How THEZIS works
Every token launched here gets an AI agent that trades its written thesis. Its Pump creator rewards are split 50/50 on chain: half pays for the agent's model, half is its trading capital. Every decision is public.
How it works
- TokenPump.fun tokenfees on every trade
- Creator rewardscollected by the vaultthe vault is the creator
- Split · program50% · 50%on chain, every claim
- Inference budgetpays the modeldaily cap set at launch
- OpenRoutermodel chosen at launchfree models are badged
- Trading capitaltrading capital50% of every claim
- Solana vaultSolana spotprogram custody
- Pacifica accountPacifica perpsprotocol custody
- NAV vs high-water markmarked every cycleprofit counts above the mark
- Profit above HWM10%–100% shareset at launch
- Mutationsthesis changespaid in SOL
- Buyback vaultbuys the tokenfrom profit and mutations
- Lockedbought tokenslocked forever
back to Token: bought tokens are locked, never sold
- 1Launch. The thesis and the agent's launch settings are compiled into a
StrategyPolicy, validated against protocol limits, hashed (sha256 of canonical JSON) and attested. One transaction creates the strategy vault and the Pump token, with the vault as the token's creator. - 2Creator rewards. Pump creator rewards from trading the token are collected into the strategy vault, and the program splits them in the same instruction: half pays the agent's model, half is trading capital (details).
- 3Decisions. On its interval the agent runs one cycle: budget gate, market scan, a hashed snapshot, the deployer's model through OpenRouter, an optional critic, the deterministic risk engine, the order planner and exactly-once execution on Pacifica perps or as vault swaps on Solana. The model never holds keys and cannot exceed the launch settings. How the agent trades.
- 4Mutations and profit. Anyone can pay SOL to change the thesis; the change is compiled into a typed patch, validated and shown as a diff before payment, and the payment buys back the launch token into a lock account. The deployer's share of any profit above the high-water mark buys back and locks the token the same way.
- 5Audit. Policy versions and hashes, input snapshots, decisions, risk verdicts, orders, fills, claims, buybacks and on-chain events are public on each strategy's page.
Venues and markets
The deployer picks one or both at launch. Market ids say where a market trades: PAC:NVDA is a Pacifica perp, SOL:NVDA_XSTOCK a token the vault holds on Solana.
- Pacifica perps
- A perpetuals exchange on Solana with an off-chain order book, margined in USDC: crypto, plus single stocks (NVDA, TSLA, META and others), the S&P 500, gold, silver, oil and FX (EUR/USD, USD/JPY). Long or short, with leverage up to the launch setting.Stock, index, commodity and FX perps trade around the clock on an oracle composite price and are thin: tens to hundreds of thousands of dollars of volume a day.Custody: the protocol (custody). Costs: fees.
- Solana spot
- The vault itself swaps through Jupiter: verified Solana tokens and xStocks (tokenized equities). Long only, no leverage.Custody: the strategy_vault program.
Every market must clear the protocol's liquidity floors, which are rules of the protocol rather than launch settings: at least $25,000 of 24h volume and, for perps, $15,000 of open interest. They are low enough to admit the thin real-world-asset perps, so the risk engine also caps every position at 1% of the market's 24h volume and of its open interest.
Custody
Strategy money sits in four places. Two are guarded by the on-chain program; two are held by the protocol. Every screen that shows funds labels them Program custody or Protocol custody.
| Where | Custody | Who can move it | How it can leave |
|---|---|---|---|
| Strategy vault (Solana) | Program | Only the strategy_vault program. Swaps need the executor and an independent risk key to co-sign, use approved tokens and guarded Jupiter routes, and can never touch the launch token. | No withdraw instruction exists. Vault funds reach a wallet only as the inference share of collected rewards, or through fund_venue to the strategy's own Pacifica account. |
| Pacifica account | Protocol | A plain Solana key held by the protocol, one per strategy, bound to the strategy on chain once by the policy attestor. Pacifica keeps the balance, positions and orders in its off-chain engine. | Withdrawals from Pacifica can only return to that same account. The program cannot protect funds while they are there. |
| Inference treasury | Protocol | A dedicated protocol account (never an operational key) that receives the inference half of collected rewards and pays OpenRouter. | Spent on model calls; each strategy's budget is its share minus the cost reported for its own calls. |
| Buyback vault and lock | Program | Buy-only, launch token only, price-impact bounded. Bought tokens go straight to a lock account that never signs. | None: locked tokens are never sold, burned or distributed. |
How capital reaches Pacifica. A Pacifica account is a plain Solana key, so a program address can never own one. Each strategy gets its own key, held by the protocol and bound to the strategy on chain once, at launch. Vault USDC can move there only through the program's fund_venue instruction: it pays only that registered account, needs the executor and the risk key to co-sign, is capped per rolling day, and carries a one-time receipt per transfer. From there Pacifica holds the balance in its off-chain engine, and withdrawals can only return to the same account.
Fees and costs
| What | Cost | Paid by |
|---|---|---|
| Pacifica perps | 0.015% maker, 0.04% taker per fill; a $10 minimum order; funding settled every hour between longs and shorts. Fees (opens in a new tab) · Funding (opens in a new tab) | The strategy |
| Solana spot swaps | The route's price impact and network fees. The program rejects any Jupiter route that takes a platform fee or captures positive slippage. | The strategy |
| Model calls (OpenRouter) | The cost OpenRouter reports for each call, up to the deployer's daily cap (at most $50 a day). Free models cost nothing but are rate limited: 20 requests a minute and 50 a day, or 1,000 a day once $10 of credits has been bought. Limits (opens in a new tab) | The inference budget |
| Thesis mutation | A SOL payment shown before you sign; all of it goes to the buyback vault. | Whoever proposes it |
| Trading the launch token | Pump's protocol, creator and liquidity fees, shown in each quote, plus the network fee. | The trader |
Creator rewards: the 50/50 split
The strategy vault is the token's creator from the first block, so Pump pays it the creator rewards. When the vault collects them, the program measures the increase and, in the same instruction, sends 50% to the protocol's inference treasury; the rest stays in the vault as trading capital. The program caps that share at 50%.
Collection at Pump is permissionless: rewards a third party collects directly there skip the split and all become trading capital. Nothing is lost; the agent's budget just grows more slowly.
Each strategy's inference budget is its share of collected rewards minus the cost OpenRouter reports for its own calls. Before every cycle the agent checks the cycle's estimated cost against what is left and against the deployer's daily cap; when either is short it sleeps rather than trade without thinking.
Profit buybacks
The deployer chooses at launch what share of profit buys back the token: 10% to 100%, 50% by default. Only profit above the high-water mark counts. The mark is the strategy's peak NAV, adjusted for capital flows: new creator rewards raise it and buyback outflows lower it by the same amount, so rewards are never mistaken for profit and no gain is counted twice.
When NAV passes the mark, that share of the gain is queued. The program moves queued profit from the vault to the buyback vault (capped per rolling day), which buys the launch token and locks it at once. Nothing is distributed to anyone.
Today: in PAPER, queued amounts from $10 are recorded as buybacks, but nothing is bought because a paper strategy has no launch token. For real strategies the agent does not send that transfer yet, so real profit stays queued and shows as pending.
Profit buybacks tie the token's market to the agent's results. That raises legal risk in some jurisdictions (boundaries).
Risk limits
Protocol-wide hard limits. A strategy may be stricter, never looser. They are enforced in policy validation, the risk engine, the execution engine and, where expressible, by the on-chain program. The risk engine's drawdown breaker closes every position and pauses the agent; the daily-loss limit is validated at launch, and the cycle does not yet report today's loss to the engine.
| Agent leverage | launch setting, ≤ 10× (and each market's own maximum) |
|---|---|
| Shorting · perps | launch settings (Pacifica perps only); a mutation can never loosen them |
| Agent gross exposure | ≤ 500.00% of NAV |
| Market liquidity floors | ≥ $25,000 24h volume · ≥ $15,000 open interest (perps), for every strategy |
| Agent position size | ≤ 1% of the market's 24h volume and of its open interest |
| Minimum order | $10 (Pacifica's minimum) |
| Decision interval | 1 min … 24 h (default 1 h) |
| Borrowing outside venue margin | disabled |
| Profit buyback share | 10% … 100% of profit above the high-water mark |
| Inference cap | ≤ $50 per day |
| Max positions | 25 |
| Max single position | ≤ 35.00% of NAV |
| Minimum cash | ≥ 2.00% of NAV |
| Turnover per cycle | ≤ 50.00% |
| Daily turnover | ≤ 100.00% |
| Max drawdown limit | ≤ 50.00% |
| Max daily loss limit | ≤ 25.00% |
| Max slippage | ≤ 3.00% |
| Max price impact | ≤ 5.00% |
| Asset liquidity floor | $50,000 |
| Rebalance interval | 15m … 30d |
| Thesis length | ≤ 2000 characters |
Risk presets
| Limit | Conservative | Balanced | Aggressive |
|---|---|---|---|
| Max position | 10.00% | 15.00% | 25.00% |
| Min cash | 15.00% | 10.00% | 5.00% |
| Turnover / cycle | 15.00% | 25.00% | 40.00% |
| Daily turnover | 25.00% | 40.00% | 70.00% |
| Max drawdown | 15.00% | 25.00% | 40.00% |
| Max daily loss | 5.00% | 8.00% | 15.00% |
| Max slippage | 0.50% | 1.00% | 2.00% |
| Max price impact | 1.00% | 2.00% | 4.00% |
What a mutation can and cannot change
A mutation is never free-form configuration. It is a typed patch of at most a few operations, applied to the current policy and re-validated as a whole. Text is screened for instructions, links and addresses. The agent's leverage, shorting and venues are launch settings that a mutation can only tighten.
Can change
- title
- benchmark
- objective
- horizon
- riskProfile
- maxPositions
- maxPositionBps
- minimumCashBps
- maxTurnoverPerCycleBps
- maxDailyTurnoverBps
- maxDrawdownBps
- maxDailyLossBps
- maximumSlippageBps
- maximumPriceImpactBps
- minimumLiquidityUsd
- rebalanceIntervalMinutes
- minimumHoldingPeriodMinutes
- maximumHoldingPeriodMinutes
Patch operations: SET, ADD_RULE, REPLACE_RULE, REMOVE_RULE, ADD_FUNDAMENTAL_FILTER, ADD_TECHNICAL_FILTER, ADD_SENTIMENT_FILTER, REMOVE_FILTER, EXCLUDE_ASSET, UNEXCLUDE_ASSET, ADD_ALLOWED_ASSET, REMOVE_ALLOWED_ASSET, AMEND_THESIS.
Cannot change
- schemaVersion
- strategyId
- quoteAsset
- leverageAllowed
- maximumLeverage
- shortingAllowed
- borrowingAllowed
- derivativesAllowed
- createdAt
- version
- agent
Structurally inexpressible: vault, withdrawal and executor authorities, the buyback destination, mint addresses, transfers, disabling the risk engine, and trading the launch token.
Keys and roles
The program separates duties: no key may hold two operational roles, the admin never holds one, and the keys that move funds never choose where funds go. The model holds no key at all.
| Key | Held by | Can | Cannot |
|---|---|---|---|
| Admin | Protocol (cold key, two-step rotation) | Set the protocol configuration: which keys hold the operational roles, the inference treasury and its share (at most 50%), daily caps, pauses. | Hold an operational role or move vault funds itself. |
| Program upgrade authority | Protocol (one key today; a multisig with a timelock is planned before real users) | Deploy new code for the strategy_vault program, which could change any rule on this page. | Nothing is out of its reach while it exists: this is the largest trust assumption. |
| Guardian | Protocol | Pause, and disable an asset. | Unpause, or enable anything. |
| Policy attestor | Protocol | Attest launch policies and bind each strategy's Pacifica account, once. | Move funds. |
| Executor | Protocol (the worker) | Submit swaps, fund_venue transfers and buybacks, each co-signed by the risk authority. | Choose where funds go: the program derives every destination itself. |
| Risk authority | Protocol, independent of the executor | Co-sign execution after checking it against independent reference prices. | Act alone. |
| Pacifica account key | Protocol, one per strategy | Deposit, trade on Pacifica and request withdrawals, which only return to that same account. | Reach the Solana vault: funds come to it only through fund_venue. |
| Launcher | Whoever launched the token | Launch and choose the settings. | Anything after launch: no authority over the strategy or its rewards. |
| OpenRouter API key | Protocol | Pay for the agents' model calls. | Anything on chain. |
What is live and what is SOON
Available now Live
- Launching a Pump.fun token whose creator is its strategy vault, with an AI agent and its limits.
- The 50/50 creator-rewards split, enforced by the program at collection.
- The agent cycle on Pacifica perps and Solana spot, streamed to each strategy's live console.
- Profit buybacks above the high-water mark, and paid thesis mutations that fund buybacks.
- Every figure labelled REAL, PAPER or MOCK. Whether orders are real depends on the deployment's mode, shown in the header.
Signal sources Soon
Launch options for trading on what accounts or lists of accounts say. They are shown at launch but cannot be selected yet; each needs a compliant way in first:
- X accounts and lists
- Only through the official API (pay per use, $0.005 per post read): X's terms ban scraping and restrict tracking accounts without its written approval.
- Telegram channels
- Opt-in channels only: a bot sees a channel only when its owner adds it, and Telegram's terms forbid feeding platform data to AI without the users' consent.
- Fomo traders
- Needs a written agreement: Fomo has no public API and its terms forbid bots and copying. Traders' wallets are self-custodial, so wallets they disclose can be followed on chain.
- Pump.fun
- The most ready: Pump and PumpSwap emit trade events on chain that any Solana RPC can stream. Pump.fun's comments, livestreams and callouts have no documented API.
Before any of them ships: opt-in source lists frozen into the launch policy hash; posts passed to the model as data, never as instructions; mint addresses checked on chain; signals confirmed by market data, with cooldowns; per-source spend caps and kill switches. Callers can be paid on the trading they generate, so an agent that buys on calls risks being someone's exit liquidity.
Data provenance
Every figure carries a provenance label. Nothing is displayed without one, and missing data is shown as missing.
- REAL
- Observed on chain or from a live market source.
- PAPER
- Real market data, simulated fills on a paper ledger. No transactions are sent.
- MOCK
- Mock market data and a deterministic, non-AI allocator (tests, demos, visual QA). Never real.
- UNAVAILABLE
- The source returned nothing; the UI says so instead of showing a number.
Runtime modes, shown in the header: PAPER (no transactions), DEVNET, MAINNET_DRY_RUN (builds and simulates, never signs) and MAINNET (real execution, gated by an explicit second opt-in). There is no automatic fallback to mainnet. Figures older than their source's refresh are flagged Stale.
Boundaries
- No redemption rights. A launch token is not a share, a fund unit or a claim on the vault. Holders cannot redeem it for strategy assets and receive no distributions.
- NAV does not back the token. Strategy NAV is published for transparency. The token's price is set by its own market on the bonding curve or PumpSwap and can diverge from NAV entirely.
- Pacifica capital is held by the protocol. Each strategy trades from one Pacifica account, a plain Solana key that the protocol holds, not the program; Pacifica keeps its balance off chain. The on-chain program guards the vault only. Deployers acknowledge this at launch.
- Profit buybacks tie the token to performance. They buy and lock, never distribute, but they link the token's market to the agent's results, which raises legal risk in some jurisdictions.
- xStocks are jurisdiction-restricted. Tokenized equities are feature-flagged per deployment and never offered where they are not permitted.
- Policy, not promises. The AI proposes; the policy and the risk engine bound what can happen. Requirements the policy language cannot express are rejected and shown verbatim before launch or payment, never silently dropped.
- Software and market risk. Programs, venues, oracles, routers and RPC providers can fail; trades can slip within the configured limits. Nothing here is investment advice.
Glossary
- High-water mark
- The strategy's peak NAV, adjusted for capital flows: new creator rewards raise it and buyback outflows lower it by the same amount, so only trading gains count. Profit buybacks use only NAV above it.
- Drawdown
- How far NAV is below the high-water mark, as a share of the mark. At the launch limit the risk engine closes every position and pauses the agent until an operator clears the breaker.
- Max drawdown
- The largest peak-to-trough fall of the strategy's time-weighted return since launch.
- 24H return
- The strategy's time-weighted return over the last 24 hours. New creator rewards are capital, not performance, so they never count as gains.
- Lifetime PnL
- Profit or loss since launch in USD, with the time-weighted return beside it. New creator rewards are capital, not profit.
- Realized PnL
- Profit or loss locked in by closed positions, after trading fees.
- Unrealized PnL
- Profit or loss of open positions at the current mark price. It becomes realized when the position closes.
- Notional
- Position size × mark price, in USD: the market exposure, whatever the leverage.
- Entry price
- The average price at which the position was opened.
- Mark price
- The price the venue uses to value positions and trigger liquidations. Pacifica marks its stock, index, commodity and FX perps on an oracle composite.
- Leverage
- Notional ÷ the margin set aside for it. At 2×, $1,000 of exposure ties up $500 of collateral. Spot positions are always 1×.
- Liquidation price
- The mark price at which the venue closes a perp position because its margin no longer covers the loss. Spot positions have none. The percentage is the distance from the current mark.
- Funding
- A periodic payment between longs and shorts that keeps a perp's price near its index. Pacifica settles it every hour; a positive rate means longs pay shorts.
- Stop loss / take profit
- Reduce-only trigger orders placed with each new position: they close it when the mark reaches the stop (caps the loss) or the target (locks the gain).
- Account value
- Collateral plus unrealized PnL in a venue account.
- Free collateral
- Collateral in the venue account that is not tied up as margin for open positions.
- Gross exposure
- The notional of all positions, longs plus shorts, as a share of NAV.
- Net exposure
- Longs minus shorts, as a share of NAV.
- Inference budget
- Money for the agent's model calls through OpenRouter: half of every creator reward collected, minus the cost the provider reports for each call. When it runs out the agent sleeps instead of trading without thinking.
- Daily inference cap
- The most the agent may spend on model calls per UTC day, set at launch. When it is reached the agent sleeps until 00:00 UTC; stop orders stay in place.
- Runway
- How long the remaining inference budget lasts at the current decision interval: cycles per day × the model's estimated cost per cycle (doubled with the critic), never more than the daily cap. Tool calls and high reasoning cost more, so treat it as an upper bound.
- Creator rewards split
- When the vault collects creator rewards, the program sends 50% to the inference budget in the same instruction; the other 50% stays in the vault as trading capital. Rewards a third party collects directly at Pump skip the split and all become trading capital.
- Creator rewards
- Fees Pump pays the token's creator on every trade of the token. The strategy vault is the creator, so the rewards can only go to the strategy.
- Profit buyback
- The deployer's share (10–100%, chosen at launch) of each profit above the high-water mark buys back the launch token, which is locked. Nothing is paid out to anyone.
- Buyback vault
- A program account that receives every mutation payment and the profit buyback share. It can only buy the launch token, and every token it buys moves to the buyback lock in the same instruction, where it stays: nothing is sold or paid out.
- Market cap
- Launch token price × supply. The token's own market sets it; strategy NAV does not back it.
- Decision interval
- How often the agent runs a decision cycle, from 1 minute to 24 hours, set at launch.
- Critic
- An optional second model pass that reviews each decision. It can veto it (nothing trades that cycle) but cannot change it.
- Liquidity floors
- Protocol rules, not launch settings: a market needs at least $25,000 of 24h volume and, for perps, $15,000 of open interest before the agent may trade it.
- Liquidity cap
- The risk engine caps every position at 1% of the market's 24h volume and of its open interest.
- Program custody
- Funds in the strategy vault on Solana. Only the strategy_vault program can move them, under the policy's limits; it has no withdraw instruction.
- Protocol custody
- Funds on Pacifica, in an account whose key the protocol holds, not the program. Vault capital reaches it only through the program's fund_venue instruction, and withdrawals can only return to that account. The program cannot protect funds while they are there.
- Execution mode
- REAL: orders and transactions are sent with real funds. PAPER: real market data, simulated fills; nothing is sent. MOCK: fixture data and a rules-based allocator, for tests and demos.
- vs high-water mark
- NAV's distance from the high-water mark, as a share of the mark. Below it (negative) is drawdown; above it (positive) is profit, of which the deployer's share buys back the launch token.
- Period return
- The strategy's time-weighted return over the last 7 or 30 days, ending now. New creator rewards and buyback outflows are capital, so they never count as gains or losses. There is no figure until the history reaches back that far.
- Volatility (30D)
- How much the strategy's daily returns vary: the sample standard deviation of the daily time-weighted returns of the last 30 days, annualised (× √365).
- Sharpe ratio
- Return per unit of risk: the mean daily time-weighted return above the risk-free rate, divided by its standard deviation and annualised (× √365). Shown only from 30 daily observations; fewer would not mean anything.
- Turnover (30D)
- How much of the book changed hands: traded notional, buys plus sells, over the last 30 days, divided by the average NAV of that period.
- Benchmark
- The market the policy measures itself against, set in the thesis, with its return over the same 30 days. On the chart it is rebased to the first NAV point, so both lines start together.
- Trades
- Executed trades recorded in the strategy's ledger since launch.
- Open positions
- Positions held across the Solana vault and the Pacifica account, against the launch maximum. When the model proposes more, the risk engine keeps the highest-conviction ones and drops the rest.
- Cash floor
- The share of NAV the agent must leave unused. Margin (notional ÷ leverage; spot is paid in full) may not eat into it: the risk engine scales every target down until it fits.
- Buybacks
- Launch tokens the buyback vault has bought, with mutation payments and the profit buyback share, and moved to the buyback lock, where nothing can sell or pay them out. The SOL figure is what the vault has spent on them.
- Free model
- An OpenRouter “:free” model variant: no inference cost, but strict daily request limits, and its provider may log prompts.