BeamA home for your fees. On Solana.
CA soon
Technical reference

What a vault is, and what it is not.

Getting started? Follow the short guide to launch a coin, create a vault or withdraw your assets. This page explains the protocol behind those actions.

Read the step-by-step guide

Ordinary Solana wallets authorize transactions with ed25519 signatures. Their addresses expose their public keys, so a future break of that signature scheme would affect those wallets. Beam uses hash-based signatures for withdrawals, while still depending on Solana and the other programs it uses.

Beam puts value in a program-controlled vault whose withdrawal authority is a one-time hash key.

The vault

A vault is an account owned by the Beam program at a program-derived address. Program addresses have no private key at all. Your recovery words must still be protected from theft and phishing. The program moves funds out for one reason only: a valid Winternitz one-time signature.

  • Winternitz signatures are built from SHA-256 and nothing else: 30 hash chains of 255 steps. Breaking one means inverting SHA-256. Shor’s algorithm does not apply, and no discrete-log shortcut helps.
  • Each key signs once. Every signature also names the hash of the next key, so the vault rotates on every spend and a used key is worthless.
  • Signing keys come from one 24-word secret processed in your browser. The server receives public key hashes, the exact withdrawal request, public coordination credentials and authentication proofs, and finished signatures. It does not receive your recovery words.
  • Spending takes two steps: authorize checks the signature on chain and records the exact action; execute carries it out. Anyone can submit either. When the relay is active and funded, it pays the withdrawal network fees. The signature is the authority, not the fee payer.

Coins

Every coin launched here is a Meteora Dynamic Bonding Curve pool. In the launch transaction the pool’s creator seat is handed to the coin’s vault, and the program refuses to open the vault unless the pool sends every trading fee and all graduated liquidity to it, in SOL, with a fixed supply and no freeze authority.

Trading fee1% or 2%, chosen at launch (99% for the first 20 seconds, so snipers pay the vault)
Who collectsAnyone. The engine does it every few minutes; the fees are unwrapped into plain SOL inside the vault
Split80% stays in the coin’s vault for its creator, 20% goes to the Beam platform vault
GraduationAt about 85 SOL raised, to Meteora DAMM v2. 100% of the LP is locked forever and its fees keep flowing to the vault
Creator withdrawsWith the 24 words saved at launch. A funded relay can pay network fees; otherwise connect a wallet.

What it does not do

  • It cannot save Solana from itself. Validators, the token program and every user wallet still use ed25519. If the curve breaks for real, the chain itself needs a fix, which is Anza’s job, not ours. A vault is the part of your value that no cracked key can move while that happens.
  • The coin itself is still a normal SPL token. Holding the coin in your Phantom wallet is exactly as safe as Phantom. Put it in a personal vault if you want it behind a hash key.
  • Lose the words, lose the vault. There is no recovery, no admin and no backdoor. That is the point.
  • One key, one message. Signing two different withdrawals with the same key number would weaken it. Before signing, the site reserves the exact action in a shared coordinator. An unfinished action must be resumed rather than replaced. This protection requires one consistent coordinator whose history is never lost, rolled back or split between servers; a malicious coordinator or bypassing the signing client can break the guarantee.
  • The whole stack is not unconditionally post-quantum. Coordination authentication uses ed25519, and Solana and the external programs retain their own security assumptions. The protocol has not had an independent security audit.
  • Fees waiting inside Meteora are Meteora’s risk until collected, which happens every few minutes.
  • Upgradeable until frozen. The program’s upgrade key is itself an ed25519 key. Before real money goes in, the program is made immutable; until you see that on Solscan, treat it as experimental.
  • Tokens with transfer hooks cannot be withdrawn from a personal vault. Use plain SPL tokens and SOL.

The numbers

SignatureWOTS, w = 256, SHA-256 truncated to 224 bits, 28 message + 2 checksum chains, 840 bytes
Securityabout 112 bits against a quantum attacker (Grover), more classically
Verificationon chain, about 600–700k compute units, in one transaction
Program3KKrFCiemR1BGfTgZX8DWk1G9f9UJt2ziyUh89PQq9Xt

Launch a coin Open a vault