metaspace
Getting started / Overview

Getting started

Overview

A vault locked by a hash commitment instead of a keypair, and where to read next.

What metaspace is

metaspace is a vault program for Solana. A vault holds SOL behind a 32-byte hash commitment instead of a keypair. To withdraw, the owner reveals a one-time signature over the exact withdrawal they want. The program walks the hash chains to the committed endpoints, pays the destination, and replaces the commitment in the same instruction. No instruction that moves value checks a wallet signature.

Every other Solana vault, multisig and timelock authorises spending with an Ed25519 signature, and rests on one assumption: the private key cannot be derived from the public key. metaspace rests on a different one. SHA-256 cannot be inverted. Grover’s algorithm takes a 256-bit preimage search to about 2128 operations; Shor’s algorithm takes Ed25519 to polynomial time.

The program has six instructions, in two groups.

InstructionWhat it doesWho may call it
init_vaultOpens a vault behind a commitment.Anyone. The payer is recorded as a hint, not an authority.
depositTransfers lamports into a vault.Anyone, into any vault.
open_withdrawalWrites down the amount, destination and next commitment.Anyone who pays the rent.
push_signatureDelivers up to 8 chains of the signature and verifies each walk.Anyone.
finalize_withdrawalChecks the commitment, pays out, rotates the lock.Anyone. No signer is required.
cancel_withdrawalReclaims an expired or superseded request.Anyone, once the request has expired.

What is deliberately absent: an admin, a pause, an oracle, a fee inside the program, and any close_vault. A vault whose operator can intervene is a vault with a keypair again, just further away.

How these docs are organised

Read Getting started to open a vault. Read The lock and Withdrawals for the construction, with the formulas. The reference pages list every instruction, account and error.

Getting started

  • Getting started. Connect a wallet, create a vault, write down the twelve words, deposit, withdraw.
  • Vault types. Personal, authority and staking vaults: one lock, pointed at three things a key can hold.

Concepts

  • Threat model. What an Ed25519 wallet assumes, why a published key is permanent, and what Shor and Grover change.
  • Recovery words. The twelve words are the seed. Everything that can open the vault is derived from them.

Protocol

  • The lock. The Winternitz one-time signature over SHA-256: keys, commitment, signing, verification, the checksum.
  • Rotation. A one-time key signs once. The lock rotates in the same instruction that spends it.
  • Withdrawals. Open, push, finalise: how a 1,088-byte signature crosses the chain in seven transactions.

Reference

  • Instructions. The six instructions: accounts, arguments, checks and errors for each.
  • Accounts. Vault and WithdrawalRequest: seeds, fields, byte sizes.
  • Errors. Every error the program returns, and the instruction that raises it.

Security

  • Security model. The assumption the vault rests on, the construction, what it protects against, and the NIST context.
  • FAQ. Short answers to the questions people ask first.