The fee harvester
The contract that receives the token's creator fees and turns half of them into gas and holder yield, on-chain.
On Pons, every trade of a token pays a 1% fee, and the creator's share of it goes to the token's creator fee
recipient. For QSHIELD that recipient is a contract: FeeHarvester.
harvest()
harvest() is permissionless. Each call:
- Collects the creator fees Pons holds for the token.
- Splits what it collected:
TEAM_SHARE_BPS = 5000, so half is owed to the team's recipient. - Tops up the gas deposit. If the vault's EntryPoint deposit is below
targetDeposit(0.02 ETH), ETH goes there first. - Buys the token with what is left, and donates it to the vault.
- Refunds the caller's gas, within strict limits.
- Pays the team its accrued half.
Buys that are not worth attacking
A contract that buys on a public market is a target for sandwiching. The harvester sizes its buys so that the attack loses money:
| Limit | Value | Meaning |
|---|---|---|
MAX_IMPACT_BPS | 50 | A single buy moves the price by at most 0.5% |
| One buy per L1 block | lastBuyBlock | |
MAX_PREMIUM_BPS | 1500 | Never pays more than 15% above the vault's price average, after fees |
MAX_HALVINGS | 8 | A buy the market does not take is halved and retried, up to 8 times |
Pushing the price up before a buy and selling after costs the market fee on both legs, about 2%, to capture at most the 0.5% the buy moves the price. The buy size comes from the pool's active liquidity, read on-chain. What does not fit waits in the contract for the next harvest.
The price average the limit refers to is the vault's own, which a single block cannot move (see the vault).
The caller's refund
Anyone can run the system. A caller is refunded the gas of a call that put ETH to work, at no more than twice the base
fee and never more than 0.5% of that work (CALLER_TIP_BPS). A call that does nothing earns nothing, so there is no
reason to spam it.
Roles
| Role | Can | Cannot |
|---|---|---|
| Owner | Change the team's recipient; propose or cancel a successor; hand on or renounce ownership | Touch the holders' half; change any limit; move the vault's deposit |
| Anyone | harvest(), payTeam(), executeSuccessor() after the delay |
A successor is a new creator fee recipient for the token. Proposing one is public and takes effect only after
SUCCESSOR_DELAY (24 hours), when anyone can execute it.
The keeper
A keeper watches the chain and calls harvest() when fees have built up or the gas deposit runs low, and poke() to
keep the price average close to the market. It uses only permissionless functions: if it stops, anyone else can do the
same job, and the refund pays for it.