DocsKeys and trust

Page 10 of 14

Contents

Update authority and pause key

Two keys exist around the program. One gets destroyed; the other can only close a door.

The pool address has no key. The program around it is a different matter, and it would be dishonest to leave that out.

The update authority

On Solana, a deployed program can be replaced by whoever holds its update authority. That is a back door, however well meant: code you audited on Monday can be different code on Tuesday. Plenty of projects keep it forever and call it responsibility.

The plan here is to revoke it before mainnet. After that the program is immutable: nobody can change it, us included, and what an audit read is what will keep running.

The pause key

One key is meant to survive: a pause key that stops new deposits. If a flaw turns up, the useful response is to stop people putting more money in while it is fixed.

It can do that, and nothing else. It cannot block or delay a withdrawal, cannot move a lamport, cannot change the code, cannot see anything hidden. Someone who steals it can annoy people. They cannot take anything.

What there is no key for

Your money. No key exists that moves a deposit, freezes one, or claims an unclaimed one. That is not a policy we could change our minds about — it is what the pool address makes impossible.