Workbench →
solana devnet · live program X · @KarpionSpace ↗

KARPION · THE ON-CHAIN ORCHARD · SOLANA DEVNET

Every fee ripens. Anyone picks.

Karpion is a self-paying orchard on Solana. Every $KAR swap on the main pool pays a toll; the toll ripens inside the vault; anyone can pick it — one permissionless strike every 60 seconds. Each pick loads five crates at 40/40/10/5/5: burn, stocks, ops, liquidity, chaos. No keys. No votes. No backend.

THE PICKING LEDGER · CUMULATIVE FEES CLAIMED · DEVNET $ — awaiting first print — USDC
reading vault history · the ledger grows with the first picks
WINDOW START — FIRST VISIBLE PICK SETTLEMENT 40 / 40 / 10 / 5 / 5 · KEEPER 0.25% NOW · SLOT —
fees picked · usdc ··· all time — everything the orchard has paid out
$kar burned ··· supply only ever falls
live supply · $kar ··· 1,000,000,000 at deployment
on the branch · pending ··· ripening between strikes

02LIVE FIGURES

The orchard, measured

read straight from Solana devnet · no backend · no api keys · refreshes every 15s

fees picked · usdc···all time, net of nothing
$kar burned···through the burn crate only
keeper cut0.25%plus rounding dust, to whoever picks
strike window···harvest cooldown on devnet
the law40 / 40 / 10 / 5 / 5fixed in bytecode — no key can re-weight it
pool toll4.2%a quarter of it accrues to the orchard

03THE FIVE CRATES

Five crates. One law.

every pick is loaded 40 / 40 / 10 / 5 / 5 — constants in the program, not settings for a key to change

C/1 · BURNBuy & burn

The heaviest crate buys $KAR back on the open pool and burns it in the same strike. Supply only ever falls through this crate — every pick tightens the float.

INV-1 ··· claimed = keeper + pending + paid — asserted by the program after every strike, checked live in the workbench

04THE PICKING

How a pick runs

one transaction · five crates · failure-isolated by construction

01

A swap pays its toll

Every $KAR swap on the main pool pays a 4.2% toll; a quarter of it accrues to the protocol inside the pool, owed to the orchard. Between picks, the fruit only ripens.

02

Anyone picks

harvestClaim() is permissionless — the caller pockets 0.25% of the claim plus rounding dust. A cooldown rate-limits the orchard: 60s on devnet.

03

The pick loads five crates

40 / 40 / 10 / 5 / 5, hardcoded. Minimum claim, per-crate minimums and integer dust guards keep the arithmetic honest.

04

Every crate runs alone

Guards validate before a lamport moves; each route runs as its own instruction. A stale feed or thin pool soft-skips — that crate's share stays pending, the pick never halts, and the ledger records every skip.

INV-1 · CLAIMED = KEEPER + PENDING + PAID the invariant the vault asserts about itself, every single strike

05THE ESTATE

Nine stocks, held by bytecode

40% of every pick lands here · equal weight · nobody can raid the rows

SPY11.11%±3% TWAP gate
NVDA11.11%±3% TWAP gate
TSLA11.11%±3% TWAP gate
SPCX11.11%±3% TWAP gate
MSTR11.11%±3% TWAP gate
GOOGL11.11%±3% TWAP gate
CRCL11.11%±3% TWAP gate
AAPL11.11%±3% TWAP gate
META11.11%±3% TWAP gate
9 ASSETS EQUAL WEIGHT 50 / 50 SWAP-LP ±3% TWAP GATE

see the live holdings board in the workbench →

06SAFEGUARDS

Walls, not promises

six gates every crate passes · G-01 → G-06

G-01

TWAP drift gate

Before any pool trade, spot must sit within ±3% of the 30-minute TWAP. Manipulation inside the window is refused, not punished.

G-02

Feed staleness & pause

Stock routes skip any asset whose oracle is older than 15 minutes, paused, or negative. Skips are ledger events, not errors.

G-03

Pool impact cap

No single route moves more than 0.5% of a pool per execution. Oversized amounts batch across future strikes.

G-04

Soft-skip isolation

Guards validate first, then each route runs as its own instruction. A failing route emits RouteFailed and holds its funds pending — never takes the pick down.

G-05

Timelocked custody

Fee-recipient and dev-treasury changes need a request/confirm delay — 60 seconds in this devnet edition. The world watches the intention first.

G-06

Self-auditing ledger

INV-1 asserts claimed = keeper + pending + paid after every strike. INV-4 asserts the vault holds zero $KAR when the dust settles.

07QUESTIONS

The fine print

eight answers · zero marketing

Q1What exactly is Karpion?
An autonomous orchard. $KAR trades on its own pool; the pool tolls are periodically picked by the vault program and settled along five fixed crates — buy&burn, stock estate, operations, liquidity, chaos. No human in the loop, no off-chain infrastructure: the whole engine is one on-chain program.
Q2Why "Karpion"?
From Greek karpos — fruit — and Latin carpere, to pluck: the carpe of carpe diem. Fees are fruit. They ripen on-chain whether anyone is watching or not, and the protocol exists so that anyone — not a key-holder — gets to pick them. The five-way split is the crate stack; the area chart of cumulative fees is the picking ledger.
Q3Who can call the harvest?
Anyone, from any wallet. The caller receives 0.25% of the claim plus rounding dust as a keeper reward. Harvests are rate-limited by a cooldown — 60 seconds on Solana devnet, five minutes planned for mainnet.
Q4What happens if a crate fails mid-pick?
Nothing catastrophic — by construction. On Solana a transaction cannot half-revert, so every guard is checked up front and each route runs as its own permissionless instruction. If a guard trips (stale feed, drift gate, thin pool), the route soft-skips — a RouteFailed entry lands on the ledger, the amount stays pending for that crate, and every other route completes normally. The failed amount retries next strike.
Q5Are the stock positions real?
On devnet they're simulated — mock feeds push plausible prices for SPY, NVDA, TSLA and six others so you can watch the routing work end to end. On mainnet the same program consumes real equities price feeds and real position tokens.
Q6Why does 5% go to "chaos"?
An orchard that can only grow sensible things is an orchard that can be modeled, front-run and farmed. The chaos crate buys a volatile side asset and burns it — deliberately inefficient value that keeps the system from becoming a deterministic payoff matrix.
Q7Can the weights or destinations be changed later?
Not by any key we hold. The split lives in the program as constants. The authority role can rotate operational parameters (cooldowns, caps, asset list) — all timelock-protected and visible on-chain — but re-weighting would require deploying an entirely new protocol nobody is obliged to follow.
Q8When mainnet?
After the external audit completes and timelocks are extended to production values. Watch @KarpionSpace — the launch announcement is the only signal worth trusting.

The crop is ripening.

Every pick, every crate, every skip lands on-chain where anyone can read it. Open the workbench and pick the pot yourself — follow the account for the launch signal, read the program for everything else.

  • announcement channelx.com/KarpionSpace
  • home of the orchardkarpion.space
  • the split · fixed40 / 40 / 10 / 5 / 5
  • keeper reward0.25% + dust
  • cooldown · devnet60 seconds
  • keys heldnone that matter