Repayment order

The debt is senior and is repaid from every SOL inflow, from all of the vault's free lamports (the reserve included), before the beneficiary sees anything:

  • buy: after the premium-funded buy (half the net premium), what is left repays.
  • collect_fees: collect and unwrap, then the backers' fee share, then repay, then, only if nothing is owed, everything above the 0.25 SOL reserve to the beneficiary.
  • unwind_stake: the recovered SOL repays first; if the curve cannot return the whole cost, the rest stays owed until write-off.

Source: tender_vault collect_fees and unwind_stake at d330cc3; SPEC-SOLANA section 5 "As built" (Repayment order).

Instructions

InstructionProgramWhoEffect
init_distributorbackstopregistrarcreates the distributor; the signer is its registrar forever
registerbackstopregistrarlets a pool report fees to the distributor
init_pool(cap, mode, distributor)backstopthe coin's mint keypaircreates the pool; cap above 0; mode 0 or 1
deposit(amount)backstopbackershares at face value (idle + lent); refused when closed or over the cap; resets the 1-day lock
withdraw(shares)backstopbackerafter the lock and only while nothing is lent: idle x shares / total SOL and, after a write-off, the same share of the tokens
claimbackstopbackerpays accrued rewards, any time, also after a write-off
draw, repay, notify_fees, write_offbackstopthe vault's creator PDA only (CPI from tender_vault)borrow, repay, pay the fee share and report points, cancel the debt
fund(amount, today)backstopwhoever receives the platform token's 20%adds SOL to today's epoch
claim_platformbackstopanyoneafter the day ends: rewards x points / total points into the pool's accumulator (to the vault if the pool has no backers) and closes the points account
roll(day, today)backstopanyonemoves a finished day with no points forward
write_offtender_vaultanyonesee below

Source: tender_backstop lib.rs at d330cc3.

Return

backer_share(collected, principal, cap, shares): weighted = collected x min(principal, cap) / cap, cut = 30% of that (BACKER_FEE_BPS 3,000). notify_fees pays the cut to the pool and, when the pool is registered and has backers, reports the weighted amount as the launch's points for the day. With no backers nothing is paid and the vault keeps its money. A 1-lamport pool against a 5 SOL cap takes 0 of 1 SOL of fees (tested). Rewards accrue per share (ACC 1e12).

Source: tender_backstop backer_share and notify_fees at d330cc3; SPEC-SOLANA section 5 "As built" (Return).

Write-off

tender_vault::write_off, callable by anyone, when all of these hold:

  • the vault is active or unwound;
  • the vault holds SHORT in no unsettled series (open_series = 0) and nothing it sold is live;
  • the pool has debt that has seen no draw or repayment for 7 days (WRITE_OFF_DELAY).

Mode a: free tokens worth the debt at the vault's average cover cost (cover_bought / cover_spent, counting the stake and every cover buy) go to the pool's Token-2022 account, capped at what the vault holds. Mode b: the stake is burned and the debt is a realized loss; the stake is never handed to backers (owner). Either way the debt is cancelled and the pool closes to deposits and draws. burn_leftover is refused while anything is owed (DebtOutstanding), so the burn of a backer-funded stake and the loss are one event.

This differs from the EVM rule and the main text of SPEC-SOLANA 5 ("7 days after the vault's last series settled"): the Solana clock is 7 days without a draw or repayment, plus no unsettled series.

Source: tender_vault write_off and burn_leftover, tender_backstop Pool::write_off_ready at d330cc3; SPEC-SOLANA section 5 "As built" (Write-off).

Parameters

ParameterValueSource
Backers' fee share30% x min(principal, cap) / cap of each fee collectioncode BACKER_FEE_BPS; owner 2026-09-27 (30%, kept per SPEC-SOLANA 5); pro-rata rule a323611 after report 18
Platform stream20% of the platform token's creator fees, split by reported fees per UTC dayowner 2026-09-27 (SPEC-BACKSTOP); code
Lock1 day after each depositcode LOCK
Exit while in debtnot allowedcode (DebtOutstanding)
Write-off delay7 days without a draw or repayment, and no unsettled seriescode WRITE_OFF_DELAY, tender_vault write_off
Write-off claimmode a: tokens worth the debt at average cover cost; mode b: none (stake burned)code
Capper pool, set by the launcher at init_pool; Solana default open (a backer-funded pool needs at least the stake budget, about 3.2 SOL)code; SPEC-SOLANA 5 "As built"
Vault SOL kept for PumpSwap user accounts on a cover buy0.004 SOLcode AMM_USER_RENT
Launch vault SOL reserve (kept before the beneficiary is paid, only when nothing is owed)0.25 SOLcode FEE_RESERVE (mirrors the EVM feeReserveTarget of 0.25 ETH)
Platform claims per callone day (the EVM walks 90)SPEC-SOLANA 5 "As built"

Tests and compute

8 LiteSVM tests in tests-svm/tests/backstop.rs on the same mainnet pump, PumpSwap, pump_fees and mpl-core bytecode as launch.rs, and 2 unit tests in tender_backstop (cargo test reports 3 with Anchor's generated test_id). The 19 launch tests run with a platform-funded pool and no backers. The shared harness is tests-svm/tests/common/mod.rs. SPEC-SOLANA 5 "As built" lists CU per instruction (for example launch 424k backer-funded, 447k platform-funded; a buy that draws a cover shortfall 529k); see verification.md for the verification run.

Source: SPEC-SOLANA section 5 "As built"; verification run at d330cc3.

Economics (EVM, pons cohort, ETH)

Report 18, 613 pons graduates: 597 launches draw, all at the graduation block; peak debt median 0.075 ETH, max 0.14 ETH; repaid at the first fee sweep (about 10 min); no write-off in any case; worst launch +0.10 ETH to backers. A full 0.25 ETH pool earns 1.82 ETH mean (0.89 median) in 24 h. The report called 30% far too generous (5% still pays 121% mean in 24 h) and recommended paying only principal present at graduation; the owner kept 30% and has not decided the second point. None of this was re-run for the Solana stake modes.

Source: 18-backstop-economics.md TL;DR; SPEC-BACKSTOP.md "Not applied, owner decisions".

Open for the owner

  • Stake funding. Mode is per pool; SPEC-SOLANA 5 recommends backer-funded as the SDK default, but who funds stakes in production is still listed as an owner decision. Report 22 suggested 10-20% of creator fees for stake funders, 0-10% for backstop-only backers.
  • The Solana default cap.
  • The platform token does not exist; who forwards its fees to the distributor is open.
  • The registrar key (a multisig in production).
  • Pay the fee share only on principal present at graduation (report 18); deposits after launch share in fees at face value, as on the EVM.

Source: SPEC-SOLANA section 5 (including "Deferred / open"); SPEC-BACKSTOP.md "Open for the owner"; 22-pumpfun-product.md sections 3(f) and 4.