Skip to content

Checking modechecking

Mode…

Custody and security

Where the money sits, who holds which key, and what you are trusting.

Four places

Where the money sits

Coin money sits in four places. The on-chain program guards two of them; the protocol holds the other two. Every screen that shows funds labels them Program custody or Protocol custody.

  • Strategy vault (Solana)Program custody

    Who moves it
    Only the strategy_vault program. Swaps need the executor and an independent risk key to co-sign, use approved tokens and guarded Jupiter routes, and can never touch the coin itself.
    How it leaves
    No withdraw instruction exists. Vault funds reach a wallet only as the inference share of collected fees, or through fund_venue to the coin's own Pacifica account.
  • Pacifica accountProtocol custody

    Who moves it
    A plain Solana key held by the protocol, one per coin, bound to the coin on chain once by the policy attestor. Pacifica keeps the balance, positions and orders in its off-chain engine.
    How it leaves
    Withdrawals from Pacifica can only return to that same account. The program cannot protect funds while they are there.
  • Inference treasuryProtocol custody

    Who moves it
    A dedicated protocol account (never an operational key) that receives the inference half of collected fees and pays OpenRouter.
    How it leaves
    Spent on model calls. Each coin's budget is its share minus the cost reported for its own calls.
  • Buyback vault and lockProgram custody

    Who moves it
    Buy-only, this coin only, price-impact bounded. Bought coins go straight to a lock account that never signs.
    How it leaves
    It does not: locked coins are never sold, burned or distributed.

fund_venue

How capital reaches Pacifica

A Pacifica account is a plain Solana key, so a program address can never own one. Each coin gets its own key, held by the protocol and bound to the coin on chain once, at launch.

Vault USDC can move there only through the program's fund_venue instruction: it pays only that registered account, needs the executor and the risk key to co-sign, is capped per rolling day, and leaves a one-time receipt per transfer. From there Pacifica holds the balance in its off-chain engine, and withdrawals can only return to the same account.

Pacifica is in closed beta: it caps an account's equity and its withdrawals per day, and it blocks restricted jurisdictions. Launchers acknowledge this custody at launch.

Separation of duties

Keys and roles

No key may hold two operational roles, the admin never holds one, and the keys that move funds never choose where funds go. The model holds no key at all.

  • Admin

    Held by
    The protocol (cold key, two-step rotation)
    Can
    Set the protocol configuration: which keys hold the operational roles, the inference treasury and its share (at most 50%), daily caps, pauses.
    Cannot
    Hold an operational role, or move vault funds itself.
  • Program upgrade authority

    Held by
    The protocol: one key today; a multisig with a timelock is planned before real users.
    Can
    Deploy new code for the strategy_vault program, which could change any rule on this page.
    Cannot
    Nothing is out of its reach while it exists: this is the largest trust assumption.
  • Guardian

    Held by
    The protocol
    Can
    Pause, and disable an asset.
    Cannot
    Unpause, or enable anything.
  • Policy attestor

    Held by
    The protocol
    Can
    Attest launch policies and bind each coin's Pacifica account, once.
    Cannot
    Move funds.
  • Executor

    Held by
    The protocol (the worker)
    Can
    Submit swaps, fund_venue transfers and buybacks, each co-signed by the risk authority.
    Cannot
    Choose where funds go: the program derives every destination itself.
  • Risk authority

    Held by
    The protocol, independent of the executor
    Can
    Co-sign execution after checking it against independent reference prices.
    Cannot
    Act alone.
  • Pacifica account key

    Held by
    The protocol, one per coin
    Can
    Deposit, trade on Pacifica and request withdrawals, which only return to that same account.
    Cannot
    Reach the Solana vault: funds come to it only through fund_venue.
  • Launcher

    Held by
    Whoever launched the coin
    Can
    Launch and choose the settings.
    Cannot
    Anything after launch: no authority over the coin's vault, its agent or its fees.
  • OpenRouter API key

    Held by
    The protocol
    Can
    Pay for the agents' model calls.
    Cannot
    Anything on chain.

On chain

What the program refuses

  • Any withdrawal: no such instruction exists.
  • Trading the coin itself: the coin, its bonding curve and its pool are forbidden on every swap route, even if the coin were approved as an asset.
  • A route it did not expect: swaps use the pinned Jupiter program and exact-in routes only, with no platform fee and no positive-slippage capture, and the output must reach the vault at the agreed minimum.
  • Tampering during a swap: afterwards every vault token account must keep its owner, with no delegate and no close authority, and no intermediate balance may end lower than it started.
  • Running anything twice: every execution writes a one-time receipt for its intent.
  • Selling the coin: buybacks can only buy, within a price-impact limit, and every coin bought moves to a lock that no instruction can sign for.
  • Going too fast: swaps, venue funding and profit buybacks are rate limited per rolling day.

These rules are tested against the real Pump, PumpSwap and Jupiter programs, including a hostile program loaded at Jupiter's address. An external audit, a verified build and a multisig with a timelock on the upgrade key are still to come before mainnet.

Read this

Boundaries

  • No redemption rights. A coin is not a share, a fund unit or a claim on the vault. Holders cannot redeem it for the treasury's assets and receive no distributions.
  • The treasury does not back the coin. Treasury value (NAV) is published for transparency. The coin's price is set by its own market on the bonding curve or PumpSwap and can diverge from NAV entirely.
  • Pacifica capital is held by the protocol. Each coin trades from one Pacifica account, a plain Solana key that the protocol holds, not the program; Pacifica keeps its balance off chain. The on-chain program guards the vault only. Launchers acknowledge this at launch.
  • Profit buybacks tie the coin to performance. They buy and lock, never distribute, but they link the coin's market to the agent's results, which raises legal risk in some jurisdictions.
  • xStocks are restricted by jurisdiction. Tokenized stocks are switched on per deployment and never offered where they are not permitted.
  • Policy, not promises. The AI proposes; the policy and the risk engine bound what can happen. Requirements the policy language cannot express are rejected and shown verbatim before launch or payment, never silently dropped.
  • Software and market risk. Programs, venues, oracles, routers and RPC providers can fail; trades can slip within the configured limits. Nothing here is investment advice.

How the agent is boxed in: Limits. How to tell real money from a simulation: Data and provenance.