THE KEY THAT SIGNS
NEVER HOLDS IT▌
On Pump.fun the coin's creator receives its whole fee stream — and almost every launch points that at the hot wallet doing the launching. Here it points at a cold wallet or a multisig instead, proved before the coin exists.
> HOW IT WORKS
A cold wallet or a Squads vault. Anything except the wallet you are launching with — that one is refused outright.
Sign a message with the destination key, or use a Squads vault and we verify the multisig on chain. A typo here would send the fee stream somewhere nobody can reach, forever.
It signs, pays and can take a dev buy like anyone. What it cannot do — ever — is claim a lamport of this coin's creator fees.
> LAUNCHED WITH THE KEYS SPLIT
view all →> UNDER THE HOOD
create_v2's `creator` is a plain pubkey, not a signer. Every interface defaults it to the launching wallet; nothing requires that. We just let you point it somewhere safe and make you prove the somewhere is real.
A signature proves somebody holds the key right now — that is what a cold wallet does. A Squads vault cannot sign, because it has no key; there the proof is that the account exists and the multisig program owns it. The certificate records which one was used.
It still signs the launch, pays the fees and can buy the coin. Separating the keys does not make the launch harder — it makes one specific catastrophe impossible.
The verifier reads the bonding curve and compares its creator against both the certificate and the launching wallet. If they turn out to be the same account, the coin's page says so in red.
READ THIS BEFORE YOU LAUNCH: this protects the fee stream and nothing else. Your dev buy still sits in the hot wallet, and so does everything else in it. A signature proves somebody held the key at that moment, not that they still do or that they are you — and a Squads vault proof is weaker still, since it only shows the account is a multisig, not who is on it. One destination, not a team split: configuring Pump.fun's fee sharing needs the creator to sign, which would mean reaching for the cold key during a launch. Let the multisig do the splitting instead. And a community takeover (admin_cto) can still reassign a coin's creator afterwards — the coin's page compares the live creator against the certified one on every load.
STOP POINTING IT AT A HOT WALLET
It takes one extra field at launch, and it is the difference between a drained extension costing you a session and costing you the coin's entire revenue.
Launch with split keys →