Custody and security
Where the money sits, who holds which key, and what you are trusting.
Four places
Where the money sits
Coin money sits in four places. The on-chain program guards two of them; the protocol holds the other two. Every screen that shows funds labels them Program custody or Protocol custody.
Strategy vault (Solana)Program custody
- Who moves it
- Only the strategy_vault program. Swaps need the executor and an independent risk key to co-sign, use approved tokens and guarded Jupiter routes, and can never touch the coin itself.
- How it leaves
- No withdraw instruction exists. Vault funds reach a wallet only as the inference share of collected fees, or through fund_venue to the coin's own Pacifica account.
Pacifica accountProtocol custody
- Who moves it
- A plain Solana key held by the protocol, one per coin, bound to the coin on chain once by the policy attestor. Pacifica keeps the balance, positions and orders in its off-chain engine.
- How it leaves
- Withdrawals from Pacifica can only return to that same account. The program cannot protect funds while they are there.
Inference treasuryProtocol custody
- Who moves it
- A dedicated protocol account (never an operational key) that receives the inference half of collected fees and pays OpenRouter.
- How it leaves
- Spent on model calls. Each coin's budget is its share minus the cost reported for its own calls.
Buyback vault and lockProgram custody
- Who moves it
- Buy-only, this coin only, price-impact bounded. Bought coins go straight to a lock account that never signs.
- How it leaves
- It does not: locked coins are never sold, burned or distributed.
fund_venue
How capital reaches Pacifica
A Pacifica account is a plain Solana key, so a program address can never own one. Each coin gets its own key, held by the protocol and bound to the coin on chain once, at launch.
Vault USDC can move there only through the program's fund_venue instruction: it pays only that registered account, needs the executor and the risk key to co-sign, is capped per rolling day, and leaves a one-time receipt per transfer. From there Pacifica holds the balance in its off-chain engine, and withdrawals can only return to the same account.
Pacifica is in closed beta: it caps an account's equity and its withdrawals per day, and it blocks restricted jurisdictions. Launchers acknowledge this custody at launch.
Separation of duties
Keys and roles
No key may hold two operational roles, the admin never holds one, and the keys that move funds never choose where funds go. The model holds no key at all.
Admin
- Held by
- The protocol (cold key, two-step rotation)
- Can
- Set the protocol configuration: which keys hold the operational roles, the inference treasury and its share (at most 50%), daily caps, pauses.
- Cannot
- Hold an operational role, or move vault funds itself.
Program upgrade authority
- Held by
- The protocol: one key today; a multisig with a timelock is planned before real users.
- Can
- Deploy new code for the strategy_vault program, which could change any rule on this page.
- Cannot
- Nothing is out of its reach while it exists: this is the largest trust assumption.
Guardian
- Held by
- The protocol
- Can
- Pause, and disable an asset.
- Cannot
- Unpause, or enable anything.
Policy attestor
- Held by
- The protocol
- Can
- Attest launch policies and bind each coin's Pacifica account, once.
- Cannot
- Move funds.
Executor
- Held by
- The protocol (the worker)
- Can
- Submit swaps, fund_venue transfers and buybacks, each co-signed by the risk authority.
- Cannot
- Choose where funds go: the program derives every destination itself.
Risk authority
- Held by
- The protocol, independent of the executor
- Can
- Co-sign execution after checking it against independent reference prices.
- Cannot
- Act alone.
Pacifica account key
- Held by
- The protocol, one per coin
- Can
- Deposit, trade on Pacifica and request withdrawals, which only return to that same account.
- Cannot
- Reach the Solana vault: funds come to it only through fund_venue.
Launcher
- Held by
- Whoever launched the coin
- Can
- Launch and choose the settings.
- Cannot
- Anything after launch: no authority over the coin's vault, its agent or its fees.
OpenRouter API key
- Held by
- The protocol
- Can
- Pay for the agents' model calls.
- Cannot
- Anything on chain.
On chain
What the program refuses
- Any withdrawal: no such instruction exists.
- Trading the coin itself: the coin, its bonding curve and its pool are forbidden on every swap route, even if the coin were approved as an asset.
- A route it did not expect: swaps use the pinned Jupiter program and exact-in routes only, with no platform fee and no positive-slippage capture, and the output must reach the vault at the agreed minimum.
- Tampering during a swap: afterwards every vault token account must keep its owner, with no delegate and no close authority, and no intermediate balance may end lower than it started.
- Running anything twice: every execution writes a one-time receipt for its intent.
- Selling the coin: buybacks can only buy, within a price-impact limit, and every coin bought moves to a lock that no instruction can sign for.
- Going too fast: swaps, venue funding and profit buybacks are rate limited per rolling day.
These rules are tested against the real Pump, PumpSwap and Jupiter programs, including a hostile program loaded at Jupiter's address. An external audit, a verified build and a multisig with a timelock on the upgrade key are still to come before mainnet.
Read this
Boundaries
- No redemption rights. A coin is not a share, a fund unit or a claim on the vault. Holders cannot redeem it for the treasury's assets and receive no distributions.
- The treasury does not back the coin. Treasury value (NAV) is published for transparency. The coin's price is set by its own market on the bonding curve or PumpSwap and can diverge from NAV entirely.
- Pacifica capital is held by the protocol. Each coin trades from one Pacifica account, a plain Solana key that the protocol holds, not the program; Pacifica keeps its balance off chain. The on-chain program guards the vault only. Launchers acknowledge this at launch.
- Profit buybacks tie the coin to performance. They buy and lock, never distribute, but they link the coin's market to the agent's results, which raises legal risk in some jurisdictions.
- xStocks are restricted by jurisdiction. Tokenized stocks are switched on per deployment and never offered where they are not permitted.
- Policy, not promises. The AI proposes; the policy and the risk engine bound what can happen. Requirements the policy language cannot express are rejected and shown verbatim before launch or payment, never silently dropped.
- Software and market risk. Programs, venues, oracles, routers and RPC providers can fail; trades can slip within the configured limits. Nothing here is investment advice.
How the agent is boxed in: Limits. How to tell real money from a simulation: Data and provenance.