security and status
This program controls emission and stake vaults. Mint authority is revoked during launch, but the program remains upgradeable. Below is what has been demonstrated and what remains unproven.
proven
Program deployed
The mainnet-beta program dumps to the pinned artifact hash below
proven
Build reproduces
Pinned Docker build from clean committed source 468cc6a; artifact hash matches the deployed program
unproven
External audit
Not commissioned
unproven
Upgrade authority
No. Upgrade and platform fee control sit with one key and fee receipt with a second, all held by one operator
the ledger
Proven means there is an artifact or a test run behind it today. Unproven means the step has not been taken, not that it failed. Nothing here is described as safe, audited or verified.
Mint authority is revoked in the launch transaction
Compiled-program integration suite, including metadata and authority assertions
proven§2.4
No post-launch instruction grants creators administrative control
Program source and independent review of the on-chain scope
proven§2.1
A solution for one token is rejected by another
Tenant isolation and cross-token replay cases in the integration suite
proven§6.2
Splitting a position across wallets does not multiply weight
Wallet-splitting case in the integration suite
proven§4.1
Direct transfers into a stake vault credit nobody
Donation case in the integration suite; liabilities stay bounded by the balance
proven§4.6
A lapped round stops resolving instead of returning newer numbers
Ring eviction covered by unit tests and by the integration suite
proven§4.5
Settlement cannot pay out more than a round reserved
Integer truncation, exercised across three weighted rounds with exact balances
proven§4.4
Proof verification fits the compute budget
Measured at approximately 220,000 units in local validator acceptance
proven§5.5
The SBF build reports no stack-frame diagnostic
Verifier log grepped for stack, frame, exceed and error matches
proven§9.2
Two independent reviews found no remaining high-severity issues
One program review and one web transaction review, each within its reviewed scope
proven§9.2
The deployed program bytes match the reviewed release artifact
The mainnet-beta program dumps to the pinned artifact hash below
proven§9.1
The exact release artifact completes the deployed acceptance path
Two tokens, two wallets, three weighted rounds, exact claims and full withdrawal passed on mainnet-beta against the pinned artifact
proven§9.2
The release build is reproducible from committed source
Pinned Docker build from clean committed source 468cc6a; artifact hash matches the deployed program
proven§9.2
The real browser wallet path works against the reviewed artifact
Phantom lookup table preparation, atomic mint and pool launch, stake, browser proof, claim and withdrawal finalized and independently checked
proven§9.2
A full mining cycle has completed on mainnet-beta
Two tokens, two wallets and three weighted rounds through claim and withdrawal with the release program
proven§9.3
Upgrade and fee control are protected by multiple independent signers
No. Upgrade and platform fee control sit with one key and fee receipt with a second, all held by one operator
unproven§9.4
The source is publicly readable
No public repository is configured, so the citations throughout this site are not yet checkable by you
unproven§10.3
check it yourself
The useful checks do not require trusting this site. All three read the cluster directly.
Confirm a token's supply cannot grow
spl-token display <MINT> --url mainnet-betaMint authority and freeze authority must both read as none. If either is set, the supply is not fixed, whatever any page says.
Confirm the program is what you were told it is
solana program dump <PROGRAM_ID> out.so --url mainnet-beta && sha256sum out.soCompare the result with the reviewed artifact hash above. A mismatch means the program you are reading is not the reviewed release.
Read a token's frozen parameters
solana account <CONFIG_PDA> --url mainnet-betaThe config PDA is derived from the seeds lode-config and the mint. Supply, round length, halving interval, difficulty target and creator allocation are all in it, and no instruction writes to any of them after launch.
standing prohibitions
Recorded in the repository as rules for anyone working on it, so they survive a change of contributor rather than living in someone's judgement.
No admin, update instruction or economic setter may be added to a launched token.
The token mint may never be removed from the Equihash input block.
The creator allocation ceiling may not be raised above 10% without an explicitly recorded decision.
No random-payout feature: no jackpots, lotteries or prize draws.
No difficulty retargeting.
No claim that a deploy, test run or acceptance flow succeeded without the actual output.