Skip to main content
This page describes the internals of the Molpha Solana program: its accounts, every instruction, how epoch rewards are paid and how nodes are punished. To read or write feeds from your own program, see Solana verifier instead. The program (molpha, Anchor, ID MoLF3pgVA9MENSuEujxNNSMaTo71aLyewaH5nrWfUZs) is Molpha’s canonical settlement layer. It holds the versioned node registry, node deposits, registered gateways, plans and subscriptions, epoch rewards and Feed accounts. All amounts are USDC, the mint in ProtocolConfig.usdc_mint.

Account model

A Registry stores Node addresses, not keys. Verification reads each signer’s key from its Node account, and bit i of a signers bitmap refers to registry.nodes[i].

Main instructions

Permissionless

Subscribers

Node owners

Protocol authority

The program has no per-round settlement instruction, round receipt or escrow. For subscriptions, the gateway counts rounds off chain against the plan limits. For x402, the payer’s USDC goes directly to the treasury and the gateway enforces payment at admission.

Epoch settlement

Nodes are paid per epoch from a pool, not per round. A small, unpredictable sample of rounds (tickets) measures who was selected and who signed. The ticket labels are raw ASCII, not hashed. Other domain separators are listed in Cryptography.

Deposits and punishments

register_node moves minimum_node_deposit USDC from the node owner into a deposit vault owned by RegistryState, separate from the treasury. After deactivate_node, or after a tombstoning slash, the owner can withdraw what remains with withdraw_node_deposit once withdrawal_cooldown_slots have passed. Anyone can call slash_offence with evidence. The program validates it, applies the penalty to every guilty node, removes them from the registry in a new version and records a PunishmentCase.
  • The slash percentage applies to both the node’s locked deposit and its unclaimed rewards.
  • The reporter receives challenger_bounty_bps of the slashed total. The rest goes to the protocol reserve.
  • A tombstoned node cannot return. A frozen node returns through reinstate_node.

Next steps

Solana verifier

Submit attestations and read Feed accounts.

Security model

Trust assumptions and slashing in context.

Registry versions

How node-set changes create new versions.