◂ labs
TIER 0 · FOUNDATIONS
PDAS — PROGRAM DERIVED ADDRESSES
A PDA is an address derived deterministically from seeds + program id that deliberately falls OFF the ed25519 curve — no private key exists, so only the program can "sign" for it (via invoke_signed + the same seeds). PDAs are how programs hold authority: vaults, mint authorities, pool signers. The seeds ARE the security policy — collide them or reuse one PDA for everything and the walls come down.
seen in the wild
PDA seed design is protocol design. Wormhole-era exploits, share-inflation attacks and vault drains routinely trace back to seeds that didn't encode enough context.
next labCPI — CROSS-PROGRAM INVOCATION ▸