on record

Program Stats

mainnet·last 168h·1,007 programs·266 new · 741 upgrades

Deploys over timei

01252509/89/99/119/129/14

Frameworksi

anchor29559% → 49% -10pp
native15125% → 32% +7pp
pinocchio9015% → 19% +4pp
unknown52% → 0% -2pp

Categoriesi

DEX
50
STAKING
18
LAUNCHPAD
6
LENDING
8
PERPS
6
BRIDGE
7
ORACLE
9
NFT
5
GOV
2
AIRDROP
4
TOKEN
1
INFRA
6
DEFI
26
UNKNOWN
393

Integrationsi

SPL Token
284
Token-2022
189
Associated Token
89
Pump.fun
47
Meteora DLMM
35
Raydium CLMM
32
Raydium AMM
30
Orca Whirlpool
28
Jupiter
23
Metaplex Metadata
18

Identityi

namedA project name was recovered from the binary.
291
has repoA source-code repo was found in the binary or a verified build.
4
opaqueNo name, repo, or security.txt — anonymous bytecode.
250

Lineagei

novelNo known code relative on record — genuinely new code.
0
variantLoosely similar to a known program, but not a direct copy.
526
fork≥60% code match to a known program — a fork or close derivative.
15

Controli

mutableHas an upgrade authority — the deployer can still replace the code (including to rug).
537
frozenUpgrade authority is null — the code can never be changed by anyone.
4
verified buildThe on-chain bytecode reproduces from public source code.
4

Fundingi

known entityDeployer was funded from a labeled exchange or bridge.
0
traced funderFunded from a specific wallet we could trace, but not a labeled entity.
0
untracedCouldn't reach the funding origin.
541

Recycled — byte-clone redeploysi

4.5%of today's 266 new deploys are byte-clone redeploys, not new code
redeploysNew deploys that are byte-clones of known code — same program, fresh id. A fact, not a judgment.
12
Pump.fun snipersThe confident bot subset: redeploys wired to Pump.fun — the launch-sniper signature.
4
already closedDeploys whose ProgramData is already gone — rent reclaimed, likely a throwaway bot that moved on.
232
What's a throwaway bot?

A disposable on-chain program a trader deploys to run one strategy — almost always sniping new Pump.fun token launches — then closes minutes later to reclaim its rent, redeploying under a fresh id for the next run.

Why a program at all?

Sniping means "buy the instant the pool exists, atomically, or abort" — you can't do that reliably from a wallet. A tiny custom program bundles the whole attempt (and often multi-venue routing) into a single instruction that either lands complete or reverts.

Why thousands of failed transactions?

That's the race. The bot fires on every launch; most attempts lose the block or the token rugs, so they revert. The failures are the strategy — spray for the few that land.

Why redeploy and close?

The ~0.2 SOL of rent is refundable on close, and a fresh program id sidesteps any blocklist or reputation built against a known address. Cheaper and stealthier to burn identities than to keep one — so one operator can wear dozens of "new program" identities in a day.

How On Record catches it

Exact-bytecode dedup (same sha256 = same bot) collapses the redeploys into one cluster; lifecycle tracking sees the deploy → close; the failed-tx count confirms the intent. No explorer distinguishes "new protocol" from "same bot, 30th identity today" — that's a novelty-definition problem, which is exactly what this radar solves.

last 7d · updated 2026-09-14 22:51 UTC