HOW IT PAYS
Shillpay is an escrow between a coin's dev and a KOL. The dev locks SOL for one post with the coin's CA. The KOL gets it when the post is up and still up after the hold. Otherwise the dev gets 100 % back.
The deal
- Open. The dev picks a KOL and a coin and locks the KOL's price plus the fee (0 % for coins launched here). The KOL has 24 hours to accept; otherwise the dev can take it all back.
- Accept. The KOL accepts. From now he has 24 hours to post.
- Post. He posts on X and pastes the link on Shillpay. The post checker reads it and signs a confirmation; the hold starts.
- Hold. 24 hours. Four checks at times committed at confirmation, then a final check at the end.
- Settle. A signed verdict waits 2 hours (guardian veto). Then anyone can settle: post up = paid to the KOL, post gone = 100 % back to the dev.
What counts as a post
- From the X account the KOL bound to his wallet, matched by X user id (a handle rename does not break it).
- Created after he accepted the deal (60 s tolerance).
- The CA in the text or in a link (pump.fun, dexscreener). Long posts are cut at about 280 characters by the reader: put the CA in the first lines.
- "#ad" in the post (paid promotion).
- Not a reply. A new post or a quote.
- Edits are followed to the newest version: editing the CA out fails the check.
- One post serves one deal.
The checks
The checker reads public X data without a key from two sources (the embed data and the oEmbed endpoint). At confirmation it commits to a secret seed (its hash goes on chain); the four check times are drawn from that seed between the first and the last hour of the hold. Nobody, the KOL included, can see them in advance. The seed is revealed with the verdict, so anyone can recompute the times.
"Gone" means a tombstone or not-found answer from both sources, seen twice at least 5 minutes apart. Protected, suspended or withheld counts as gone. X errors, rate limits and timeouts never count as gone. Every read's raw JSON is published in the deal's report, and its hash is in the signed verdict.
Exits that need no checker
- The dev can cancel while the deal is open (100 % back).
- The dev can release to the KOL at any time after accept.
- The KOL can refund the dev at any time after accept.
- Not accepted in time, or no post in time: anyone can settle a 100 % refund.
- The checker silent for 24 hours after the hold of a confirmed post: anyone can settle and the KOL is paid. The post was proven; an outage of our checker must not take his pay.
The deal is about the hold window. A KOL who deletes the post after the final check is out of scope.
Fees
| What | Fee | When |
|---|---|---|
| Deal, coin launched elsewhere | 2.5 % | Paid by the dev on top of the KOL's price, taken only when the KOL is paid. A refund returns 100 %. |
| Deal, coin launched on Shillpay | 0 % | Always. |
| Launch | 0.02 SOL | Flat. pump.fun's create with you as the creator: 100 % of the creator fee stays yours. |
Scores
For every confirmed post the service takes the coin's median trade price in the 15 minutes before the post and around 1 h and 24 h after it, from pump.fun trades on chain, and publishes the transaction signatures it used. No trades in a window: "n/a". A flag shows when the KOL's bound wallet traded the coin within 24 h of his post. Front-running cannot be prevented, only shown. Scores are information, not money; followers are self-declared.
Parameters
| Deal size | 0.05 - 25 SOL |
| Accept window | 24 hours |
| Post window | 24 hours |
| Hold | 24 hours |
| Verdict grace (silent checker pays the KOL after) | 24 hours |
| Guardian veto | 2 hours |
| X account age | 90 days |
| Bind age before taking deals | 1 day |
| "#ad" required | yes |
Read live from the program's config. A change needs a proposal and a 24 h timelock.
Trust points
- The program cannot read X. An attestor key signs what the checker saw. It decides what happened, never how much: amounts and payees are fixed in each deal when the dev opens it. It can only move one deal's own escrow between that deal's dev and KOL, and never receives money.
- Guardian veto. Every verdict waits 2 hours. A guardian process re-reads the post and vetoes a verdict that does not match. The guardian can revoke the attestor at once. Disputes from the deal page ping the guardian.
- Collusion bound. An attestor colluding with a KOL or a dev can only affect deals that are on hold, each at most 25 SOL, and only toward that deal's own parties.
- X data is public but undocumented. If X changes it, checks turn "unknown", never "gone"; then the timeouts above decide.
- Key rotation of the attestor or guardian takes a 3-day timelock.
- Program
- ...
- Attestor
- ...
- Guardian
- ...
- Treasury
- ...