Cashout, the whole thing.
Everything the program does, everything it doesn't, and how to use it without getting played. If anything here disagrees with the code, the code wins.
Vision
Turning on-chain gains into money you can spend should be as easy as paying a friend back. It isn't. Centralized exchanges demand documents, freeze accounts, take days and decide who gets to withdraw. The "buy/sell" Telegram groups run on trust and on people getting scammed.
Cashout puts a Solana program in the middle. Not a company with a bank account: a public program with no master key that holds the seller's SOL until they confirm they've been paid, and pays the buyer in the same transaction. Fiat moves person to person through the app they already use. We never touch it.
Three principles that don't move:
- No custody. Cashout has no instruction that can move anyone else's SOL. If we vanish tomorrow, every seller can close their ad and recover their SOL, and every buyer who already paid can open a dispute.
- Everything public. Ads, trades, payment references, arbiter decisions: all on-chain, auditable by anyone.
- Rules over promises. What the program guarantees is written in code. What it doesn't guarantee is written here, under Risks, with no fine print.
2-minute guide
- Install a Solana wallet (Phantom, Solflare, Backpack) and fund it with a little SOL.
- Open the market and hit Connect wallet.
- To sell: "Post a sell ad". Amount, price per SOL, minimum per trade, how you get paid and where. You sign one transaction: the SOL is locked in the ad's vault.
- To buy: pick an ad, enter how much SOL you want and a payment window. Sign: that amount is reserved for you. Pay the seller through the ad's rail and press I've paid with the reference.
- The seller sees the money in their account and presses Confirm payment & release. The SOL arrives in your wallet in that same transaction.
- If something goes wrong, Open dispute. The arbiter resolves on-chain.
Cashing out any token
You don't need to hold SOL to use Cashout. The Exit terminal on the home page and the Cash out a token button in the market take any Solana token: paste the address, enter the amount, and you get a live Jupiter quote to SOL, the price impact for your size, an exit check against pool liquidity, and what that is worth on the rail you choose. Pressing Swap to SOL with Jupiter executes the swap from your wallet (one signature); the SOL lands in your wallet and the sell-ad form opens prefilled with it (second signature locks it in escrow). Cashout never holds the tokens or the SOL in between: the swap is a standard Jupiter transaction signed by you.
Exit check thresholds: price impact under 3% is a clean exit; 3–10% is thin and the terminal suggests splitting into two trades; over 10% means the pool can't absorb your size in one go.
Exit Radar: every launch, read before you click
The Exit Radar is the other half of cashing out: knowing when not to get in. It watches new pump.fun tokens as they appear and, seconds later, publishes what the opening blocks say about each one. It is the same engine that decides when a position is still worth holding, pointed at the launch itself. Open the live feed.
What it reads
- The creation slot. Which wallets bought in the very same slot the token was created, and how much SOL they put in. Humans don't buy in slot zero; bundles do.
- The next five slots. Sniper packs: many wallets filling the first blocks, and whether they are still inside or already sold.
- The dev wallet. How much of the supply it bought at launch, what it holds now, how many tokens it has created before, how many of those ever migrated, and where its SOL came from (an exchange withdrawal reads differently from a fresh wallet funded by a mixer).
- Known wallets. The 273 KOL wallets we vetted on-chain (win rate, median hold, realized PnL), our own elite list (wallets that repeatedly bought winners early) and insider networks we have mapped. A buy from one of them is shown with its track record.
- Repeat bundlers. Wallets we have already seen bundling other launches, with the count. One bundle is a launch; the same six wallets on their fortieth launch is a business.
- The token itself. Transfer fees, freeze or mint authority still live, a recycled ticker reusing the same art, suspicious metadata.
- The market. Age, market cap, liquidity, holders and the current venue from DexScreener and Jupiter.
Flagged and clean
flagged means at least one structural red tag: a bundle at creation, a dev who already dumped, one wallet funding most of the open, a transfer fee, KOLs already out, an insider-network wallet inside. Someone has, in effect, already cashed out on that token before you saw it. clean so far means none of those were found in the opening blocks. It is not a recommendation; clean tokens die every day. It only tells you the launch was not pre-arranged.
Tag glossary
| Tag | Meaning | Why it matters |
|---|---|---|
| BUNDLE · n wallets · x SOL in slot 0 | n wallets bought in the creation slot with x SOL in total. | Supply was taken before any human could click. Those wallets sell into the first wave of real buyers. |
| REPEAT BUNDLERS | Some of those wallets bundled other launches we scanned; ×n is how many times. | A professional operation. The ending is usually the same as their previous launches. |
| DEV SOLD | The creator bought a share of supply at launch and now holds zero. | The person who made the token has already taken the money. |
| ONE WALLET PRINTED n% | A single wallet provided n% of the SOL in the opening. | The chart was painted by one actor, not demand. |
| SNIPERS · n wallets | Three or more wallets filled the five slots after creation and still hold a meaningful share. | Fast sellers sitting above the price you'd pay. |
| SERIAL DEV | The creator has launched many tokens; the second number is how many ever migrated. | A launch factory. Check the ratio: thousands created, a handful migrated. |
| n KOLs INSIDE | Vetted KOL wallets currently holding. Three or more is a crew. | Most vetted KOLs are flippers with a median hold under ten minutes. A crew exits together. |
| n KOLs ALREADY OUT | KOL wallets that bought and already sold. | The attention trade is over. |
| TRANSFER FEE | The mint charges a fee on every transfer. | You lose on the way in and on the way out, and exits are hard to quote. |
| RECYCLED TICKER + ART | Same symbol and image as an earlier token. | Re-launch of something that already died once. |
| INSIDER NETWORK WALLET | A wallet from a cluster we have mapped buying early across related launches. | Coordinated distribution. |
| DEV FUNDED FROM <exchange> | The creator's SOL came from a centralized exchange withdrawal. | Neutral to mildly positive: a traceable origin, not a fresh mixer wallet. |
| FARM n/11 | How many of eleven farm signals fired. | Our composite score for "built to be harvested". |
Tracked wallets
The right column shows buys of young tokens by wallets we track: vetted KOLs with their win rate and median hold, elite wallets with their repeat-winner count and realized gains, and supplier wallets that buy early and distribute. A buy is shown, not endorsed. Many of these wallets make their money selling to the people who follow them.
Limits
- Latency. A token enters the radar once it has a market and at least ninety seconds of history; a reading takes eight to fifteen seconds. Most of the damage in a farm happens after that, not before.
- False negatives. A clean opening can still be dumped by wallets that bought in minute three. The radar reads structure, not intent.
- Sources. On-chain data through our RPC, DexScreener and Jupiter. If any of them lags, a tag can be late or missing.
- No advice. Nothing on the radar tells you to buy, sell or hold. It tells you who was in the room before you.
Case files: following the money
When a launch makes a verifiable promise, we verify it on-chain and publish what we find. Addresses are abbreviated here; every transaction is public on any Solana explorer.
Case 001 · HUMAN (Team Human) · October 4, 2026
The claim. A token launched minutes after a real creator campaign about AI went live. A promoter account with a memecoin bio announced that "100% of the fees are going to the Center for AI Safety". The campaign's website lists its signatories and a pledge; it never mentions a token, a wallet or a donation route. The nonprofit accepts crypto only through its donation portal, which issues no public address.
What we read. The pump.fun bonding-curve account stores the creator: D9Xy…egUa. Its creator-fee vault was empty at the time of reading because the fees had already been claimed.
| UTC | Claimed | Hop 1 (same minute) | Hop 2 |
|---|---|---|---|
| 20:58 | 82.25 SOL | 4q5j…Wh3P then FLYC…cokz | 52.3 · 26.0 · 4.0 SOL into three pool wallets |
| 21:05 | 27.84 SOL | 4q5j…Wh3P then 2cin…4NDK | 24.7 · 3.1 SOL |
| 21:55 | 103.92 SOL | 4q5j…Wh3P then 3R7v…2sJR | 65.1 · 24.7 · 14.1 SOL |
| 22:10 | 44.64 SOL | 4q5j…Wh3P then 8SbW…gWZV | 35.1 · 9.5 SOL |
| 22:14 | 5.83 SOL | 4q5j…Wh3P then BNVh…z1n6 | forwarded |
| 22:18 | 2.28 SOL | 4q5j…Wh3P then 66aS…PAyk | forwarded |
- Every hop-1 wallet was created at the moment of its claim and has exactly two transactions: receive and forward. All sit at zero now.
- Both forwards go through the same program,
RLAYHr9T…47RZu, which splits each amount into two or three outputs to wallets processing more than a hundred transactions a minute. - No step sends anything to a donation address, a known nonprofit processor or a fixed public wallet. Whether a donation happens off-chain later is unknowable from the chain; what is visible is a trail built to end.
- Separately, the launch wallet that bought 14.4% of supply at creation sold it within the first minute for 8.6 SOL.
What this is not. Not an accusation about the campaign or the nonprofit, neither of which announced a token. Not advice. A statement of what the ledger shows, published so the next reader does not have to take a thread's word for it.
Selling SOL, step by step
1. Decide how much, at what price, on which rail
Price is set in US dollars per SOL. The market shows your price against Jupiter's reference so buyers see the premium. Typical P2P premiums: 2 to 6% over market on reversible rails (PayPal Goods & Services), 0 to 3% on irreversible ones (SEPA instant, Zelle, cash).
2. Where you get paid is public
The "contact" field is stored on-chain. Use a PayPal email, a @Revtag, a Zelle alias or a Telegram handle. Don't put your full name or IBAN if you don't want it public forever: write "IBAN via Telegram" instead.
3. Posting locks the SOL
The posting transaction moves the ad's amount into its vault. Until you close the ad, that SOL is not in your wallet. You can close any time: you get back everything not reserved by open trades. Reserved amounts free up as those trades finish.
4. When someone buys
The trade shows up under "My trades" with the window the buyer picked. When they mark it paid, check in your payment app, not in an email, that the money is available. Then release. If the window expires with no payment, cancel and the SOL returns to your ad.
Buying SOL, step by step
Pick an ad by rail and price. Open a trade with the amount (between the ad's minimum and what's available) and the window (15, 30, 45 or 60 minutes). On signing, that amount is reserved: nobody else can buy it and the seller can't withdraw it. Pay exactly what the trade shows, through the named rail, to the named contact, and keep the receipt. Press I've paid and type the reference (PayPal id, transfer note, gift card code). If the seller doesn't release within a reasonable time, open a dispute: the reference you wrote is your main evidence.
The full flow
| Step | Who signs | On-chain | Off-chain |
|---|---|---|---|
| create_ad | Seller | Ad account (PDA) is created and receives the SOL | The ad appears in the market |
| open_trade | Buyer | Trade account is created; the ad moves the amount from "available" to "reserved"; the deadline is set | The buyer sees whom and how much to pay |
| mark_paid | Buyer | State → paid; reference stored | The buyer has sent the money |
| release | Seller | SOL leaves the vault: amount − fee to the buyer, fee to the treasury; state → released | The seller verified the payment |
| cancel | Buyer (before paying) or seller (after the window) | Amount returns from "reserved" to "available"; state → cancelled | Nobody paid |
| dispute | Either party | State → disputed; frozen | Disagreement about the payment |
| resolve | Arbiter | Release to buyer or return to the ad | The arbiter reviewed the evidence |
| close_ad | Seller | Available SOL returns to the wallet; the ad stops accepting trades | The seller is done |
Trade states
| State | Meaning | Can move to |
|---|---|---|
| open | SOL reserved, waiting for the fiat payment | paid (buyer), cancelled (buyer any time; seller after the window), released (seller, if they got paid before the buyer marked it) |
| paid | The buyer declared the payment with a reference | released (seller), disputed (either) |
| released | SOL sent to the buyer, fee to the treasury | final |
| cancelled | SOL returned to the ad | final |
| disputed | Frozen until the arbiter resolves | released or cancelled (arbiter) |
A trade in paid cannot be cancelled by the seller. If a buyer marks paid without paying, the seller opens a dispute and the arbiter returns the SOL. That buyer's wallet carries that record forever.
Windows and cancellations
The buyer picks the window when opening: 15 to 60 minutes. Until it expires the seller cannot cancel: the SOL is reserved for that buyer. Once it expires without "paid", the seller may cancel and the SOL returns to the ad. The buyer may cancel any time before marking paid (for example, if the payment fails). Once marked paid, the only moves are release, dispute or resolve.
Seller tip: if your rail is slow (regular SEPA), write "instant transfers only" in the contact or accept 60-minute windows and confirm through your private channel.
Disputes and the arbiter
The arbiter is a public key fixed in the program's configuration (Config.arbiter). Anyone can read it. Its powers are exactly two, and only on trades in disputed state: release to the buyer (fee to treasury) or return the SOL to the seller's ad. It cannot move SOL to its own wallet or touch trades that aren't disputed.
What counts as evidence: the reference the buyer wrote on-chain, timestamped screenshots of the payment, and both wallets' history. Decisions are published with reasons. Today the arbiter is the team; the roadmap has a 2-of-3 arbiter panel and, later, reputation-elected arbiters.
Fees
| Item | Who pays | How much | When |
|---|---|---|---|
| Cashout fee | Seller | 1% of the amount (100 bps) | Inside the release transaction, to the treasury |
| Solana network fee | Whoever signs | ~0.000005 SOL per signature | Every step |
| Ad account rent | Seller | ~0.0025 SOL, recoverable on close | On posting |
| Trade account rent | Buyer | ~0.0025 SOL | On opening |
| PayPal, Revolut, etc. | Per app | Whatever the app charges | Off-chain |
No fee to post, cancel or dispute. The buyer receives amount − 1% in SOL and pays the full amount in fiat; the seller receives the full amount in fiat and gives up the full amount in SOL. That 1% difference is the fee.
The program: architecture
One Anchor program on Solana, cashout_escrow. No tokens of its own, no external dependencies: only the System Program to move SOL. Accounts are PDAs (program-derived addresses), so nobody holds their private key: only the program can sign for them, and only through the defined instructions.
Config (PDA ["config"]) admin, treasury, arbiter, fee_bps, ads Ad (PDA ["ad", seller, ad_id]) seller, price_cents, min_lamports, available, reserved, trades, method, contact, active Trade (PDA ["trade", ad, index]) ad, seller, buyer, amount, fee, state, opened_at, pay_deadline, paid_at, closed_at, reference
The vault is the ad account itself: its lamports are the sellers' SOL. Each Trade reserves a slice; total reservations never exceed the balance. The program subtracts lamports from an ad only in release, resolve and close_ad, always with the matching signature.
Accounts in detail
Config
| admin | Who initialized the program. Has no power over funds. |
| treasury | Wallet that receives the fee. |
| arbiter | Key that can resolve disputes. |
| fee_bps | Fee in basis points (100 = 1%). Fixed in code. |
| ads | Counter of ads created. |
Ad
| seller | Seller's wallet; the only one that can close and release. |
| price_cents | US cents per 1 SOL. |
| min_lamports | Minimum per trade. |
| available / reserved | Free lamports and lamports reserved by open trades. |
| trades | Counter; each new trade uses trades + 1 as its index. |
| method / contact | Up to 64 bytes each. Public. |
| active | Whether it accepts new trades. |
Trade
| amount / fee | Reserved amount and fee computed at open. |
| state | 0 open · 1 paid · 2 released · 3 cancelled · 4 disputed |
| pay_deadline | Payment deadline (unix). |
| reference | Fiat payment reference written by the buyer (up to 64 bytes). |
Instructions
| Instruction | Signer | Arguments | Checks |
|---|---|---|---|
| init_config | admin | arbiter | Once only (single PDA) |
| create_ad | seller | amount, price_cents, min_lamports, method, contact, ad_id | amount ≥ 0.01 SOL; min ≤ amount; texts ≤ 64 |
| close_ad | seller | — | has_one seller; returns available only |
| open_trade | buyer | amount, window_secs | ad active; min ≤ amount ≤ available; 900 ≤ window ≤ 3600; buyer ≠ seller |
| mark_paid | buyer | reference | state open |
| release | seller | — | state open or paid; buyer and treasury validated by has_one |
| cancel | buyer, or seller after the window | — | state open; seller only if now > pay_deadline |
| dispute | buyer or seller | — | state paid |
| resolve | arbiter | to_buyer | state disputed; arbiter = Config.arbiter |
Program errors
| TooSmall | Minimum 0.01 SOL per ad |
| BadLimits | Minimum per trade exceeds the ad amount |
| TextTooLong | Method, contact or reference longer than 64 bytes |
| NotSeller / NotBuyer / NotParty / NotArbiter | Wrong signer |
| AdClosed | The ad doesn't accept trades |
| BadAmount | Out of limits or not enough available |
| BadWindow | Window outside 15–60 minutes |
| SelfTrade | Trading with yourself |
| BadState | The action isn't valid in this state |
| WindowNotOver | Seller tried to cancel before the deadline |
Integrate: read the market from your own app
There is no private API. Everything is read from the Solana RPC with getProgramAccounts, filtering by the account discriminator (first 8 bytes of sha256("account:Ad") or "account:Trade"). The reference client, app.js, uses no Anchor library: it encodes instructions by hand with Borsh and decodes accounts with DataView. Any bot, aggregator or wallet can list ads, open trades and release.
// instruction discriminator: sha256("global:open_trade")[0..8]
// open_trade accounts: ad (mut), trade (init, PDA ["trade", ad, trades+1]), config, buyer (signer, mut), system_program
// data: disc(8) | amount u64 LE | window_secs i64 LE
Security model
- No master key. No instruction moves SOL to an arbitrary address. The only possible destinations are the trade's buyer, the treasury (fee only) and the ad's seller.
- Bounded arbiter. Acts only on
disputedand only picks between the two legitimate destinations. - No silent upgrades. On mainnet the upgrade authority goes to a public multisig and every change is announced with its hash. End goal: authority revoked.
- No dependencies. No oracles, no external programs: price is an agreement between two people.
- Arithmetic. All amounts are
u64; subtractions from an ad happen only after checking that reserved or available covers the amount.
Threat model: what each party can try
| Attacker | Attempt | Outcome |
|---|---|---|
| Buyer | Marks "paid" without paying | Seller doesn't release; opens dispute; arbiter returns the SOL. Wallet marked on-chain. |
| Buyer | Pays with a reversible rail and charges back later | Real risk. That's why sellers pick rails and price. See Payment rails. |
| Seller | Gets paid and doesn't release | Buyer disputes with the reference; arbiter releases. Seller can't withdraw reserved SOL. |
| Seller | Closes the ad with open trades | Only recovers available; reserved stays locked until each trade ends. |
| Cashout / admin | Takes the SOL | Impossible: no instruction. The admin can do nothing; the arbiter can only resolve between the two legitimate destinations. |
| Arbiter | Resolves wrongly on purpose | Possible. Mitigation: known public key, on-chain record, multisig panel on the roadmap. |
| Third party | Impersonates the payment contact | The contact is on-chain, signed by the seller; the site reads it from there. Pay only the contact the trade shows, never one sent in a chat. |
Payment rails and reversals
| Rail | Reversible | Recommendation |
|---|---|---|
| PayPal Goods & Services | Yes (chargeback up to 180 days) | High-reputation buyers only; 4–6% premium |
| PayPal Friends & Family | Practically no | The P2P standard; 2–4% premium |
| Revolut, Wise, Zelle, Cash App, Venmo | Not in practice | Good for sellers; confirm in the app, not the email |
| SEPA instant / bank transfer | No | Safest for the seller; ask for "instant" |
| Gift cards | Code may be already used | Redeem before releasing; accept only brands you can verify |
| Cash in person | No | Public place; release in front of the buyer |
Seller's golden rule: release when the money is available in your balance, not when you get a notification, an email or a screenshot.
Privacy
Solana is public. Written forever: your wallet, the rail, the contact you post, amounts, references and timestamps. Not written: your name, IP or email, unless you type them into the ad. Use payment aliases and a Telegram handle for sensitive details. Cashout has no server that logs anything: the site is static and talks straight to the RPC.
Risks (read this)
- Fiat counterparty risk. The program protects the SOL, not the cash. A reversible payment can be charged back after release.
- Arbiter risk. A person can be wrong or act badly. Bounded, but real.
- Code risk. The program is new. Until the external review is published, keep amounts sensible.
- Price risk. SOL can move while a trade is open. The price is the ad's price; nobody adjusts it.
- Legal risk. Operating a fiat–crypto P2P market is regulated in many countries (VASP, AML/KYC). Every user is responsible in their jurisdiction. The team will publish its terms before mainnet.
- Impersonation risk. There will be fake sites and tokens with this name. The real program is identified by its address, published here and on the official profile.
Market rules
- Pay only the contact the trade shows on the site, read from the chain. Never one received in a chat.
- Pay the exact amount, within the window. If you can't, cancel before it expires.
- As a seller, release only with the money available in your balance.
- No third-party payments: the paying account must be the buyer's.
- One trade, one reference. Write the real reference: it's your evidence in a dispute.
- Disputes with fake evidence are resolved against you and the wallet is publicly marked.
- Using Cashout to launder money, fund illegal activity or evade sanctions is prohibited. The team cooperates with competent authorities when required.
Reputation
No stars you can buy. Your reputation is your on-chain history: trades released, cancelled on expiry, disputes opened and how they were resolved. The site shows it next to every wallet and anyone can recompute it from the RPC. Roadmap: a composite score (volume, age, dispute ratio) and public blocklists.
How to price
The market shows your price against Jupiter's reference. Usual P2P premiums: 0–2% on irreversible rails with known buyers; 2–4% on PayPal Friends & Family, Revolut or Zelle; 4–8% on gift cards and PayPal Goods & Services. Too high doesn't fill; too low attracts people looking to reverse. Start with small lots and sensible minimums.
Why it exists
Because the last mile of crypto is still broken. You win on-chain and lose on the way out: paperwork, freezes, days of waiting, limits. Informal P2P groups fix speed but not trust. An escrow in a public program fixes trust without putting a company back in the middle of the money. It's the model that made the first-era Bitcoin P2P markets big, except here the custodian isn't a company that can go bankrupt or run: it's code anyone can read.
Comparison
| Cashout | Centralized exchange | Telegram P2P | Outpay (reference) | |
|---|---|---|---|---|
| SOL custody | Program, no master key | The company | Nobody (trust) | Announced, not launched |
| KYC | No (wallet) | Yes | No | No |
| Fiat rails | 30+, the people's own | The exchange's | Any | 38 announced |
| Fee | 1% seller | 0.1–1.5% + spread + withdrawal | 0, plus scams | 1% illustrative |
| Status | Program live, working site | Live | Live | Mockup ("design preview") |
Roadmap
| Phase | What | Status |
|---|---|---|
| 0 · Launch | Escrow program, web market, documentation | Now |
| 1 · Harden | Automated tests, external program review, upgrade authority in a multisig | Next |
| 2 · Mainnet | Deployment, 2-of-3 arbiter panel, reputation panel, jurisdiction notice | After review |
| 3 · SPL tokens | Ads in USDC and pump.fun tokens with the same vault | Design |
| 4 · Open | Reputation-elected arbiters, SDK, wallet and Telegram bot integrations | Idea |
Token: $CASH
Cashout will have one token, $CASH, launched on pump.fun. These rules were written before the contract address existed and every one of them is verifiable on-chain after.
- 100% of creator fees buy back and burn $CASH, every 30 minutes. Creator fees are claimed into one public fee wallet. Every 30 minutes that wallet swaps its whole balance above a small gas reserve into $CASH and burns it. No treasury, no market-making wallet, no discretionary spending. The live ledger with every claim, buy and burn is at cashoutexit.com/cash.
- The fee wallet only ever does three things: claim fees, buy $CASH, burn $CASH. Any other transaction from it is a broken promise, visible on the ledger page and flagged by the radar like any other launch.
- No hidden allocation. The team buys on the curve like everyone else, from one public wallet listed on the ledger page, and does not sell that allocation for 90 days.
- The CA is published on this site and on @cashoutexit at the same moment, nowhere else. Any token using this name before that is fake. The radar will read our own launch with the same rules it applies to everyone.
What $CASH is not: it is not required to use the market or the radar, it carries no rights over the program, and nothing here is advice to buy it.
Legal
Cashout is software. The escrow program does not custody fiat or intermediate payments: it lets two people exchange SOL for a payment they make between themselves. Depending on the country, operating or using such a market may require licenses or carry tax obligations. Before mainnet the team will publish where it operates, which terms apply and which countries are excluded. Nothing on this site is financial, legal or tax advice.
FAQ
Can Cashout freeze my SOL?
No. There is no instruction for it. Only you (close ad or cancel), the buyer (cancel before paying) or the arbiter (in a dispute) change the state of your SOL.
What if the site disappears?
The program stays on Solana. Anyone can host the client (it's static) or call the program directly. Your SOL doesn't depend on our site.
Is the program audited?
It is new and under open review. The source is public, the program address is published here, and every change is announced with its hash.
Can I sell memecoins directly?
Not yet: v1 is native SOL. Sell the token for SOL on a DEX and post. The SPL vault is phase 3.
What do PayPal/Revolut charge?
Their own fees; Cashout neither sees nor controls them. Build them into your price.
Are there limits?
Minimum 0.01 SOL per ad. No maximum in the program. Start small with new counterparties.
Who can be an arbiter?
Today, the key fixed in Config. Later, a multisig panel and, after that, arbiters elected by on-chain reputation.
Glossary
| Escrow | Funds held by a third party until a condition is met. Here the third party is a program. |
| PDA | Program-derived address: an account with no private key that only the program controls. |
| Lamport | The smallest unit of SOL: 1 SOL = 1,000,000,000 lamports. |
| Ad | A funded sell offer: locked SOL, price, rail and contact. |
| Trade | A buyer's reservation of part of an ad, with a window and a state. |
| Release | The seller's transaction that pays the buyer and the fee to the treasury. |
| Dispute | A frozen state only the arbiter can resolve. |
| Reference | The fiat payment detail (id, note, code) the buyer writes on-chain. |
Changelog
- 2026-10-04 · v0.1 —
cashout_escrowprogram: config, funded ads, trades with windows, payment, release, cancel, dispute and resolve. Static web client with no backend. Initial documentation.