Launchpad (design)
Architecture
Token-2022 transfer hooks, what they cannot do, and the gap that has to be designed.
The foundation already exists#
This is not a proposal for technology that has to be invented. Solana's Token-2022 program has a transfer hook extension: a mint can name a program that must run on every transfer of that token. Solana's own documentation lists the use cases it was built for — custom fees, allow and deny lists, custom transfer events, and tracking.
token transfer
↓
Token-2022
↓
transfer hook extension
↓
custom program
↓
execute the rule
if the hook fails, the transfer failsThat last line is the whole security model in one sentence, and it cuts both ways. A rule cannot be skipped — but a broken rule stops the token moving at all.
The gap nobody should paper over#
A Token-2022 transfer hook fires on transfers. Uniswap v4 hooks — the model Hookr builds on — fire on the lifecycle of a pool: before and after a swap, on liquidity added, on liquidity removed. Those are not the same thing, and the difference is exactly where a naive port would break.
| Needed for | Uniswap v4 hook | Token-2022 transfer hook |
|---|---|---|
| Knowing a transfer is a buy | Given by the callback | Not given — a transfer is a transfer |
| Knowing a transfer is a sell | Given | Not given |
| Reacting to liquidity changes | Given | Not visible at all |
| Reading the price of the swap | Given | Not available in the hook |
| Charging a fee on any movement | Possible | Possible |
| Allow and deny lists, caps, cooldowns | Possible | Possible, and natural |
So the honest statement is: we cannot translate a Solidity hook into Rust and call it done. Half the catalogue — transfer rules, access rules, caps, cooldowns, burns on transfer — maps directly onto Token-2022 and could be built on it today. The other half — anything that needs to know a buy from a sell, or to react to a pool — needs more than the extension gives.
The shape that closes the gap#
Three pieces, in increasing order of how much has to be designed:
| Piece | Job | Where the difficulty is |
|---|---|---|
| Token-2022 extensions | Everything that is genuinely about a transfer: rules, caps, lists, per-transfer fees. | Low. This is what the extension is for. |
| A router the pools trade through | Gives swap semantics back: it knows direction, size and price, and can call hooks before and after with that context. | Routing is only honoured if trades actually go through it. A trade routed around it must still be safe, never silently fee-free. |
| Hook runtime and registry | Resolves a token's stack, enforces the fee ceiling, meters usage per hook for hook mining, and isolates one hook's failure from the rest. | Compute budget, account limits, and making sure a bad hook degrades instead of bricking a token. |
Designing for failure#
Because a failed hook fails the transfer, failure handling is not a detail to add later:
- Hooks are metered. A hook that exceeds its compute or account budget is cut off at the stack level rather than being allowed to fail the transfer.
- Reward hooks never run inline. Distribution is queued and settled separately. A payout failing must not stop someone moving their own tokens.
- Blocking hooks are a separate, audited tier. Only rules whose whole purpose is to refuse — deny lists, lockups — may fail a transfer at all.
- Every token publishes its stack. Which hooks, which versions, which parameters, and whether any of it can change. A buyer can read what the token will do to them before buying it.
What carries over from what already works#
The launchpad is new, but it does not start from nothing. Four decisions that the live marketplace already proves are carried over without change:
| From the marketplace | Into the launchpad |
|---|---|
| No custody | Fees and rewards move between wallets and programs. The platform is never the holder of anyone's money. |
| Signed terms | A launch is signed over its exact configuration — supply, hooks, parameters — so what the wallet showed is what deploys. |
| Ownership check | Becomes the balance check that access hooks use to gate a utility. |
| Moderation | Reports and takedowns apply to hooks as well as products. A hook that harms its users is delisted. |