How SHIPLOG works.
One public pixel arcade. Every $SHLOG buy of 0.1 SOL or more opens a slot; you spend it on one feature request. An AI builds it, CI checks it, and the arcade hot-reloads with the buyer's wallet on the commit. No wallet connect. No payouts to users.
Request flow
- Buy $SHLOG on pump.fun from any wallet. Keep the transaction signature.
- Paste the signature into the form. The server reads that transaction over Solana RPC (read only) and checks: it succeeded, the signer spent at least 0.1 SOL, the signer received $SHLOG in the same tx, and it is recent.
- Type a feature, 3 to 120 characters. A filter runs before any model sees it.
- Watch the log. Your request is ranked by the $SHLOG your wallet holds now. When a builder is free and the compute budget allows, it builds in a sandbox, runs CI, and ships to the arcade.
The 10 rules
- 1 slot per 0.1 SOL
- max 10 slots per tx
- max 3 active per wallet
- rank = the $SHLOG you hold now
- hold 50% of that buy until your build starts,
or DROPPED · SELLER - filter rejections refund the slot
- paste within 30 minutes of your buy
- no wallet connect
- credit always goes to the buyer's wallet
- edit or cancel for 10 minutes
Unused slots stay with the buyer's wallet for 24 hours. The 30 minute window applies to the first request only. One request per buy is in line at a time; the next slot opens when it ships or is rejected.
States
- QUEUED
- Waiting, ranked by the $SHLOG the signer holds now, re-checked every 5 minutes.
- BUILDINGbuilding now
- A builder is writing the code in a sandbox (cap: $2 of tokens and 10 minutes).
- CI
- 6 checks: build, unit tests, lint, diff gate, page classifier, Playwright.
- SHIPPED
- Committed with the buyer's wallet and buy tx in the commit trailers, deployed, live in the arcade.
- REJECTED BY CI
- A check failed, or the build hit the cap ("over budget"). The partial diff stays public; the compute is charged.
- REJECTED BY FILTER
- Links, addresses, wallet or claim requests, hate, or political, national, ethnic or religious themes. The slot is refunded.
- DROPPED · SELLER
- When the build starts, the signer holds less than 50% of what that buy got. No compute is spent; the slot is gone.
Fees and the ledger check
Fees every 5 minutes: 60% builds, 20% buyback and burn, 20% ops. Every 5 minutes the engine collects the $SHLOG creator fees, splits them in integer lamports (the remainder goes to builds), sends the builds share to the COMPUTE wallet, buys $SHLOG with the burn share and burns it in the same transaction, and sends the ops share to the OPS wallet.
Each build's measured model cost is converted at a free SOL/USD read (pump.fun or DexScreener) and booked against the compute budget. The model bill is settled off-chain by the operator; the COMPUTE wallet never spends. A build starts only when the unspent budget covers the per-request cap.
Ledger check, every cycle, to the lamport: fees in = compute spent + unspent budget + burn + ops. On chain: the COMPUTE and OPS balances must equal what was allocated to them, and every burn signature must be confirmed. If anything is off by one lamport, the cycle halts, builders stop, and the page shows "ledger check failed" until the operator clears it.
service wallets: CREATOR / PAYER / COMPUTE / OPS / BUYBACK are generated by the project's own signer. No user ever receives a payout.
Models and caps
- Builder: Sonnet-class model, $2.00 of tokens and 10 minutes per request, max 300 changed lines.
- Filter: Haiku-class classifier plus fixed wordlists and patterns.
- 3 builders in parallel, one serial deploy lane.
Security model
- No wallet connect and no transaction building for users. The only thing you give us is a signature of a tx you already sent; we read it, we never write to the chain on your behalf.
- The model never holds the code: a host-side loop holds the API key and sends tool calls (read, edit, write, build, test) to an executor in a sandbox with no network, no environment, a read-only system and only the job's worktree writable.
- A static diff gate rejects any change outside the game's source, any URL, network call, storage access, wallet code, eval, or reach outside the iframe.
- The arcade runs in an iframe sandbox="allow-scripts" without same-origin: game code cannot read this page, the CA, the buy buttons, cookies or storage. Its Content-Security-Policy is set by the web server, outside the builder's reach.
- A failed health check after a deploy reverts the arcade automatically.
Known risk
A signature is public once your buy lands. Someone watching the chain could paste your fresh signature before you do and file junk text in your first slot. That request is still credited to your wallet, it is limited to one slot, it passes the same filter, and only the person who filed it can cancel it. Paste your signature right after you buy.
FAQ
- Do I connect a wallet?
- No. Paste the signature of your buy.
- Who gets credit?
- Always the wallet that signed the buy, never the person who pasted it.
- Why did my request drop?
- You held less than 50% of what that buy got when your build started. No compute was spent.
- Can a request break the arcade?
- It must pass 6 CI checks first, and a failed health check reverts the deploy.
- What happens when the town gets crowded?
- After 400 features a new season starts from the seed; old history stays readable.
- Does anyone get paid?
- No payouts to users. Fees buy compute and burn only.
No payouts to users. Fees buy compute and burn only. Not financial advice. demo replay