Overview
Why HELIX
HELIX is a token standard, a DEX, a launchpad and a bridge in one Solana program. A HELIX token calls its hook before and after every transfer, mint and burn, and the hook can answer: take a cut of the amount for an account it names, and keep state inside every holder's account. The DEX lives in the same program, so every swap runs the hook and tells it why the tokens move.
Program id · same on every cluster
HLX49qz3CSKQrHrdzrrWygZBaKHWWSG8JwUMFHcZ47Fr
Example hook (trade_tax): AvY5wRP672DpNod6TWvMcNx9ekjgxoBjmj42ijbHenhz
- program for the token, the DEX, the launchpad and the bridge
- 1
- deployed size (≈0.86 SOL of rent to deploy)
- ~168 KB
- instructions
- 31
- hook callbacks
- 6
- bytes of hook state in every holding
- 64
- LiteSVM tests in packages/sdk/test
- 42
Token-2022, Solana's newer token program, lets a mint name a transfer hook: a program that Token-2022 calls on every transfer.[1] It was built to enforce rules, and that is all it can do.
- It can only say yes or no. Every account of the original transfer reaches the hook read-only, and the sender's signature does not extend to it.[1] The hook can fail the transfer. It can't change the amount, keep part of it or send any of it elsewhere. Fees on Token-2022 are a separate extension: a fixed rate, withheld in the recipient's account.[2]
- It runs once, after the fact. The call happens after all other transfer logic, so the accounts already show the end state.[2]
- It isn't told why tokens move. It receives the source, the mint, the destination, the authority and the amount.[3] A sale to a pool and a gift between friends look the same, unless the hook recognises the pool's accounts by itself.
- It covers transfers. Token-2022 calls it during a transfer.[2] Minting and burning don't call it.
- Its state lives elsewhere. Per-holder state sits in accounts the hook owns. Every transfer must carry them as extra accounts, listed in a PDA of the hook program seeded with
extra-account-metasand the mint.[1] Every program that moves the token, a DEX included, has to resolve and pass them.
- It runs before and after each transfer, mint and burn. A mint opts into each of the 6 callbacks with a flag.
- It is told why. Every call carries a context:
Plain,Buy,Sell,LiquidityorBridge. HELIX sets it, not the caller: thetransferinstruction always saysPlain, only the DEX's own swap and liquidity instructions sayBuy,SellorLiquidity, and only the bridge saysBridge, for tokens moving into or out of its vault. A caller can't pass a gift off as a trade, or a trade as a gift. - It can answer.
before_transfermay return up to three cuts of the amount, each credited to a holding of the same token that the hook lists among its accounts. The recipient receives the rest. HELIX checks every answer against the mint's flags before it applies it. - It keeps state where it is needed. Every holding carries 64 bytes that only the mint's hook can write, and each callback receives the source's and the destination's 64 bytes in its arguments.
- It knows HELIX called it. Every callback is signed by HELIX's PDA
["hook-authority", hook_program]. - It runs on every trade. The DEX is the same program, so buys, sells and liquidity changes all go through the hook, with the pool as the source or the destination.
Launches can also use the built-in kit: holder rewards in SOL, a max wallet, a creator lock and an early-buyer lock. It is a hook that runs inside HELIX, without a cross-program call. See Launches.
| Token-2022 transfer hook | HELIX hook | |
|---|---|---|
| Called on | Transfers [2] | Transfers, mints and burns |
| When | Once, after the transfer logic [2] | Before (may answer) and after (sees the result). Each callback is opt-in. |
| What it can do to the amount | Nothing: the transfer succeeds or fails [1] | Up to 3 cuts, credited to holdings it names; or fail the operation |
| Why the tokens move | Not told; it infers from the accounts [3] | Told: Plain, Buy, Sell, Liquidity or Bridge, set by HELIX |
| Accounts of the transfer | Read-only; the sender's signature doesn't extend to the hook [1] | Read-only too; HELIX applies the checked answer itself |
| State per holder | In accounts the hook owns, passed as extra accounts | 64 bytes inside every holding, written only by the mint’s hook |
| How it knows who called | It checks that the token accounts are marked as transferring [1] | Account 0 is HELIX's signer PDA ["hook-authority", hook_program] |
| Extra accounts | Listed in the hook's PDA ["extra-account-metas", mint] [1] | Passed after the hook program and its signer, up to 11 |
| Fees on transfers | A separate extension: a fixed rate in tokens, withheld in the recipient's account [2] | The hook decides per call, for example only on trades |
| Wallets and explorers | SPL Token-2022: listed by wallets and explorers | HELIX’s own program: wallets don’t list these tokens yet |
- Solana docs: Transfer Hook extension · read-only accounts, signer privileges, extra-account-metas PDA
- Token-2022 extensions guide · transfer hook (called during transfer, after the transfer logic), transfer fees
- Transfer hook interface · the Execute instruction and its accounts
- HELIX hook interface · programs/helix-hook/src/lib.rs; calls and checks in programs/helix/src/hook.rs