Docs
The rulebook
Call Market is a parimutuel market on calls about pump.fun coins. A caller says a coin will reach a multiple inside a window and stakes SOL on it. Everyone else backs or lays the call. The coin's own on-chain median decides.
Overview
No oracle covers memecoins, so the program keeps its own price record for every coin it follows: a ring of the last 16 observations of the pump.fun bonding curve (or the canonical PumpSwap pool after migration). Anyone can add an observation, at most one a minute; our keeper does it every minute. Every stored observation is clamped to 15% of the median of the newest 7, can be corrected by a more honest reading for 30 seconds, and every decision reads the median of final observations, never a single trade.
- Call: coin, target 1.5x to 100x, window 1 hour to 7 days (24 hours by default), a stake of at least 0.05 SOL. The stake rides on YES.
- Bet: YES or NO, one side per wallet, from 0.01 SOL, during the first quarter of the window and while both the median and the live price are less than halfway to the target. Each side may hold at most half of the pot cap.
- Settle: HIT when the median holds at or above the target; MISS when the window ends first. Settlement and payouts are permissionless.
- Record: every settled call moves the caller's on-chain score. The form guide is every caller record, sorted.
Lifecycle
| State | How it gets there | What can happen |
|---|---|---|
| Pending | A dev launched a coin with a call (launch_with_call). The coin has no price history yet. | Anyone opens it (activate_call) once the coin has 15 minutes of history. After 24 hours without history anyone can cancel it; the stake comes back. |
| Open | open_call, or an activated dev call. The start price is fixed: the highest of the history median, the fresh median and (for open_call) the live price. | Bets until the betting window closes. observe or check settles it the moment the rule is met. |
| Hit | The HIT rule held on the median before the end. | YES wins the NO pool, minus the win fee. If NO was empty, everyone gets the stake back. |
| Missed | The end passed without a HIT (the end is a unix timestamp). | NO wins the YES pool, minus the win fee. If NO was empty, everyone gets the stake back. |
| Cancelled | A pending dev call that never got price history. | Every stake comes back through claim. No score change. |
The HIT rule
Only final observations count: the newest one is left out for its first 30 seconds, while a more honest reading can still replace it. Walk back from the newest final observation, skip anything after the end of the window, and take up to 7 observations that lie within 30 minutes of the first one taken. The call is a HIT when:
- all 7 were taken, and at least 4 of them (the median) are at or above the target;
- those above-target observations were all taken after the call opened;
- they span 4 minutes or more (
hit_hold_secs, 240 s by default).
A MISS is the same rule failing on the observations up to the end, 30 seconds after the end (so every observation up to the end is final). Observations after the end never count, even if the coin keeps running.
Manipulation defenses
- Clamped observations. A stored observation is at most 15% above or below the median of the newest 7. A one-block pump moves one sample by at most 15%.
- The revise window. For 30 seconds after an observation, a reading that is closer to the median it was clamped to replaces it, and until then it counts nowhere. A bundle that buys, observes and sells in one go wins nothing: the keeper's next honest reading takes the sample back, so a fake move has to be really held, with sellers on the other side.
- The median, not a wick. The rule needs 4 of 7 samples above the target, held for 4 minutes. To fake a 1.5x HIT an attacker has to win about 16 consecutive observation slots against the keeper and hold the price there the whole time.
- Alone in its transaction.
observerefuses to share a transaction with anything but other observes, checks, compute budget and transfers, so no trade can sit next to the reading. - End of window is a timestamp. A pump in the last minutes can at most add a few clamped samples; it cannot move the median of 7 to a large target in time (see the delay below).
- Betting closes early. At a quarter of the window, and as soon as the median or the live price is halfway to the target: nobody bets on a race that is already decided.
- Pot cap. A call's total pot is capped at 5% of the coin's liquidity (the SOL side of its reserves at the median price), the smaller of the value at the open and now, and each side holds at most half of it, so the other side always has room. Winning must cost more than pumping.
- The caller and the coin's dev never bet NO on their own call or coin.
- An honest start. A call opens only on 15 minutes of history (at least 7 observations) that spread less than 1.5x. The start is the highest of the history median, the fresh median and the live price, so a call never opens part of the way to its target.
The delay the clamp adds
The median moves once 4 of 7 samples moved, so a real move reaches it at about x1.15 per 4 observations (4 minutes at one observation a minute), plus the 4-minute hold:
| Real move | The median shows it after | Earliest HIT on that target |
|---|---|---|
| 1.5x | ~12 min | ~16 min |
| 2x | ~20 min | ~24 min |
| 3x | ~32 min | ~36 min |
| 10x | ~66 min | ~70 min |
| 100x | ~132 min | ~136 min |
Add 30 seconds until the last of them is final. So a real 100x inside the last hour of a window is not a HIT. The call slip shows this delay next to every target.
Worked example
Start (the highest of the history median, the fresh median and the live price): mcap 30 SOL. Target: mcap 60 SOL. Halfway: mcap 45 SOL.
Liquidity at the start 30 SOL, pot cap 5% = 1.50 SOL, at most 0.75 SOL a side.
Bets: another wallet YES 0.40, two wallets NO 0.45 + 0.30. Pools: YES 0.60, NO 0.75 (the NO side is full).
Betting closes 6 h after the open, or earlier once the median or the live price reaches mcap 45 SOL.
HIT: fee = 3% of 0.75 = 0.0225. The caller gets 0.20 + (0.75 - 0.0225) x 0.20 / 0.60 = 0.4425 SOL; the other YES wallet 0.40 + 0.7275 x 0.40 / 0.60 = 0.8850 SOL. NO gets nothing. Caller score +14 x 10 = +140.
MISS: fee = 3% of 0.60 = 0.018. NO 0.45 gets 0.45 + 0.582 x 0.45 / 0.75 = 0.7992 SOL, NO 0.30 gets 0.5328 SOL. Caller score -140.
Payouts and fees
Winners always get their own stake back in full; the fee comes from the losing pool only. Payouts are pushed to each ticket's wallet by anyone (the keeper does it every few seconds), or claimed by the wallet itself from Mine. Rounding dust below one lamport per winning ticket stays in the call account. Launches pay 2.5% of the dev buy to the treasury; creator fees of coins launched here are split 20% treasury, 80% dev.
Caller score
Under a random-walk price a target of x is reached with probability about 1/x, so a random caller scores zero on average. A positive score is skill, not volume, and the square root keeps whales from buying the board. The weight is the stake fixed at the open: a caller cannot add weight later to calls that are already going his way. Refunded calls still count (the call was right or wrong); cancelled dev calls do not.
Launch with a call
A dev can launch a pump.fun coin through Call Market and open their own call on it in the same transaction. The coin is created with the pad's fee account as its pump creator (mayhem, cashback, holder rewards and fee sharing off), the dev buy goes through, and the first observation is taken from the new curve. The dev's call is parked as Pending until the coin has 15 minutes of price history; then anyone (the keeper first) opens it at the history median. The part of the stake above half the coin's pot cap goes back to the dev at that moment. The dev can never bet NO on any call about their coin.
Parameters
Read from the live config.
| Parameter | Value | What it does |
|---|
Program reference
Program id (explorer). Anchor 0.31. Every account below can be read by anyone.
| Account | Seeds | Holds |
|---|---|---|
| Config | ["config"] | admin, treasury, pause flag, parameters, counters of calls and coins |
| PriceObs | ["obs", mint] | the coin's ring of 16 clamped observations |
| Call | ["call", id u64 le] | one call: caller, coin, target, window, start / target / halfway prices, pot cap, pools, state, settlement. Stakes and bets ride in its lamports. Never closed. |
| Position | ["pos", call, wallet] | one wallet's side and amount on one call (closed by claim, rent back) |
| Caller | ["caller", wallet] | the on-chain record: calls, hits, misses, staked, won, lost, score, best hit |
| Coin | ["coin", mint] | coins launched here: dev, name, ticker, dev call, creator fee ledger |
| Fees | ["fees", mint] | system account, the pump creator of coins launched here |
| Instruction | Who | What |
|---|---|---|
| open_call | anyone (caller signs) | opens a call at the start price; refuses without 15 minutes of history, above halfway, or a stake above half the pot cap |
| bet | anyone | YES or NO before the betting window closes; one side per wallet |
| observe | anyone | adds a clamped observation (at most one a minute), or revises the newest one inside 30 s with a closer reading, and settles the passed calls of that coin that met the rule |
| check | anyone | settles one open call now (HIT or MISS) or refuses with NotSettleable |
| claim | anyone | pays one ticket to its wallet and closes it |
| launch / launch_with_call | anyone (dev signs) | creates the pump coin with the dev buy; the second parks the dev's call |
| activate_call / cancel_pending | anyone | opens a parked dev call once history exists / cancels it after its timeout |
| collect_win_fee, collect_fees, claim_dev, collect_treasury, unwrap_fees | anyone | move booked fees to the treasury and devs (only there) |
| init_config, update_config, set_treasury, set_paused, propose_admin / accept_admin | admin | settings for calls created afterwards; two-step admin handover |
Errors
What the program answers when it refuses a transaction. The site shows these messages as they are.
| Code | Name | Message |
|---|
Verify on chain
- Every call is an account at
["call", id]: its state, pools, start / target / halfway prices, settlement median and hit time are public. - Every observation emits an
Observedevent with the stored (clamped) price, the raw venue price and the median. The traces on the site are drawn from those events. - Every settlement emits
CallSettledwith the median, how many of 7 were above the target, the pools and the score change. - The IDL is served at /idl/calledit.json.
Admin powers
The admin can
- change parameters within fixed bounds, for calls created afterwards only
- set the treasury
- pause new coins, new calls and new bets
- hand over the admin key in two steps
The admin cannot
- move a stake, a bet or a payout
- settle a call, change its prices or its result
- stop settlement or claims (they work while paused)
- touch a dev's creator fees
Risks
- Median, not truth. The result is what the recorded observations say. If nobody observes, a real hit can be missed; anyone can observe from the race card.
- Sustained manipulation. A pump actually held for the whole catch-up time and the hold is a real market move and counts. On a thin coin nobody may sell into it, so a held pump can cost only its round-trip fees; the pot cap bounds what it can win. Check a coin's volume before you lay a call on it.
- A censored keeper. The revise window needs an honest reading within 30 s of each observation. Someone who can keep every honest reading out for 30 s at a time, on every observation, can still steer the series.
- Self-dealing. A caller can bet NO on their own call from a second wallet. It only moves their own money between wallets minus the win fee, and the pot cap bounds it.
- Start-price bias. A dump held for many minutes lowers the start; the site shows start against the current median.
- Migration gap. Between curve completion and the PumpSwap pool there is nothing to read, so no observation and no HIT in that gap.
- Rent. The caller pays the call account rent (~0.0034 SOL, kept as history). Each ticket's rent comes back with its payout.
FAQ
Why can't I bet anymore?
The betting window closed: a quarter of the window passed, or the median is already halfway to the target, or the pot reached its cap.
The coin pumped past my target. Why no HIT?
The median needs 4 of the newest 7 observations above the target for 4 minutes. A spike that fades inside a few observations is a wick; the clamp and the median ignore it by design.
Who pays me?
The keeper pushes every payout to the ticket's wallet within seconds of settlement. If it is late, Mine has one button to claim everything.
What if nobody bets NO?
Then there is nothing to win: at settlement everyone gets the stake back, and the call still counts on the caller's record.