underwater.fun

Documentation

A launchpad on InkChain where the math is published before you buy. This page is the whole thing in one scroll: the curve a token sells on, what graduation does to the liquidity, the plates collection that reads a lending position, every fee with the ceiling it cannot pass and who collects it, what $WATER will and will not be, and the list of things that are not finished. The code is public, and every number below was checked against it.

Overview

what this is

underwater.fun lets anyone create a token in one transaction and sell it on a bonding curve whose formula is fixed and public. There is no presale, no team allocation and no allowlist on the curve — being early to the curve is the only discount, and it is the same curve for every token.

At 4 ETH raised the curve closes itself. The ETH and the 200M tokens held back from the sale go into a real Uniswap-V2-style pool, and the liquidity is burned to a dead address. Not locked, not vested — burned. There is no key, no timelock and no multisig, because after graduation there is nobody left who could move that liquidity, including us.

Alongside the launchpad is Underwater Plates, a 2222-piece collection drawn entirely on chain, where a plate that is pointed at a leveraged Aave position dissolves as that position's health factor falls — and can be burned by a stranger when it liquidates.

Statuscheckable
Live on
Ink Sepolia · Robinhood Testnet
Mainnet
neither, yet
Audit
none
Test suite
354 passing, 0 skipped

We are on testnets and validating in public before mainnet. Launching real money is not open yet.

Products

five of them

Five things, each with its own page in the app.

Launchpad/create

Create a token, then buy and sell it on the curve. Creation and the creator's first buy are the same transaction, so a launch cannot be sniped between the two. The market lists every launch with its curve progress; a token's own page carries the chart, the trade panel and the trade history.

DEX/swap

Our own Uniswap-V2-style exchange, which is where a graduated token trades. It exists because a graduation needs a pool to land in and neither testnet has an exchange to supply one — the addresses labelled Uniswap V3 on Robinhood are proxies with nothing behind them — so without ours the launchpad could not run end to end anywhere. Swaps are ETH↔token.

2222 hydrographic survey plates, drawn on chain rather than hosted anywhere. Attach an Aave position and the drawing reads it: crisp in dry dock, dissolving into ink plumes as the health factor falls, burnable by anyone once it liquidates.

The waterdrop/waterdrop

Allowlist intake for the plates mint. One transaction registers a wallet — no form, no email, and a registration is only ever accepted from the wallet being registered. Registration is intake, not entitlement: the allowlist is drawn from the registrants under criteria published before anyone could register.

Profile/profile

One wallet's own view — the launches it created, the positions it holds, and what a $WATER distribution would draw on. Nothing there is claimable yet.

The curve

price ∝ (1 + eth)²

A launch mints 1,000,000,000 tokens. 800M are sold on the curve and 200M are held back for the pool. The curve is a constant product against a virtual 1 ETH reserve — virtual because nobody deposited it; it exists to give the first buyer a price instead of a division by zero.

x · y = kx0 = 1 ETH (virtual) · y0 = 1,000,000,000raise(S) = x0 · S / (y0 − S)

Put the 800M curve supply through that and the answer is the graduation threshold: 1 ETH × 800M / 200M = 4 ETH. So 4 ETH is not a number somebody picked — it is the exact raise that empties the curve supply, which is why graduation and sell-out are the same event.

Price is quadratic in the raise, so the multiple from launch to graduation is an identity rather than a target:

(1 + 4)² ÷ (1 + 0)² = 25×, exactly, every time1 gwei → 25 gwei · FDV 1 ETH → 25 ETH
25×024 ETHgraduates
Price against ETH raised, drawn from the formula above rather than sketched. The shape is the part the arithmetic hides: at 2 ETH — half the raise — a token is at , not 12.5×. Two thirds of the whole 25× arrives in the second half of the curve. That is what being early is worth here, and it is worth exactly that and no more.

Two properties worth knowing because they cost you something. Rounding always favours the pool — buys round tokens out down, sells round ETH out down — so splitting a buy into ten never beats making it once, and a round trip never profits. Both are checked over 10,000 randomised runs. And a curve that never reaches 4 ETH simply stays a curve: it does not expire, refund, or graduate on a timer.

Usage

start to finish
Createone transaction
Curve1% per trade
4 ETHcloses itself
Poolliquidity burned

Launch a token

  1. Connect a wallet on /create. The app opens on Robinhood Testnet, which is live, so there is nothing to switch unless you want Ink Sepolia instead.
  2. Give it a name, a symbol and an image. The app handles hosting the image for you.
  3. Optionally attach a first buy. It settles in the same transaction as the creation, which is what makes the creator's own entry unsnipeable.
  4. Send it. The token, the curve and the market listing all exist at that block.

Trade the curve

  1. Open the token from the market. The depth bar is curve progress toward 4 ETH.
  2. Buy with ETH or sell tokens back. The quote is the curve evaluated at the current reserves — no order book, no counterparty, and no way to be filled at a different price than the one the formula gives at your block.
  3. A 1% fee applies to each trade, taken in ETH. It is settable, and it cannot exceed 2%.

Graduation

Automatic. The buy that carries the raise to 4 ETH is sized down to land exactly on it and the excess ETH is refunded in the same transaction, so nobody overshoots and nobody pays for tokens the curve no longer has. Then, still in that transaction:

  1. The graduation fee is taken from the 4 ETH — 5%, capped at 10%.
  2. The remaining ETH and the held-back 200M create the pool.
  3. The liquidity from that deposit is burned.
  4. Any curve tokens still unsold after the size-down are burned, so the circulating supply matches what was actually bought.

Swap a graduated token

  1. Go to /swap, or use the swap panel on the token's own page.
  2. Pick a direction. Pairs are ETH↔token.
  3. 0.30% of each swap is the pool fee. 0.25% stays with liquidity providers; 0.05% is the protocol's cut.

Mint a plate

  1. Register on /waterdrop while the window is open. One transaction, from the wallet itself.
  2. If the allowlist includes you, the app proves your place for you. Whatever the allowlist phase does not take rolls into the public phase.
  3. Mint on /mint. What you receive is a sealed survey tube — the same drawing for every plate, stamped with its own number and nothing else.
  4. After minting closes, the reveal draws the offset that maps plate numbers onto the sealed trait list, and the art appears.
A sealed survey tube drawn in brown on cream: a capped cylinder with a wax seal at its middle, stamped No. 0006 of 2222 and SEALED, carrying no traits.
What arrives at mint. Every plate is this drawing, differing only in the number stamped at the bottom — there is no trait on it to grade, because the plate-to-slot offset does not exist yet.

Attach a position

Optional, and the one decision on this page that can lose you the token. Point a plate at an address with an Aave position and the drawing starts reading that position on every view — the plate dissolves as the health factor falls, can be engraved with a scar below 1.4, and at 1.0 anyone may drown it: burn it, and mint themselves a trophy. A plate with nothing attached cannot be drowned by anybody. See Risks.

Fees

four, and where they go

There are four, and this is the complete list. Three belong to the launchpad and are settable by its owner within hard ceilings that cannot themselves be raised; the fourth belongs to the DEX and only starts applying after a token graduates. If you find a fifth, it is a bug and we want the report.

FeeNowHard capWhere
Trade, buy and sell1%2%on the curve
Token creation00.01 ETHonce, at launch
Graduation, of the 4 ETH5%10%once, at graduation
Pool swap0.30%fixedafter graduation

The ceilings are the part worth checking. A settable fee with no ceiling is a promise; a settable fee under a ceiling that nobody can raise is a bounded parameter, and the bound holds whatever we intend.

The pool fee is not settable at all — 0.30% is fixed. What is switchable is the protocol's share of it, which works out to 0.05% of swap volume, and it is switched on for our deploy.

Two more fees exist on the plates rather than the launchpad. The mint price is owner-settable under a 1 ETH ceiling, because it targets a dollar figure while ETH moves. Secondary royalty is 5%, fixed, and reported through the standard royalty interface so marketplaces can read it.

Where the money goes

Every fee above is the protocol's revenue, and there is no other. No subscription, no listing fee, no paid promotion on the market page, no spread added to a quote, and nothing taken from a wallet for holding or transferring. If we ever earn from this it is because tokens were created, traded and graduated — which is the only revenue model we want, because it cannot pay unless the thing works.

A creator earns nothing from their own token's trading. Some launchpads route a slice of every trade back to whoever launched it; ours does not, and that is deliberate rather than unbuilt. A per-launch revenue share is a standing reason to spam launches, and the incentive we would rather create is to launch something people want to hold. What a creator gets instead is the curve: they can buy their own launch first, in the same transaction that creates it, at the lowest price it will ever have.

Three of the four arrive as ETH the moment they are charged. The pool's 0.05% is the exception — it accrues inside each graduated pool and has to be settled before it is anything, which is covered under Risks. Whoever deployed the launchpad can read the running total on /profile; nobody else sees that tab, and it is a readout rather than a button.

Tokens

launches, and plates

A launch token

Standard ERC-20, 18 decimals. Fixed supply per launch, and nothing can mint more of it afterwards:

AllocationAmountShareFate
Sold on the curve800,000,00080%to buyers; unsold remainder burned
Held for the pool200,000,00020%paired with the raise; liquidity burned
Team, presale, advisors00%there is no allocation

Underwater Plates

ERC-721, 2222 in total and capped there. The allowlist phase is allocated 2000 and the public phase takes whatever it does not use. Per-wallet limits are settable under a ceiling of 222. Royalty is 5%. Nothing is hosted anywhere: both the artwork and its metadata are built on chain, at the moment they are asked for.

  1. A survey plate on cream paper, every line crisp and fully legible.Dry docknothing attached
  2. The same plate with its lines smeared and softened, a faint ink ghost of the drawing showing behind them.Twilighthealth factor 1.90
  3. The same plate far further gone, its lines dragged out into ink plumes, with three faint ringed marks across the paper.Crush depth1.05, three scars
  4. A near-black field with the drawing gone entirely, stamped DROWNED.Drowned1.00 — anyone may burn it
The same plate — number 6 — at four states of the position behind it. A plate with nothing attached stays in dry dock permanently; the other three are what attaching one can do. The scars in the third are not damage from that moment: they count the near-death dips the position already survived, up to eight. The fourth is not a state a plate sits in for long: at 1.00 anyone at all may burn it, and the trophy they mint for doing so is the point of it.

Rewards

$water, and what counts

$WATER

$WATER is coming, and it does not exist yet. There is no contract, no address, no sale, no allocation table, no date and nothing to claim. It is a protocol token planned to be shared with the people who make the market: token creators, liquidity providers and traders. Anything you find elsewhere offering to sell you one is not us — the security policy lists every account and domain that is.

uwPoints

Four things earn uwPoints: registering for the waterdrop (10,000, once), a referral that clears the activity bar (1,000 each), launching a token (20,000 each), and a trade, on a curve or in a pool (10 each). A coupon code or a hand grant can add to a balance. Nothing subtracts from one — there is nothing to spend points on, so there is no way to lose them either.

The activity bar on a referral is the same one the waterdrop uses: the referred wallet needs at least ten transactions on Ink, mainnet or Sepolia. Referrals short of it are shown and pay nothing, so the count you see is every registration through your link and the number that pays is the subset above the bar. It is there because a referral rate with no bar pays for wallets made to collect it.

No balance is stored anywhere. It is the rate card multiplied by counts of on-chain events, plus whatever has been granted, recomputed from the logs on every read. So there is no database behind it: you do not register, sign anything or keep a tab open for activity to count — it counted when the transaction confirmed — and we cannot quietly re-weight a number we never stored, or wake up one morning having lost everyone's history.

The Points tab on /profile shows the total, the terms that sum to it, this wallet's rank, and every event each term was counted from, each row linking to the transaction it was read from. That list is the point of it: a balance nobody can check is a balance nobody has to believe.

What there is not: no multiplier, no season and no streak. Rates live in a contract, and changing one re-prices history rather than grandfathering it — the rows on that tab are priced at today's card, not at whatever the rate was on the day. The points contract is live on both testnets and on neither mainnet; on a network without it the rates shown are the launch defaults, labelled indicative rather than quoted as settled.

Alongside it is a readout in ETH, which no rate card prices. The Rewards tab on the same page shows four numbers for the connected wallet:

Counted todayWhy it is there
Launches createdyou brought a token that did not exist before
ETH raised across themseparates a launch people bought from one nobody did
Positions heldyou are holding, not only passing through
Portfolio valuethe size of what you are holding, priced now

All four are read live from the chain when the page loads, the same way a points balance is and for the same reason.

Liquidity provision is not counted yet. It is in the plan and nothing prices it — not the rate card, not these four numbers — so an LP reading either tab today is not seeing that half of it. Trading is counted, but per trade at a flat rate rather than by size, so volume is not itself the thing that earns.

None of these numbers is a promise of an allocation. There is no formula yet, and when there is one it will be published before it runs — not inferred from this page.

Networks

four, in two families

Four networks, two chain families. These name actual chains — what a wallet has to be switched to, where a pool opens — and the app opens on Robinhood Testnet, which is what a visitor who never touches the switcher is reading. It opens on a testnet because neither mainnet is deployed yet; the day one is, that is the network the front door moves to.

“InkChain” is the brand word and never a claim about where something is deployed — a distinction that did some work when both chains were Ink and does all of it now. What differs between the families is not cosmetic: the launchpad, the exchange and uwPoints run on all four, but the plates collection and the waterdrop cannot run on Robinhood at all, because the art reads Aave V3 health factors and there is no Aave V3 there. On those two networks they are absent rather than pending — including on the one the app opens on.

 Chain IDGas tokenExplorerOur deploy
Robinhood Chain4663ETHrobinhoodchain.blockscout.comnot deployed
Robinhood Chain Testnet46630ETHexplorer.testnet.chain.robinhood.comlive
Ink Mainnet57073ETHexplorer.inkonchain.comnot deployed
Ink Sepolia763373ETHexplorer-sepolia.inkonchain.comlive

Deployed addresses are published in SECURITY.md and not repeated here — one list that a scanner and a reader both arrive at, rather than two that can disagree. Explorer source verification is still outstanding, so an explorer label is not yet evidence of what we deployed.

Roadmap

in order, without dates

In order, and deliberately without dates. A missed date is the one mistake on this page that cannot be walked back, so nothing here carries one.

  1. Validate on the testnets, in public. Where we are. The whole lifecycle runs against real chains on both: Ink Sepolia carries every surface, including the collection and the waitlist, and Robinhood Chain Testnet carries the three that can exist there.
  2. Explorer source verification for everything we deployed, so a reader can confirm it on the explorer rather than take our word for it.
  3. An audit. Before real money, not after it. 354 tests including randomised runs and tests against a live fork is not an audit, and running our own exchange raises the stakes rather than lowering them.
  4. The plates drop, on Ink. The waterdrop window closes, the allowlist is selected under the published criteria and committed publicly before minting opens.
  5. Mainnet. The same build, once testnet validation is clean and the audit is done. Robinhood Chain is the one this is aimed at, and the network the app will open on once it exists; Ink Mainnet is the same deploy on the chain we started on, and the order between them is a launch decision rather than a technical one — the build does not care. We will post the block the first curve graduates in.
  6. $WATER. The protocol token, to creators, liquidity providers and traders — and the point-counting that has to exist before it can be distributed. See Rewards.
  7. An indexer, and aggregator listings. A token's whole life is already recorded on chain in a shape one indexer can read across both halves of it — the curve, and the pool after graduation.

Risks

the unflattering part
Not audited. Do not put money on this that you would mind losing.

Everything below is a known trade-off rather than a discovered bug, and it is here because a docs page that lists only what works is an advertisement.

  • No audit. 354 passing tests, 10,000-run randomised invariants and tests against a live fork of both Ink chains. That is diligence, not assurance.
  • Where graduations land is an owner setting. The launchpad's owner can point them at a different exchange. A wrong destination fails at deploy rather than quietly parking every graduation — but it is an owner power, and we are naming it.
  • A pool can be opened before graduation. Anyone may open one for a curve token early and price it however they like. Graduation still deposits into the one we open; an early pool is just a worse price that existed first.
  • A curve can park. Nothing forces a launch to reach 4 ETH. A token that never graduates stays tradeable on its curve indefinitely, and there is no refund mechanism, because there was never a raise held in escrow to refund.
  • Curve trades can be sandwiched like any on-chain trade. The formula is public, which cuts both ways: you can compute your own fill, and so can somebody ahead of you.
  • Our share of the pool fee accrues where nobody can poke it. A graduated pool's liquidity is burned, so the event that would settle that share never happens on its own — it sits uncollected until somebody adds liquidity. This is our accounting problem, and it is disclosed because it explains why a fee readout can show value that has not moved.
  • Running our own DEX costs distribution. Aggregators and chart sites have no adapter for it, so a graduated token is not automatically visible where traders look. The alternative was having no testnet path at all.
  • The plates depend on a whitelabel Aave. The health factor comes from a whitelabel Aave V3 market, fixed at deploy. If that market changes or empties, the plates read whatever it reports — that is the honest version of the premise: a plate tracks a leveraged position on the chain it lives on, so it inherits whatever lending market that chain has. The plate itself holds no approval, takes no custody and cannot liquidate anybody; it reads, and it draws.
  • Drowning is real, and anyone can do it. Two conditions, both required: the plate has a position attached, and Aave reports a health factor at or below 1.0. A plate with nothing attached cannot be drowned by anyone, and attaching one is a choice — this is what the choice costs.
  • What the reveal does and does not promise. The trait list is committed to a hash before minting can open, so the art cannot respond to demand, and no mint position can be timed to land a rare plate — the plate-to-slot offset does not exist until minting closes. But the draw itself is a one-shot call anyone can make, and whoever makes it can work out the offset they are about to get. We are saying that plainly rather than promising a fairness property nothing enforces.

Report anything else to the address in SECURITY.md, which also lists every domain and account that is actually ours.