PROTOCOL PAPER
Introduction
Liquidity, unlocked.
Bastion organizes isolated lending around eligible, user-owned PumpSwap LP positions. Borrowers place LP tokens in a dedicated collateral vault and draw the market’s approved quote asset. Lenders supply that asset to a specific market and take its credit risk.
The collateral adapter verifies ownership and withdrawal entitlement. The credit ledger tracks lender shares and borrower debt. The risk engine values reserves and applies limits. The liquidation mechanism exchanges repayment for bounded collateral seizure when a position becomes unhealthy.
Two separate relationships.
BAST/PUMP is Bastion’s token trading pair. The 3% fee on that route funds protocol capital, liquidation resources and infrastructure. It does not determine the loan currency of every credit market.
Each lending market defines its own approved quote asset, such as SOL or USDC, consistent with its underlying collateral pool. A lender’s claim and a borrower’s debt are accounted for in that market asset. The Risk Lab uses SOL display units.
Choose a path.
- Borrowers: start with eligible collateral and borrowing limits.
- Lenders: understand shares, withdrawals and losses.
- Builders: inspect accounts, invariants and observations.
- Token holders: read the BAST/PUMP fee allocation.
PROTOCOL PAPER
Collateral valuation
Reserve-aware recognition
share = collateral LP / pool accounting LP supply reserve = min(current eligible measure, observation-window measure) collateral = share × physical quote reserve × recognition factor initial borrowing limit = collateral × initial LTV health factor = collateral × liquidation LTV / accrued debt
The Risk Lab uses 80% recognition, 20% initial LTV and 30% liquidation LTV. Its reserve input stands for the conservative physical reserve measure. Market caps, available cash, withdrawal constraints and freshness checks also restrict actual borrowing.
Use the pool’s withdrawal accounting.
PumpSwap’s pool accounting LP supply can differ from circulating mint supply after burns. Substituting the wrong denominator can overstate the claim. The adapter must match the deployed withdrawal behavior and validate account state.
Virtual quote reserves used in pricing are not physical assets available for withdrawal. They are excluded from collateral recognition. The volatile base-token leg receives zero value in this recognition model.
Worked SOL scenario
| Input or result | Value |
|---|---|
| LP share | 1,000 / 100,000 = 1% |
| Physical SOL-side reserve | 10,000 SOL |
| Withdrawable quote-side claim | 100 SOL |
| 80% recognized collateral | 80 SOL |
| 20% initial borrowing limit | 16 SOL |
| Debt and health factor | 10 SOL debt / health 2.40 |
A reserve claim is not a floor.
A 60% reserve decline reduces the example’s recognized collateral to 32 SOL. At 10 SOL debt, health falls to 0.96 before additional interest. Sales into the pool can drain quote reserves quickly.
Use coherent observations across multiple slots, depth controls, exposure caps and conservative withdrawal estimates. A historical window alone cannot prevent every form of reserve manipulation.
PROTOCOL PAPER
Borrowing & supplying
The borrower lifecycle
- Deposit: transfer eligible LP to the correct collateral vault.
- Borrow: accrue interest, check valuation, caps, cash and utilization, then transfer the market asset.
- Manage: add LP or repay debt. New borrowing still requires a fresh risk check.
- Exit: repay debt to release collateral, or withdraw a permitted amount while maintaining required health.
There is no fixed maturity in this model. Position health and market permissions determine the borrower’s ability to keep or change the loan.
Lender shares and liquidity
A lender supplies the approved quote asset to a chosen market and receives a claim on its net assets. Share issuance accounts for cash, accrued debt and recognized losses. Conservative rounding prevents value being manufactured through repeated deposits and redemptions.
A share’s accounting value is not instantly withdrawable cash. Borrowed capital can constrain redemptions. Failed liquidations can reduce market assets and lender share value.
Accrue before changing state.
Update interest before debt or share changes. Verify accounts and authorization, compute a permitted transition, transfer assets and verify balance changes. Custody and ledger changes must succeed atomically.
SOL-denominated markets account for wrapped SOL in token vaults. Wrapping and unwrapping are explicit client instructions; rent and network fees remain separate from principal.
PROTOCOL PAPER
Liquidation
The health boundary
Health at or below 1 places a position in the liquidation region. Execution still requires valid observations, correct accounts and an enabled liquidation path. A threshold does not guarantee timely execution during congestion or an observation failure.
The ordinary close factor limits repayment to 50% of outstanding debt per step. Re-evaluate health afterward. Deep insolvency requires a defined terminal-loss path so repeated partial liquidations do not strand unrecoverable debt.
Atomic repayment and seizure
repayment ≤ close factor × outstanding debt seized value ≤ repayment × (1 + liquidation incentive) seized LP ≤ collateral LP held in custody
The example incentive is 8%. Repayment, debt-share reduction and collateral transfer form one atomic state transition. The liquidator receives LP and must account for withdrawal restrictions, reserve movement and exit costs.
Deficits stay visible.
When recoverable collateral cannot satisfy the debt, the market recognizes a deficit. Buffer support is finite, explicitly authorized and capped. It is not assumed in valuation before settlement. Uncovered losses reduce the affected market’s assets.
PROTOCOL PAPER
BAST / PUMP · 3%
A route-specific creator fee
The BAST/PUMP design assigns a 300 basis point creator fee to eligible trades through the configured route. Platform fees, LP fees, lending interest and network costs are separate. This is not a universal token transfer tax.
The PUMP quote mint, custom-pair eligibility, configurable-fee flag and basis-point cap must match deployed program state. Standard SOL and USDC schedules are not substitutes for the selected BAST/PUMP configuration.
Three destinations
| Budget | Trade-value allocation | Share of net receipts |
|---|---|---|
| Protocol credit capital | 2.00% | 200 / 300 |
| Liquidation buffer | 0.75% | 75 / 300 |
| Infrastructure | 0.25% | 25 / 300 |
Received PUMP is the starting point.
Allocate only finalized net receipts, deduplicated by transaction and instruction identity. Accrued but unclaimed fees are not spendable capital. Conversion into a market’s SOL or USDC lending asset is a separate, approved transaction with route, slippage and budget checks.
The receipt allocator uses integer arithmetic with six decimal places for its interface calculation. Production accounting reads the mint’s actual decimals. Round credit and buffer shares down and assign the remaining units to infrastructure.
Token ownership and lending are different.
Holding BAST does not itself create a lender share, borrower position, equity claim, redemption right or guaranteed yield. Lending requires a separate deposit into a selected market. Fee revenue is variable and is not future collateral.
PROTOCOL PAPER
Program architecture
Four program boundaries
| Module | Responsibility | Boundary |
|---|---|---|
| Pool adapter | LP identity, custody and entitlement | Physical withdrawal accounting |
| Credit ledger | Shares, cash, debt and interest index | Accrue before mutation |
| Risk engine | Observations, valuation, caps and health | Reject stale risk increases |
| Liquidation | Repayment, seizure and loss recognition | Atomic and bounded transfers |
Deterministic relationships
Market(pool, quote_mint, risk_version) Position(market, owner) CollateralVault(market, lp_mint) LiquidityVault(market, quote_mint) ObservationWindow(market) DebtIndex(market)
These describe account relationships. Actual seeds, serialized layouts and instruction discriminators come from the verified implementation interface. Clients must not guess addresses from descriptive account names.
Required invariants
- Correct signer, account owner, mint, program, PDA relationship and market identity.
- Checked arithmetic and verified token decimals.
- Actual received amounts rather than unverified client balances.
- Interest accrual before share and debt changes.
- Fresh valuation, available cash and caps before risk increases.
- Atomic custody and ledger transitions.
Events record the market, owner, action, amount, debt index and configuration version. Indexing is replay-safe and tied to finality.
PROTOCOL PAPER
Risk factors
Reserve and market risk
A falling base-token market can drain quote reserves faster than liquidations recover debt. SOL and other market assets can fluctuate against external currencies. Thin liquidity, concentrated ownership and coordinated trading can undermine collateral measurements. Borrowers and lenders can lose funds.
Program and execution risk
Arithmetic bugs, incorrect account checks, unsafe upgrades and dependency failures can affect custody. Congestion, RPC outages, paused withdrawals and unprofitable liquidation routes can delay recovery. A transaction simulation cannot guarantee later execution at identical state.
Liquidity and loss risk
Lender shares may exceed immediately available cash while funds are borrowed. Redemptions can be constrained. Bad debt reduces the relevant market’s assets. Buffer resources are finite and conditional.
Operational and authority risk
Compromised signers, observers or capital operators can cause loss. Markets can share vulnerable code or services despite separate accounting. Risk controls reduce exposure; they cannot remove every failure mode.

