Proofs
Service wallets
- payer
- 3F2RLgH2BQGmQjwu9KLf18PPpD7W6Z94HvT6NeoJeenZ
- rooms + inference
- 7ff79QcAqQfSoQ5ACT6Z7Y4Q3Y9QSjQANNkQ39R2awtR
- buyback + burn
- 5WTXPZEwP3GbVHuT8xsuUsJo8o1UWwrrs4GzRqfGM8Yp
- $PPOST creator (fee route A)
- 9fpW4SphqgTS1kkJBZFAQkKg1RRoso684Q4drBmsNTRr
Signer allow-list
The signer has no network and answers only these purposes (read from its own status); it re-decodes the exact message bytes before every signature and refuses anything else:
- status: reports the public keys and whether it is armed; signs nothing.
- derive_pub: a game's creator key; binds the serial to the prompter wallet, first write wins.
- collect_split: collect from that game's vault + exactly three transfers equal to the split of the collected lamports, destinations derived inside the signer.
- parent_collect_split: the $PPOST creator vault (fee route A key 9fpW…NTRr): collect + exactly PARENT_SPLIT_BPS 60/20/20 to PARENT_OPS (the operator wallet, never a service wallet) / OPS_TREASURY / BUYBACK, once per period, refused unless PARENT_CREATOR_OPTION=A (it is A in this build).
- buyback: only a buy of the $PPOST mint by the buyback wallet + a burn of exactly the bought amount.
Money Edge Test
not yet run