Security
Review vault custody, signing keys, and upgrade permissions.
Not auditedPublic beta. Only deposit what you can afford to lose.
On-chain checks
Checks are unavailable until a vault deployment is connected.
- registered key root
- Unavailable
- remaining one-time keys
- Unavailable
- program upgrade authority
- Unavailable
Protocol rules
Defined by the implementation. These are not live checks or an independent audit.
- signing algorithm
- LMS_SHA256_M32_H10 + LMOTS_SHA256_N32_W4 (RFC 8554, NIST SP 800-208)
- signature verification
- LMS signatures are verified on-chain before withdrawal.
- dependency security
- Solana, the AMM, Pump, and Turnkey remain conventional. LMS protection applies to vault authorization.