Trust center
Check us. Don't trust us.
Every address StackLive uses, the key that signs claims, and the record of what has gone wrong. If something here does not match the chain, the chain is right.
No login needed. Your payouts go only to an address you published yourself.
- 01Security model
No custody
Fees never touch a wallet we control. Each streamer has their own program-derived vault address, and the program has no withdraw instruction for us.
- 02Fee split
Locked split
The split is written into pump.fun's own fee-sharing config and the admin is revoked in the launch flow. Nobody can change it afterwards, including us and the launcher.
- 03How payouts work
Paid to their own address
Payouts go only to a Solana address the streamer published or proved: a public address on their channel, a Reclaim proof, a channel code, a login, or a signature from the wallet that owns their pump.fun profile. No KYC, no country list, no minimums, no expiry.
- 04Verify a vault
Public receipts
Every deposit and claim is a Solana transaction. Our figures are computed from chain data, and /verify recomputes a vault in your browser against a public RPC.
- 05Consent and opt-out
Streamer-first
Streamers can hide or block coins that name them. We never post on their behalf, never tag them and never imply endorsement.
A vault pays one Solana address, and only the streamer can put it there. We never choose it, and once it is bound the program pays nothing else. Published addresses are re-checked; if one disappears or changes, payouts freeze and the money stays in the vault.
- 01About a minute, no access
Verify with ReclaimTwitch · Kick
You log in to Twitch or Kick inside Reclaim's flow. We receive only a zero-knowledge proof of your user ID. No access is granted to us.
- 02One signature
Sign in with Solanapump.fun
You sign a free, readable message with the wallet that owns your pump.fun profile. The message names your payout wallet. No transaction, no funds move.
- 03Nothing to do
Public payout addressAll three
A Solana address you already show in your Twitch or Kick channel description (or a tip page it links to), or the wallet shown on your pump.fun profile.
- 04About a minute, no login
Channel codeTwitch · Kick
A short code (like STK-7K3F) you or your manager put in the stream title or channel bio for a moment.
- 05One login
LoginTwitch · Kick
Log in with Twitch or Kick. We read your user ID once and revoke the token.
pump.fun live: how the signature is checked
A pump.fun profile belongs to a Solana wallet, and that wallet is public on the profile, so pump.fun streamers need no login, code or Reclaim proof. For method 5 (wallet_signature) we accept a Sign-In With Solana signature only if the signer is the wallet that owns the profile, re-read from pump.fun at the moment we verify, not when the message was issued. Each message is single-use, expires after 10 minutes and names the payout wallet inside the signed text, so it cannot be replayed or redirected. Without any signature, the profile wallet can still be bound as a public address under the usual rule: seen on 2 checks at least 24 hours apart.
Commitments about the vault program itself, each with its real status today.
- Planned before mainnet
Attestor key in KMS
On mainnet the Ed25519 attestor key lives in a cloud KMS and never leaves the HSM. Rotating it takes a public proposal and a 48-hour timelock.
- Planned before mainnet
Upgrade authority: multisig with timelock
The program's upgrade authority is a Squads multisig behind a timelock, so no single key can change the code and every upgrade is visible in advance. The plan is to make the program immutable after audits.
- In the program spec
Per-vault rate limits
Withdrawals and auto-forwards are capped per vault per rolling 24 hours, with a minimum interval, so even a bug or a compromised key cannot drain a vault at once.
- Site log live (DEMO)
Public event log
Every attestation and every binding change (bound, pending, frozen, unfrozen, rebind) is published with its hash and time, and emitted as an on-chain event.
- Planned before mainnet
Open source, verifiable build
The program's source will be public, built reproducibly with solana-verify, and the build hash published here so anyone can check that the deployed bytecode matches the code.
Addresses
These are the only addresses that belong to StackLive. Anything else claiming to be our program or treasury is not. In DEMO mode they are placeholders; the real ones will be published here before mainnet.
Vault program DEMO
Placeholder. Nobody holds a key for it.
Mock…1111MockVau1t1111111111111111111111111111111111
Protocol treasury DEMO
Placeholder until the Squads multisig exists.
Mock…1111MockTreasury1111111111111111111111111111111
Attestor public key DEMO
DEMO key: generated in memory and rotates on every server start.
DrCA…ejdDDrCA7WYPr9bkjv4nuizDW663LZBGPsPdp9GLYtgxejdD
pump.fun programs (reference)
Not ours. The programs that create coins and distribute creator fees.
- Websitestacklive.xyz
- XNo account yet
- ContactComing soon
We never DM first, never ask for a seed phrase, and never ask you to send funds to claim. Lookalike domains are not us.
Vault program audit
An external review of the on-chain program. The report will be linked here in full, including unresolved findings.
Attestor key and treasury multisig
Creation of the KMS attestor key and the Squads treasury signers, documented step by step with the resulting public keys and the transactions that register them.
No incidents recorded.
Any security incident, outage affecting claims, or attestor rotation will be listed here with a timeline.