LootLoop

Nothing live yet.

↑↓ move↵ open⌘K from anywhere
Whitepaper · v0.3 · devnet

The LootLoop whitepaper

Provably fair NFT loot drops on any Solana coin, and a marketplace that settles in SOL and pays creators on every resale. Every number on this page is read from the live settings.

Odds per buy
1%
up to 15%, by default
Minting a prize
0.1 SOL
claim-to-mint is on
Creator's share
50%
of every mint fee
Platform cut
0%
of each resale
Contents
Part I The idea

01Abstract

Memecoins live or die on attention. Most launches have exactly one mechanic, price, and once the first wave of buyers has rotated out there is nothing left to do but watch a chart. LootLoop adds a second mechanic that rewards the behaviour a coin actually needs: real trading by real wallets.

Every eligible trade of a LootLoop coin is a ticket in a provably fair draw. Winners receive an NFT minted to their wallet within seconds or, when the operator prefers, a sealed prize they mint themselves for a small fee. Either way it comes from a loot table the coin’s creator designed: supplied artwork, pre-minted NFTs, or AI-generated pieces painted at the moment of the win. Winners can sell their prizes on LootLoop’s marketplace at a fixed price or by auction, always priced in SOL, and every resale pays the coin’s creator a fee.

A configurable anti-bot layer keeps the loop honest: cooldowns, wash-trade detection, hold requirements, wallet-age checks, same-slot bundle rejection and an accumulating bot score decide who is eligible, while loyalty and pity multipliers tilt the odds toward patient traders. Randomness uses a commit-and-reveal scheme, so anyone can audit every roll after the fact.

02The problem

Three failure modes show up in nearly every pump.fun launch:

  • No retention. There is nothing to do with the coin except sell it. Volume decays as soon as the narrative does.
  • Bots capture the upside. Snipers, bundlers and wash traders farm every incentive faster than people can react. Any naive “reward for trading” scheme becomes a bot subsidy.
  • Creators cannot fund a community. Creator fees are the only revenue, and the only lever a creator has is spending them on marketing.

NFT projects have the inverse problem: strong culture and collectibles, but liquidity that dies the day the mint closes. LootLoop bolts the two together. The coin gets a reason to be traded; the NFTs get a permanent source of demand.

03How LootLoop works

Tradea buy, on any venueRecordHelius webhook · pollerScoreanti-bot rules → oddsRollHMAC(seed, signature)Fulfilmint, or bank to claimIneligiblerecorded, no rollflagsMissloyalty & pity accrueMarketplacepriced in SOLlist / sell
Figure 1. From a trade to an NFT in the trader's wallet. A trade that fails a rule is still recorded, and a miss still counts toward loyalty and pity. Swipe sideways to see all of it.
  1. Trade. A wallet buys the coin anywhere: on pump.fun, through an aggregator, on a DEX, or with LootLoop’s own trade widget. A campaign can count sells too.
  2. Record. Helius pushes every transaction touching the coin’s watched accounts (its bonding curve or pools) to LootLoop, which decodes pump.fun’s TradeEvent when present and otherwise derives the swap from the signer’s token and SOL balance changes. Each trade is written down before anything is judged, so no buy can be lost to a downstream error. An RPC poller covers webhook gaps and only advances its cursor over trades it actually stored.
  3. Score. A worker claims recorded trades oldest first and checks them against the campaign’s rules. Ineligible trades keep their reasons but never roll. Every window is measured from the trade’s own block time, so a trade scored a week late gets the verdict it would have had live. Failures keep an attempt count and are retried.
  4. Roll. A deterministic roll is derived from the epoch seed and the trade’s own signature. If it lands under the trade’s chance, the trader wins.
  5. Fulfil. A prize is selected (collection, tier, item) and its supply reserved atomically. With instant minting a separate, secured invocation generates and mints the NFT to the winner straight away. With claim-to-mint the win is banked instead: the trader sees the rarity they hit and pays a small fee when they want the art. Failures retry automatically in both modes.
  6. Move it on. Winners can list the NFT for SOL at a fixed price or as an auction, accept an escrowed offer from somebody who wants it whether or not it is for sale, or negotiate a trade of several prizes at once with another wallet. A sealed prize can be sold before it is even minted. It can also simply be sent, or burned. The creator earns a fee on every sale.
Part II Making a collection

04Launching & attaching

Creators can launch a brand-new pump.fun coin from LootLoop or attach LootLoop to a coin that already exists. Both paths produce a campaign: the coin, its rules, its loot table and its marketplace. A coin carries one campaign.

Launching from LootLoop

Coin metadata is hosted on Vercel Blob, the create_v2 instruction (optionally bundled with a first buy) is built server-side and partially signed by a fresh mint keypair, and the creator signs and pays in their own wallet. The creator remains the on-chain creator of the coin and keeps its creator fees. LootLoop never holds the creator’s keys.

Attaching an existing coin

Any Solana token can be attached, not only pump.fun coins: search by name, ticker or mint address, or pick from the trending list (market data via Jupiter). LootLoop checks the mint exists on the current cluster, classifies it as a pump.fun bonding curve, a graduated PumpSwap pool or a DEX-listed token, and subscribes to the accounts that carry its trades: the bonding curve, or the most liquid pools reported by DexScreener. Trades on any venue (Raydium, Orca, Meteora, PumpSwap, Jupiter routes) are detected from token and SOL balance changes when no pump.fun TradeEvent is present.

Attaching does not start from zero. LootLoop walks the coin’s history backwards in resumable batches and records the trades that happened before it was watching, so a campaign attached late has a real picture of its wallets from the first minute. Both SPL Token and Token-2022 mints are supported; the program is read from the mint account rather than assumed, because pump.fun’s current launch instruction issues Token-2022 mints.

Official and community campaigns

Anyone can attach a campaign to a coin they did not create. That lets a community build around a coin, and it is also a way to impersonate a project, so every campaign and every collection is marked Official when the wallet behind it is the wallet that created the coin on chain, and Community otherwise. The marker is computed from chain data, not claimed in a form, and it is shown wherever the campaign is listed. Every on-chain address in the interface is one click to copy, so a trader can check for themselves.

Who can manage a campaign

A campaign’s creator can hand access to other wallets, either to the whole campaign or to a single collection inside it. The scope is the whole permission: a collection-scoped member never sees the campaign’s rules, its other collections or their generation prompts, because the view itself is filtered to what they were granted rather than merely hiding the links.

One power stays with the creator alone: deciding who else gets in. A member who could add members could promote themselves, which would make the distinction meaningless. The only change a member may make to the list is removing themselves. Every route enforces this server-side; nothing relies on the interface not offering a button.

05Loot tables

A campaign holds one or more collections, each a real Metaplex Core collection. A collection carries a weight (its share of drops), a set of rarity tiers with weights of their own, and the prizes themselves.

Winone roll succeededCollection Aweight 70 · imagesCollection Bweight 20 · AI generatedCollection Cweight 10 · depositedCommon60%Uncommon25%Rare10%Epic4%Legendary1%item 13 leftitem 212 leftitem 31 leftitem 40 left← weighted by remaining supplyAI collections skip the item step:tier → entity → traits → prompt → image.Deposited collections hand over pre-mintedCore NFTs from the vault, one of one each.
Figure 2. A win resolves collection, then rarity tier, then item, each step weighted by the creator. The tiers shown are the defaults a new collection starts with. Swipe sideways to see all of it.
SourceHow prizes existBest for
Images suppliedThe creator drags in artwork; each file becomes an item with a name, tier and supply (editions). Minted when won.Existing art, PFP sets, edition runs.
AI generatedThe creator defines the entities, style, references, traits and templates. Nothing is pre-made; each win is painted and minted live.Very large or open-ended sets, unique 1/1s, themed drops.
Existing NFTsThe creator deposits pre-minted Core NFTs into the platform vault; each is handed to a winner.Established collections, blue-chip giveaways.

Visibility

Each collection is either fully visible or revealed on win. In reveal mode the public loot table shows only silhouettes and tiers; art and names appear the first time an item drops. AI prompts and reference images are never public in either mode.

Pacing a loot table

Odds decide how often somebody wins. These controls decide how often a particular prize can be won, which is what stops a small table emptying in an afternoon and what makes a legendary feel scarce. Each accepts plain language such as “3 days” or “90m”.

ControlScopeEffect
Collection cooldownOne collectionAfter any drop from it, the whole collection is skipped for this long. Other collections still draw.
Wallet cooldownOne collection, one walletA wallet that just won from this collection cannot win from it again until the timer runs out.
Tier lockoutOne rarity tierAfter a Legendary drops, Legendary is locked for the chosen period while the other tiers keep drawing.

A campaign-wide ceiling on wins per hour sits alongside these, listed with the anti-bot rules because it doubles as a defence against a table being drained during a burst.

06AI-generated collections

Configstyle · refsEntityweighted pickRolltraits + variationPrompttier skin appliedImageOpenAI gpt-imageBlobPNG + metadataMintCore → winnerPOST /api/internal/fulfill/[reward] · bearer secret · retried by cron until mintedWith reference images → edit endpoint (consistent characters) · without → generate endpoint · square, portrait or landscape
Figure 3. An AI collection paints each NFT at the moment it is won, in its own serverless invocation, and retries until it is minted. Swipe sideways to see all of it.

Instead of uploading a finished set, a creator describes one: an art style, things to avoid, an aspect ratio shared by the whole collection (square, portrait or landscape), quality, and up to six reference images that keep designs consistent. Optional traits are weighted option lists; each mint samples one value per trait from the epoch seed, so the rarity of a “Golden Sword” is exactly the weight the creator set and is auditable like any roll. Name and description templates, plus optional generated lore, finish the piece.

A trait option carries two things, because a good attribute and a good instruction are rarely the same sentence: the value the NFT records and, optionally, the words the image model is given instead. “Crimson Cloak” is the first; “a tattered crimson cloak shot through with gold filigree” is the second.

Entities

1 · Raritytier weights2 · Entityweighted, tier-gated3 · Contextentity over collection4 · Prompt+ variation axesEmberwing60%Mirefang25%Thornback15%relative weights, set per entityEach field falls back on its own:descriptionentity ▸ collectionreference artentity ▸ collectionart styleentity ▸ collectionthis tier's skinentity ▸ collectionextra traitsentity ▸ collectionA collection with no entities uses one shared description for everything.
Figure 4. A mint rolls a rarity, then an entity, then builds the prompt from that entity's own context. Swipe sideways to see all of it.

A collection is rarely one thing. It is usually a bestiary, an armoury or a cast, and each member needs its own art direction. So a collection can hold a list of entities: characters, creatures, items and places, each with its own description, reference art, weight, and its own version of what each rarity looks like. A mint rolls a rarity first, then an entity, then generates from that entity’s context.

Every field falls back on its own. An entity with no art style of its own uses the collection’s; one with no reference images uses the collection’s; one that says nothing about Legendary uses the collection’s legendary flavour. Entities can be restricted to certain rarities, so a boss appears only at the top of the table, and each carries its own traits alongside the shared ones. The chosen entity is written to the asset as an attribute by default, which makes a drop filterable by entity. A collection with no entities generates everything from one shared description.

Bringing entity data in from elsewhere

Thirty entities is a lot of typing, and that data usually exists somewhere already: another model, another project, a spreadsheet. LootLoop therefore publishes a documented interchange format and, with it, a brief written for an AI rather than a person. The brief explains every field and the rules that matter (stable identifiers, relative rather than percentage weights, tier names that must match exactly) and includes a complete worked example. Hand it to whatever holds the entity data, get one file back, drop the file on the collection.

Import is all-or-nothing and strictly validated: a file that names a rarity the collection does not have is rejected with that name and the list of known ones, and nothing is written. Export produces the same format from a live collection, so a configuration can be copied between collections, reviewed, or kept in version control. The brief itself is public at /api/ai/spec.

Why every piece looks different

An image model returns near-identical pictures for a fixed prompt, which is the single biggest failure of generated collections. Each mint therefore also rolls a seeded set of variation directives from the same committed seed, across nine axes: pose and action, camera and composition, expression and mood, setting, lighting, colour palette, accessory, time and weather, and rendering finish. The creator chooses which axes may move and how strongly, so a collection keeps one identity while every piece differs. Conflicting combinations are dropped rather than sent, so nothing asks for weather in an indoor scene.

Every axis ships with a list of phrases, and every list is editable. A creator can rewrite an axis to match their world, add phrases, delete the ones that do not fit, or empty it to skip that axis, without touching the others. Lists they have not edited keep the shipped defaults.

What ends up on the NFT

Everything a mint rolls steers the art. What a holder and a marketplace get to see is a separate decision, made per source: the entity that was drawn, the rarity, the campaign’s ticker, each of the creator’s own traits, and each variation axis individually. A trait switched off still rolls and still shapes the picture; it simply is not something anybody can read off the token.

Generation happens at win time inside a dedicated, bearer-secured fulfilment endpoint, so several drops can be painted in parallel without slowing trade ingestion. A creator can render samples for any rarity, and for any specific entity, before a single NFT is minted, at 0.01 SOL an image. Supply can be capped or left open.

Part III Winning

07The odds engine

Every eligible trade receives a chance expressed in basis points (100 bps = 1%). The chance is a product of a size term and several multipliers:

chance = min(maxChance, base × size(credited) × decayentries × loyalty × pity)
TermDefinitionDefault
baseThe chance for a trade exactly at the minimum size.100 bps (1%)
creditedTrade size clamped between the minimum and the whale cap. SOL above the cap buys no extra odds.0.05–2 SOL
size()flat → 1 · sqrt → √(credited ÷ min) · linear → credited ÷ minsqrt
decayApplied once for each earlier entry by the wallet in the past hour.×0.75
loyalty1 + the daily bonus × days since the wallet's first buy, capped.×1.005 a day, up to ×1.2
pityRamps from 1× to the maximum as eligible volume since the wallet's last win approaches the pity threshold.off
maxChanceThe hard ceiling after every multiplier.1500 bps (15%)
0.0%3.8%7.5%11.3%15.0%0 SOL0.5 SOL1 SOL1.5 SOL2 SOL2.5 SOL3 SOLmin tradewhale caplinearsquare root (the default)flattrade size →
Figure 5. Chance per trade against trade size, from the engine's own formula: 1% at 0.05 SOL, no extra odds past the 2 SOL whale cap, and never above 15%. Swipe sideways to see all of it.

The square-root default is deliberate: a trade forty times the minimum earns about six times the odds, not forty. Whales still matter, but a hundred small traders collectively out-roll one large one, which is exactly the volume profile a coin wants. Creators who prefer a different shape can pick flat or linear, and every parameter is a slider with a plain-English summary.

The chance a trader is shown before buying comes from the same formula that scores the trade afterwards, so the quote and the roll cannot drift apart.

08Anti-bot & fairness

Scoring is a pure function of the trade and the wallet’s observed history, so it is testable, explainable and shown to traders. A trade is eligible only when every hard rule passes; unknowns (a wallet whose age could not be checked yet, for example) are soft and do not disqualify.

RuleWhat it stopsDefault
Buys onlySell-side farming and round-trip volume.on
Minimum tradeDust spam.0.05 SOL
CooldownRapid-fire entries from one wallet.60s
Hourly entry capEntry flooding.10 an hour
Daily win capOne wallet draining the table.2 a day
Wash-trade windowA buy then sell, or sell then buy, inside the window is flagged and penalised.300s
Must still holdBuy-and-dump bundles: the wallet must hold the coin after the transaction.on
Net buyerWallets that have sold more than they bought cannot win.on
Same-slot bundlesSeveral trades from one wallet in one slot (Jito bundles, sandwich bots).on
Wallet ageFreshly made wallets, measured from the wallet's first on-chain activity.24h
Bot scoreWallets gain penalty points for each flagged trade and lose them for each clean one; above the threshold they are excluded.70 of 100
Deny listManual moderation by the creator from the dashboard.—
Global throttleCaps wins per hour across the campaign, to stretch a small prize pool.off

On the positive side, loyalty rewards wallets that keep holding and pity gives a trader who keeps losing rising odds. Together they shift expected value from “whoever trades fastest” to “whoever trades genuinely and sticks around”.

09Verifiable randomness

Server secretnever publishedseed = HMAC(secret, campaign:epoch)one per epochPublish sha256(seed)the commitment, public from day oneTrade signaturefrom the trader's wallet and the networkroll = HMAC(seed, campaign:sig:ix:win)a win when roll × 10 000 < chance in bpsRotate the epochthe creator's actionReveal the seed: anyone recomputes every roll
Figure 6. The seed is committed before any trade and revealed when the epoch rotates, so every roll can be recomputed by anyone. Swipe sideways to see all of it.

Each campaign runs in epochs. For epoch e the server derives seed = HMAC(secret, campaignId:e) and publishes sha256(seed) straight away. Every roll is HMAC(seed, campaignId:signature:index:win), mapped to a uniform number in [0, 1); the trade wins when that number times 10 000 is below its chance in bps. Prize selection (collection, tier, item, and AI traits) uses the same seed with different labels.

Because the transaction signature is produced by the trader’s wallet and the network, the operator cannot steer outcomes without changing the seed, and the seed is bound by its published hash. When the creator rotates the epoch the old seed is revealed, and anyone can recompute every roll of that epoch from public data via /api/campaigns/[slug]/seed.

10How a prize is delivered

LootLoop NFTs are Metaplex Core assets: single-account NFTs with a plugin system, roughly an order of magnitude cheaper to mint than legacy Token Metadata NFTs, with the royalty recorded on the collection itself (5% unless the creator sets another). The platform authority is each collection’s update authority so it can mint on demand; creators receive royalties on secondary sales wherever Core royalties are honoured. Declared traits are written to the asset itself through the Attributes plugin, so a trait is on-chain data rather than a line in a JSON file somewhere.

Instant mint, or claim to mint

Winroll succeededMint nowthe platform pays rentNFT in walletwithin secondsclaim-to-mint offSell it sealedthe buyer claims it insteadSealed prizerarity shown, art hiddenTrader pays0.1 SOL base priceNFT in walletthe same mint pathclaim-to-mint on · in forceor list it sealedNothing is lost either way: the win is recorded before any payment, and an unpaid prize stays claimable for good.
Figure 7. Two ways a win is delivered. The highlighted path is the one in force here: claim-to-mint is on, so the win is real at once and the art stays sealed until the trader pays. Swipe sideways to see all of it.

The operator chooses one of two ways to deliver a win, for the whole platform. Instant mint mints every win straight away and the platform pays the rent. It is the smoothest experience, and it means the platform carries the cost of every drop, including the ones nobody cares about.

Claim-to-mint records the win exactly the same way and the trader sees it at once, but only its rarity: a sealed card that says they hit a Legendary without showing what it is. The art is minted when they choose to pay the claim fee, 0.1 SOL before any tier pricing. Nothing expires: an unclaimed prize stays claimable indefinitely, and it can be sold sealed instead. Several sealed prizes can be minted together; each is still its own payment, verified and recorded on its own, and one wallet prompt approves them all. Claim-to-mint is on here.

The fee does not have to be the same for every tier. A collection can price each rarity either as a multiple of the base claim price (Legendary at 3×, say, so the base stays the one lever that moves everything) or as a flat amount in SOL, for a creator who wants a number they can advertise. Tiers left alone charge the base. Because the fee is split with the treasury and the burn pot, every tier price is held between 0.01 SOL and 10 SOL: a tier cannot be made free at the treasury’s expense, nor priced as a trap. The winner is quoted their own tier’s price on the sealed card before they pay.

Where the mint fee goes

What a trader pays to mint a sealed prizeverified from the transaction's own balance change, then split50%Campaign creatorthe coin's own creator25%Treasuryruns the platform25%Buy & burna token the operator choosesBatched until a recipient is owed 0.5 SOL, so the network fee stays worth paying.
Figure 8. Every mint fee is divided the moment it lands. The shares shown are the live settings, not constants. Swipe sideways to see all of it.

Every claim payment is verified from the transaction’s own balance change rather than trusted from the client, recorded against its signature so one payment cannot claim two prizes, and then divided: 50% to the campaign’s creator, 25% to the treasury and 25% to a pot earmarked for buying and burning a token the operator chooses. All three shares, the destination wallets and the burn token are settings, not constants.

Payouts run in one of two modes. Instant pays each share as it is earned. Threshold accrues shares and pays a recipient once they are owed at least 0.5 SOL, so a stream of small drops does not spend more on network fees than it moves. Threshold is in force here. A cron settles what is due either way, and only the network fee of the payout transaction is recorded as a running cost; the payout itself is a transfer, not an expense.

Part IV Trading & money

11The marketplace

Everything won on LootLoop can be sold here, and so can any Metaplex Core NFT its owner brings in. Every sale of a prize pays the creator of the campaign it came from.

Everything on the marketplace is priced in SOL. Pricing each campaign’s NFTs in its own coin would make every listing two bets at once, on the art and on the coin, and a buyer would have to acquire the right coin before they could buy anything at all. Floors would not compare either: “12,000” means nothing across two campaigns whose coins are worth different amounts. SOL is the one currency every Solana wallet already holds, so a floor, a bid and a sale mean the same thing everywhere. The campaign’s coin is what you trade to win a prize; SOL is what you use to buy one.

The creator’s fee on a sale is theirs to set per campaign: 2.5% unless they choose otherwise, up to 20%. The platform’s own cut sits beside it rather than inside it, and is zero today.

Bringing an NFT in signs nothing and moves nothing: LootLoop reads the chain to confirm who holds it, records it, and from then on it can be listed, offered on and traded like anything won here.

Escrow by delegate

SellerNFT (Core)PlatformBuyeradd FreezeDelegate (frozen) + TransferDelegate → platformbuy: ask for the settlement transactionre-check the escrow on chain, partial-sign thaw + transferprice less fees, in SOLcreator fee · platform cutNFT transferred, all in one transaction
Figure 9. Listing never moves the NFT out of the seller's wallet. A sale pays everyone and moves the NFT in a single transaction. Swipe sideways to see all of it.

Listing does not move the NFT. The seller adds two owner-managed plugins pointed at the platform: FreezeDelegate (frozen) and TransferDelegate. The asset stays in the seller’s wallet, visibly theirs, but cannot be moved. A purchase is a single transaction the buyer signs and pays for: SOL to the seller, the creator’s fee to the creator and, when the operator has set one, the platform’s cut to the treasury; then the platform, as delegate, thaws the NFT and transfers it to the buyer. The platform co-signs only after re-checking the escrow on chain, and it never has custody of the NFT or the payment. Delisting is the mirror image.

Because a listing spans a wallet signature and an on-chain read, a node that has not caught up can report an asset as unescrowed when it is not. Confirmation therefore polls rather than reading once, an already-escrowed asset is detected and skipped rather than charged twice, and a reconciliation job re-reads chain state for every active listing and corrects the database from it. Chain state is the source of truth; the database is a cache of it.

Auctions

last 2 minlistedreserve setbidescrowedbid+5% minimumbidin the last minuteswas endingnow endingextendedBids are escrowedheld by the platform, not the sellerOutbid is refundedautomatically, in the same stepSettled by cronbelow the reserve, every bid goes back
Figure 10. A bid in the last 2 minutes puts 2 minutes back on the clock, so an auction cannot be won by arriving a second before the end. Swipe sideways to see all of it.

A seller can take a fixed price or run an English auction with an opening bid, an optional reserve and a duration. Bids are escrowed in SOL when placed, so a leading bid is money that exists rather than a promise; being outbid refunds the previous leader in the same step. Each new bid must clear the current one by a minimum increment, 5% unless the seller sets otherwise.

An auction settles on the same terms as a fixed price: the creator’s fee and the platform’s cut come out of the winning bid and the rest goes to the seller, at the rates the listing was created under, so an auction that runs for a week settles on the numbers its bidders were shown.

A bid in the final two minutes resets the clock to two minutes. Sniping an auction in its last second therefore does not work: it extends the auction and invites a reply. When the clock finally runs out a cron settles it, delivering the NFT and paying the seller. An auction that never cleared its reserve simply ends, and every escrowed bid is returned.

Selling a prize before it is minted

With claim-to-mint on, a won prize is real but has no asset yet. It can still be sold. A sealed listing shows exactly what its owner sees, the rarity and nothing else, and transfers the right to claim rather than an NFT. There is nothing on chain to escrow, so claiming is blocked for as long as the listing stands, which is what stops the same prize being sold and claimed at once.

The buyer pays in SOL; the creator takes their usual fee and the treasury takes 10% for the convenience. Both rates are snapshotted onto the listing when it is created, so a settings change never alters the split a buyer was shown. Payment is verified from the transaction’s balance changes before the claim moves.

Offers

A listing asks the owner to name a price first, so nothing happens until they decide they are selling. An offer reverses that: anybody can name a price on any prize, listed or not, and the owner decides. The buyer’s SOL is escrowed the moment the offer is made, which is what makes it worth an owner’s attention: it is money that exists rather than a message, and an owner who accepts is paid in the same transaction they sign.

Accepting an offer on a minted prize is a single atomic transaction: the NFT moves and the escrow pays the owner, the creator and the treasury together, so neither side can give something away without being paid. An accepted offer is split exactly like a sale of the same kind: a minted prize pays the marketplace cut, a sealed one pays the unminted tax. Accepting an offer on something that is listed cancels the listing; the one case that is refused is an auction somebody has already bid on, because that bidder’s escrowed SOL is a promise the platform made, not just the seller’s.

Offers expire, and an offer holds real money, so expiry is not something that can simply lapse: a sweeper refunds them. A refund that fails leaves the offer exactly where the sweeper looks again, rather than marking it settled with the money still held.

Trades

termsA agreedB agreedA proposesv1——cannot runnobody has agreedboth agreev1v1v1runsagreements match the termsA rewrites and re-acceptsv2v2v1cannot runB never saw v2B reviews and agreesv2v2v2runsboth saw the same terms
Figure 11. An agreement is to a version of the terms, not to a trade. Revising bumps the version, so the trade cannot run until both sides have agreed again. Swipe sideways to see all of it.

Two wallets can negotiate a swap of any shape: any number of prizes each way, SOL on one side or both, or SOL for an NFT. Either side can counter as many times as it takes, and every counter can carry a message. The terms say what, the thread says why, and each message records which version of the terms was on the table when it was written.

A trade does not have to start with somebody in mind. An open call puts prizes on the table and leaves the other chair empty: anyone can answer it, and each answer forks into its own private negotiation while the call itself stays up. Several people can bid for the same prizes at once and the poster chooses between them, rather than the first responder claiming it. An open call cannot ask for prizes from a wallet that has not answered, since there is nobody yet to ask.

The whole design hangs on one rule: nobody is ever bound to terms they have not seen. The terms carry a version; an agreement records which version it agreed to; and the trade runs only when both recorded versions equal the current one. Revising therefore withdraws both agreements as a matter of arithmetic rather than as a step somebody has to remember. The same check runs when an acceptance is built, when it is confirmed and again at settlement, so a stale browser tab cannot agree to terms that changed while it sat open.

The same prize may sit in as many proposals as you like; an open call collects several answers, and every answer repeats what the caller put up. Exclusivity belongs at the moment somebody commits: once a wallet has agreed to a trade containing a prize, it cannot agree to another containing the same prize. Two agreements over one prize would both escrow it, both reach settlement, and the second would find it gone.

Proposing a trade signs nothing and locks nothing, so asking whether somebody is interested never costs the use of your prizes. Escrow happens at the moment of agreement, which is when a trade stops being a conversation. Each side escrows its own half as it agrees: NFTs frozen and delegated in place, SOL deposited. The platform then moves everything in one transaction it signs alone, and the NFTs never leave their owner’s wallet until that moment. Countering releases whatever was escrowed, because it was escrowed against terms that no longer exist, and calling a trade off returns both halves.

12Tokenomics

LootLoop will launch its own coin, $LOOP, as a fair launch on pump.fun: no presale and no allocation beyond a small, publicly disclosed dev buy. The treasury is funded by fees, not supply. The design goal is simple: every launch, drop and resale on the platform should push $LOOP.

Coin creator fees10% by fee sharingMarketplace10% unminted · cut offMint fees25% treasury · 25% burnServicesdesign · samples · promotion$LOOP creator fee50% ops · 50% buybackTreasuryruns the platformBurn potbuys & burns a chosen tokenRunning costsHelius · AI · rent · team$LOOPfair launch on pump.funbuy & burnHoldersLOOP boost · fee tiersUntil $LOOP exists, the potburns the token the operator names.
Figure 12. Where platform income comes from and where it goes, at the live settings. Service income divides 50% treasury and 50% burn. Dashed boxes wait on $LOOP itself. Swipe sideways to see all of it.

Revenue sources

SourceWho pays, and in whatStatus
Mint fee splitEvery claim-to-mint payment is divided the moment it lands: 50% to the campaign's creator, 25% to the treasury, 25% to the buy-and-burn pot. Paid in SOL.Built
Unminted sale tax10% of the price when a sealed prize is sold before it is minted, on top of the creator's own fee. Paid in SOL, to the treasury.Built
Marketplace cutA platform share of every minted sale, beside the creator's own fee, paid in SOL to the treasury. Applies to fixed-price sales and auctions alike. Set to zero today, so a creator's marketplace costs nothing until the operator decides otherwise.Built
Collection designWhat a creator pays to have their entities written for them, 0.05 SOL. No creator share: it buys a service, so it divides 50% / 50% between the treasury and the burn pot.Built
Coin creator fee · launched hereA coin launched through LootLoop is offered a pump.fun fee-sharing config naming the treasury for 10% of its creator fee. pump.fun pays the treasury out of every trade, directly; the creator keeps the other 90%.Built
Coin creator fee · attachedAn existing coin can opt into the same split, 10%, in exchange for paying no platform cut at all on its marketplace. Only the wallet that created the coin can do it.Built
Test renders0.01 SOL per sample image a creator renders of their own collection before anything is minted, priced per image because each is a real model call. Divides like every other service.Built
Promotion slots0.5 SOL to pin a campaign to the top of the listings for 7 days. Divides like any other platform income.Built
$LOOP creator feepump.fun's creator fee on $LOOP itself, split 50% operations and 50% buyback through the same fee-sharing config every other coin uses.Builtawaiting the coin
Priority infrastructureHigher webhook throughput and generation priority for campaigns that want it, paid in $LOOP.Proposed

Everything marked built is a live setting rather than a constant: the three mint shares, the unminted tax, the marketplace cut, the design price, the sample-render price, the fee-share percentages and the discount they buy, the promotion price and duration, the split of platform income, the destination wallets and the token to be burned are all changed from the operator console without a deploy. The accrual ledger records what each recipient is owed and what has been paid.

Sharing a coin’s creator fee

Most of the income above passes through LootLoop before it reaches anyone. The coin creator fee does not, and that is the point. pump.fun pays a coin’s creator a share of every trade, and a fee-sharing config replaces that single recipient with up to ten shareholders whose shares total 100%. A coin launched here is offered a config naming its creator and the LootLoop treasury, so the program itself pays both. The platform never holds the money, so there is no balance to reconcile, nothing to withhold, and nothing to lose if the platform disappears.

Two consequences are worth stating plainly, because they cut against the platform’s own interest. The config’s admin is the coin’s creator, not LootLoop: a creator can rewrite the split afterwards and keep the whole fee. Nothing on chain prevents that, so the split is re-read from the chain rather than trusted, and the marketplace discount it earns follows what the chain says today rather than what was agreed at launch. And distribution is permissionless: the fees accrue in a pump.fun vault until somebody asks for them to be paid out, and anybody can ask. LootLoop runs that job every six hours and pays the network fee for it, so a creator is paid their share on a schedule whether or not they ever think about it.

What a creator keeps

The split is weighted toward the person who made the collection. On a claim they take 50% of the mint fee, the largest single share. On a resale they take their own marketplace fee, which they set per campaign, and the platform takes its cut beside it rather than out of it, so raising one never quietly lowers the other.

WhenCreatorTreasuryBuy & burnSeller
A winner mints a sealed prize50%25%25%—
A minted NFT is soldtheir marketplace feethe platform cut (zero today)—the rest
A sealed prize is soldtheir marketplace fee10%—the rest
A collection is designed—50%50%—
A promotion slot is bought—50%50%—
A creator renders a sample—50%50%—
Anyone trades a fee-shared coin90% of the coin's creator fee10%——

Three rules hold across all of it. A split never creates or destroys value: the shares always add back to exactly the price, with rounding crumbs going to the burn pot rather than vanishing. The treasury takes one cut per sale, never two: a sealed sale is taxed for being unminted and a minted one pays the marketplace cut, never both. And a campaign that shares its coin’s creator fee is not charged twice for the privilege: sharing buys a discount on the marketplace cut, so the two move in opposite directions by design.

Value return Planned

  • Buy & burn. The burn pot accrues SOL today. Once $LOOP exists, it buys $LOOP and burns it, and every burn is listed on a public ledger.
  • Utility sinks. Services that are paid in SOL today (designs, sample renders, promotion) become payable in $LOOP, and the $LOOP spent is burned.
  • LOOP boost. Campaign creators can opt in to a small odds multiplier for traders holding a threshold of $LOOP, giving every trader on every campaign a reason to hold it.
  • Creator tiers. Holding $LOOP lowers platform fees and unlocks higher-quality generation models and featured placement.
  • Dogfooding. $LOOP runs as a LootLoop campaign of its own, with a flagship AI collection.

What $LOOP is not

$LOOP does not pay dividends, and marketplace proceeds are not distributed to holders. Value accrues through usage-driven burns and utility. That keeps the coin a product credential rather than a claim on revenue.

Part V Reference

13Architecture & security

SOLANApump.fun programscreate_v2 · curve · PumpSwapMetaplex Corecollections · assets · pluginsSOL transferssales · bids · offers · feesPlatform authoritymints · escrow · co-signsVERCELNext.js 16 apppages + route handlersPostgres (Neon)Prisma 7Blobart · metadata · AI outputCron10 jobs · poll → payoutsthe internal fulfilment endpoint generates and mints in parallel invocationsHeliusraw webhooks · RPC · indexerAI modelsOpenAI images · Claude agentWalletsWallet Standard · signed sign-in · the user signs every paymenttradesmint / settle
Figure 13. The system end to end. It runs on devnet today and every part of it switches cluster from one setting. Swipe sideways to see all of it.
Custody
Users sign every payment in their own wallet. The platform key mints prize NFTs (it pays the rent), holds deposited prizes, holds escrowed SOL for offers, bids and agreed trades, and co-signs marketplace settlements only after checking the chain.
Sign-in
Sign-in with Solana style: the wallet signs a timestamped message, accepted for 15 minutes, which is exchanged for a signed, httpOnly session cookie that lasts seven days. No passwords, and no session token a page script can read.
Trade ingestion
Helius raw webhooks (with a shared secret) as the primary path, an RPC poller cron as the fallback, and an instant path from the in-app trade widget. Every (signature, instruction) pair is processed once.
Scheduled work
10 cron jobs: poll for trades, score recorded trades, retry failed fulfilment, replay failed webhook deliveries, reconcile listings against chain state, settle due auctions, pay out accrued revenue shares, distribute coin creator fees to their shareholders, refund offers nobody answered, and, when the operator switches it on, keep a short queue of AI-drafted collection proposals for review. Each is idempotent and safe to run twice.
Reading after writing
Public RPC replicas lag. Collections are created at finalized commitment, because minting into a collection a node has not seen makes the program abort, and every read-after-write on a listing or a sale polls with backoff and then reconciles from chain state rather than trusting one response.
Escrowed money
Offers, auction bids and each half of an agreed trade are held in the platform wallet. Every deposit is credited from the transaction's own balance change rather than from what the request claimed, every payout and refund claims its row with a conditional update before any SOL moves, and a failed transfer puts the row back where the sweeper will retry it rather than marking it settled.
Supply safety
Prize supply and AI generation slots are reserved with conditional atomic updates, so concurrent wins can never over-mint.
Durability
Detection and scoring are separate phases. A trade is recorded before it is judged, scoring is claimed atomically so it cannot be double-counted, and failed trades, prize mints and webhook deliveries are all retried from stored state. A win banked while the loot table was empty is paid out once prizes are added.
Abuse limits
Sign-in, anything that writes or spends, and anything that costs a model call or an indexer request are each rate-limited per wallet and per address.
Failures
A failed job or fulfilment is reported in one shape to one place: the server log, a webhook when one is configured, and the operator console's list of recent failures.
Uploads
Browser to Vercel Blob with short-lived tokens issued only to signed-in wallets. Object names are random UUIDs plus Blob's random suffix; the store cannot be enumerated.
Secrets
The lottery secret never leaves the server; only per-epoch commitments and revealed seeds are published.
Cost accounting
Every mint, claim, payout and AI call is written to a cost ledger with its network fee and, for generation, its token usage. The operator console prices it in dollars, so the running cost per drop is a number rather than a guess.
Operator console
Gated on a server-side wallet allow list and a signed message, not on a client-side flag. With no allow list configured, nobody has access.
Environment
Everything switches cluster from one setting. The service runs entirely on devnet until launch.

Being told what happened

Wins, mints, offers received, offers accepted, declined or expired, and sales are all recorded as notifications at the moment the event happens rather than derived when somebody looks. That gives them a read state, lets them survive the row that caused them changing again, and leaves one place for email or chat delivery to hook into later. Each carries a key derived from the event, so a retried webhook or a re-run cron cannot say the same thing twice.

14Roadmap

PhaseScopeStatus
0 · DevnetLaunch and attach, three loot sources, the odds engine, anti-bot rules, commit and reveal, Core minting, an escrow marketplace, AI collections, the creator hub.Built
0.2 · DepthClaim-to-mint with the mint-fee split and payout policy, auctions with escrowed bids and anti-snipe, selling unminted prizes, per-entity AI generation with an importable interchange format, loot-table pacing controls, official markers, and a dollar-denominated cost ledger.Built
0.3 · A real marketSOL pricing across the marketplace, escrowed offers on anything listed or not, negotiated multi-item trades with version-bound agreement, pump.fun creator-fee sharing with permissionless distribution, paid promotion slots, per-collection collaborators, in-app notifications, paid sample renders, campaign browsing with search and a watchlist, a filterable marketplace, importing Core NFTs a wallet already holds, and minting several sealed prizes in one approval.Built
1 · Devnet hardeningDone: automated tests over the money and odds functions, rate limiting, error reporting, session cookies, mobile polish. Next: live campaigns with real trade flow, and public tools for auditing seeds.In progress
2 · Mainnet betaCluster switch, Helius mainnet webhooks, re-resolving watch addresses when a coin graduates, the public burn ledger, invited creators.Planned
3 · $LOOP launchFair launch on pump.fun, the locked fee split, LOOP boost and creator tiers, the flagship campaign.Planned
4 · ExpansionCollection and collector pages, a public activity feed across campaigns, email and chat delivery of notifications, creator analytics, more NFT standards, and moving rolls to an on-chain VRF.Exploring

15Risks & disclosures

  • Market risk. Coins launched on pump.fun are highly volatile and can lose all value. LootLoop does not control, endorse or guarantee any campaign’s coin.
  • Operational dependencies. Drop detection relies on Helius and Solana RPC; AI collections rely on OpenAI. Outages delay fulfilment but do not lose it: prizes persist and retry.
  • Adversarial traders. Anti-bot rules raise the cost of gaming the draw; they cannot make it impossible. Creators have moderation tools and live rule controls.
  • Randomness trust model. Commit and reveal lets anyone verify past outcomes; it does not let a trader predict future ones. It does require trusting that the operator does not leak a seed within its epoch, and that test wins stay labelled. Moving rolls to an on-chain VRF is on the roadmap.
  • Platform key. The platform authority can mint into the collections it controls, and while something is in escrow it can move it: offered and bid SOL, each half of an agreed trade, and listed NFTs it is the delegate for. Its key is held in server secrets with no human access path in production. It has no access to anything else in a user’s wallet.
  • Regulatory. Digital asset rules vary by jurisdiction. Nothing in this document is financial, legal or tax advice.

16Glossary

Campaign
A coin plus its rules, loot table and marketplace on LootLoop. A coin carries one.
Bonding curve
pump.fun's on-chain pricing account for a coin before it graduates to an AMM. LootLoop watches it for trades.
bps
Basis points. 100 bps = 1%.
Epoch
A period of a campaign covered by one lottery seed. Rotating it reveals the old seed.
Metaplex Core
Solana's current NFT standard: single-account assets with plugins such as freeze and transfer delegates.
Escrow by delegate
Listing by freezing the NFT in the seller's wallet and delegating transfer rights, rather than moving it to an escrow account.
Whale cap
The trade size above which more SOL no longer improves the odds.
Pity timer
A rising odds multiplier for wallets that keep trading without winning.
Claim-to-mint
A mode where a win is banked showing only its rarity, and the trader pays a fee to mint the art.
Sealed prize
A win that is recorded and owned but not yet minted. It can be minted or sold as it is. Also called a banked prize.
Entity
One character, creature, item or place an AI collection can generate, with its own art direction and per-rarity look. The interchange file lists them under subjects.
Interchange file
The documented JSON format for moving entity data into and out of an AI collection.
Offer
A price somebody names on a prize whether or not it is for sale, with the SOL escrowed up front so accepting it always pays.
Trade
A negotiated swap between two wallets: any number of prizes each way plus SOL, countered until both sides agree.
Open call
A trade posted with nobody named. Anyone can answer it, and each answer becomes its own negotiation.
Terms version
The number a trade's terms carry. An agreement records the version it agreed to, so revising withdraws both agreements automatically.
Fee sharing
A pump.fun config that splits a coin's creator fee between up to ten wallets on chain, letting a campaign pay the platform without the platform holding the money.
Anti-snipe
Extending an auction when a bid lands near the end, so it cannot be won in the final second.
Official
A campaign or collection whose creator wallet is the wallet that created the coin on chain.

Put it to work

Give a coin a loot table in a few minutes, or find a coin that already has one.