Launchpad (design)

Architecture

Token-2022 transfer hooks, what they cannot do, and the gap that has to be designed.


The foundation already exists#

This is not a proposal for technology that has to be invented. Solana's Token-2022 program has a transfer hook extension: a mint can name a program that must run on every transfer of that token. Solana's own documentation lists the use cases it was built for — custom fees, allow and deny lists, custom transfer events, and tracking.

token transfer
      ↓
  Token-2022
      ↓
  transfer hook extension
      ↓
  custom program
      ↓
  execute the rule

  if the hook fails, the transfer fails

That last line is the whole security model in one sentence, and it cuts both ways. A rule cannot be skipped — but a broken rule stops the token moving at all.

The gap nobody should paper over#

A Token-2022 transfer hook fires on transfers. Uniswap v4 hooks — the model Hookr builds on — fire on the lifecycle of a pool: before and after a swap, on liquidity added, on liquidity removed. Those are not the same thing, and the difference is exactly where a naive port would break.

Needed forUniswap v4 hookToken-2022 transfer hook
Knowing a transfer is a buyGiven by the callbackNot given — a transfer is a transfer
Knowing a transfer is a sellGivenNot given
Reacting to liquidity changesGivenNot visible at all
Reading the price of the swapGivenNot available in the hook
Charging a fee on any movementPossiblePossible
Allow and deny lists, caps, cooldownsPossiblePossible, and natural

So the honest statement is: we cannot translate a Solidity hook into Rust and call it done. Half the catalogue — transfer rules, access rules, caps, cooldowns, burns on transfer — maps directly onto Token-2022 and could be built on it today. The other half — anything that needs to know a buy from a sell, or to react to a pool — needs more than the extension gives.

The shape that closes the gap#

Three pieces, in increasing order of how much has to be designed:

PieceJobWhere the difficulty is
Token-2022 extensionsEverything that is genuinely about a transfer: rules, caps, lists, per-transfer fees.Low. This is what the extension is for.
A router the pools trade throughGives swap semantics back: it knows direction, size and price, and can call hooks before and after with that context.Routing is only honoured if trades actually go through it. A trade routed around it must still be safe, never silently fee-free.
Hook runtime and registryResolves a token's stack, enforces the fee ceiling, meters usage per hook for hook mining, and isolates one hook's failure from the rest.Compute budget, account limits, and making sure a bad hook degrades instead of bricking a token.

Designing for failure#

Because a failed hook fails the transfer, failure handling is not a detail to add later:

  • Hooks are metered. A hook that exceeds its compute or account budget is cut off at the stack level rather than being allowed to fail the transfer.
  • Reward hooks never run inline. Distribution is queued and settled separately. A payout failing must not stop someone moving their own tokens.
  • Blocking hooks are a separate, audited tier. Only rules whose whole purpose is to refuse — deny lists, lockups — may fail a transfer at all.
  • Every token publishes its stack. Which hooks, which versions, which parameters, and whether any of it can change. A buyer can read what the token will do to them before buying it.

What carries over from what already works#

The launchpad is new, but it does not start from nothing. Four decisions that the live marketplace already proves are carried over without change:

From the marketplaceInto the launchpad
No custodyFees and rewards move between wallets and programs. The platform is never the holder of anyone's money.
Signed termsA launch is signed over its exact configuration — supply, hooks, parameters — so what the wallet showed is what deploys.
Ownership checkBecomes the balance check that access hooks use to gate a utility.
ModerationReports and takedowns apply to hooks as well as products. A hook that harms its users is delisted.
NextPayments →