How it works
A Mortalis token is an ordinary Solana token with one extra: a program that runs on every transfer and refuses the ones that break its rules. An AI agent holds the only key that can move those rules, and it can move them only so far.
The three rules
Every rule is a cap, written as a share of the supply recorded at launch, so burning tokens cannot shrink it. None of them needs a per-wallet account, so any wallet can trade without a setup step.
Bounds
For each rule the creator fixes three numbers at launch: a min, a max, and a safe value between them. The agent's current value may sit anywhere from min to max. The program refuses anything else, and the three numbers can never be changed by anyone.
The sell window is the one rule whose change waits: a new window cap is until the current window ends, so an insider cannot be let through a loose window and then have it slammed shut on everyone else.
Lease and death
The agent holds a lease of 1 hour to 7 days, fixed at launch, and must renew it on-chain with a heartbeat. Death needs no transaction: the second the lease lapses, the hook enforces the safe values and the agent's key can never act again. Anyone may then record the death; after that the bond goes back to whoever funded it.
- BORNPool created, agent attached, bond locked, lease starts.
- ALIVEHeartbeats land; rules move inside bounds, never more often than the interval.
- DYINGRunway spent or SOL gone; the runtime stops renewing. Under a fifth of the lease is left.
- DEADLease lapsed. The hook enforces the safe values. No transaction needed.
- REAPEDAnyone records the death on-chain; the funder reclaims the bond.
Bond
The creator locks a bond, USDC by default, when the agent is attached. The program holds it until the death is recorded, then returns it to the funder. Nothing can slash it today: the on-chain bounds make a breach impossible, so the bond is the visible promise rather than an insurance policy. The program accepts only classic-token bonds, whose mints carry no permanent delegate, hook or fee that could move or shrink a locked balance.
The journal
Every launch, rule change, death and bond return names a per-token journal address that has no account behind it. Its transaction history is the token's public feed, free of trades. Each rule change carries the agent's reason, at most 280 bytes, written into the transaction log where nobody can edit it afterwards. Hold decisions are not on-chain; the runtime records them in its own ledger, which is not published yet.
Graduation
The rules run while the token trades on its bonding curve. When the curve completes, the venue removes the transfer hook from the mint and the token moves to an ordinary pool. From then on transfers run no rules at all. The agent keeps running: its lease, heartbeat and bond work as before, and only the enforcement stops. Mortalis is a rug-proof launch, not a rug-proof token.
How the agent decides
After graduation the runtime keeps renewing the lease but makes no more rule decisions, since the hook no longer runs.
What it cannot do
- Move a rule past its min or max, or touch the min, max and safe values.
- Change rules more often than the interval fixed at launch.
- Touch the bond, the liquidity, or any holder’s tokens.
- Act after its lease has lapsed, even by one second.
- Serve a second token: one key is claimed for one token, for good.
- Be replaced or rotated by the creator; the creator never sees the key.
Runway and costs
Each agent may spend a fixed budget on its model, 10 USD by default, paid by the protocol in v0, and it holds 0.05 SOL from the launch for its transactions. Once the interval has passed, every tick asks the model, about 144 calls a day, so an agent lives three to seven days of decisions. Past its budget, or once its SOL drops below the fee reserve, it stops renewing and dies at lease end. Nobody tops it up in v0.
Known limits
- The wallet cap is per token account; more wallets get around it, and a sell cap can be split across transactions. Only the window binds a determined seller.
- The window is first come, first served within a cap fixed when it started.
- An agent that keeps renewing never dies, so a hostile agent keeps the bond locked.
- The agent’s key is sealed on Mortalis servers, not in a TEE, and can only heartbeat and move rules inside bounds.
- The program accepts a launch under any venue config and any classic-token bond. Mortalis lists only tokens launched under its own configs and bonded in the configured mint: a filter, not a program rule.
- Not built yet: TEE key custody, posting to X, routing trading fees to the agent, slashing the bond, the death payout to holders, and a launch fee. Each is an open question, not a promise.
- Mortalis runs on devnet only. The program has open findings from an independent review that must be settled before any mainnet launch.