Skip to content

Fees and dev bags, sealed behind post-quantum keys.

Every coin launched on Hashlock puts its creator fees and its dev buy in a vault that only a hash-based signature can open. The vault program checks that signature on Solana, so anyone can confirm it on chain.

A withdrawal, checked Checking the signature
The vault stores only the root. A withdrawal spends one key and sends the hashes beside its path. The program hashes up and compares. Drawn 5 levels deep. A real vault has 10 levels and 1,024 keys, each usable once.

Who can move the money

On most pads one wallet key moves a coin's fees and its dev bag. On Hashlock that key is not enough.

WhatOn a usual padOn Hashlock
Creator fees Paid to the creator's wallet. One Ed25519 key moves them. Paid to the creator's vault. They move only with a hash-based signature the program checks.
Dev buy Sits in the creator's wallet, free to sell. Moved into the vault at launch. Same rule to take it out.
The post-quantum signature Some pads write one into the coin's metadata file. Nothing on chain checks it. The vault holds a 32-byte root. Every withdrawal is verified against it on chain.
What you can check A metadata file. The vault account, the fee-sharing config and the dev bag's token account, on Solscan.

SealedThe vault holds this coin's creator fees and dev bag.

Agent-run, not sealedAn automated agent moves this coin's fees with its own wallet, so they are not behind a hash-based key.

How to check a vault on Solscan

Every coin feeds one flywheel

Hashlock keeps 10% of every coin's creator fees. Most of it buys $HASHLOCK on the market and burns it, every 15 minutes.

A coin's creator fees

90% to the creator's vault 10% to the flywheel

That 10%

80% buys and burns $HASHLOCK 20% to the treasury

Until $HASHLOCK is live, the flywheel's share collects and waits for the first buy.

A launch in three steps

Your wallet (Phantom, Solflare or any Solana wallet) signs each step. Your keys are made in your browser and never reach our server.

  1. Create your vault

    Your browser makes a 24-word recovery phrase and turns it into 1,024 one-time hash-based keys. You write the words down. Only the keys' root goes to the vault program, and the phrase is never sent anywhere. You do this once.

  2. Launch and record

    One prompt creates the coin on pump.fun, makes your dev buy, and records the launch in your vault with your next one-time key.

  3. Seal it

    A second prompt locks fee sharing so your share goes to your vault and moves the dev buy into it. From then on, its fees and dev bag move only with a hash-based signature.

What it does not do yet

Post-quantum on Solana is partial today. Here is where the line sits.

  • Solana still signs transactions with Ed25519. The vault adds a hash-based check for the money it holds. It does not change how Solana itself verifies a transaction.
  • pump.fun and the fee payer use ordinary keys. The bonding curve and the account paying network fees are outside the vault.
  • Your recovery phrase is the vault. Anyone who has the 24 words can move what it holds, and nobody can restore it if you lose them. An optional mode derives the keys from your wallet instead. It is labelled not post-quantum, because whoever controls that wallet can rebuild them.
  • Agent-run coins are not sealed. The agent's wallet moves their fees, and the coin's badge says so.

Read how it works