Pre-audit application · Colosseum Crypto World's Fair

riff.

Community coins for music on Solana, where every trade pays the artist, and the artist's identity is verified on-chain.

github.com/use-riff/riff

riffpad.fun (devnet)

@useRiffPad

The problem

Anyone can launch a coin in an artist's name.

Nothing says what's real

A coin called $DRAKE takes seconds to make, and nothing on-chain says whether Drake is behind it.

One hacked account is enough

Hijacked Instagram accounts of Adele, Future, Tyla and the Michael Jackson estate pushed a fake Solana memecoin to about $900k before it was dumped.

The artist gets nothing

Coins trade on the artist's name and their fans' money, and none of it reaches the artist.

Source: BitDegree, "Celebrity Instagram accounts hacked to pump fake Solana meme coin"

02

How it works

A riff coin, from launch to payout.

01 · launch

Anyone launches a coin for an artist. 1B tokens, fixed; mint and freeze authority revoked.

02 · trade

A bonding curve prices it. Each trade pays 1%: 0.5% artist, 0.2% creator, 0.3% riff.

03 · graduate

When the curve sells out, liquidity moves to a Raydium CPMM pool and the LP tokens are burned.

04 · claim

The artist verifies and claims their share. Unclaimed after the window, it goes to music charity.

riff · pre-audit application

03

Architecture

Two Anchor programs, one narrow link.

riff

14 instructions · ~2,100 lines of Rust

  • Coins, bonding curve, fee split
  • Artist claim and charity sweep
  • Graduation into Raydium CPMM

CPI into riff's own claim_artist and withdraw_artist_fees; the passport vault signs with its PDA seeds. riff needs no change.

riff-passport

16 instructions · ~1,400 lines of Rust

  • Multi-proof artist identity
  • Passkey 2FA (secp256r1)
  • Recovery, vault, endorsements

The only off-chain signer either program trusts is riff's verifier: it can link an unclaimed coin to a wallet and attest identity proofs. It can't move curve SOL, fees or vault funds.

Anchor 1.2 · Rust 1.89 · SBPF v0 · Token-2022

04

Design

Rules the riff program enforces.

Fixed supply

Mint and freeze authority revoked at launch.

No launch sniping

Only the creator's capped buy happens in the launch slot.

Solvency on every payout

All SOL leaves a coin through one function that re-checks rent plus everything owed.

Rounding favours the curve

Quotes round against the trader, so every token can be repaid.

Graduation can't be blocked

The pool address is a riff PDA; donated tokens or SOL are ignored.

Three places for the artist's share

Held for the artist, paid to the claimed artist, or swept to charity.

Full list and reasoning: README "Design notes" and docs/AUDIT_PACKAGE.md

05

Artist Passport

An identity one hacked account can't take.

Two independent proofs

One strong Spotify for Artists proof (a DKIM-signed email or a code in the bio), plus another source: a distributor or Apple Music for Artists email matched track for track.

Passkey, checked by Solana

Wallet changes, endorsements and large withdrawals need Face ID or a fingerprint, verified by the secp256r1 precompile. The challenge binds the exact action and a nonce.

Recovery with a veto

Fresh proofs and a new passkey start a public time-lock. The old passkey, or a fresh proof of a kind already on the passport, can cancel it.

Vault and endorsements

Fees from every claimed coin collect in a program-owned vault. Endorse or disavow any mint, on any launchpad, readable by any app.

programs/riff-passport · live on devnet

06

Security so far

Reviewed internally, fixed with regression tests.

IDFinding (internal review)Status
H-01Graduation into the DEXFixed
M-01Artist claim and charity flowFixed
M-02Launch-slot bundling around the creator-buy capFixed
L-01Coin metadata could change after launchFixed

Real programs, not mocks. Tests run against the SPL Token, Token-2022 and Raydium CPMM binaries as deployed on mainnet.

CI on every change. Build, tests, clippy with warnings as errors, cargo audit, gitleaks, and checks that the IDL and curve vectors match the code.

Not audited externally yet · docs/AUDIT_PACKAGE.md · SECURITY.md

07

118

program tests: 108 for riff, 22 for the passport

2

programs live on devnet, driven end to end by the web app

0

mocks of external programs in the tests

Plus thousands of buy, sell and fee-split cases in vectors/curve.json, computed by the program's own math, that any off-chain port must reproduce exactly.

riff · pre-audit application

08

Readiness

Where the code stands today.

AreaState
RepositoryPublic, with a reviewer README, audit package, SECURITY.md and CI
DeploymentsBoth programs on devnet; deployments.json records program IDs, build settings and binary hashes
InterfaceIDL and TypeScript types published in idl/; checked against the code in CI
ProductWeb app at riffpad.fun runs the full lifecycle on devnet: launch, trade, claim, graduate
Not yetExternal audit, multisig admin, verifiable builds, mainnet

riff 59MehWKu…KsosqtV · passport 2nke6euX…dcY5kwj (devnet)

09

The ask

Where we'd like fresh eyes.

  1. Graduation. The two-step CPI into Raydium CPMM, the pool PDA, the LP burn and front-running.
  2. Fee accounting and solvency. The single payout path, rounding and the running totals.
  3. Claim and charity. Late claims, the sweep, and the verifier's limited power.
  4. Passkey verification. secp256r1 instruction introspection, offsets, challenge binding and replay.
  5. Recovery and the vault. Time-lock and veto rules, and the vault's signer seeds in CPIs to riff.

Scope: programs/riff and programs/riff-passport at a pinned main commit

10

Path to mainnet

Audited before real money moves.

now

Devnet, hackathon submission

next

Pre-audit, fixes with regression tests

then

Squads multisig admin and upgrade authority, verifiable builds

launch

Mainnet beta with the first artists

github.com/use-riff/riff riffpad.fun x.com/useRiffPad

Kevin Fransman, founder · useriffpad@gmail.com

11