DocsUnder the hood

Page 09 of 14

Contents

What the program cannot do

A short list. Everything not on it is a promise, and promises are not what you want here.

  • It cannot move a single lamport except to pay a withdrawal that carries a valid proof.
  • It cannot invent SOL. A receipt is worth nothing unless the matching deposit actually arrived.
  • It cannot pay the same deposit twice: the nullifier makes the second attempt fail.
  • It cannot choose where a withdrawal lands. The destination is sealed inside the proof.
  • It cannot tell who you are. It is never given anything that would say.
  • It cannot be quietly replaced, once the update authority is revoked.
  • It cannot stop you withdrawing. The pause key only closes the door to new deposits.

The part that matters

These are design requirements, written down so they can be checked — not test results. Nothing here has been audited, and the program is not deployed. A requirement and a working program are different things, and only the second one keeps money safe.

The way to tell them apart is boring and public: read the status page, and once there is a deployment, read the code and the audit rather than this paragraph.