Slice
Security

Addresses

Every address involved in moving creator fees: the programs we build on, the one wallet we operate, and the addresses each token gets. There is nothing here you should ever send SOL to.

The treasury

One wallet. It receives every sweep, holds recipients’ balances until they are paid, and signs every payout, buy, burn and platform withdrawal. Its balance is what the proof of reserves compares with what is owed.

Treasury
Published at launch
A hot key we operate. Its history on Solscan is the whole money flow: sweeps coming in, payouts, buys, burns and platform withdrawals going out. See Security model.

The programs

None of these are ours. They are the programs the product uses, listed so you can check that a transaction touches what it should.

pump.fun
6EF8rrecthR5Dkzon8Nwu78hRvfCKubJ14M5uBEwF6P
The bonding-curve program. Creates every token (create_v2), holds the bonding-curve creator vault of each creator address, and pays it out with its collect instruction.
PumpSwap
pAMMBay6oceH9fJKBRHGP5D4bD4sWpmSwMn52FMfXEA
pump.fun’s AMM, where a token trades after it migrates. Holds the creator fees of migrated tokens as wrapped SOL, per creator address.
pump.fun fees
pfeeUxB6jkeY1Hxd7CsFCAjcbHA9rWtchMGdZ6VojVZ
Holds pump.fun’s fee configuration. The creator fee rate shown on Fees & limits is read from it.
Token-2022
TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb
The token program of mints created with create_v2. A burn is sent to the program that owns the mint, read from the mint account rather than assumed.

Addresses of each token

Every launch gets its own addresses, published on its token page and in GET /api/tokens/<mint>.

AddressFieldWhat it is
MintmintThe token. Generated in the deployer’s browser
CreatorcreatorThis token’s own fee address, derived for it alone
Creator vaultcreatorVaultWhere its bonding-curve creator fees wait to be swept
DeployerdeployerThe wallet that signed and paid for the launch. It has no claim on the fees

How the creator and its vaults relate is on Per-token vaults.

Verifying an address

  1. Programs: open them on Solscan. Each is labelled there as pump.fun, PumpSwap or Token-2022, and a launch or sweep transaction lists them as the programs it invoked.
  2. The treasury: open any sweep in the ledger on Solscan. The SOL collected from the vault ends up at this address.
  3. A token’s creator: open its launch transaction. The creator passed to create_v2 is the address on the token page.

Base58 addresses are case-sensitive. Compare them character by character, or better, copy them rather than retyping.