Security & control
Program & verified builds
The wagers program id, its source code, security.txt, and how to check that the deployed bytecode matches the source.
Program
| Program id | 3TojGaWF1N3V1JFtaRWnr2Y2e8qRtNLZPX2ZV7eZbW9y |
| Framework | Anchor 1.2 |
| Source | github.com/AYZNN/wagers.fun, in programs/wagers |
| License | Apache-2.0 |
| Security contact | [email protected] (also in the on-chain security.txt) |
Accounts
| Account | Seeds | Holds |
|---|---|---|
Config | "config" | Admin, settler, treasury, fee caps, refund timeout, pause and backing flags |
| Rewards pool | "rewards" | USDC for promo codes and referral payouts |
UserVault | "vault", owner | Your vault. Its USDC sits in the token account "vault_token", owner. |
Contest | "contest", contest id | The contest's rules, rake tier and state. Its USDC sits in "contest_token", contest id. |
Entry | "entry", contest, player | One seat: who paid, which side, whether it was claimed |
Backing | "backing", contest, backer | One backer's bet on a side |
Order | "order", order id | Makes a purchase, tip or promo payment happen exactly once |
Every account also stores a layout version and zeroed reserved bytes, so the program can gain fields in an upgrade without moving any existing data.
Verified builds
Every program release is tagged program-v*. A GitHub workflow builds that tag deterministically with solana-verify in Docker and publishes the executable hash. To check it yourself:
cargo install solana-verify --locked
solana-verify get-program-hash -u mainnet-beta 3TojGaWF1N3V1JFtaRWnr2Y2e8qRtNLZPX2ZV7eZbW9y
solana-verify verify-from-repo -u mainnet-beta \
--program-id 3TojGaWF1N3V1JFtaRWnr2Y2e8qRtNLZPX2ZV7eZbW9y \
--library-name wagers --mount-path programs/wagers --arch v3 \
https://github.com/AYZNN/wagers.funThe two hashes must match. If they do, the code running on-chain is exactly the code in the repository.
Upgrades and configuration
The program's upgrade authority and its admin are a Squads multisig, not a single key. Fee caps, the refund timeout and whether backing is on can only change inside limits written into the program.