Sign it once
A launch record is a name, a ticker, a supply, a mint, a creator, a moment, an image hash and a description. In Quantum mode one of your 256 one-time keys signs those exact fields and is then spent, the mint address is derived from that same key so a leaf can only ever produce one coin, and anyone can check the result against your root without asking this site anything.
In Standard mode nothing is signed, no leaf is spent, and the mint is a random keypair. It is the same coin pump.fun would make on its own. The mode is offered so the two can be compared rather than asserted, and every page about such a coin says it proves nothing about who created it.
The launch button sends a real mainnet transaction. It calls pump.fun’s create_v2, pays the network fee from your wallet, and creates a coin that cannot be deleted. In Quantum mode an Attest only button sits beside it and spends a leaf and no SOL; in Standard mode there is nothing to attest, so there is only the one button. What is not deployed is the on-chain verifier: the 2,436-byte attestation exceeds Solana’s 1,232-byte transaction limit and has to be staged into a program account to be checked by a program. Until that is deployed, the attestation is checkable by anyone with the algorithm and not by the chain itself. This project has no coin of its own yet.
00 · wallet and identity
No Solana wallet announced itself to this page, so nothing below can be signed. Everything on the form still reads, and the verify page needs no wallet at all.
01 · launch mode
02 · image
signedDrop an image, or click to choose one
The signature covers the image's sha256, not its url. No image is also a signed value.
03 · the record
0
The lowest key nobody has spent. 256 of 256 remain.04 · links
The X handle is not part of the digest: a social link can be corrected without lying about what the coin is, and a name cannot. The website is not yours to set at all, because it is where the attestation gets re-checked.
05 · signature scheme
All eight sign here, and every byte figure below is the length this site’s own code produced rather than the one a standard document publishes. Run npm run probe-pq: each one signs, verifies, and refuses a flipped bit. Only WOTS + Merkle burns a leaf, though, and only it can carry a launch today: an attestation here is bound to a Merkle identity with a leaf and an authentication path, and that is the one shape the server verifies. The other seven are selectable nowhere until it verifies them too, because a picker offering what the server refuses is the fault this page exists to avoid.
06 · pair with
Both of these were asked of the program rather than inferred from its published interface, by simulating a create with each mint in the quote slot and reading what came back.
- USDC is accepted. It is the single entry in
Global.whitelisted_quote_mints,EPjFWdd5…TDt1v. The quote mint rides in three accountscreate_v2’s IDL does not name, which is why this page said for a week that it could not be done. - Tokenized stocks are refused, in the program’s own words. TSLAx and NVDAx both answer
UnsupportedQuoteMint, and so do USDT and JUP. The expandableQuoteControllist that would hold more has zero accounts on chain, andadd_quote_mintis signed by pump.fun’s own authority.
Stocks stay struck through rather than hidden, because a reader comparing launchpads should see what was tried and what the chain said.
07 · dev buy
not signedSOL spent on the curve’s first trade, in the same transaction as the create, so nobody can buy in front of it. Leave it at zero to launch without one. It is not covered by the signature: the attestation is about who made the coin, not about what they bought.
No dev buy. The create goes out on its own.
08 · sign, and launch
Two buttons because they are two different acts. The first spends a leaf and nothing else. The second spends a leaf, sends a real mainnet transaction, pays the network fee and creates a coin that cannot be deleted.
Both buttons need a connected wallet: one to sign the record, the other to pay for the transaction.