Skip to content

Tech deep dive · Economic & Game-theoretic · 16 min

Token Curves & Bonding Curves

How bonding curves set a token’s price from its supply as it is minted and burned, and how they differ from AMM curves like x·y=k.

On this page
Why this matters

A is a contract that sells a token at a price set by how many tokens exist. It powered curation-market experiments in 2017, friend.tech’s “keys” in 2023 and the millions of pump.fun meme coins since 2024. It is easy to confuse with the curve inside an such as Uniswap’s x · y = k, but the two do different jobs. Knowing which is which tells you who pays you back when you sell, and why the first buyers usually do best.

Standard Explanation

A bonding curve is a smart contract that mints a token on each buy and burns it on each sell. The price is a fixed function of the current supply, and the money paid in is held as a reserve that pays sellers. An AMM curve such as x · y = k instead prices two existing tokens against each other in a pool that liquidity providers filled; a swap creates neither token.

What a bonding curve is

Simon de la Rouviere set out the idea in November 2017 as part of his work on “curation markets”. You send ETH to a contract and it mints new tokens at a price “hardcoded according to some algorithmic curve” of the current supply; at any time you can sell back, and the contract burns the tokens and pays you from the communal pool. He credits the Zap project with the name.

Every design has three parts:

  • A price function. price = f(supply). No one sets the price by hand and there is no order book.
  • . Buying creates tokens and selling destroys them, so supply moves with demand.
  • A reserve. The money paid in stays in the contract to pay sellers. In the simplest design it always equals the area under the curve up to the current supply, so if everyone leaves, all the ETH goes back out and every token ceases to exist.

Because the contract always trades, the token has a market from its first second without anyone seeding a pool. If it also trades elsewhere, arbitrage keeps the two prices close.

Curve shapes and the area under them

ShapePrice ruleHow it behaves
Linearprice = m × supply + bEach token costs a fixed step more than the last.
Polynomialprice = k × supplyⁿWith n above 1, rises ever faster; early buyers gain most from later demand.
Exponentialprice = a × e^(r × supply)Cheap at first, quickly out of reach.
Sigmoid (S-curve)price = max ÷ (1 + e^(−r × (supply − mid)))Flat, then steep around a midpoint, then levels off at a ceiling.

Because the price changes with every token, buying Δ tokens walks up the curve: the cost is the area under the curve (the integral of f) between the old supply S₀ and the new supply S₁ = S₀ + Δ. A sale walks back down and pays out the same area. For a linear curve the area is a trapezoid:

cost = b × Δ + (m ÷ 2) × (S₁² − S₀²)

A worked example: a linear curve

Take a curve with b = 0 and m = 0.0001, priced in ETH, so price = 0.0001 × supply.

  1. Starting point. 1,000 tokens exist. The spot price is 0.0001 × 1,000 = 0.1 ETH. The reserve is the area under the curve from 0 to 1,000: 0.00005 × 1,000² = 50 ETH.
  2. Buy 1,000 tokens. The cost is 0.00005 × (2,000² − 1,000²) = 150 ETH, an average of 0.15 ETH: the midpoint of the 0.1 ETH start and 0.2 ETH end.
  3. After the buy. 2,000 tokens exist, the spot price is 0.2 ETH and the reserve holds 50 + 150 = 200 ETH.
  4. Sell them back. Selling those 1,000 tokens returns exactly 150 ETH, ignoring fees, and everything goes back to where it started.

Step 3 holds the point people most often miss. At 0.2 ETH, the 2,000 tokens look worth 400 ETH, but the reserve holds 200 ETH. It can buy back every token, but each sale lowers the price for the next seller: the first gets close to 0.2 ETH, the last close to nothing. The reserve backs the curve, not the headline price.

The Bancor formula and the reserve ratio

The Bancor Protocol whitepaper (the version cited here is dated January 2018) packaged the same idea as “Smart Tokens”. Each holds a balance of another token in a “connector” (BNT’s held ETH); buying adds to the balance and issues Smart Tokens, and selling removes them and withdraws from it.

Instead of naming a curve, Bancor fixes the connector weight (CW, later usually called the ):

CW = connector balance ÷ (price × supply)

so

price = connector balance ÷ (supply × CW)

Holding that ratio constant through every trade, the CW alone fixes the curve’s shape. At 100% the price never moves; at 50% it rises in a straight line with supply; at 10% it rises much faster. For a power curve price = k × supplyⁿ starting at zero, the ratio is 1 ÷ (n + 1), which is why the linear example held exactly half of price × supply. One parameter covers the whole family of power curves.

For a trade of any size:

tokens issued = supply × ((1 + paid ÷ balance)^CW − 1)

The whitepaper’s example: with a supply of 1,000, a balance of 250 and a CW of 50%, the quoted price is 0.5, and paying in 10 tokens issues about 19.8, an effective price of about 0.505, because the buyer pays for the price move her own trade causes. Ten small trades cost exactly the same as one large one.

Spreads, tributes and augmented curves

With one curve for buys and sells, there is no revenue: every ETH paid in is owed to some future seller. Later designs pull the curves apart.

  • Buy/sell spreads. The Continuous Organizations whitepaper (version 1.2, October 2019) puts the buy curve above the sell curve: only part of each purchase goes to the reserve, and the rest funds the organization. It says plainly that its tokens are securities.
  • Augmented bonding curves. The Commons Stack design, described in December 2019, adds a “hatch” in which early backers buy at a fixed price, with tokens that vest. Hatch money is split between a reserve pool backing the curve and a funding pool the community spends, and an exit tribute sends a slice of each sale to the funding pool. The vesting exists, the authors say, because bonding curves are very exposed to pump-and-dump attacks; they also list front-running as unsolved.

The cost: the reserve no longer covers the area under the buy curve, so buying and immediately selling loses money even if no one else trades.

Bonding curves vs. AMM curves

Uniswap holds two tokens in a pool and keeps the product of the reserves, x · y = k, from falling, adding a 0.30% fee from each trade to the pool. A swap adds one token and removes the other; both already existed, deposited by liquidity providers. The only tokens a pair mints or burns are liquidity tokens, and only when liquidity is added or removed. The DeFi module covers pools in more detail.

Bonding curveAMM curve (e.g. x · y = k)
Price depends onThe token’s own supplyThe ratio of two reserves in a pool
A buy…Mints new tokensTakes existing tokens out of the pool
A sell…Burns tokensPuts existing tokens back into the pool
Who supplies the other sideThe contract itself, from its reserveLiquidity providers’ deposits
Total supply of the traded tokenChanges with every tradeUnchanged by swaps

The history is tangled because Bancor’s maths can produce both. Uniswap went live on 2 November 2018, implementing the constant-product market maker Vitalik Buterin had sketched in 2016 and 2017. Almost a year earlier, Bancor was already running relays: Smart Tokens with two connectors, each weighted at 50%. One example was the MANA/BNT relay that Decentraland and Bancor announced in December 2017. Converting A to B through a relay meant buying the relay token with A and selling it for B in one step, so its supply ended where it started and the two reserves were simply traded against each other.

So the line between the two is not the formula’s shape but what the contract does with the traded token: issue it against a reserve (bonding curve) or swap it against other people’s deposits (AMM). pump.fun, below, uses constant-product maths for what is functionally a bonding curve.

Where bonding curves have been used

The 2017–2019 designs above were mostly experiments; mass use came later, in social and meme-coin apps.

friend.tech (2023–2024). friend.tech launched on Base on 10 August 2023. Each user’s “keys” sat on a quadratic curve: with S outstanding, the next cost S² ÷ 16,000 ETH (0.625 ETH at 100 keys), and sales ran back down the same curve. Only the owner could buy their first key, which was free, and the last key could never be sold. A 10% fee on top went half to the protocol and half to the owner. A quadratic curve’s reserve ratio is about one third, so the contract held roughly a third of the keys’ headline value. The Block reported the developers took at least $20 million in fees in the early surge; a May 2024 version 2 failed to revive it, and on 8 September 2024 the team handed control of the contracts to the null address.

pump.fun (2024–). pump.fun launched on Solana in January 2024. Anyone can create a coin that is “instantly tradeable on a bonding curve without having to seed liquidity”. Per its public program documentation, as of 2026:

  • Each coin has a fixed supply of 1 billion, of which 793.1 million are sold through the curve.
  • The curve uses Uniswap-v2-style constant-product maths over synthetic reserves: a virtual 30 SOL against a virtual 1.073 billion coins. No one deposits that 30 SOL; it sets a non-zero starting price. Strictly, the contract sells from an inventory of existing coins rather than minting, but the effect is the same: price depends on how many coins have left the curve, and the SOL paid in pays sellers.
  • The curve is complete when its last coin is sold. On these parameters that takes about 85 SOL before fees, and the price ends about 15 times where it began (our arithmetic).
  • A completed curve graduates: anyone can move its liquidity into a pool on PumpSwap, pump.fun’s own constant-product AMM, and the pool’s liquidity tokens are burned.

Graduation is where the token switches from a bonding curve to an ordinary AMM pool. In 2024, graduating coins went to Raydium once their market cap reached about $69,000, with roughly $12,000 of liquidity deposited and burned. By August 2024, fewer than 1.5% of more than 1.8 million coins had got that far. Since 20 March 2025 they graduate to PumpSwap, which dropped the 6 SOL migration fee and charges 0.25% a swap.

Risks and limits

  • Front-running and sandwiching. Curve prices are public and deterministic, so a large pending buy is a known price move. A bot buys first, the victim buys higher up the curve, and the bot sells straight back into the reserve: the same seen on DEXs. pump.fun’s buy and sell instructions accept a maximum cost and a minimum output; set limits tightly.
  • Early-buyer advantage and dumps. Early buyers pay least, and any profit they take comes out of the reserve paid in by later buyers. Without outside revenue it is zero-sum before fees and negative-sum after. An insider who buys first and sells into a rush is running a .
  • The reserve is not a price floor for everyone. A same-curve reserve pays every holder back only down the curve, in order; the last sellers get the lowest prices. Designs with spreads, tributes or a funding pool hold less. And the guarantee ends at graduation: once a pump.fun coin is in an AMM pool, no reserve is committed to buying it back.
  • Who controls the reserve. The maths protects you only while the reserve stays put. In May 2024 an attacker using flash-loaned SOL, and reportedly privileged keys, took about 12,300 SOL from pump.fun’s bonding curves before trading was paused. Admin keys and upgradeable programs are ways around any curve.
  • Regulation. It depends on what is sold and where. In February 2025 the US SEC’s Division of Corporation Finance said typical meme coins are not securities, but the statement excludes tokens sold on the promise of profit from others’ efforts, does not excuse fraud, and is not binding. Curve tokens sold to fund a project, as in Continuous Organizations, may be securities.

Key takeaways

  • A bonding curve mints on buy and burns on sell, at a price set by current supply, and holds what buyers pay as a reserve for sellers. Buying Δ tokens costs the area under the curve; for a linear curve, b × Δ + (m ÷ 2) × (S₁² − S₀²).
  • Bancor’s connector weight fixes the reserve as a share of price × supply: 100% is flat, 50% linear, lower ratios steeper.
  • AMM curves like x · y = k swap two existing tokens from liquidity providers’ deposits and mint nothing. What separates the two is what the contract does with the token, not the formula’s shape.
  • friend.tech priced keys on a quadratic curve; pump.fun sells coins along a constant-product-style curve over synthetic reserves, then graduates the few that sell out to an AMM pool.
  • The reserve backs selling down the curve, not the headline price. Early buyers gain at later buyers’ expense, and bots target predictable curve trades.
Educational only, not financial or legal advice.