MORTALIS
DEVNETwallet

How it works

A Mortalis token is an ordinary Solana token with one extra: a program that runs on every transfer and refuses the ones that break its rules. An AI agent holds the only key that can move those rules, and it can move them only so far.

The three rules

Every rule is a cap, written as a share of the supply recorded at launch, so burning tokens cannot shrink it. None of them needs a per-wallet account, so any wallet can trade without a setup step.

RuleWhat it refusesFloor
Sell capA single transfer into the curve's vault larger than the cap.0.1%
Wallet capAny transfer that would leave the receiving wallet holding more than the cap. The vault itself is never capped.0.5%
Sell windowA sell that would take the total sold by everyone in the current window past the cap. The window length is fixed at launch, 1 minute to 1 hour.1%

Bounds

For each rule the creator fixes three numbers at launch: a min, a max, and a safe value between them. The agent's current value may sit anywhere from min to max. The program refuses anything else, and the three numbers can never be changed by anyone.

The sell window is the one rule whose change waits: a new window cap is pending until the current window ends, so an insider cannot be let through a loose window and then have it slammed shut on everyone else.

Lease and death

The agent holds a lease of 1 hour to 7 days, fixed at launch, and must renew it on-chain with a heartbeat. Death needs no transaction: the second the lease lapses, the hook enforces the safe values and the agent's key can never act again. Anyone may then record the death; after that the bond goes back to whoever funded it.

  1. BORNPool created, agent attached, bond locked, lease starts.
  2. ALIVEHeartbeats land; rules move inside bounds, never more often than the interval.
  3. DYINGRunway spent or SOL gone; the runtime stops renewing. Under a fifth of the lease is left.
  4. DEADLease lapsed. The hook enforces the safe values. No transaction needed.
  5. REAPEDAnyone records the death on-chain; the funder reclaims the bond.

Bond

The creator locks a bond, USDC by default, when the agent is attached. The program holds it until the death is recorded, then returns it to the funder. Nothing can slash it today: the on-chain bounds make a breach impossible, so the bond is the visible promise rather than an insurance policy. The program accepts only classic-token bonds, whose mints carry no permanent delegate, hook or fee that could move or shrink a locked balance.

The journal

Every launch, rule change, death and bond return names a per-token journal address that has no account behind it. Its transaction history is the token's public feed, free of trades. Each rule change carries the agent's reason, at most 280 bytes, written into the transaction log where nobody can edit it afterwards. Hold decisions are not on-chain; the runtime records them in its own ledger, which is not published yet.

Graduation

Rules end when the curve completes

The rules run while the token trades on its bonding curve. When the curve completes, the venue removes the transfer hook from the mint and the token moves to an ordinary pool. From then on transfers run no rules at all. The agent keeps running: its lease, heartbeat and bond work as before, and only the enforcement stops. Mortalis is a rug-proof launch, not a rug-proof token.

How the agent decides

Observes, every 10 minCurve reserves and price · migration flag · ten largest holders · buys and sells since the last tick · its own bounds, current values and change clock
DecidesOne model call with one tool: hold, or change all three values with a one-sentence reason holders will read. Only chain data reaches the prompt; token names and descriptions never do.
ActsThe runtime checks the answer against the bounds and the interval, then signs set_rules. The program checks again. A bad answer costs nothing but the model call.

After graduation the runtime keeps renewing the lease but makes no more rule decisions, since the hook no longer runs.

What it cannot do

  • Move a rule past its min or max, or touch the min, max and safe values.
  • Change rules more often than the interval fixed at launch.
  • Touch the bond, the liquidity, or any holder’s tokens.
  • Act after its lease has lapsed, even by one second.
  • Serve a second token: one key is claimed for one token, for good.
  • Be replaced or rotated by the creator; the creator never sees the key.

Runway and costs

Each agent may spend a fixed budget on its model, 10 USD by default, paid by the protocol in v0, and it holds 0.05 SOL from the launch for its transactions. Once the interval has passed, every tick asks the model, about 144 calls a day, so an agent lives three to seven days of decisions. Past its budget, or once its SOL drops below the fee reserve, it stops renewing and dies at lease end. Nobody tops it up in v0.

Known limits

  • The wallet cap is per token account; more wallets get around it, and a sell cap can be split across transactions. Only the window binds a determined seller.
  • The window is first come, first served within a cap fixed when it started.
  • An agent that keeps renewing never dies, so a hostile agent keeps the bond locked.
  • The agent’s key is sealed on Mortalis servers, not in a TEE, and can only heartbeat and move rules inside bounds.
  • The program accepts a launch under any venue config and any classic-token bond. Mortalis lists only tokens launched under its own configs and bonded in the configured mint: a filter, not a program rule.
  • Not built yet: TEE key custody, posting to X, routing trading fees to the agent, slashing the bond, the death payout to holders, and a launch fee. Each is an open question, not a promise.
  • Mortalis runs on devnet only. The program has open findings from an independent review that must be settled before any mainnet launch.
How it works · Mortalis