Getting started
Vault types
Personal, authority and staking vaults: one lock, pointed at three things a key can hold.
One lock, pointed at three different things a key can hold.
Personal
SOL behind a commitment. Withdraw any amount at any time. The lock rotates on every withdrawal, so nothing an observer sees in a landed transaction helps them with the next one.
Token support follows the SOL path. The signed digest then binds the mint and the token amount as well, which moves its version tag from metaspace:withdraw:v1 to v2.
Authority
A project moves its upgrade authority, mint authority and treasury authority into a vault instead of a keypair or a multisig. The vault then signs those operations as a PDA, under a commitment: set_upgrade_authority, an SPL mint authority transfer, a treasury spend.
A multisig does not help here. Five Ed25519 keys break the same way one does, at the same time, for the same reason. The asset at risk is not a balance but the program itself: whoever holds an upgrade authority can replace the program and take everything every user has ever approved.
Staking
A stake account has two authorities, staker and withdrawer. The withdrawer is the one that matters. Putting it behind a commitment protects the principal while delegation continues and yield keeps accruing. It is the same vault with a different authority type.