core

security and status

This program controls emission and stake vaults. Mint authority is revoked during launch, but the program remains upgradeable. Below is what has been demonstrated and what remains unproven.

proven

Program deployed

The mainnet-beta program dumps to the pinned artifact hash below

proven

Build reproduces

Pinned Docker build from clean committed source 468cc6a; artifact hash matches the deployed program

unproven

External audit

Not commissioned

unproven

Upgrade authority

No. Upgrade and platform fee control sit with one key and fee receipt with a second, all held by one operator

programCoreWBGScwpt9Fj44SRaHXLHfu1u5YP4m3msVmFrhvpM
reviewed artifact sha256fc787f1a91158c5616c6181f34499837d38b1167c3811f6e86c57f565f236a87

the ledger

Proven means there is an artifact or a test run behind it today. Unproven means the step has not been taken, not that it failed. Nothing here is described as safe, audited or verified.

  • Mint authority is revoked in the launch transaction

    Compiled-program integration suite, including metadata and authority assertions

    proven§2.4

  • No post-launch instruction grants creators administrative control

    Program source and independent review of the on-chain scope

    proven§2.1

  • A solution for one token is rejected by another

    Tenant isolation and cross-token replay cases in the integration suite

    proven§6.2

  • Splitting a position across wallets does not multiply weight

    Wallet-splitting case in the integration suite

    proven§4.1

  • Direct transfers into a stake vault credit nobody

    Donation case in the integration suite; liabilities stay bounded by the balance

    proven§4.6

  • A lapped round stops resolving instead of returning newer numbers

    Ring eviction covered by unit tests and by the integration suite

    proven§4.5

  • Settlement cannot pay out more than a round reserved

    Integer truncation, exercised across three weighted rounds with exact balances

    proven§4.4

  • Proof verification fits the compute budget

    Measured at approximately 220,000 units in local validator acceptance

    proven§5.5

  • The SBF build reports no stack-frame diagnostic

    Verifier log grepped for stack, frame, exceed and error matches

    proven§9.2

  • Two independent reviews found no remaining high-severity issues

    One program review and one web transaction review, each within its reviewed scope

    proven§9.2

  • The deployed program bytes match the reviewed release artifact

    The mainnet-beta program dumps to the pinned artifact hash below

    proven§9.1

  • The exact release artifact completes the deployed acceptance path

    Two tokens, two wallets, three weighted rounds, exact claims and full withdrawal passed on mainnet-beta against the pinned artifact

    proven§9.2

  • The release build is reproducible from committed source

    Pinned Docker build from clean committed source 468cc6a; artifact hash matches the deployed program

    proven§9.2

  • The real browser wallet path works against the reviewed artifact

    Phantom lookup table preparation, atomic mint and pool launch, stake, browser proof, claim and withdrawal finalized and independently checked

    proven§9.2

  • A full mining cycle has completed on mainnet-beta

    Two tokens, two wallets and three weighted rounds through claim and withdrawal with the release program

    proven§9.3

  • An independent security firm has reviewed the program

    Not commissioned

    unproven§9.3

  • Upgrade and fee control are protected by multiple independent signers

    No. Upgrade and platform fee control sit with one key and fee receipt with a second, all held by one operator

    unproven§9.4

  • The source is publicly readable

    No public repository is configured, so the citations throughout this site are not yet checkable by you

    unproven§10.3

check it yourself

The useful checks do not require trusting this site. All three read the cluster directly.

Confirm a token's supply cannot grow

shell
spl-token display <MINT> --url mainnet-beta

Mint authority and freeze authority must both read as none. If either is set, the supply is not fixed, whatever any page says.

Confirm the program is what you were told it is

shell
solana program dump <PROGRAM_ID> out.so --url mainnet-beta && sha256sum out.so

Compare the result with the reviewed artifact hash above. A mismatch means the program you are reading is not the reviewed release.

Read a token's frozen parameters

shell
solana account <CONFIG_PDA> --url mainnet-beta

The config PDA is derived from the seeds lode-config and the mint. Supply, round length, halving interval, difficulty target and creator allocation are all in it, and no instruction writes to any of them after launch.

standing prohibitions

Recorded in the repository as rules for anyone working on it, so they survive a change of contributor rather than living in someone's judgement.

  • No admin, update instruction or economic setter may be added to a launched token.

  • The token mint may never be removed from the Equihash input block.

  • The creator allocation ceiling may not be raised above 10% without an explicitly recorded decision.

  • No random-payout feature: no jackpots, lotteries or prize draws.

  • No difficulty retargeting.

  • No claim that a deploy, test run or acceptance flow succeeded without the actual output.