OBSCURA

> HOW IT WORKS

The first seat on a bonding curve is worth real money — on a 20-seat block of one-SOL bids it is worth about 40% of the bid. Normally that value goes to whoever has the fastest infrastructure. Obscura hides the book so nobody can size a bid against anyone else's, then draws the order from a seed no single party can steer.

01

SEAL — a bid is a hash

A bidder picks an amount between 0.05 and 10 SOL. Their browser generates 32 random bytes and sends only SHA256("obscura-seal-v1" ‖ auctionId ‖ bidder ‖ amount ‖ nonce). No transaction, no cost, nothing readable.

The domain tag and the auction id mean a commitment cannot be replayed into a different launch; the bidder's own address means it cannot be claimed by anyone else; the nonce means the amount cannot be brute-forced out of the hash. We never learn the number, so there is nothing for us to leak, sell or trade against.

The amount and nonce live only in the bidder's browser. Lose them and the seat cannot be claimed — which is why the page writes them to local storage and offers a backup file the moment a bid is sealed.

02

ANCHOR — the book shuts and goes on chain

When the window closes, every commitment is sorted and hashed into a Merkle tree with separate domain prefixes for leaves and internal nodes, and the root is written on chain. Because the leaves are sorted, the root is a function of the set of bids — anyone can rebuild the identical root from the published list without trusting our ordering, and we cannot add or drop one afterwards.

The blockhash of the slot that carries the root becomes an entropy input for the draw. That is the point of anchoring after the window shuts: while people were bidding, this value did not exist.

03

REVEAL — open your commitment

Bidders publish the amount and nonce behind their hash. Each one is checked against the commitment it was sealed with, so the reveal cannot be used to change a bid after seeing the field. A bidder who does not reveal within 10 minutes forfeits their seat, and their unrevealed commitment stays published.

04

DRAW — three authors, no steering

seed = SHA256("obscura-draw-v1" ‖ root ‖ anchorBlockhash ‖ nonce₁ ‖ … ‖ nonceₖ)

Then Fisher–Yates over a SHA-256 counter stream, with rejection sampling rather than a modulo — taking u32 % n would quietly favour the low seats, and a thumb on the scale is exactly what this is supposed to not have.

Three parties contribute and none of them is enough alone. We cannot choose the nonces. Bidders cannot choose the blockhash. Nobody can change the root once it is anchored. Every input is published, and the auction page re-runs the whole draw in your browser and tells you whether the order on screen is the one those inputs produce.

05

QUOTE — a good seat is a discount, never a bigger bag

This is the part that makes a random order safe to accept. Every bidder is quoted the token amount they would receive from the worst seat — last, behind the dev buy and every other bid — with their bid as the spend ceiling.

So no draw can make a bid fail: the quoted cost is the maximum, and every real seat has less SOL in front of it than the worst case does. And landing early means paying less for the same tokens and keeping the difference. The randomness can only ever help you.

Bags are quoted 30 basis points under the true worst-seat maximum. At the worst seat the quoted cost lands on the bid to the lamport, and the program recomputes its own fee from live state; one lamport of disagreement would fail that buy and, because the bundle is atomic, kill the launch for everyone. That margin is the slack that makes it impossible.

06

PACK — why twenty seats

A Solana transaction is capped at 1232 bytes and a Jito bundle at five transactions. A Pump.fun buy touches 18 accounts, so an address lookup table absorbs all the shared ones at a byte per reference — without it two bidders per transaction would be the ceiling.

What is left is about 156 bytes per bidder. 5 fit in 1129 bytes; six overflow at 1285. Transaction one carries creation, the dev buy, the platform fee and the tip, leaving 4 for bidders:

5 × 4 = 20 seats

Each packed transaction uses its own durable nonce account — a durable nonce is consumed by the transaction that advances it, so four sharing one would mean three were invalid the moment the first landed. The nonces are also what let a bidder sign once and walk away instead of racing a 60-second blockhash.

07

FIRE — one slot or nothing

Creation and all the buys go to Jito as one bundle: same slot, all-or-nothing, in the drawn order. Nothing can trade between the coin's creation and the last seat, because there is no between.

Every signature is checked against the exact message bytes we handed out before anything is submitted, and the whole bundle is simulated against live state as the last gate.

08

WHAT THIS DOES NOT DO

Stated plainly, because the rest of the page is a list of guarantees and these are the holes in them.

  • The last-revealer problem is real. A bidder who dislikes the seed can refuse to reveal, dropping their nonce and redrawing the order. It costs them their seat, it is publicly visible, and it cannot be aimed at a chosen outcome — but it is not zero. Removing it entirely needs a verifiable delay function or an external VRF, and we run neither.
  • We choose when to anchor. The root is fixed by the sealed bids, but the slot it lands in is whenever the anchor transaction confirms. Anyone can trigger the anchor once the window shuts, and the transaction is published in the certificate — but a determined operator has some influence over which blockhash the seed uses. The bidder nonces are in the seed precisely because that influence exists.
  • The book is capped at 35 SOL. A Pump.fun curve graduates at about 85.8 SOL; a block that pushed past it would complete the curve part-way through and fail every remaining buy. An oversubscribed book is scaled down pro rata — every bid by the same factor — rather than anyone being turned away.
  • Auction state is in memory. It does not survive a restart or a deploy. That is why the windows are short (10 minutes to reveal, 10 to sign) and why we say so here rather than after you lose a book.
  • A sealed book does not stop sniping afterwards. It governs the opening block only. In the slots after it, the coin is an ordinary Pump.fun token and anyone can buy it as fast as they like. No launchpad can change that.
  • Every seat has to sign. An atomic bundle needs every signature it was built with, so one bidder who walks away after the draw stalls the launch until the signing window expires.