Security

Nothing to trust
that you can’t check.

UNRENT has no on-chain program of its own. Every transaction you sign calls programs other teams wrote, had audited and run for the whole network. Below: each of those programs, who audited it, what our server checks and where trust remains.

01 What UNRENT never does

Non-custodial.
By construction.

✕Hold your SOL or your keys
SOL moves from your accounts straight to your wallet in the same transaction. There is no UNRENT account in between.
✕Ask for a token approval
No delegate, no allowance, no authority change. Nothing you sign lets anyone move your tokens later.
✕Sign for you
Your wallet pays the network fee and is the only signer of every transaction UNRENT builds for you.
✕Touch tokens you did not pick
Tokens move only for dust you tick to burn, or when you choose Claim & buy $UNRNT.
✕Run a program of its own
UNRENT has no on-chain program and no upgrade key over anything you hold. It only builds transactions for programs listed below.

02 Programs you sign for

Upgrade status read on chain 2026-10-07

Audited code.
Not ours.

Your wallet shows the program behind every instruction before you sign. These are the only ones UNRENT puts there.

  1. Reclaim · Burn dust

    Token program (p-token)

    WithdrawExcessLamports · CloseAccount · BurnChecked

    Solana’s own token program, rewritten by Anza as p-token and live since May 13, 2026 (SIMD-0266, epoch 971). It already holds your token accounts; UNRENT calls three of its instructions, signed by you as the owner.

    No upgrade key

    No upgrade authority. It changes only through a feature gate the validators activate, the way p-token itself arrived.

  2. Reclaim · $UNRNT

    Token-2022

    WithdrawExcessLamports · CloseAccount · BurnChecked

    The same three instructions for accounts of Token-2022 mints. $UNRNT is a Token-2022 mint too.

    Upgradeable

    Upgradeable by its maintainers. The upgrade authority is shown on Solscan.

  3. Holder rewards

    Jito merkle-distributor

    NewDistributor · NewClaim · Clawback

    Pays holder rewards. Every period gets its own distributor with a Merkle root of who receives how much. The program pays each wallet exactly its amount and records the claim on chain, so nothing can be claimed twice. Written and published by the Jito Foundation.

    Immutable

    No upgrade authority. Its code can never change.

  4. Claim & buy $UNRNT

    Pump and PumpSwap

    buy_exact_sol_in · buy_exact_quote_in

    Only when you choose Claim & buy: the $UNRNT bonding curve, after graduation its canonical PumpSwap pool. Built with Pump’s official SDK. Your SOL is a hard cap and the slippage setting becomes an on-chain minimum you receive, or the whole transaction fails.

    Upgradeable

    Upgradeable by Pump. We found no public audit report. Claim SOL never calls it.

  5. Fees · Network

    System, Compute Budget, Associated Token Account

    Transfer · SetComputeUnitPrice · CreateIdempotent

    Visible SOL transfers for the service fee, a referrer’s share and the Claim & buy interface fee; the priority fee; the token account $UNRNT lands in.

    Immutable

    System and Compute Budget are part of the validator. Associated Token Account runs on the non-upgradeable loader.

03 What the server checks

Before your wallet.
And after.

Your wallet simulates every transaction on its own as well. If it warns that a simulation failed, do not sign.

Claim SOL

  • ✓Amounts come from a fresh read of the chain at build time, never from your browser.
  • ✓Every transaction is simulated against current state. One that would fail never reaches your wallet.
  • ✓After you sign: the fee payer must be your wallet, the number of transactions must match, and the service fee transfer must still be there, unchanged.
  • ✓A holder discount holds only while you still hold: your balance is read again right before sending.

Claim & buy $UNRNT

  • ✓Checked instruction by instruction: only the programs above, SOL transfers only from your wallet to the planned recipients, exactly one buy, you as the only signer.
  • ✓The signed bytes must equal the prepared transaction. A quote is valid for 45 seconds.
  • ✓Reclaim and buy share one transaction when they fit: if the buy fails, the reclaim is reverted too. When they do not fit, the review says so before your first signature.
  • ✓After it lands, the transaction is read back: same message, fee to the right address, at least the minimum $UNRNT received.

Holder rewards

  • ✓Before a period goes live, its distributor is read back from the chain: root, totals, admin and where unclaimed SOL returns to.
  • ✓You always claim your full amount; a failed claim or buy leaves it claimable.
  • ✓The claim record on chain makes a second claim impossible, for anyone.

04 Where the money goes

Every address.
On chain.

Treasury
9C2wveyr…awGTPrpp ↗

Receives the service fee and unclaimed rewards after the claim window.

Holder Reward Vault
D9EwJdYH…MavCPuoi ↗

Receives the holders’ half of Pump’s creator fee and funds each period.

Interface fee
H3d91VzJ…PByoxLMH ↗

Receives the Claim & buy interface fee.

$UNRNT mint
UR9gqF12…FVDzVksZ ↗

The launch only counts as live once the mint has no mint and no freeze authority.

05 Where trust remains

The honest part.

Our server
It builds the transactions you sign. A compromised server could hand your wallet something else. Your wallet’s preview is the last check: it shows which SOL and tokens leave your wallet. Read it, every time, on any site.
Reward vault
Rewards run automatically: the vault key is stored encrypted on our server. A period above 1 SOL, or one wallet above 50% of it, waits for manual approval, and payouts have an emergency stop. At risk on a compromised server is what sits in the vault at that moment. Published rewards are paid by the immutable distributor: within the claim window, nobody can take or change a holder’s amount. The vault, as the distributor’s admin, only decides where unclaimed SOL goes after the window.
Upgradeable programs
Token-2022, Pump and PumpSwap can be upgraded by whoever holds their upgrade authority. That is true for every app that uses them. Claim SOL on a classic token account needs neither.
Our own code
There is no UNRENT program to audit. The code that builds and checks transactions is covered by our own tests; the token launch, Claim & buy and holder rewards run against Pump’s and Jito’s real programs in LiteSVM, a local Solana runtime.

Report a vulnerability

Found something?

Write to hey@unrent.xyz before you publish anything. Please do not test against other people’s wallets.

What you sign →