Documentation

Cashout, the whole thing.

Everything the program does, everything it doesn't, and how to use it without getting played. If anything here disagrees with the code, the code wins.

The program, the rules and this document can change; every change lands in the changelog with its program hash.

Vision

Turning on-chain gains into money you can spend should be as easy as paying a friend back. It isn't. Centralized exchanges demand documents, freeze accounts, take days and decide who gets to withdraw. The "buy/sell" Telegram groups run on trust and on people getting scammed.

Cashout puts a Solana program in the middle. Not a company with a bank account: a public program with no master key that holds the seller's SOL until they confirm they've been paid, and pays the buyer in the same transaction. Fiat moves person to person through the app they already use. We never touch it.

Three principles that don't move:

  • No custody. Cashout has no instruction that can move anyone else's SOL. If we vanish tomorrow, every seller can close their ad and recover their SOL, and every buyer who already paid can open a dispute.
  • Everything public. Ads, trades, payment references, arbiter decisions: all on-chain, auditable by anyone.
  • Rules over promises. What the program guarantees is written in code. What it doesn't guarantee is written here, under Risks, with no fine print.

2-minute guide

  1. Install a Solana wallet (Phantom, Solflare, Backpack) and fund it with a little SOL.
  2. Open the market and hit Connect wallet.
  3. To sell: "Post a sell ad". Amount, price per SOL, minimum per trade, how you get paid and where. You sign one transaction: the SOL is locked in the ad's vault.
  4. To buy: pick an ad, enter how much SOL you want and a payment window. Sign: that amount is reserved for you. Pay the seller through the ad's rail and press I've paid with the reference.
  5. The seller sees the money in their account and presses Confirm payment & release. The SOL arrives in your wallet in that same transaction.
  6. If something goes wrong, Open dispute. The arbiter resolves on-chain.

Cashing out any token

You don't need to hold SOL to use Cashout. The Exit terminal on the home page and the Cash out a token button in the market take any Solana token: paste the address, enter the amount, and you get a live Jupiter quote to SOL, the price impact for your size, an exit check against pool liquidity, and what that is worth on the rail you choose. Pressing Swap to SOL with Jupiter executes the swap from your wallet (one signature); the SOL lands in your wallet and the sell-ad form opens prefilled with it (second signature locks it in escrow). Cashout never holds the tokens or the SOL in between: the swap is a standard Jupiter transaction signed by you.

Exit check thresholds: price impact under 3% is a clean exit; 3–10% is thin and the terminal suggests splitting into two trades; over 10% means the pool can't absorb your size in one go.

Exit Radar: every launch, read before you click

The Exit Radar is the other half of cashing out: knowing when not to get in. It watches new pump.fun tokens as they appear and, seconds later, publishes what the opening blocks say about each one. It is the same engine that decides when a position is still worth holding, pointed at the launch itself. Open the live feed.

What it reads

  • The creation slot. Which wallets bought in the very same slot the token was created, and how much SOL they put in. Humans don't buy in slot zero; bundles do.
  • The next five slots. Sniper packs: many wallets filling the first blocks, and whether they are still inside or already sold.
  • The dev wallet. How much of the supply it bought at launch, what it holds now, how many tokens it has created before, how many of those ever migrated, and where its SOL came from (an exchange withdrawal reads differently from a fresh wallet funded by a mixer).
  • Known wallets. The 273 KOL wallets we vetted on-chain (win rate, median hold, realized PnL), our own elite list (wallets that repeatedly bought winners early) and insider networks we have mapped. A buy from one of them is shown with its track record.
  • Repeat bundlers. Wallets we have already seen bundling other launches, with the count. One bundle is a launch; the same six wallets on their fortieth launch is a business.
  • The token itself. Transfer fees, freeze or mint authority still live, a recycled ticker reusing the same art, suspicious metadata.
  • The market. Age, market cap, liquidity, holders and the current venue from DexScreener and Jupiter.

Flagged and clean

flagged means at least one structural red tag: a bundle at creation, a dev who already dumped, one wallet funding most of the open, a transfer fee, KOLs already out, an insider-network wallet inside. Someone has, in effect, already cashed out on that token before you saw it. clean so far means none of those were found in the opening blocks. It is not a recommendation; clean tokens die every day. It only tells you the launch was not pre-arranged.

Tag glossary

TagMeaningWhy it matters
BUNDLE · n wallets · x SOL in slot 0n wallets bought in the creation slot with x SOL in total.Supply was taken before any human could click. Those wallets sell into the first wave of real buyers.
REPEAT BUNDLERSSome of those wallets bundled other launches we scanned; ×n is how many times.A professional operation. The ending is usually the same as their previous launches.
DEV SOLDThe creator bought a share of supply at launch and now holds zero.The person who made the token has already taken the money.
ONE WALLET PRINTED n%A single wallet provided n% of the SOL in the opening.The chart was painted by one actor, not demand.
SNIPERS · n walletsThree or more wallets filled the five slots after creation and still hold a meaningful share.Fast sellers sitting above the price you'd pay.
SERIAL DEVThe creator has launched many tokens; the second number is how many ever migrated.A launch factory. Check the ratio: thousands created, a handful migrated.
n KOLs INSIDEVetted KOL wallets currently holding. Three or more is a crew.Most vetted KOLs are flippers with a median hold under ten minutes. A crew exits together.
n KOLs ALREADY OUTKOL wallets that bought and already sold.The attention trade is over.
TRANSFER FEEThe mint charges a fee on every transfer.You lose on the way in and on the way out, and exits are hard to quote.
RECYCLED TICKER + ARTSame symbol and image as an earlier token.Re-launch of something that already died once.
INSIDER NETWORK WALLETA wallet from a cluster we have mapped buying early across related launches.Coordinated distribution.
DEV FUNDED FROM <exchange>The creator's SOL came from a centralized exchange withdrawal.Neutral to mildly positive: a traceable origin, not a fresh mixer wallet.
FARM n/11How many of eleven farm signals fired.Our composite score for "built to be harvested".

Tracked wallets

The right column shows buys of young tokens by wallets we track: vetted KOLs with their win rate and median hold, elite wallets with their repeat-winner count and realized gains, and supplier wallets that buy early and distribute. A buy is shown, not endorsed. Many of these wallets make their money selling to the people who follow them.

Limits

  • Latency. A token enters the radar once it has a market and at least ninety seconds of history; a reading takes eight to fifteen seconds. Most of the damage in a farm happens after that, not before.
  • False negatives. A clean opening can still be dumped by wallets that bought in minute three. The radar reads structure, not intent.
  • Sources. On-chain data through our RPC, DexScreener and Jupiter. If any of them lags, a tag can be late or missing.
  • No advice. Nothing on the radar tells you to buy, sell or hold. It tells you who was in the room before you.

Case files: following the money

When a launch makes a verifiable promise, we verify it on-chain and publish what we find. Addresses are abbreviated here; every transaction is public on any Solana explorer.

Case 001 · HUMAN (Team Human) · October 4, 2026

The claim. A token launched minutes after a real creator campaign about AI went live. A promoter account with a memecoin bio announced that "100% of the fees are going to the Center for AI Safety". The campaign's website lists its signatories and a pledge; it never mentions a token, a wallet or a donation route. The nonprofit accepts crypto only through its donation portal, which issues no public address.

What we read. The pump.fun bonding-curve account stores the creator: D9Xy…egUa. Its creator-fee vault was empty at the time of reading because the fees had already been claimed.

UTCClaimedHop 1 (same minute)Hop 2
20:5882.25 SOL4q5j…Wh3P then FLYC…cokz52.3 · 26.0 · 4.0 SOL into three pool wallets
21:0527.84 SOL4q5j…Wh3P then 2cin…4NDK24.7 · 3.1 SOL
21:55103.92 SOL4q5j…Wh3P then 3R7v…2sJR65.1 · 24.7 · 14.1 SOL
22:1044.64 SOL4q5j…Wh3P then 8SbW…gWZV35.1 · 9.5 SOL
22:145.83 SOL4q5j…Wh3P then BNVh…z1n6forwarded
22:182.28 SOL4q5j…Wh3P then 66aS…PAykforwarded
  • Every hop-1 wallet was created at the moment of its claim and has exactly two transactions: receive and forward. All sit at zero now.
  • Both forwards go through the same program, RLAYHr9T…47RZu, which splits each amount into two or three outputs to wallets processing more than a hundred transactions a minute.
  • No step sends anything to a donation address, a known nonprofit processor or a fixed public wallet. Whether a donation happens off-chain later is unknowable from the chain; what is visible is a trail built to end.
  • Separately, the launch wallet that bought 14.4% of supply at creation sold it within the first minute for 8.6 SOL.

What this is not. Not an accusation about the campaign or the nonprofit, neither of which announced a token. Not advice. A statement of what the ledger shows, published so the next reader does not have to take a thread's word for it.

Selling SOL, step by step

1. Decide how much, at what price, on which rail

Price is set in US dollars per SOL. The market shows your price against Jupiter's reference so buyers see the premium. Typical P2P premiums: 2 to 6% over market on reversible rails (PayPal Goods & Services), 0 to 3% on irreversible ones (SEPA instant, Zelle, cash).

2. Where you get paid is public

The "contact" field is stored on-chain. Use a PayPal email, a @Revtag, a Zelle alias or a Telegram handle. Don't put your full name or IBAN if you don't want it public forever: write "IBAN via Telegram" instead.

3. Posting locks the SOL

The posting transaction moves the ad's amount into its vault. Until you close the ad, that SOL is not in your wallet. You can close any time: you get back everything not reserved by open trades. Reserved amounts free up as those trades finish.

4. When someone buys

The trade shows up under "My trades" with the window the buyer picked. When they mark it paid, check in your payment app, not in an email, that the money is available. Then release. If the window expires with no payment, cancel and the SOL returns to your ad.

Buying SOL, step by step

Pick an ad by rail and price. Open a trade with the amount (between the ad's minimum and what's available) and the window (15, 30, 45 or 60 minutes). On signing, that amount is reserved: nobody else can buy it and the seller can't withdraw it. Pay exactly what the trade shows, through the named rail, to the named contact, and keep the receipt. Press I've paid and type the reference (PayPal id, transfer note, gift card code). If the seller doesn't release within a reasonable time, open a dispute: the reference you wrote is your main evidence.

The full flow

StepWho signsOn-chainOff-chain
create_adSellerAd account (PDA) is created and receives the SOLThe ad appears in the market
open_tradeBuyerTrade account is created; the ad moves the amount from "available" to "reserved"; the deadline is setThe buyer sees whom and how much to pay
mark_paidBuyerState → paid; reference storedThe buyer has sent the money
releaseSellerSOL leaves the vault: amount − fee to the buyer, fee to the treasury; state → releasedThe seller verified the payment
cancelBuyer (before paying) or seller (after the window)Amount returns from "reserved" to "available"; state → cancelledNobody paid
disputeEither partyState → disputed; frozenDisagreement about the payment
resolveArbiterRelease to buyer or return to the adThe arbiter reviewed the evidence
close_adSellerAvailable SOL returns to the wallet; the ad stops accepting tradesThe seller is done

Trade states

StateMeaningCan move to
openSOL reserved, waiting for the fiat paymentpaid (buyer), cancelled (buyer any time; seller after the window), released (seller, if they got paid before the buyer marked it)
paidThe buyer declared the payment with a referencereleased (seller), disputed (either)
releasedSOL sent to the buyer, fee to the treasuryfinal
cancelledSOL returned to the adfinal
disputedFrozen until the arbiter resolvesreleased or cancelled (arbiter)

A trade in paid cannot be cancelled by the seller. If a buyer marks paid without paying, the seller opens a dispute and the arbiter returns the SOL. That buyer's wallet carries that record forever.

Windows and cancellations

The buyer picks the window when opening: 15 to 60 minutes. Until it expires the seller cannot cancel: the SOL is reserved for that buyer. Once it expires without "paid", the seller may cancel and the SOL returns to the ad. The buyer may cancel any time before marking paid (for example, if the payment fails). Once marked paid, the only moves are release, dispute or resolve.

Seller tip: if your rail is slow (regular SEPA), write "instant transfers only" in the contact or accept 60-minute windows and confirm through your private channel.

Disputes and the arbiter

The arbiter is a public key fixed in the program's configuration (Config.arbiter). Anyone can read it. Its powers are exactly two, and only on trades in disputed state: release to the buyer (fee to treasury) or return the SOL to the seller's ad. It cannot move SOL to its own wallet or touch trades that aren't disputed.

What counts as evidence: the reference the buyer wrote on-chain, timestamped screenshots of the payment, and both wallets' history. Decisions are published with reasons. Today the arbiter is the team; the roadmap has a 2-of-3 arbiter panel and, later, reputation-elected arbiters.

Fees

ItemWho paysHow muchWhen
Cashout feeSeller1% of the amount (100 bps)Inside the release transaction, to the treasury
Solana network feeWhoever signs~0.000005 SOL per signatureEvery step
Ad account rentSeller~0.0025 SOL, recoverable on closeOn posting
Trade account rentBuyer~0.0025 SOLOn opening
PayPal, Revolut, etc.Per appWhatever the app chargesOff-chain

No fee to post, cancel or dispute. The buyer receives amount − 1% in SOL and pays the full amount in fiat; the seller receives the full amount in fiat and gives up the full amount in SOL. That 1% difference is the fee.

The program: architecture

One Anchor program on Solana, cashout_escrow. No tokens of its own, no external dependencies: only the System Program to move SOL. Accounts are PDAs (program-derived addresses), so nobody holds their private key: only the program can sign for them, and only through the defined instructions.

Config  (PDA ["config"])                 admin, treasury, arbiter, fee_bps, ads
Ad      (PDA ["ad", seller, ad_id])       seller, price_cents, min_lamports, available, reserved, trades, method, contact, active
Trade   (PDA ["trade", ad, index])        ad, seller, buyer, amount, fee, state, opened_at, pay_deadline, paid_at, closed_at, reference

The vault is the ad account itself: its lamports are the sellers' SOL. Each Trade reserves a slice; total reservations never exceed the balance. The program subtracts lamports from an ad only in release, resolve and close_ad, always with the matching signature.

Accounts in detail

Config

adminWho initialized the program. Has no power over funds.
treasuryWallet that receives the fee.
arbiterKey that can resolve disputes.
fee_bpsFee in basis points (100 = 1%). Fixed in code.
adsCounter of ads created.

Ad

sellerSeller's wallet; the only one that can close and release.
price_centsUS cents per 1 SOL.
min_lamportsMinimum per trade.
available / reservedFree lamports and lamports reserved by open trades.
tradesCounter; each new trade uses trades + 1 as its index.
method / contactUp to 64 bytes each. Public.
activeWhether it accepts new trades.

Trade

amount / feeReserved amount and fee computed at open.
state0 open · 1 paid · 2 released · 3 cancelled · 4 disputed
pay_deadlinePayment deadline (unix).
referenceFiat payment reference written by the buyer (up to 64 bytes).

Instructions

InstructionSignerArgumentsChecks
init_configadminarbiterOnce only (single PDA)
create_adselleramount, price_cents, min_lamports, method, contact, ad_idamount ≥ 0.01 SOL; min ≤ amount; texts ≤ 64
close_adseller—has_one seller; returns available only
open_tradebuyeramount, window_secsad active; min ≤ amount ≤ available; 900 ≤ window ≤ 3600; buyer ≠ seller
mark_paidbuyerreferencestate open
releaseseller—state open or paid; buyer and treasury validated by has_one
cancelbuyer, or seller after the window—state open; seller only if now > pay_deadline
disputebuyer or seller—state paid
resolvearbiterto_buyerstate disputed; arbiter = Config.arbiter

Program errors

TooSmallMinimum 0.01 SOL per ad
BadLimitsMinimum per trade exceeds the ad amount
TextTooLongMethod, contact or reference longer than 64 bytes
NotSeller / NotBuyer / NotParty / NotArbiterWrong signer
AdClosedThe ad doesn't accept trades
BadAmountOut of limits or not enough available
BadWindowWindow outside 15–60 minutes
SelfTradeTrading with yourself
BadStateThe action isn't valid in this state
WindowNotOverSeller tried to cancel before the deadline

Integrate: read the market from your own app

There is no private API. Everything is read from the Solana RPC with getProgramAccounts, filtering by the account discriminator (first 8 bytes of sha256("account:Ad") or "account:Trade"). The reference client, app.js, uses no Anchor library: it encodes instructions by hand with Borsh and decodes accounts with DataView. Any bot, aggregator or wallet can list ads, open trades and release.

// instruction discriminator: sha256("global:open_trade")[0..8]
// open_trade accounts: ad (mut), trade (init, PDA ["trade", ad, trades+1]), config, buyer (signer, mut), system_program
// data: disc(8) | amount u64 LE | window_secs i64 LE

Security model

  • No master key. No instruction moves SOL to an arbitrary address. The only possible destinations are the trade's buyer, the treasury (fee only) and the ad's seller.
  • Bounded arbiter. Acts only on disputed and only picks between the two legitimate destinations.
  • No silent upgrades. On mainnet the upgrade authority goes to a public multisig and every change is announced with its hash. End goal: authority revoked.
  • No dependencies. No oracles, no external programs: price is an agreement between two people.
  • Arithmetic. All amounts are u64; subtractions from an ad happen only after checking that reserved or available covers the amount.

Threat model: what each party can try

AttackerAttemptOutcome
BuyerMarks "paid" without payingSeller doesn't release; opens dispute; arbiter returns the SOL. Wallet marked on-chain.
BuyerPays with a reversible rail and charges back laterReal risk. That's why sellers pick rails and price. See Payment rails.
SellerGets paid and doesn't releaseBuyer disputes with the reference; arbiter releases. Seller can't withdraw reserved SOL.
SellerCloses the ad with open tradesOnly recovers available; reserved stays locked until each trade ends.
Cashout / adminTakes the SOLImpossible: no instruction. The admin can do nothing; the arbiter can only resolve between the two legitimate destinations.
ArbiterResolves wrongly on purposePossible. Mitigation: known public key, on-chain record, multisig panel on the roadmap.
Third partyImpersonates the payment contactThe contact is on-chain, signed by the seller; the site reads it from there. Pay only the contact the trade shows, never one sent in a chat.

Payment rails and reversals

RailReversibleRecommendation
PayPal Goods & ServicesYes (chargeback up to 180 days)High-reputation buyers only; 4–6% premium
PayPal Friends & FamilyPractically noThe P2P standard; 2–4% premium
Revolut, Wise, Zelle, Cash App, VenmoNot in practiceGood for sellers; confirm in the app, not the email
SEPA instant / bank transferNoSafest for the seller; ask for "instant"
Gift cardsCode may be already usedRedeem before releasing; accept only brands you can verify
Cash in personNoPublic place; release in front of the buyer

Seller's golden rule: release when the money is available in your balance, not when you get a notification, an email or a screenshot.

Privacy

Solana is public. Written forever: your wallet, the rail, the contact you post, amounts, references and timestamps. Not written: your name, IP or email, unless you type them into the ad. Use payment aliases and a Telegram handle for sensitive details. Cashout has no server that logs anything: the site is static and talks straight to the RPC.

Risks (read this)

  • Fiat counterparty risk. The program protects the SOL, not the cash. A reversible payment can be charged back after release.
  • Arbiter risk. A person can be wrong or act badly. Bounded, but real.
  • Code risk. The program is new. Until the external review is published, keep amounts sensible.
  • Price risk. SOL can move while a trade is open. The price is the ad's price; nobody adjusts it.
  • Legal risk. Operating a fiat–crypto P2P market is regulated in many countries (VASP, AML/KYC). Every user is responsible in their jurisdiction. The team will publish its terms before mainnet.
  • Impersonation risk. There will be fake sites and tokens with this name. The real program is identified by its address, published here and on the official profile.

Market rules

  1. Pay only the contact the trade shows on the site, read from the chain. Never one received in a chat.
  2. Pay the exact amount, within the window. If you can't, cancel before it expires.
  3. As a seller, release only with the money available in your balance.
  4. No third-party payments: the paying account must be the buyer's.
  5. One trade, one reference. Write the real reference: it's your evidence in a dispute.
  6. Disputes with fake evidence are resolved against you and the wallet is publicly marked.
  7. Using Cashout to launder money, fund illegal activity or evade sanctions is prohibited. The team cooperates with competent authorities when required.

Reputation

No stars you can buy. Your reputation is your on-chain history: trades released, cancelled on expiry, disputes opened and how they were resolved. The site shows it next to every wallet and anyone can recompute it from the RPC. Roadmap: a composite score (volume, age, dispute ratio) and public blocklists.

How to price

The market shows your price against Jupiter's reference. Usual P2P premiums: 0–2% on irreversible rails with known buyers; 2–4% on PayPal Friends & Family, Revolut or Zelle; 4–8% on gift cards and PayPal Goods & Services. Too high doesn't fill; too low attracts people looking to reverse. Start with small lots and sensible minimums.

Why it exists

Because the last mile of crypto is still broken. You win on-chain and lose on the way out: paperwork, freezes, days of waiting, limits. Informal P2P groups fix speed but not trust. An escrow in a public program fixes trust without putting a company back in the middle of the money. It's the model that made the first-era Bitcoin P2P markets big, except here the custodian isn't a company that can go bankrupt or run: it's code anyone can read.

Comparison

CashoutCentralized exchangeTelegram P2POutpay (reference)
SOL custodyProgram, no master keyThe companyNobody (trust)Announced, not launched
KYCNo (wallet)YesNoNo
Fiat rails30+, the people's ownThe exchange'sAny38 announced
Fee1% seller0.1–1.5% + spread + withdrawal0, plus scams1% illustrative
StatusProgram live, working siteLiveLiveMockup ("design preview")

Roadmap

PhaseWhatStatus
0 · LaunchEscrow program, web market, documentationNow
1 · HardenAutomated tests, external program review, upgrade authority in a multisigNext
2 · MainnetDeployment, 2-of-3 arbiter panel, reputation panel, jurisdiction noticeAfter review
3 · SPL tokensAds in USDC and pump.fun tokens with the same vaultDesign
4 · OpenReputation-elected arbiters, SDK, wallet and Telegram bot integrationsIdea

Token: $CASH

Cashout will have one token, $CASH, launched on pump.fun. These rules were written before the contract address existed and every one of them is verifiable on-chain after.

  1. 100% of creator fees buy back and burn $CASH, every 30 minutes. Creator fees are claimed into one public fee wallet. Every 30 minutes that wallet swaps its whole balance above a small gas reserve into $CASH and burns it. No treasury, no market-making wallet, no discretionary spending. The live ledger with every claim, buy and burn is at cashoutexit.com/cash.
  2. The fee wallet only ever does three things: claim fees, buy $CASH, burn $CASH. Any other transaction from it is a broken promise, visible on the ledger page and flagged by the radar like any other launch.
  3. No hidden allocation. The team buys on the curve like everyone else, from one public wallet listed on the ledger page, and does not sell that allocation for 90 days.
  4. The CA is published on this site and on @cashoutexit at the same moment, nowhere else. Any token using this name before that is fake. The radar will read our own launch with the same rules it applies to everyone.

What $CASH is not: it is not required to use the market or the radar, it carries no rights over the program, and nothing here is advice to buy it.

Cashout is software. The escrow program does not custody fiat or intermediate payments: it lets two people exchange SOL for a payment they make between themselves. Depending on the country, operating or using such a market may require licenses or carry tax obligations. Before mainnet the team will publish where it operates, which terms apply and which countries are excluded. Nothing on this site is financial, legal or tax advice.

FAQ

Can Cashout freeze my SOL?

No. There is no instruction for it. Only you (close ad or cancel), the buyer (cancel before paying) or the arbiter (in a dispute) change the state of your SOL.

What if the site disappears?

The program stays on Solana. Anyone can host the client (it's static) or call the program directly. Your SOL doesn't depend on our site.

Is the program audited?

It is new and under open review. The source is public, the program address is published here, and every change is announced with its hash.

Can I sell memecoins directly?

Not yet: v1 is native SOL. Sell the token for SOL on a DEX and post. The SPL vault is phase 3.

What do PayPal/Revolut charge?

Their own fees; Cashout neither sees nor controls them. Build them into your price.

Are there limits?

Minimum 0.01 SOL per ad. No maximum in the program. Start small with new counterparties.

Who can be an arbiter?

Today, the key fixed in Config. Later, a multisig panel and, after that, arbiters elected by on-chain reputation.

Glossary

EscrowFunds held by a third party until a condition is met. Here the third party is a program.
PDAProgram-derived address: an account with no private key that only the program controls.
LamportThe smallest unit of SOL: 1 SOL = 1,000,000,000 lamports.
AdA funded sell offer: locked SOL, price, rail and contact.
TradeA buyer's reservation of part of an ad, with a window and a state.
ReleaseThe seller's transaction that pays the buyer and the fee to the treasury.
DisputeA frozen state only the arbiter can resolve.
ReferenceThe fiat payment detail (id, note, code) the buyer writes on-chain.

Changelog

  • 2026-10-04 · v0.1 — cashout_escrow program: config, funded ads, trades with windows, payment, release, cancel, dispute and resolve. Static web client with no backend. Initial documentation.