Custody Architecture
ESTABLISHEDPROPOSED
Solana Program Derived Addresses (PDAs) are accounts with no private key. Only the owning program can sign for them via invoke_signed. This is an established Solana capability and the foundation of AFTRKEY custody.
PROPOSED FLOW
A user deposits tokens from a conventional wallet into a vault PDA. The program then credits an internal ledger entry keyed to an identity commitment, not to the depositing wallet. After deposit, the wallet key has no direct authority over the vault.
IMPORTANT LIMIT
Program custody does not make Solana itself quantum-resistant. Validators, the program upgrade authority and every transaction fee payer still use Ed25519. If the upgrade authority is compromised, custody logic can be replaced. Immutable deployment is under consideration.