upstream

Trust

Limits and risks

What is built and checked, what is not, and where it can break. Read this before anything else.

What exists and has been checked

  • The engine: platform adapters, codes, attestations, the vault. 34 tests, including attacks.
  • The attester network software, tested over real HTTP with servers that fail, hang and lie.
  • An on-chain vault program in Rust (56 KB), tested on a local Solana runtime: every instruction, every refusal, exact time boundaries, and the native Ed25519 precompile.
  • A differential test: the program and the JS engine run the same random histories and must agree to the lamport (60 histories of 46 operations at the last run).
  • An integration test against the real pump.fun programs on a mainnet fork.
  • The CLI, and this website, which runs the JS engine in your browser.

Numbers and dates: Verification report.

What does not exist yet

An independent audit. The tests are the author's. The program holds money, and it should be read by someone else before any real coin is routed to it.

A deployment. The program has never been deployed to devnet or mainnet, so it has not run on a validator cluster. The runtime used for testing is a faithful simulation, not the same thing.

Independent attesters. The ones on this site are demo keys. The software to run real ones exists; nobody operates one yet.

The coin. The Upstream coin is not used by the engine or the program.

What can break

PieceRisk
Twitch readsUses a public endpoint Twitch has not promised to keep.
Kick readsUnofficial endpoint behind a bot filter. May refuse some browsers.
YouTube in a browserNeeds an API key you restrict to your domain, and a daily quota. An attester server needs no key.
GitHub60 anonymous requests per hour per IP.
Bio length limitsA platform could cap bios below what the code needs. The code is 18 characters.
pump.funThe vault depends on pump.fun's Pump Fees program behaving as it does today. Tested against the deployed programs on a fork, not guaranteed for the future.

Known limits of the design

  • SOL fees from the bonding curve only. Fees on coins that graduated to PumpSwap, or coins quoted in another token, flow through a wrapped-SOL path the vault does not accept yet.
  • A brand-new wallet needs the rent minimum. Solana will not credit an empty account with less than 890,880 lamports. A claim to a wallet that holds nothing, with less than that pending, fails and changes nothing; it works once the wallet holds some SOL or more has accrued.
  • The routing is one-way. After pump.fun's update_fee_shares_v2 nobody can change it. That protects the streamer, and it means a bug in the vault cannot be routed around.
  • Unswept fees must be swept first. pump.fun will not change a coin's creator while creator_fee is unswept. Sweeping is open to anyone and pays the original creator.

Honest trade-offs

  • The attesters are trusted. The design limits what they can do but does not remove the trust.
  • If both the account and the old wallet are lost, a rotation cannot be vetoed.
  • The proof lives on a third party's page. If a platform deletes the account, the vault can still pay a wallet already bound, but cannot bind a new one.
  • The launcher chooses the attesters and the split. Holders should read them before buying.

The coin

The Upstream coin is not used by the engine or the program. There is no fee in the rules, no staking, and no claim on any revenue. See the token page.

Not financial advice

Nothing on this site is investment advice. Coins are volatile and most lose value.