Security

What you trust

You trustFor
pump.fun's program and fee sharingPricing and custody on Solana, the split of creator fees
The Pons contractsPricing and custody on Robinhood Chain
The Glint contractsThe launch on Pons, the vault, the fee split on that side
The keeperThe launch sequence, the maker, the pool's wallets

See the operator and the trust model for the last line.

What the contracts prevent

What the contracts do not prevent

Attacks considered

AttackDefence
Sandwiching a maker tradeEach trade carries a minimum output, the simulated output minus 1.5 %, and the maker stops at the target
Pushing one curve to drain the poolThe maker only buys the cheap side or sells inventory and never chases a price beyond the target. The pool's allocation per coin caps the loss
A manipulated rateThe rate is the median of three sources and the keeper does not trade when they disagree by more than 2 %
Griefing the launchThe sequence is checked step by step and the deposit is refunded if the launch cannot complete
Fake coin pagesThe launcher's list is on-chain and the coin page lists both token addresses
Anti-sniper window on PonsThe launcher and the vault are exempted at launch so the maker's first buys are not taxed
Keeper downtimePrices drift until it comes back, nothing else breaks. The monitor shows the age of the last update
A runaway keeperGuards cap each trade, each tick and each coin's cash, and a KILL file stops everything

Reading, not trusting

The numbers in these docs can be read from the chains. See verify on-chain.

Audit

The Robinhood Chain contracts are small but hold money. They are tested on a fork against the real Pons (see test results). An independent audit comes before the first coin, and the report will be linked here. The keeper has no audit. Until both exist, do not send funds to any Glint address. See status.