Docs
How a flock walks: one pool, one price, the flock sells first, and the leader pays for jumping early. Everything below is what the program enforces.
Overview
A flock is the leader's pool. The leader opens one vault with two ledgers: his own SOL and the followers' pooled SOL. When he buys, both ledgers spend the same share of their free SOL in one buy, so everyone gets one price. When he sells, the flock's tokens are sold first and his own second, in the same instruction. Selling before the minimum hold, or at a deep loss, is a cliff jump: 20 % of the leader's proceeds of that sale go to the flock. Followers unplug any time and take their slice of the cash and of every coin. The leader's cut is a share of a follower's profit above his high-water mark, taken only when the follower leaves, and only on profit.
The walk in 6 levels
LEVEL 1Join
Send SOL to a flock. You get shares at the flock's value per share. Shares are a ledger entry, not a token, and cannot be transferred.
LEVEL 2One price
A leader buy spends the same share of his SOL and of the flock's SOL in one buy. Tokens split by what each side put in. Rounding favours the flock.
LEVEL 3Flock sells first
A leader sale sells the flock's slice first and the same share of his own second. If the sale moves the price, he eats the worse half.
LEVEL 4The jump
Sold before 30 min since the last buy of that coin, or with the flock losing more than 30 % on the slice: 20 % of the leader's proceeds go to the flock.
LEVEL 5Leader's cut
When you unplug, the leader takes his fee (picked at creation, at most 20 %) of your profit above what you put in. No profit, no fee.
LEVEL 6Guard rails
Only coins launched here, no fresh coins, no buying into a pump above the median price, at most 3 % price impact, the leader keeps skin in every buy, caps per follower and per flock.
Lifecycle of a flock
| Step | Instruction | Who | What happens |
|---|---|---|---|
| Open | create_flock | leader | Flock account with his first deposit in the leader ledger. The pad's current flock rules are copied in and frozen. The leader picks his fee. |
| Follow | follow | follower | SOL goes into the flock ledger, shares are minted at the flock's value. Refused while any open coin has no fresh median price. |
| Lead buy | lead_buy | leader | One buy for both ledgers, same share of each one's free SOL, tokens split pro rata. |
| Lead sell | lead_sell | leader | Flock slice sold first, then the same share of the leader's tokens. Proceeds to each ledger. |
| Cliff jump | inside lead_sell | automatic | Early or deep-loss sale: 20 % of the leader's proceeds move to the flock ledger. |
| Unplug | unfollow → exit_sell per slice → exit_pay | follower (anyone cranks after 2 min) | Your shares become an exit: your cash slice plus your slice of every coin. You sell each slice with your own limit, then the exit pays you, minus the leader's fee on profit. |
| Sunset | sunset, sunset_sell | anyone | No leader instruction for 30 days: the flock stops buying and following, its coins are sold in small chunks (flock first), and anyone can unplug the followers. The money goes to them. |
| Close | close_flock | leader (anyone in sunset) | Only when empty: no followers, no coins, no pending exits. Everything left goes to the leader. |
Worked example
Round numbers, pump fees left out so the arithmetic is visible. The program does the same in lamports.
The buy
Leader ledger: 2 SOL. Flock ledger: 8 SOL (Alice put in 2 SOL, others 6 SOL). The leader buys 10 %.
- leader spends
- 0.2 SOL
- flock spends
- 0.8 SOL
- one buy of
- 1.0 SOL
- tokens out
- 1,000,000
- leader gets
- 200,000 (20 %)
- flock gets
- 800,000 (80 %)
Both paid 0.000001 SOL per token. Free SOL after: leader 1.8, flock 7.2. Leader skin check: 0.2 ≥ 5 % × 0.8 = 0.04, passes.
The early sale
10 min later the leader sells everything. The flock's 800,000 go first and fetch 1.62 SOL. His 200,000 go second, at the lower price, and fetch 0.38 SOL. The sale is younger than 30 min: cliff jump.
- penalty
- 0.38 × 20 % = 0.076
- leader keeps
- 0.304 SOL
- flock gets
- 1.62 + 0.076 = 1.696
- leader free SOL
- 1.8 + 0.304 = 2.104
- flock free SOL
- 7.2 + 1.696 = 8.896
Alice unplugs
Alice holds 25 % of the shares (2 of 8). The flock is all cash now.
- her slice
- 8.896 × 25 % = 2.224
- her basis
- 2.000 SOL
- profit above HWM
- 0.224 SOL
- leader fee 10 %
- 0.0224 SOL
- Alice receives
- 2.2016 SOL
Plus the rent of her follower and exit accounts back. The 0.0224 goes to the leader ledger. Had her slice been worth 1.9 SOL, the fee would be 0.
Parameters
Each value below is read live from the program's Config account (showing defaults). A flock copies the flock rules when it is created and keeps them for life. A coin copies its fee split at launch.
Coins
| Param | Value | Bounds | Meaning |
|---|---|---|---|
launch_fee | 0.02 SOL | ≤ 0.1 SOL | paid by the dev at launch, to the treasury |
dev_bps | 40 % | ≤ 50 % | dev share of creator fees |
pad_bps | 20 % | 5..30 % | share of creator fees that buys $CLIFF and burns it |
| treasury | 40 % | ≥ 5 % | the rest |
$CLIFF buyback
| Param | Value | Bounds | Meaning |
|---|---|---|---|
buy_max | 0.5 SOL | 0.01..5 SOL | largest single buyback |
buy_impact_bps | 1 % | 0.1..3 % | largest price move of one buyback |
buy_slip_bps | 2 % | 0.2..10 % | how far the live quote may sit from the median |
buy_gap_secs | 5 min | 60 s..1 day | pause between buybacks |
Flocks
| Param | Value | Bounds | Meaning |
|---|---|---|---|
min_hold_secs | 30 min | 5 min..1 day | a sale younger than this since the coin's last buy is a cliff jump |
cliff_bps | 20 % | 5..50 % | share of the leader's proceeds of a cliff-jump sale that goes to the flock |
cliff_loss_bps | 30 % | 0..90 % | the flock slice fetching less than cost minus this is a cliff jump too |
max_leader_fee_bps | 20 % | 0..30 % | ceiling of the fee a leader may pick (suggested 10 %) |
max_trade_bps | 50 % | 5..100 % | one buy spends at most this share of each ledger's book value |
follower_cap | 5 SOL | 0.1..100 SOL | most one follower can have in (by cost basis); never above the flock cap |
flock_cap | 100 SOL | 1..1000 SOL | largest flock value after a follow |
min_leader_stake | 0.5 SOL | 0.05..100 SOL | leader ledger book value needed to buy |
min_leader_bps | 5 % | 1..50 % | in every buy the leader's SOL is at least this share of the flock's SOL |
min_follow | 0.05 SOL | 0.01..1 SOL | smallest follow |
max_impact_bps | 3 % | 0.5..5 % | a flock buy moves the price at most this; bigger buys are cut, both ledgers by the same factor |
buy_slip_bps | 2 % | 0.5..10 % | the live quote must be within this of the median price |
sell_slip_bps | 5 % | 1..15 % | floor of the flock slice in a sale |
min_coin_age | 10 min | 60 s..7 days | no flock buys into a coin younger than this |
stale_secs | 30 days | 7..365 days | no leader instruction for this long: sunset |
max_positions | 3 | 1..3 | open coins per flock |
min_trade | 0.01 SOL | 0.001..1 SOL | smallest flock buy |
Fixed in the program
- observation gap
- 60 s
- fresh median
- ≥ 5 of last 7
- median window
- 15 min, span ≥ 4 min
- buy dispersion
- ≤ 20 %
- obs clamp
- ±10 % of median
- virtual shares / assets
- 1000 / 1
- small sale (curve / pool)
- 1.25 % / 0.25 %
- exit crank grace
- 2 min
The math
Exact integers. SOL in lamports, prices per raw token.
Follow
NAV = f_sol + Σ f_tok × max(median, spot) / 1e9
shares = floor(lamports × (S + 1000) / (NAV + 1))
Coins are valued at the higher of the median and the live price. A dump right before your follow cannot make shares cheap, and a pump the median has not seen yet is charged at the live price. SOL sent straight to the flock account is not in the ledgers, so it never enters the NAV.
Lead buy sizing
eff = req_bps × 1e5 (parts per billion), then clamped by max_trade × book_L / l_sol, max_trade × book_F / f_sol and 1e9, then by the impact cap isqrt(L² × 1.03) − L on l_sol + f_sol.
l_spend = l_sol × eff / 1e9, f_spend = f_sol × eff / 1e9. One buy of the sum, with min_out = net(spend) / median × (1 − buy_slip).
Split: f_tok = ceil(tokens × f_spend / spend), f_used = floor(sol_used × f_spend / spend), the leader gets the rest. The flock's price per token is never worse than the leader's.
Lead sell slices
f_amt = ceil(f_tok × bps / 1e4), l_amt = floor(l_tok × bps / 1e4). Flock slice first, leader slice second. A small sale (worth up to the small-sale size of the pool) sells at the live price with floor liq × (1 − slip). A bigger one must fetch f_amt × median × (1 − 1.25 %) × (1 − slip) for the flock slice, or it is refused.
Sales against the median (audit fixes)
Every flock sale (lead sell, sunset sell) and every exit crank needs a fresh median; anyone may push an observation, and the site does it for you. A leader sale bigger than the sandwich-proof size also needs spot ≥ median × (1 − 2 %) before it, so a bundle in front of it has the same ~2 % of room a flock buy has. Sandwich-proof sizes are measured on the reserves at max(spot, median), which a push in front cannot move. When the band refuses a big sale, sell in smaller chunks: the console shows the largest one that goes through at the live price.
A slice worth less than 10,000 lamports (0.00001 SOL) is written off instead of sold: no swap, its cost leaves the books, the tokens stay in the vault until burn_strays. On the site it reads "dust written off". It is never a cliff jump.
Cliff rule
If the flock sold something and the leader got more than 0:
early = now − last_buy_at < min_hold · loss = f_got × 1e4 < f_cost_sold × (1e4 − cliff_loss)
If either: penalty = l_got × cliff_bps / 1e4 moves to f_sol. Cost basis leaves pro rata, so the average entry stays the same.
Unplug
Fraction s / S: cash f_sol × s / S, and of each coin tokens × s / S and cost × s / S (floor; the last follower takes exactly everything). Basis leaves pro rata.
fee = leader_fee_bps × max(0, total − basis) / 1e4 at exit_pay. The high-water mark is settled on the part you take out only. Profit you had and lost is never charged.
Accounts and seeds
| Account | Seeds | Holds | Closed |
|---|---|---|---|
| Config | ["config"] | admin, pending admin, treasury, $CLIFF mint, paused, coin / buyback / flock rules, version | never |
| Pad | ["pad"] | $CLIFF buyback bucket + treasury share waiting to be paid | never |
| Burner | ["burner"] | nothing between instructions; the buyer of $CLIFF buybacks | never |
| Coin | ["coin", mint] | dev, fee split, dev balance, price observations, migration, stats | never |
| Fees | ["fees", mint] | the coin's pump.fun creator; creator fees land here until collect | never |
| Flock | ["flock", leader] | frozen rules, leader fee, leader / flock / exit SOL (all the vault's SOL), total shares, up to 3 coins | close_flock |
| Purse | ["purse", flock] | nothing between instructions; trades on pump.fun for the flock and owns its token accounts | with the flock |
| Follower | ["follow", flock, wallet] | shares, basis (HWM), deposited / received / fees paid | exit_pay at 0 shares, rent to you |
| Exit | ["exit", flock, wallet] | an unplug in progress: shares, basis, cash, slice of each coin | exit_pay, rent to its payer |
Instructions
| Instruction | Who can call | What |
|---|---|---|
init_config | deploy key, once | creates Config and Pad with checked rules |
set_params | admin | rules for future coins and flocks only, within bounds |
set_treasury, set_paused, propose_admin / accept_admin | admin / proposed key | pause blocks only launches, new flocks, follows and flock buys |
set_pad_mint / register_pad_mint | admin, once | sets $CLIFF (launched here, or elsewhere as a fee-less record) |
launch | dev | creates the coin on pump.fun with the Fees PDA as creator, optional dev buy, launch fee to the treasury |
collect | anyone | pulls creator fees and splits dev / $CLIFF / treasury |
claim_dev, pay_treasury | anyone | pays only the dev / only the treasury |
observe | anyone | records a price, clamped to ±10 % of the median, one per 60 s |
sync_migration | anyone | marks a graduated coin, prepares its pool fee account (caller pays) |
prepare_burner | anyone | one-time accounts for the $CLIFF buyer |
buy_cliff | anyone | the bucket buys $CLIFF in a program-sized chunk and burns it |
create_flock | leader | opens a flock with his deposit and fee |
leader_deposit / leader_withdraw | leader | only his own ledger's free SOL |
follow | follower | shares at NAV, with your own minimum |
lead_buy | leader | one buy for both ledgers |
lead_sell | leader | flock slice first, then his; cliff rules |
unfollow | follower (anyone in sunset, paid to the follower) | opens an exit with cash and coin slices |
exit_sell | follower, any size, own limit; anyone after 2 min, program-sized chunk | sells one slice of an exit |
exit_pay | anyone | pays a finished exit to the follower, minus the fee on profit |
sunset | anyone | stale flock goes to sunset |
sunset_sell | anyone | sells a sunset flock's coin in small chunks, flock first |
burn_strays | anyone | burns tokens sent to a purse account that is not a position |
close_flock | leader (anyone in sunset) | empty flock closed, everything to the leader |
Trades are top-level only and cannot share a transaction with a pump.fun instruction, so nobody can wrap a flock trade in their own buy and sell.
Errors
Read from the program's IDL. The number is what a wallet shows as a custom program error.
| Code | Name | Message | What to do |
|---|
Honest limits
- The original idea was auto-buying from followers' wallets when the leader buys. Not possible on Solana: a program cannot spend a wallet's SOL without its signature, and the leader would front-run the copy in the same transaction. So the flock is a pool the leader trades for everyone at once.
- The leader can still trade his own wallet on pump.fun. The program only controls the vault. Front-running his flock that way earns at most the flock buy's impact (≤ 3 %) minus pump fees both ways (~2.5 %), and his push above the median makes the flock buy fail. Tested: about zero. His wallet is shown on his profile.
- The leader may be the dev of a coin through another wallet. The program only checks that the coin's dev is not the leader's own key.
- The median guard refuses buys into a fast pump until the median catches up (+10 % per about 4 observations). After a 15x run that is about 70 min. On purpose. The leader can still sell in small chunks at any time.
- Someone could walk the median up with buy, observe, sell bundles. Each step costs about 2.5 % of the push and can only raise the price a new follower pays. Your follow has a minimum shares limit from the page.
- Shares are not a token. They cannot be sold or transferred, only unplugged.
- A flock's rules and fee are frozen at creation. The leader picks his fee, at most 20 %.
- pump.fun's own admin powers over coins are pump.fun's, not ours.
- SOL sent to a coin's creator vault is split like fees. It buys nothing for the sender.
Trust points
Keeper
A bot that does the chores: records prices, collects creator fees, pushes dev and treasury payouts, runs $CLIFF buybacks, marks graduated coins, finishes unplugs a follower left half done (after the grace), puts stale flocks in sunset, sells their coins, unplugs their followers and closes them when empty.
Every one of those is an instruction anyone can call. If the keeper stops, nothing is stuck: you finish your own exit, anyone can observe a price or collect fees. It can steal nothing: every crank pays only fixed recipients (the follower, the dev, the treasury, the leader ledger), and its chunks are sized by the program.
Admin
- can
- pause launches, new flocks, follows, flock buys
- can
- change rules for future coins and flocks only
- can
- set the treasury; set $CLIFF once
- cannot
- touch any flock or its rules
- cannot
- withdraw anyone's SOL or tokens
- cannot
- block an unplug or a withdraw
While paused, unplugs, sales, leader withdrawals and claims still work. There is no attestor and no off-chain service: the page reads the chain directly.
Creator fees split
Every coin launched here has the pad's Fees PDA as its pump.fun creator. Creator fees are split at collect:
- dev
- 40 %
- $CLIFF buy + burn
- 20 %
- treasury
- 40 %
The split is copied into the coin at launch and does not change later. A flock can only trade coins launched here.
Verify on chain
Program id: LemmhtCwJ4WPn2a3yCdn3z3k7Unguxvj7NcMHeuhrSX
IDL: /idl/lemming.json
To read a flock: derive findProgramAddress(["flock", leader], program), fetch the account and decode it with the IDL type Flock. Your position is ["follow", flock, wallet], a pending unplug ["exit", flock, wallet], the flock's trading account ["purse", flock]. A healthy flock holds at least l_sol + f_sol + exit_sol above its rent, and the purse's token account holds at least both ledgers' tokens of each coin.
FAQ
- Can I leave any time?
- Yes. Unplug takes your slice of the cash and of every coin. You sell the coin slices with your own limit, then get paid. No lockup, and pause does not block it.
- What if the leader disappears?
- After 30 days without a leader instruction anyone can put the flock in sunset. Its coins are sold in small chunks, flock first, and anyone can unplug you. The money is paid to you, not to whoever pressed the button. You can also unplug yourself before that.
- What is the leader's cut?
- The fee he picked when opening the flock (at most 20 %) of your profit above your high-water mark, taken when you unplug. No profit, no fee. Plus the cliff penalty goes the other way: from him to the flock.
- Can the leader rug the vault?
- No. He can only trade coins launched here through the program, with the flock selling first, and withdraw only the free SOL of his own ledger.
- Why can't I follow with a min hold of my own?
- One pool, one set of rules. The rules are copied into the flock at creation and are the same for everyone in it, otherwise one sale would be early for some and late for others. If you disagree with a sale, unplug.
- What does "one price" mean?
- The leader's SOL and the flock's SOL go into the same buy, and the tokens are split by what each put in. Same price per token, rounding in the flock's favour.
- What is $CLIFF?
- The pad's coin. 20 % of the creator fees of every coin launched here buy $CLIFF on the market and burn it.
- Why was my buy or follow refused?
- Usually a guard: the price ran above the median, the coin is too fresh, a cap is hit. See the error table above for what each one means.