The operator and the trust model
Glint spans two chains. No contract can read both and trade on both, so a service, the keeper, does the part that crosses chains. That makes Glint partly an operated service, and it is worth saying exactly what that means.
Who holds what
| What | Held by | Where |
|---|---|---|
| The pad's pool, cash on Solana | the keeper's Solana wallet | Solana |
| The pad's pool, cash on Robinhood Chain | the coin's GlintVault, controlled by the keeper address | Robinhood Chain |
| Inventory of pump.fun tokens | the keeper's Solana wallet | Solana |
| Inventory of Pons tokens | the coin's GlintVault | Robinhood Chain |
| The creator's deposit, until it is spent | the keeper's Solana wallet | Solana |
| The creator's share of pump.fun creator fees | the creator, through pump.fun's fee sharing | Solana |
| The creator's share of Pons creator fees | the creator's address, through split() | Robinhood Chain |
What the keeper can do
- Create coins on pump.fun and trade them from its own wallet.
- Launch coins on Pons and trade them through the vault.
- Move the pool's cash and inventory to the pool address.
What the keeper cannot do
- Take the creator's share of pump.fun creator fees. pump.fun's fee sharing locks the shares after one call.
- Send a vault's funds anywhere except the pool address fixed when the launcher was deployed.
- Spend more on a coin than the vault's cash.
- Change the creator's payout address or share on a vault.
- Hide a move. Every action is a public transaction on Solana or Robinhood Chain.
What you still have to trust
- That the keeper runs the maker. If it stops, the two prices drift apart and nothing else breaks.
- That the pool's wallets are not drained by whoever holds their keys. The vault limits the damage on Robinhood Chain to the pool address. On Solana the wallet is an ordinary wallet.
- That a deposit unspent after a failed launch is returned. This is a promise of the operator, not something the code enforces.
- The rate feed. The keeper reads Coinbase spot for SOL and ETH. A wrong rate would make the maker trade against a gap that is not real.
How the exposure is limited
- Every trade passes guards in code: at most $1,500 a trade, $3,000 a tick, $5,000 of cash per coin and chain, and a loss limit per coin. See the keeper.
- The rate is the median of three sources and the keeper does not trade when they disagree by more than 2 %.
- A file named
KILLnext to the keeper stops all trading at once. - Each coin has a budget, about $5,000, so one coin cannot take the whole pool.
- All wallets and the contract addresses are published. The keeper writes a status file that the monitor shows: the rate, each coin's spread, the pool's cash and inventory, and any guard that blocked a trade.
- The Robinhood Chain contracts are small and have no owner and no upgrade path.
What is not done
- A multisig or hardware-held key for the pool. The first version uses plain keys.
- An independent audit of the contracts and the keeper.
- A way to trade the maker's decisions on-chain on Solana. That would need a Solana program and is not built.
CarefulTreat Glint as an operated service until a multisig and an audit exist. Do not put money in that you cannot afford to lose to a failure of the operator or of the keys.