Mole Pad markMOLE PAD
1UPROUND-- CASOON
LAUNCH DIG

MOLE PAD DOCS

A Solana launchpad on pump.fun where a new coin starts underground. Wallets dig its field for rights; a right is a seat in the one pooled first buy that creates the coin. Bots can only buy after.

OVERVIEW

A pump.fun coin is public from the transaction that creates it, so a coin cannot be hidden on pump. On Mole Pad it does not exist on pump at all for its first minutes. It is a burrow: the program stores only a salted hash of its name, ticker and metadata link, and a hash of the dig field's seed (the round code).

While the burrow is underground, wallets dig its field through the dig service. A dug cell shows how many buried treasures touch it. A dig that hits a treasure returns a right signed by the pad's attestor. The wallet funds the right: it locks up to the right's cap in the burrow's escrow.

At the timer, or as soon as every right is funded or the escrow is full, anyone sends surface: one instruction creates the coin on pump.fun and makes one pooled buy with the whole escrow (the diggers and the dev deposit, one price). Everybody then claims tokens in proportion to what they locked. A burrow that cannot surface refunds everybody in full.

The pad promises that diggers enter first, in one transaction. It does not promise that there are no bots: anyone can buy the coin on pump.fun right after the surfacing transaction.

LIFECYCLE

STATEWHAT HAPPENSWHO MOVES IT
PREPAREDThe creator sends name, ticker, picture link (IPFS), field size, treasures, caps and a dev deposit. The dig service draws a random field seed and a salt and co-signs the opening.creator + dig service
UNDERGROUNDopen_burrow: the escrow takes the dev deposit, the rent deposit and the launch fee. The timer runs 10 minutes. Wallets dig and fund rights.diggers
READYEvery right funded, or the escrow full, or the timer over with at least 3 funded rights.-
SURFACEDsurface: create_v2 on pump.fun (mint = a PDA of the pad, creator = the coin's Fees PDA) + one buy of the whole escrow, alone in its transaction. Then reveal_field puts the seed on chain.anyone (the keeper does it)
SETTLEDclaim per right and claim_dev_share: tokens x deposit / budget, plus a share of any SOL the capped buy did not spend. sweep returns the leftover rents to the creator.anyone; the keeper pushes after 30 min
CANCELLEDToo few diggers at the timer, nobody surfaced within 1 h after it, the creator before any right was funded, or a guardian veto. refund per right and refund_dev pay back 100 %.anyone / creator / guardian

THE DIG GAME

The field is a grid of 4-24 x 4-24 cells with at least four cells per treasure. Its layout is a pure function of the seed: treasure i sits at the first sha256("mole/cell/v1" || seed || i || generation || counter) mod cells that is free.

RIGHTS AND THE ESCROW

A right is an Ed25519 signature of the attestor over "mole/right/v1" || program || burrow || index || wallet || cap || expiry. claim_right checks it, creates the Right account (one per wallet per burrow) and moves your deposit into the escrow: min(amount, cap, room left), at least 0.02 SOL. Deposits are final until the burrow surfaces or is cancelled.

Worked example. A 16 x 12 burrow, 20 treasures, 0.25 SOL per right, escrow cap 5 SOL, dev deposit 0.3 SOL. Four diggers fund 0.25 + 0.25 + 0.1 + 0.1 = 0.7 SOL. Budget = 0.3 + 0.7 = 1.0 SOL. At surfacing one buy of 1.0 SOL takes about 3.41 % of the supply at about 1.046 x the start price. A digger who locked 0.25 SOL claims tokens x 0.25 / 1.0 = a quarter of what the buy got.

SURFACING

One instruction, alone in its transaction (only compute budget next to it): it checks the metadata against the committed hash, creates the coin with create_v2 (mayhem, holder rewards and cashback off) and buys once with the budget. The buy never offers more than the lamports that buy 15 % of the supply on the fresh curve; what it did not spend goes back pro rata (SOL back). Measured: a full 5 SOL escrow is capped at about 4.875 SOL = 14.84 % of the supply at 1.175 x the start price. The program asserts the escrow holds at most 15 % of the supply after the buy.

It is permissionless: the keeper sends it with the metadata the dig service keeps, and the creator can send it from the receipt the site gives at launch (name, ticker, link, salt).

NO SHOW, NO LOSS

A burrow that cannot surface is cancelled and every lamport goes back: each right gets 100 % of its deposit plus the Right account's rent, the creator gets the dev deposit, the rent deposit and the launch fee. Measured cost of a cancelled burrow to its creator: transaction fees only.

FEES AND $DIG

COMPROMISES, IN PLAIN WORDS

TRUST POINTS

ADMIN CAN

ADMIN CANNOT

IF THE PAD CLOSES

The site shows a SUNSET banner and stops taking new burrows. Underground burrows either surface or are cancelled by the rules above; claims, refunds and the dev share stay open on chain forever.

VERIFY ON CHAIN

  1. The program id is Dig3eAVxdv5Cd6Pek741FfMAB1Te3wcVYqghMRH3gTCK. Config PDA ["config"].
  2. A burrow is the PDA ["burrow", round code]. Its meta_hash = sha256("mole/meta/v1" || len || name || len || ticker || len || uri || salt).
  3. After surfacing, field_seed is on the burrow account and sha256(seed) == round code (checked by reveal_field).
  4. Open any surfaced burrow and press VERIFY FIELD: your browser recomputes the layout from the seed and replays every dig and re-bury of the public log.
  5. The surfacing transaction has one instruction of this program: create_v2 and the buy are its inner instructions. Open it from the burrow page.
  6. The coin's pump.fun creator is ["fees", mint] of this program; its curve is created in the same instruction as the buy.

PARAMETERS

Live from the config account (version -). Each burrow copies them when it opens.

PARAMETERVALUEMEANS
Reading the config.

ACCOUNTS AND SEEDS

ACCOUNTSEEDSHOLDS
Config["config"]admin, treasury, attestor, guardian, params (+ pending), $DIG mint, counters
Burrow["burrow", field_commit]the burrow, then the coin's record: fee books, price ring
Escrow["escrow", burrow]deposits; pump.fun payer and buyer of the pooled buy; holds the tokens until claimed
Mint["mint", burrow]the coin's mint, created by pump.fun's create_v2
Fees["fees", mint]the pump creator of the coin: creator fees, dev / treasury books
Right["right", burrow, wallet]seat index, cap, deposit; closed at claim / refund (rent back to the wallet)
Dig pot["digpot"]the $DIG share of every coin's fees
Buyer["buyer"]the pump user of $DIG buybacks (tokens burned at once)

INSTRUCTIONS

WHOINSTRUCTIONS
creatoropen_burrow (+ the attestor's Ed25519 co-sign), cancel_burrow before any right is funded
diggerclaim_right (+ the attestor's Ed25519 right)
anyonesurface, reveal_field, cancel_burrow (too few diggers / past the deadline), claim, claim_dev_share, refund, refund_dev, close_burrow, sweep, collect, claim_dev, collect_treasury, sync_migration, observe, buy_dig
guardiancancel_burrow (veto, underground only), cancel_params, cancel_attestor
admininit_config, propose_params / accept_params, set_treasury, set_paused, key rotations, set_pad_mint (once)
devpropose_dev / accept_dev (two-step handover of the fee share)

ERRORS

What the program answers when it refuses, from its IDL.

CODENAMEMEANS
Reading the IDL.

RISKS

FAQ

DO I PAY TO DIG?

No. Signing in is a signed message, digging is off chain. The wallet needs 0.01 SOL in it to sign in, but nothing is taken. You pay only when you fund a right (your deposit + about 0.0016 SOL account rent, returned at claim).

WHY ONLY 6 DIGS WITH 10M $DIG?

A new wallet always starts with 6. $DIG makes digs come back faster (up to 18 an hour) and lets a wallet that keeps holding store up to its tier. That way one bag moved between wallets is worth nothing.

WHAT IF NOBODY SURFACES IT?

Anyone can cancel it after the window, and every right is refunded in full. The keeper does it on its rounds.

CAN I WITHDRAW A DEPOSIT?

No, deposits are final until the burrow surfaces or is cancelled. That stops a seat being parked and pulled at the last second.

WHY CAN'T I SEE THE COIN WHILE IT IS UNDERGROUND?

Because it does not exist yet. Only its hash is on chain; the name and picture appear when it surfaces.