One wallet
Every capsule launches from one operator wallet, and every capsule names it as creator fee recipient. That is the whole design, and it has consequences worth reading twice.
8.1 Why one wallet
pons v2 pays creator fees to whatever creatorFeeRecipient the launcher set. If curators launched from their own wallets, the fees would go to them and there would be no capsule — just another launchpad. By launching every coin from the operator wallet with itself as recipient, every coin's creator fees arrive in one place, one engine can spend them, and the economics are identical for every capsule. Doc's phrasing: "we get all the fees". The fees then go out again, as stocks and memecoins, to holders.
8.2 Where the fees sit
Inside pons first. Fees accrue on the coin's bonding curve, or in the pons fee hook after graduation. Nothing moves until someone sweeps — curve.sweepFees(0) or hook.sweepPoolFees(poolId, minOut, 0), callable by the pons operator or by the creator fee recipient, which is us.
Then in the Fee Escrow. A sweep credits the pons Fee Escrow (0xd3afeb2a57f70ef218aa82451c51b2fb0416ac9e) to the operator's name, in USDG. The engine attributes each sweep to its coin by measuring the escrow delta around it — one coin at a time, never two sweeps in flight.
Then in the operator wallet. claimToken(USDG) pulls the escrow balance out. From here the engine swaps USDG into the capsule's assets and pays holders. The escrow balance and the operator's USDG balance are both on §11.
8.3 Custody, honestly
The coins are non-custodial. Each coin is a normal pons v2 token. Before graduation its unsold supply sits in the bonding curve contract; after graduation its liquidity is a full-range Uniswap v4 position held by the pons Launch Locker (0x267444d099b10fb5ed7c3cc7b7c767adca574952). Nobody, including the operator, can pull either. Your coin balance is in your wallet. Buying and selling happens on pons or Uniswap. The engine cannot touch any of that.
Fees, buys and drops are custodial by design. Claimed USDG lands in the operator wallet. The operator wallet swaps it for the capsule's assets. Those assets sit in the operator wallet for the seconds or minutes between purchase and payout, and tray balances (§5.5) sit there longer. This is a hot wallet running a cron job, not a contract with an audit. Treat it that way.
The operator can only spend what fees bring in. Its balance is claimed creator fees plus launch fees plus whatever assets are in flight. It holds none of your coins, none of the liquidity, and nothing you sent it except the one-time launch fee.
8.4 What the operator can do
- Launch coins on pons v2 with itself as
creatorFeeRecipient, creator tax 0, buyback off, paired with USDG. - Sweep any capsule's fees (
sweepFees/sweepPoolFees) and claim the 70% creator share from the escrow as USDG. - Swap claimed USDG into the capsule's assets on Uniswap.
- Transfer purchased assets to holders and hold tray balances until they clear the threshold.
- Keep 5% of creator fees as gas and ops reserve, and the launch fees.
- Stop. If the key is removed, the engine enters PAPER MODE and nothing moves; fees keep accruing inside pons.
8.5 What the operator cannot do
- Withdraw or unlock any coin's supply on the curve or its liquidity in the v4 pool.
- Mint, freeze, blacklist or otherwise modify any coin. pons tokens have no such functions.
- Take tokens out of your wallet. Drops are transfers to you; there is no approval in the other direction, ever.
- Change a capsule after launch — including switching buyback on, or adding a creator tax. Both are fixed at launch.
- Sell the capsule's assets back to USDG or ETH. There is no code path for it.
- Redirect another coin's fees. The escrow credits by recipient, and the recipient is set at launch.
8.6 What could go wrong
- Key compromise. An attacker with the operator key could drain the operator wallet — claimed USDG, in-flight assets, tray balances, gas reserve — and claim whatever sits in the escrow. They still could not touch the curves, the liquidity or your coins.
- Operator misbehaviour. The operator could stop running drops and keep claimed fees. Every sweep, claim and drop is logged and public, so this would be visible on the capsule page within an hour, and on §11 immediately.
- Engine bugs. Mis-attributed sweeps, mis-snapshot, mis-rounding, failed swaps. Everything is retry-safe and bounded, but software is software.
The operator address is in the footer of every page and on §11. Its balances, every launch, every sweep, every claim, every swap and every payout are on Blockscout; the escrow balance is a public read. If a capsule's fee log shows claims without matching drops for longer than 24h, something is wrong.