Skip to content
helixLaunch

Docs

Security

Security and trust

What the code guarantees, what still depends on people, and the plan to remove the people. The short version: the admin's powers are narrow and capped in the program, but while the program has an upgrade authority, its code can change, and that overrides every other guarantee on this page.

ProgramHLX49qz3CSKQrHrdzrrWygZBaKHWWSG8JwUMFHcZ47Fr
Who can upgrade it (read live)b2mD6XSraztwSuCckBohQETGmHWE1PsU198AT8ADRX9
Admin of the configb2mD6XSraztwSuCckBohQETGmHWE1PsU198AT8ADRX9
Pause flagsNothing paused

The admin is the address named in the config account. It has one instruction, update_config (tag 1), which can:

  • Set the protocol fees, the LP fee, the sniper fee and the launch fee, each up to a ceiling in the program: protocol fee 1.5% on the curve and 0.5% on the AMM, LP fee 1%, sniper fee 50% over at most 60 s, launch fee 0.1 SOL. These apply to pools and launches created afterwards.
  • Set the curve for future launches: virtual SOL, virtual tokens, tokens on the curve and total supply, within sanity checks (virtual SOL above zero, the curve's share above zero and below the supply, virtual tokens above the curve's share).
  • Change the fee collector. Protocol fees still waiting in pools go to whichever collector is set when someone collects them; this concerns HELIX's own fee only.
  • Pause new launches, buys, or new pools and added liquidity (below).
  • Propose a new admin, who must accept (below).
  • Raise any fee past its ceiling.
  • Change the fees, the curve or the rules of an existing pool or launch: each copies them when it is created and keeps them.
  • Pause sells, transfers, liquidity withdrawals or claims.
  • Move anyone's tokens or SOL, mint a launched token, or freeze a holding of one.
  • Touch creator fees or holder rewards, which only the creator and the holders can claim.
  • Withdraw locked liquidity: graduation LP and the minimum liquidity belong to no one.
FlagBitBlocks
Launches1create_launch
Buys2the buy side of swap
Pools4create_pool and add_liquidity
  • init_config (tag 0) creates the config at ["config"] and can only be called by the program's upgrade authority: HELIX reads it from the program's ProgramData account and refuses anyone else. The config can only be created once; its creator becomes the first admin.
  • The admin role moves in two steps: the admin names a pending_admin with update_config, and the role moves only when that address signs accept_admin (tag 2). Until then the old admin stays, so a mistyped address can't lose the config. Setting the pending admin to zero cancels.

HELIX is deployed with Solana's upgradeable loader. The deployed program is about 168 KB (about 0.86 SOL of rent to deploy). Whoever holds its upgrade authority can replace the code, and new code could do anything the current code refuses. Today that authority exists; its holder is shown above, read live.

The plan (not done yet)

  1. Next: move the upgrade authority to a Squads multisig behind a public timelock, so any upgrade is visible in advance and holders have time to leave. HELIX is live on mainnet; until this is done, one key held by the team can upgrade it.
  2. An independent audit of the program.
  3. Then consider revoking the upgrade authority, which makes the program immutable for good.

None of these steps has happened yet. Each token page shows who can upgrade the program at the moment, so you don't have to take this page's word for it.

  • No mint, freeze, hook or metadata authority, from the first instruction: nobody can mint more, freeze a holder, swap the hook or edit the name.
  • The whole supply is minted once, into the pool. The creator gets tokens only by buying them, like everyone else.
  • The rules and fees are fixed at creation, in the launch account.
  • At graduation the liquidity is locked for ever, and unused tokens are burned.

These hold for the current code. Tokens made directly with create_mint keep whatever authorities their creator gave them; read the mint.

  • Checked arithmetic throughout, and overflow checks on in the release build.
  • Every account is checked for its owner and its kind; PDAs are created only at their canonical address; where two accounts must differ, the same one twice is refused.
  • Pools and launch accounts are checked for solvency at the end of every instruction that pays out of them.
  • Account creation works even if someone sent lamports to the address first, so a launch, a pool or a holding can't be blocked in advance.
  • A trader's holding must be the trader's own; a hook's answer is checked before it is applied (see Hooks).
  • The SDK reads events only from log lines HELIX itself wrote, so a hook can't forge one.
  • HELIX tokens are not SPL tokens. Wallets and most explorers don't list them. This site's portfolio page does, and they trade on the HELIX DEX. A token can be bridged out to an SPL mirror that wallets do list (a launch once it graduated); see Bridge.
  • Custom hooks are unverified. HELIX checks the shape of a hook's answer, not its intent. A custom hook can refuse any transfer, sells included, or take up to the whole amount of a trade as cuts, and its own program may be upgradeable. The site marks such tokens; read the hook before you buy.
  • No audit yet. The program is covered by 42 tests on LiteSVM in packages/sdk/test (token standard, hooks, kit rules, launches, the bridge, admin and safety, config). Tests are not an audit.
  • Time-based rules (sniper fee, locks, streams) use the cluster's clock, which can differ from wall-clock time by a few seconds.
  • An external hook adds its compute cost to every trade of its token, and gets at most 11 extra accounts.
  • Integer rounding leaves dust: fees round down, curve prices round in the pool's favour, rewards leave a remainder.

Please report security issues privately, by email to the address in the repository's SECURITY.md. Include the steps to reproduce, the accounts or transactions involved, and the impact you expect. Don't disclose it publicly, and don't test against other people's funds, until it is fixed.

The program id is HLX49qz3CSKQrHrdzrrWygZBaKHWWSG8JwUMFHcZ47Fr. See also Terms.