The pool address
Deposits live at an address with no private key. There is nobody to hand them over.
An ordinary Solana address is a public key with a private key behind it. Whoever holds that private key can move everything at that address. That is true of your wallet, and it is true of every service that says it is holding your funds safely: safety there means trusting whoever keeps the key.
A pool needs a place to keep deposits, and a private key would be exactly the wrong way to do it — something to steal, to leak, to be compelled to use, or to walk away with.
A PDA has no key at all
Solana has addresses that are computed rather than generated: a program-derived address, PDA for short. It is derived from the program itself, and it is chosen precisely so that no private key exists for it. Not lost, not hidden — none was ever possible.
The Solana runtime lets the program it belongs to sign for that address, and nothing else in the world can. So the deposits sit somewhere with exactly one way out: the program’s own withdraw instruction, which runs only when it is handed a valid proof.
What that rules out
- The team moving funds. There is no key to move them with.
- A hacked server draining the pool. The server never had a key either.
- An administrator with an override. There is no admin instruction to write one into.
- An exit scam. Leaving with the money would require a key that does not exist.
What it does not rule out is a bug in the program, which is a different problem and the reason an audit comes before mainnet. See what can go wrong.