Sheaf is a launchpad on the pump.fun curve. A creator's token graduates in the transaction that creates it, and the creator's block sits in a vault that declares its size and caps how fast it can leave.
A bundle is a block of a new token's supply, bought at the mint before anyone else can bid.
From outside the launch, three things about it are unpublished: that it exists at all, how large it is, and how fast it is able to leave.
A Sheaf bundle publishes all three, in the transaction that creates it.
Not a commitment to hold. A rate written once into an account anyone can read, in a program with no upgrade authority, so it cannot be raised afterward.
The rest of this page is the cap, the fee a trader pays, the four things anyone can check, and the list of what this is not. The numbers that do not flatter this are on the page at the same size as the ones that do.
The object behind this page is a sheaf: many filaments, one band. The band is the cap. It is one number, written once when the bundle is created, into an account no instruction rewrites. The vault sells above a reference that can only move up, and the rule is a published function, not a promise. Everything below is what those two sentences cost.
flow_cap_bps = 2,500 against a basis fixed at launch, window_len_secs = 3,600, and the vault's own sell cap trade_cap_sell_bps_window = 100, all from docs/IMPLEMENTATION.md §3.4. At most 25 percent leaves in any one window, and every window is a fixed span of at least one hour counted from launch. That is not a bound on any 60 minutes: a sequence timed across a window boundary can move close to two quarters inside an interval just under one hour, measured at 1.9994 times the allowance. Over any span, outflow is at most one allowance plus one allowance per window elapsed. What this bounds is the vault, not the holder: once tokens are redeemed into a wallet no program constrains them, so four windows after launch is the soonest the block can be out of the vault, not a limit on what happens next. The unconstrained case is illustrative: no program constrains an ordinary launch bundle, so there is no measured line to draw.| Windows after launch | Fastest exit, least still held | If only the vault sold |
|---|---|---|
| 0, just after launch | 75% | 99% |
| 1 | 75% | 99% |
| 1.5 | 62.5% | 98.5% |
| 2 | 50% | 98% |
| 3 | 25% | 97% |
| 4 | 0% | 96% |
| No cap in code, any window | 0% | 0% |
The rule is a published function, not a promise.
At most a quarter of the declared block can leave in any one window.
The creator funds the whole bundle, alone, when it is created.
The cap measures against the block declared at launch, not against what is left.
The program is specified to deploy with no upgrade authority.
None. That is what makes the sentence above worth reading. It also means a bug cannot be patched.A holder redeems for a slice of two balances, in kind.
Shares mint only inside a closed funding window.
Full unwind is a computed figure, not a promise.
cap_basis_base, which extends the true unwind. The program cannot refuse an incoming transfer, so the figure is published live from two on-chain numbers rather than printed here as a constant.This part is about the fee a trader pays. pump.fun takes a cut of every trade and splits it three ways, and the coin creator's leg steps at one exact line. A token that has just graduated sits a whisker under it. Both numbers were invisible until they were read off chain.
fee_config PDA 5PHirr8joyTMp9JMm6nW7hNDVyEYdkzDqazxPD7RaTjx, seeds ["fee_config", AMM], 4,097 bytes, decoded 2026-09-28 and reconciled against the lamport deltas of a live swap. Graduation constants read from pump.fun's own Global account the same day. The live rate is read from that account at transaction time, never from this chart.| Tier, market cap from | Coin-creator leg |
|---|---|
| 0 SOL | 30 bps |
| 420 SOL | 95 bps |
| 1,470 SOL | 90 bps |
| 2,460 SOL | 85 bps |
| 3,440 SOL | 80 bps |
| 4,420 SOL | 75 bps |
| 9,820 SOL | 70 bps |
| Tiers 7 to 22 | not decoded |
| 93,330 SOL | 8 bps |
| 98,240 SOL | 5 bps |
| Where the whole 120 bps goes, above the first tier | Leg |
|---|---|
| Liquidity providers, every tier | 20 bps |
| pump.fun's protocol leg, every tier | 5 bps |
| The coin creator, at the first tier | 95 bps |
Below 420 SOL the split is different and worse for the creator: liquidity takes 2 bps, pump.fun takes 93, and the creator takes 30. That bottom tier is a penalty band on small pools, and it is where every fresh graduate starts. The creator leg is paid to the bundle's vault. At each harvest, 10 percent of the part other traders paid goes to Sheaf's protocol fee wallet, fixed in the program; the vault keeps the rest, and all of what its own trades paid.
Graduation lands near 410.9 SOL, just under the boundary.
clear_tier, makes a single capped purchase targeting 430 SOL, and it fails closed: if the spend would exceed its cap, or the buy would land short of the target, the whole transaction reverts and the vault spends nothing. Until that succeeds the creator leg is 30 bps, not 95. Measured on a mainnet fork from a fresh graduate, the purchase to 430 SOL costs 1.99 SOL, inside its 5 SOL cap. The program refuses a tier purchase above 5 SOL, or a target above 450 SOL of market cap, on any bundle.This whole schedule is a third party's editable parameter.
Everything above is a claim until you read it yourself. Four calls settle all of it, and not one of them requires running our software. Nothing is deployed, so there are no addresses to fetch yet. These are the checks, published before the addresses exist.
The exact recipe is in the litepaper, with byte offsets.
curl and xxd rather than with our client. A verification that requires running our software is not a verification. A test serializes a known struct and indexes the bytes, so the build fails if a field moves and the published recipe goes stale.Stated plainly, because the alternative is stating it later. The full version, with the figures, is in the litepaper.
This describes a specification, not a program you can call today.
Every bundle is its creator's own SOL, and no one else can deposit.
Nobody outside the build has read the code.
Fees raise the claim per share. There is no distribution step.
The creator fee belongs to pump.fun, and its config has a mutable admin.
The modeled median outcome for a creator is a loss.
The full mechanic, the decoded fee schedule with its on-chain source, the seven instructions and eight accounts, the caps and how each one is enforced, why redemption is in kind, the verification recipe with byte offsets, and the risk list with its figures.
Bundle state lives in the app, not here: the caps, the vault balances, and the disclosures before anything else is reachable. One row per declared bundle, with its creator, its cap and its speed limit.