Quantum Shielddocs

The fee harvester

The contract that receives the token's creator fees and turns half of them into gas and holder yield, on-chain.

On Pons, every trade of a token pays a 1% fee, and the creator's share of it goes to the token's creator fee recipient. For QSHIELD that recipient is a contract: FeeHarvester.

harvest()

harvest() is permissionless. Each call:

  1. Collects the creator fees Pons holds for the token.
  2. Splits what it collected: TEAM_SHARE_BPS = 5000, so half is owed to the team's recipient.
  3. Tops up the gas deposit. If the vault's EntryPoint deposit is below targetDeposit (0.02 ETH), ETH goes there first.
  4. Buys the token with what is left, and donates it to the vault.
  5. Refunds the caller's gas, within strict limits.
  6. Pays the team its accrued half.

Buys that are not worth attacking

A contract that buys on a public market is a target for sandwiching. The harvester sizes its buys so that the attack loses money:

LimitValueMeaning
MAX_IMPACT_BPS50A single buy moves the price by at most 0.5%
One buy per L1 blocklastBuyBlock
MAX_PREMIUM_BPS1500Never pays more than 15% above the vault's price average, after fees
MAX_HALVINGS8A buy the market does not take is halved and retried, up to 8 times

Pushing the price up before a buy and selling after costs the market fee on both legs, about 2%, to capture at most the 0.5% the buy moves the price. The buy size comes from the pool's active liquidity, read on-chain. What does not fit waits in the contract for the next harvest.

The price average the limit refers to is the vault's own, which a single block cannot move (see the vault).

The caller's refund

Anyone can run the system. A caller is refunded the gas of a call that put ETH to work, at no more than twice the base fee and never more than 0.5% of that work (CALLER_TIP_BPS). A call that does nothing earns nothing, so there is no reason to spam it.

Roles

RoleCanCannot
OwnerChange the team's recipient; propose or cancel a successor; hand on or renounce ownershipTouch the holders' half; change any limit; move the vault's deposit
Anyoneharvest(), payTeam(), executeSuccessor() after the delay

A successor is a new creator fee recipient for the token. Proposing one is public and takes effect only after SUCCESSOR_DELAY (24 hours), when anyone can execute it.

The keeper

A keeper watches the chain and calls harvest() when fees have built up or the gas deposit runs low, and poke() to keep the price average close to the market. It uses only permissionless functions: if it stops, anyone else can do the same job, and the refund pays for it.

On this page