Overview
ONRAMP is a peer-to-peer marketplace for Solana tokens. You sell to another person who pays you in cash through Wise, Revolut or Zelle. Neither side has to trust the other, because the tokens sit in an on-chain escrow vault until the payment is confirmed.
SOL and USDC are the primary currencies. Other Solana tokens, including memecoins, are supported too once they meet market cap and liquidity requirements.
It is also a way to exit a position without selling on the chart. You sell straight to a buyer at an agreed price, so there is no slippage, no price impact and no red candle, and you get cash in one step.
The escrow follows the Lock-Release-Equilibrium system (below). The vault is a Solana program. No person, server or support team holds a key that can move it. It can only do two things: pay the buyer or refund the seller, and each is allowed only under fixed rules.
ONRAMP never touches fiat money. Cash moves directly between the buyer's and seller's own payment apps.
Lock-Release-Equilibrium
Lock-Release-Equilibrium is the system behind every ONRAMP trade. It has three stages, each enforced by the escrow program, so neither side ever has to trust the other.
| Stage | What happens | What it guarantees |
|---|---|---|
| Lock | The seller's SOL or USDC moves into the on-chain vault. Only then does the buyer see the seller's payment details. | A buyer never pays into nothing. |
| Release | The vault pays out one of two ways: to the buyer after the seller confirms, a verified receipt, or a ruling; or back to the seller if the buyer never pays. | Funds can only reach the buyer or the seller. No third address exists. |
| Equilibrium | Both sides post bonds, every step has a deadline, and the side that breaks the rules pays the other. | Every trade ends balanced. Going quiet or cheating always costs more than it gains. |
Equilibrium in practice: an unpaid trade returns to the seller automatically, a paid trade can always be released with proof, and silence never pays either side.
Supported tokens
Every token trades through the same escrow: the seller's tokens lock in the vault before the buyer pays.
| Tier | Tokens | Status |
|---|---|---|
| Primary | SOL and USDC | Supported from launch, with the highest limits |
| Listed | Memecoins and other Solana tokens that pass the listing check | Coming soon |
Listing requirements
A token is listed automatically when it meets all of these. They are re-checked every day.
| Requirement | Minimum | Why |
|---|---|---|
| Market cap | $2M | Too-small tokens can't be priced fairly |
| Liquidity | $40K across DEX pools | Gives a reliable live price to quote against |
| Mint authority | Revoked | No one can print more supply mid-trade |
| Freeze authority | Revoked | No one can freeze tokens in the vault |
| Token type | Standard SPL, or Token-2022 without transfer fees or hooks | The vault must release exactly what it received |
| Holder concentration | Top 10 wallets hold 30% or less | Lowers the risk of a coordinated dump |
A token that stops meeting these is delisted: no new offers or bids, while open trades finish normally.
Draft figures. Final values are set before listings open.
Pricing
Sellers set a fixed price, or peg their offer to the live market price, for example 2% below. The cash amount is fixed the moment the tokens lock, so price moves during the payment window don't change what the buyer owes. Memecoin trades use a 15-minute payment window and lower trade limits than SOL and USDC.
Exit a position without selling on the chart
- No slippage or price impact. The price is agreed up front and the trade never touches a liquidity pool.
- No dump on the chart. Your sale doesn't print a red candle that spooks other holders.
- Straight to cash. You're paid in fiat directly, with no separate swap and cash-out.
- Still on the record. Every lock and release is visible on-chain. It just doesn't move the pool price.
Buyers take on the token's price risk once it's released to them. Every offer shows the token's live price, liquidity and age so you can judge the deal.
Selling crypto
You can post an offer at your own price, or fill a buyer's bid from the market.
- Lock your crypto. When a buyer takes your offer, or you fill their bid, your SOL or USDC moves into the vault.
- Wait for payment. Only now does the buyer see your Wise, Revolut or Zelle details. They pay with the trade code in the memo.
- Check your own app. Open your payment app and confirm the exact amount arrived from the buyer.
- Tap received. The vault releases the crypto to the buyer.
Only tap received after the money shows as completed in your own app. Never rely on a screenshot or an email the buyer sends you.
Buying crypto
Take a seller's offer, or post a bid and wait for a seller to fill it. Either way the seller's crypto is locked before you are shown where to pay.
- Wait for the lock. Never pay before the trade shows
Locked. - Pay the exact amount from an account in your own name, with the trade code in the memo.
- Mark the trade paid within the payment window, usually 10 to 30 minutes.
- Keep your receipt email. If the seller goes quiet, it is your proof of payment.
Trade lifecycle
Every trade moves through a fixed set of states, and every state has a deadline, so funds can never be stuck.
| State | Entered when | Leaves when |
|---|---|---|
| Locked | Seller's crypto moves into the vault | Buyer marks paid, or the payment window ends (refund) |
| Paid | Buyer marks the cash as sent | Seller confirms, a proof survives the challenge window, or a dispute opens |
| Disputed | Either side opens a dispute | The ONRAMP team reviews it manually and rules |
| Released | Crypto sent to the buyer | Final |
| Refunded | Crypto returned to the seller | Final |
Silence never pays the buyer. If the seller doesn't respond, the buyer must submit a proof or open a dispute. A timer running out alone never sends crypto to the buyer.
Escrow program
The vault is an account owned by the ONRAMP program through a program-derived address. The program checks every instruction against these rules:
release(to: buyer) requires seller.confirmed || proof.valid && challenge_window.expired || arbiters.ruled_for(buyer) refund(to: seller) requires payment_window.expired && !buyer.marked_paid || arbiters.ruled_for(seller) withdraw(to: anyone_else) // not defined
Accounts
| Account | Holds |
|---|---|
Offer | Asset, price, limits, accepted apps, payment window, the seller's hashed payment handle |
Bid | Asset, amount, price, payment app, how fast the buyer will pay, buyer bond |
Trade | Locked amount, fiat amount, trade code, deadlines, state, bonds |
Vault | The locked SOL (as wSOL) or USDC, controlled only by the Trade account |
The program's upgrade key sits in a multisig behind a timelock at launch, and is removed once the code is audited and stable.
Payment apps
ONRAMP only accepts payment apps where a sent payment can't be charged back like a card payment.
| App | Allowed transfer | Reversal risk |
|---|---|---|
| Wise | Wise to Wise, funded from balance or bank | Low |
| Revolut | Revolut to Revolut, by Revtag | Low |
| Zelle | Bank to bank | Low to medium |
| PayPal, Venmo, Cash App, cards | Not accepted | High |
Buyers must pay from an account in their own name. The name on the payment must match the buyer's verified payment account.
Payment proofs
Most trades never need a proof: the seller confirms. Proofs exist for when the seller goes quiet. Nobody is ever required to log into their bank.
| Method | What you do | What you share |
|---|---|---|
| Receipt email | Drop the confirmation email from Wise, Revolut or your bank into the app | One email. The proof is built on your device and checks the provider's DKIM signature |
| Seller receipt | The seller drops in their "you received money" email | One email, seller side |
| Bank link Later | Connect read-only through your bank's own approval screen | Read-only transactions |
| Web proof Optional | Open your payment app inside ONRAMP and prove the transaction page | Only the fields below; never your password |
A valid proof must show the recipient, an amount at least equal to the trade, the currency, the trade code or unique amount, a completed status after the lock, and a transaction ID never used before.
A proof starts a 2-hour challenge window. The seller can release early, or contest by proving from their own account that nothing arrived.
Disputes
Disputes are manually reviewed. Dispute resolution is manually reviewed by the ONRAMP team, with $ONRAMP staker arbitration planned as the system expands.
- Either side opens a dispute after the trade is marked paid. The seller can do this any time; the buyer once the seller's release window has passed.
- The trade is frozen. Neither side can release or refund it on their own.
- Both sides send their evidence to the ONRAMP team: receipts, transaction IDs and screenshots.
- The team reviews it and rules through the escrow's arbiter key: release to the buyer, or refund the seller.
- The program carries out the ruling. A buyer who loses forfeits their bond to the seller.
Bonds and limits
| Who | Bond | Lost when |
|---|---|---|
| Buyer | 0.02 SOL, posted when accepting a trade | They don't pay in time, or lose a dispute |
| Seller Planned | A standing bond per offer, sized to the app's risk | They stall on a paid trade, or lose a dispute |
| Arbiter Planned | Staked $ONRAMP | They miss votes, or their rulings are overturned on appeal |
New accounts start with a $100 limit per trade, which grows with completed trades. Each payment account can be linked to only one wallet.
Draft figures. Final values are set before mainnet.
Fees
The protocol fee is 0.5% of the trade, paid by whoever takes the order, in the traded asset when the vault releases. It funds the insurance pool, arbiter rewards and the treasury. Stakers of $ONRAMP pay a reduced fee.
$ONRAMP
Trades settle in SOL and USDC. $ONRAMP is used where the protocol needs collateral that can be taken away from people who cheat.
- Arbiter staking (planned): as the system expands, stakers will judge disputes and earn from them. Today disputes are manually reviewed by the ONRAMP team.
- Seller bonds: post bonds in $ONRAMP at a lower rate than USDC.
- Fee discount: stakers pay less per trade.
- Governance: vote on new payment apps, limits and fees, behind a timelock.
The token launches only after the escrow is audited and live on mainnet. Its contract address will be posted on the ONRAMP homepage on launch day. Treat any earlier address as a scam.
Security
- No admin withdrawal. The vault can only pay the buyer or refund the seller.
- Each trade has a unique code and a unique cents amount, so one payment can't be claimed twice.
- Independent audit, a bug bounty and capped trade sizes before and after mainnet.
- Upgrades go through a multisig and a public timelock, then the upgrade key is removed.
Risks
Escrow removes the risk of the other side running off. Some risks remain, and you should understand them before you trade.
- Fraud recalls: a payment from a stolen account can be pulled back by the bank later. Name matching, trade limits and the insurance pool reduce this risk but can't remove it.
- Payment app terms: some apps restrict using their service to buy crypto, and may limit your account.
- Smart contract risk: audited code can still have bugs, which is why trade sizes are capped early on.
- Price moves: SOL's price can change during a trade. USDC trades avoid this.
- Memecoin risk: listed tokens can lose value fast after you buy them. The listing check filters out the riskiest tokens but can't prevent a price drop.
Glossary
| Offer | A seller's standing order to sell crypto at a set price. |
| Bid | A buyer's standing order to buy crypto at a set price. |
| Vault | The program-controlled account that holds the crypto during a trade. |
| Trade code | A short code, like ONR-7Q4K, the buyer puts in the payment memo. |
| Challenge window | The 2 hours after a proof during which the seller can contest it. |
| Bond | Collateral a party loses if they break the rules. |
