// the find
bigmacman1129/solana-rust-sniper-bot
solana raydium sniper/pumpfun sniper: this solana raydium sniper/pumpfun sniper is written in Rust. In addtion to these solana raydium snipe bot(raydium sniping bot) and pumpfun snipe bot(pumpfun sniping bot), it has raydium bundler, pumpfun bundler, copy trading bot, raydium/pumpfun volume bot more
A Rust bot that watches Raydium and Pump.fun for new pools through Yellowstone or Helius gRPC feeds and submits buys through Jito and NextBlock. The description also advertises a bundler, a copy-trading bot and a volume bot, and the volume bot is the part readers should hear about first. This assessment is based on the README and file tree only; the source was not read.
- Data sources are split into separate monitor modules (yellowstone.rs, helius.rs, ws.rs), so feed latency can be compared without rewriting the engine. Each venue's logic sits in its own file under dex/ (pump_fun.rs, raydium.rs, meteora.rs, orca.rs), not inside the engine.
- Submission goes through several relays (jito.rs, nextblock.rs, jupiter.rs), so landing is not tied to one endpoint. Cargo.lock is committed, which keeps binary builds reproducible.
- The README lists the strategy parameters (SLIPPAGE, TP, SL, TIME_EXCEED, TOKEN_AMOUNT) as environment variables, so the configuration surface is visible up front.
- The trial path asks for PRIVATE_KEY in an env file and then has you run a prebuilt solana-pumpray-sniper.exe from a zip hosted in GitHub user-attachments. Nothing in the repo ties that binary to the source. Wallet-key bots distributed as prebuilt executables are a common route for wallet-draining malware, and the README gives no way to verify it.
- The volume bot and bundler are wash-trading and coordinated-buy tooling. The first generates trades that do not reflect real demand, and the second spreads buys across up to 20 wallets. The README presents both as features with no caveat about what they are used for.
- The README does not match the code. It lists services/zeroslot.rs and services/nozomi.rs, which are not in the tree, and it cites Rust's safety guarantees as a security feature. Memory safety does not protect against bad trade sizing, slippage handling or key handling, which is where a sniper loses money.
- The evidence for the bot working is one screenshot and three Solscan links from a single trade. The blocklist example uses 0x-style EVM addresses, which are not valid Solana addresses, so the text was probably copied from another project. The tree shows no tests directory and no LICENSE file at the root.