on record

Program Stats

mainnet·last 720h·2,786 programs·915 new · 1,871 upgrades

Deploys over timei

050010008/168/228/289/39/9

Frameworksi

anchor114558% → 55% -3pp
native49221% → 27% +6pp
pinocchio37620% → 17% -3pp
unknown181% → 1% 0pp

Categoriesi

DEX
153
STAKING
76
LAUNCHPAD
31
LENDING
27
PERPS
17
BRIDGE
16
ORACLE
27
NFT
16
GOV
10
AIRDROP
5
TOKEN
8
INFRA
22
DEFI
146
UNKNOWN
1477

Integrationsi

SPL Token
1068
Token-2022
669
Associated Token
262
Pump.fun
136
Meteora DLMM
113
Orca Whirlpool
89
Raydium CLMM
87
Raydium AMM
72
Metaplex Metadata
60
Jupiter
47

Identityi

namedA project name was recovered from the binary.
1152
has repoA source-code repo was found in the binary or a verified build.
41
opaqueNo name, repo, or security.txt — anonymous bytecode.
877

Lineagei

novelNo known code relative on record — genuinely new code.
3
variantLoosely similar to a known program, but not a direct copy.
1951
fork≥60% code match to a known program — a fork or close derivative.
77

Controli

mutableHas an upgrade authority — the deployer can still replace the code (including to rug).
2006
frozenUpgrade authority is null — the code can never be changed by anyone.
25
verified buildThe on-chain bytecode reproduces from public source code.
29

Fundingi

known entityDeployer was funded from a labeled exchange or bridge.
0
traced funderFunded from a specific wallet we could trace, but not a labeled entity.
3
untracedCouldn't reach the funding origin.
2028

Recycled — byte-clone redeploysi

7.4%of today's 915 new deploys are byte-clone redeploys, not new code
redeploysNew deploys that are byte-clones of known code — same program, fresh id. A fact, not a judgment.
68
Pump.fun snipersThe confident bot subset: redeploys wired to Pump.fun — the launch-sniper signature.
12
already closedDeploys whose ProgramData is already gone — rent reclaimed, likely a throwaway bot that moved on.
1427
What's a throwaway bot?

A disposable on-chain program a trader deploys to run one strategy — almost always sniping new Pump.fun token launches — then closes minutes later to reclaim its rent, redeploying under a fresh id for the next run.

Why a program at all?

Sniping means "buy the instant the pool exists, atomically, or abort" — you can't do that reliably from a wallet. A tiny custom program bundles the whole attempt (and often multi-venue routing) into a single instruction that either lands complete or reverts.

Why thousands of failed transactions?

That's the race. The bot fires on every launch; most attempts lose the block or the token rugs, so they revert. The failures are the strategy — spray for the few that land.

Why redeploy and close?

The ~0.2 SOL of rent is refundable on close, and a fresh program id sidesteps any blocklist or reputation built against a known address. Cheaper and stealthier to burn identities than to keep one — so one operator can wear dozens of "new program" identities in a day.

How On Record catches it

Exact-bytecode dedup (same sha256 = same bot) collapses the redeploys into one cluster; lifecycle tracking sees the deploy → close; the failed-tx count confirms the intent. No explorer distinguishes "new protocol" from "same bot, 30th identity today" — that's a novelty-definition problem, which is exactly what this radar solves.

last 30d · updated 2026-09-14 22:51 UTC