Risk & Terms
Any token you deposit, and the SOL you borrow, can fall sharply in price or become worthless. Nothing about Pledge protects the market value of your assets.
Pump.fun tokens routinely move tens of percent in minutes. Their liquidity can disappear quickly, creators and large holders can sell at any time, and many tokens go to zero. A loan that looks comfortable can reach its liquidation threshold in a short time.
There is no independent oracle for most Pump.fun tokens. Pledge derives prices directly from each token’s canonical on-chain market — the Pump.fun bonding curve, or the canonical PumpSwap pool after graduation. The program reads those accounts itself; neither you nor this website supplies a price.
To resist manipulation, the program keeps a time-weighted moving average (EMA) that must warm up before use and restarts if observations stop, also tracks the lowest spot price and real liquidity seen over its most recent observations, refuses new loans when spot (or that recent low) and average diverge, values collateral at the lowest of these prices, caps the value at what selling the whole deposit would return, requires minimum real liquidity (counted at its recent low), and limits price impact and per-token debt.
These defences have limits. A well-funded actor who sustains a manipulated price long enough can move the average. Thin markets give poor exit prices. Pump.fun’s programs are upgradeable by their developers; if their account layouts or behaviour change, pricing may become unavailable or wrong until Pledge is updated. Indicative prices from DexScreener or Jupiter are shown for reference only and are never used for valuation.
Borrowing takes two steps. You approve one loan request in your wallet. The program checks it straight away, then waits for a short delay (shown under Current parameters) before the loan can be paid out, and the request expires if it is not paid out in time.
A Pledge keeper pays out the loan inside that window. The program values your collateral again at that moment, using the keeper’s own price reading, so a price drop during the wait lowers or blocks the loan instead of leaving the protocol with bad debt. You choose the least you accept: if the price has fallen so far that the loan would be smaller than that, no loan is made and nothing moves — you can request again. You can cancel a request at any time before it is paid out, and cancelling is never paused.
While a request is pending, the collateral cannot be added to or withdrawn on its own. The app offers one-step “Cancel request & withdraw”, “Cancel request & close” and “Cancel request & add collateral” actions instead.
Only keys registered by the protocol admin (listed on the Protocol page) can pay out a requested loan. A keeper only chooses the moment inside your request’s window, at random so it cannot be predicted. It cannot change the amount or the terms, and the SOL always goes to the borrower’s wallet.
If no keeper acts in time — for example during an outage — your request expires and nothing is lent; cancel it or request again later. A compromised keeper key could time a payout to coincide with a briefly manipulated price. Per-token debt ceilings and liquidity limits bound the loss that could cause.
Pledge counts a token’s market liquidity at the lowest of its live real SOL, its recent low and a slow average that only rises gradually. Liquidity added shortly before borrowing — for example a temporary liquidity deposit — does not count in full, so borrowing limits on thin markets can be lower than the live figure suggests, and a newly deepened market can take hours to count fully.
A single sharp drop recorded by the price feed — whether a real move or a deliberate dip — blocks new loans on that token for about one to two minutes, and can make a pending request fail its payout check. This protects the protocol’s SOL; it does not touch any collateral or debt, and repaying, unlocking and liquidations keep working. Someone could repeat such dips to keep borrowing closed for a while; it costs them trading fees each time, and the protocol monitors for it.
Pledge is experimental software and has not been audited. The program, the Pump.fun programs it reads, the Solana runtime, your wallet and this website can all contain bugs. A vulnerability could lead to the partial or total loss of deposited collateral or of protocol liquidity.
When your debt (principal, origination fee and accrued interest) reaches the liquidation threshold fixed in your loan — measured against your collateral’s value at the higher of the spot and moving-average prices — anyone may liquidate the position. The liquidator repays the whole debt in SOL and receives collateral worth the debt plus the liquidation bonus. Any remaining collateral stays in your vault and you can unlock it.
If the collateral is worth less than the debt plus the bonus, the liquidator takes all of it and the shortfall is recorded as bad debt absorbed by the protocol. Loans are non-recourse: you never owe more than your collateral, but you can lose all of it. Liquidation is all-or-nothing in this version.
Read how loans, interest, fees and liquidation work, check the current parameters on the Protocol page, and review each transaction in your wallet before approving it. Only deposit what you can afford to lose. Nothing on this website is financial, legal or tax advice, an offer, or a recommendation.
Estimates shown in this interface — collateral value, maximum loan, liquidation price — are calculations from current on-chain data. The program re-checks everything when the keeper pays out your loan and may produce different numbers or refuse it. A request reserves nothing: protocol SOL liquidity and each token’s debt limits are finite and may be used up by others before your payout.
When this interface is connected to devnet or a local network, every token and every SOL amount is a test asset with no real value. The interface labels these clusters with an amber DEVNET or LOCALNET marker throughout.
The guardian or admin can pause new deposits, new borrows or liquidations, for example during an incident. Only the admin can unpause. Pausing borrows also stops pending loan requests from being paid out; they expire and can be cancelled. Repaying a loan, unlocking collateral, closing a position, cancelling a loan request and refreshing prices can never be paused, so you can always exit a position by repaying it. If liquidations are paused while prices fall, positions may become more undercollateralised before they can be settled.