Skip to content

Security

Security

Review vault custody, signing keys, and upgrade permissions.

How it works
Not auditedPublic beta. Only deposit what you can afford to lose.

On-chain checks

Checks are unavailable until a vault deployment is connected.

registered key root
Unavailable
remaining one-time keys
Unavailable
program upgrade authority
Unavailable

Protocol rules

Defined by the implementation. These are not live checks or an independent audit.

signing algorithm
LMS_SHA256_M32_H10 + LMOTS_SHA256_N32_W4 (RFC 8554, NIST SP 800-208)
signature verification
LMS signatures are verified on-chain before withdrawal.
dependency security
Solana, the AMM, Pump, and Turnkey remain conventional. LMS protection applies to vault authorization.