C:\COBWEB> man cobweb
NAME
Cobweb Pad - a Solana launchpad on pump.fun. Every coin is a normal pump.fun coin. Its creator fees are split by the Cobweb program: 40% to the dev, 35% buys $SPIDER and burns it, 20% is silk for the coin's holders, 5% shakes the web.
SYNOPSIS
LIFECYCLE OF ONE COIN
| step | who | what happens on chain |
|---|---|---|
| launch | dev | create_v2 with creator = the coin's Fees PDA, optional dev buy, Coin + Market accounts |
| trade | anyone | plain pump.fun / PumpSwap trades, no router, no tax |
| collect | anyone | pump creator fees -> the coin's buckets: dev 40 / $SPIDER 35 / silk 20 / vibration 5 |
| snapshot | anyone | a finished epoch with enough silk -> SilkEpoch account (the silk it may pay) |
| post | attestor | merkle root of the epoch's report, at most the snapshot; guardian may veto inside the window |
| claim | holder | once per leaf, never the dev launch wallet, never above the root's total |
| expire | anyone | unclaimed or unposted silk rolls back into the coin's next epochs |
| migrate | anyone | sync_migration when pump graduates the coin; fees keep flowing from PumpSwap |
THE SILK RULE (published verbatim, cobweb-silk-v2)
COBWEB SILK RULE (cobweb-silk-v2)
1. History. For every pad coin we replay every transaction that changed a Token-2022 balance of the coin (pump buys and
sells, PumpSwap swaps, plain transfers, closes), in slot order. In each slot every wallet's balance change of the
coin is netted into one number.
2. Lots (FIFO). A positive net change opens a lot {amount, t = block time}. A negative net change consumes the wallet's
OLDEST lots first. Buys and transfers in open lots the same way: a lot's age starts when the tokens arrived in THIS
wallet, so moving tokens to a second wallet restarts their age. Tokens that leave a wallet without a matching lot
(we never saw them arrive) consume nothing.
Balance check, per token account: every transaction carries each token account's real balance before it. If an
account holds fewer tokens than we last saw in it, the difference left unseen (its owner's oldest lots are consumed
as a transfer); if it holds more, the difference arrived unseen (a new lot of age 0 at that moment). Tokens sent to
another account of yours, or by anyone to any account of yours, never touch the age of what you already hold.
Moving tokens around can only lose silk, never gain it.
3. Weight of a lot of age a (seconds): w(a) = 0 for a <= 60; w(a) = x^2 (3 - 2x) with x = (a - 60) / 1740 for
60 < a < 1800 (a smooth S-curve, no cliff); w(a) = 1 for a >= 1800.
4. Score of a wallet for a silk epoch window [from, to): the sum over its lots of amount x the integral of w(age) dt over
the part of [from, to) the lot was held. In integers: score = sum amount x (Wq(a2) - Wq(a1)), a1 / a2 = the lot's
age at the start / end of its held part of the window, Wq(a) = 0 (a <= 60), 2*1740*d^3 - d^4 with d = a - 60
(60 < a < 1800), 1740^4 + 2*1740^3*(a - 1800) (a >= 1800). (Wq = 2*1740^3 x the integral of w.)
5. Silk of a wallet = floor(silk x score / total score), silk = the amount the program snapshotted for that epoch.
Shares below 10,000 lamports are left out; everything left out or unclaimed rolls back into the coin's next epochs.
6. Not eligible: owners that are not wallets (PDAs: the pump curve, PumpSwap pools, Cobweb's own accounts) and the
coin's dev launch wallet (it already gets the dev share; the program refuses its claims too).
7. Caught fly: every lot SOLD before age 1800 s is a fly: {wallet, amount, age, missed}. (A lot sent to another wallet
before 1800 s also stops earning, but is not shown as a fly.)
missed = what that amount would have earned at full weight from the later of its arrival and the window start to the
window end, minus what it earned while held, valued at the epoch's silk per score unit. It is an estimate: it
assumes everyone else held the same.
8. Reconciliation: if a wallet's lots add up to more than its real balance at the cut-off (a transfer we could not
see), the difference is consumed at its LAST KNOWN event. Holding is never invented.
9. The report of every epoch (every lot with its in / out transaction, every score, every leaf) is published at
/report/<mint>/<epoch>.json; its sha256 is signed by the attestor together with the root. Anyone can recompute it.
10. Complete history only: a root is signed only when the history of every holder account is complete (no signature
list cut at the page limit, every transaction returned with its block time). Otherwise the epoch is retried and,
if it stays incomplete, its silk rolls back into the coin's next epochs.This preview chain runs the ramp 10x faster: full weight at 3:00 instead of 30:00 (SILK_RAMP=6,180). Mainnet runs the rule above.
WORKED EXAMPLE
You buy at 12:00:00 and sell half at 12:12:00. The sold half was 12:00 old: it earned about 32% of what a full-weight lot earns in those 12 minutes, and it is listed as a fly with the silk it missed. The other half keeps its age and reaches full weight at 12:30:00. At the end of the epoch, the coin's silk is split by score; your leaf is in the posted root and you claim it from Mine.
PARAMETERS
| parameter | mainnet default | bounds in the program | this chain now |
|---|
ACCOUNTS
| account | seeds | holds |
|---|---|---|
| Config | ["config"] | keys, params, guard, silk rules, pad mint, tags, molt marks + stage, $SPIDER books |
| SpiderPot | ["spider"] | the $SPIDER leg of every coin until feed_spider buys and burns |
| Web | ["web"] | the program's buyer; holds only its floor between instructions |
| Coin | ["coin", mint] | dev, tag, params copy, state, fee books, silk books, vibration books |
| Fees | ["fees", mint] | the coin's pump creator; holds the pending legs |
| Market | ["market", mint] | 16-slot price observation ring, the program-buy limiter |
| SilkEpoch | ["silk", mint, epoch] | window, amount, root, total, report hash, claims, claim bitmap |
WHAT THE ADMIN CAN AND CANNOT DO
TRUST POINTS
The attestor signs each silk root and each vibration trigger. A root can pay at most what the program snapshotted for that coin's epoch, never to the dev launch wallet, once per leaf, never above its total; the guardian can veto it inside the window; the full report (every lot, every transaction) is public at /report/<mint>/<epoch>.json and its sha256 is on chain. Only the dev's launch wallet is excluded from silk. A leaked attestor key is stopped by guardian vetoes (2 h window) while its replacement goes through the 3-day rotation. A vibration trigger can spend at most 0.1 SOL of one coin's vibration bucket per hour, only on same-thread pad coins, under the price guard, and the tokens are burned.
COMPROMISE
Hold time is wallet-level data, so it cannot be read by the program itself. An attested merkle root per epoch carries it, bounded by the on-chain silk bucket, with a fully public report of every lot. There is no tax: a flipper pays nothing extra, he just does not earn.
VERIFY ON CHAIN
RISKS
Silk pots are small: 20% of a 0.3% creator fee, so 1 SOL of volume makes 0.0006 SOL of silk. The site shows the real numbers, never a projected yield. A donation to a coin's creator vault is booked as fees and split like fees. After graduation a coin needs 7 fresh pool observations before the program buys it again. Pump.fun and PumpSwap are outside this program.
ERRORS
| code | name | what it means |
|---|---|---|
| reading the IDL.. | ||
FAQ
Do I pay anything for selling early? No. Nothing is taken. The lot just stops earning and the silk stays with the holders.
Can I move tokens to a fresh wallet to keep the age? No. Tokens that arrive by transfer start at age 0.
Does the dev earn silk? The dev's launch wallet gets the 40% dev share instead and cannot claim silk; the program refuses it.
What if the attestor goes quiet? Unposted silk rolls back into the coin's next epochs after the post window. Nothing is stranded.
Fonts: VileR, int10h.org, CC BY-SA 4.0 (Web437 IBM VGA 9x16, IBM BIOS-2y). Numbers: Inconsolata, OFL. licence