Every paid ride is a ticket into a prize pool. The pool is an account on Solana that holds the entry fees itself and publishes its rules once: price, minimum riders, deadlines, the split, and where the money may go. If not enough riders commit in time, everyone gets their money back, and nobody needs our permission to make that happen.
A player's ticket payment goes straight into the pool's vault. The vault is a program-derived address: no private key exists for it, so only the program's own rules can move money out. Four exits exist, and each one is a rule written into the program. The game server watches what happens and prepares transactions for people to sign. It never holds or moves the money.
A pool opens with a commitment goal, for example 10 riders. It goes live the moment the 10th ticket is bought. If the deadline passes first, it turns into a refund pool. Every path ends either with the pot split by the rules or with every buyer paid back.
The program reads the chain's own clock, so these windows are enforced on chain and cannot be moved later. The durations below are the proposed defaults; each pool fixes its own at creation.
The pot is every ticket sold plus any sponsorship. The pool states its split in basis points when it is created; this example uses the proposed 70 / 20 / 10. Shares are rounded down, and the rounding remainder goes to fees, so the pieces always add up to the pot exactly.
It sits in the pool's vault from the moment you buy.
You don't have to wait for us to start it.
fail_pool and refund are open to any wallet once the deadline passes under the minimum. The refund pays the full ticket price to you and returns the ticket account's rent to whoever paid it.Whoever sends the refund, the money lands in your wallet.
Price, minimum, deadlines, split and treasuries are fixed.
create_pool and no instruction can edit them. Only the status and the counters move.The pot can't be paid out twice or drained through payouts.
pay_prize refuses any payout that would take the running total above the prize share of the pot, and refuses payouts before the play deadline.Lost keys or a shutdown still end in refunds or the declared split.
expire_pool to refund an unpaid pool. Sweeping an unpaid prize share to a treasury is refused with MustExpire. The admin key can also be handed over in two signed steps.No instruction can send funds to an address of the caller's choosing.
close_pool checks each receiver against the treasuries stored in the pool, and it must leave the vault at exactly zero.Pausing exists for emergencies, not for holding money.
Account rent comes back, and network fees can be covered for you.
| Action | Who | When | Money goes to |
|---|---|---|---|
| Buy a ticket | Player | Open pool before its prep deadline, active pool before its play deadline | The vault |
| Sponsor a pool | Anyone | Same windows as buying | The vault |
| Fail a pool that missed its goal | Anyone | After the prep deadline, under the minimum | Nothing moves yet |
| Refund a ticket | Anyone | While the pool is refunding | The buyer, plus rent back to its payer |
| Cancel an open pool | Admin | Before it goes live | Nothing moves yet; refunds follow |
| Pay a prize | Admin | After the play deadline | A winner, within the prize share |
| Close and split | Admin Anyone | Admin after the play deadline; anyone 14 days later if prizes were paid | The declared seed and fee treasuries |
| Expire an unsettled pool | Anyone | 14 days after the play deadline, no prize paid | Nothing moves yet; full refunds follow |
| Move any money | Game server | Never | It holds no key that can |