Understand
your
exposure.
A clearer view of your Solana wallet. Check token permissions, inspect activity, and understand the security story.

Hardpoint Check
Read-only · Solana mainnetPublic-key visibility is normal on Solana. It does not mean your wallet is compromised.
POST-QUANTUM REPORT SIGNATURES
Verify what
you received.
Was this report issued by Hardpoint? Has it changed? Check its signature here.
Your report stays in this browser.
No report upload or wallet connection.
One file · up to 2 MB
Or paste signed JSON
Paste an exported Hardpoint report. Do not paste a seed phrase or private key.
TRY IT WITH FICTIONAL DATA
Less noise.
Better context.
Wallet permissions and quantum research, with the evidence attached.
5 briefs · all topics
01ResearchPublished standardA signature can protect the report, not the walletNIST · FIPS 205Published
NIST standardized SLH-DSA, a hash-based digital signature scheme derived from SPHINCS+. A signature lets a recipient check who signed a document and whether its signed contents changed.
What it means here
Hardpoint signs its report snapshots and checks them against a published Hardpoint signing key. Try the signed fictional example to see how changing a result makes verification fail. Signing authenticates the report; it does not change the wallet.
Limits This does not change a Solana wallet's keys or transaction signatures. An authentic report can still be incomplete or out of date, and it is not a certificate of wallet safety.
Read primary source02SolanaLive capabilityA fresh Solana address still exposes a public keySolana · Account documentationUndated documentation
An ordinary Solana keypair wallet uses its public key as its address. Creating another keypair therefore does not hide the new public key from someone who knows the address.
What it means here
Do not assume advice about fresh addresses on another chain has the same effect on Solana. Public-key visibility is part of this account model; it is not evidence that a private key has leaked.
Limits Program-derived addresses use a different model and have no corresponding private key. Their security still depends on program logic and its authorities, which a basic address check cannot fully assess.
Read primary source How PDAs differ03SolanaLive capabilityAn approval is a permission worth understandingSolana · Approve DelegateUndated documentation
A token-account delegate may transfer or burn tokens up to its remaining allowance. Each token account has one current delegate and allowance; a new approval replaces the previous one.
What it means here
Hardpoint surfaces these base token-account permissions. Review which app or authority you recognize and why it still needs access before deciding what to do.
Limits A delegate is not automatically malicious. This snapshot does not show past approvals, inspect every program, or revoke permissions for you.
Read primary source04SolanaLive capabilitySome token permissions live on the mintSolana · Permanent DelegateUndated documentation
Token-2022 supports a permanent delegate set on the mint. This authority can authorize transfers or burns across accounts for that mint, and an individual token-account owner cannot revoke it from their account.
What it means here
An empty list of ordinary delegates does not describe every authority attached to a token. Mint-level permissions need a separate check.
Limits Hardpoint does not inspect mint extensions in this version. Read the token issuer's disclosures and source documentation; a clean base-account result is not an all-clear.
Read primary source05ResearchDraft guidanceA migration plan is not an attack deadlineNIST · IR 8547 initial public draftPublished
NIST's initial public draft describes an expected transition from quantum-vulnerable cryptography to post-quantum standards. It is planning guidance for systems and standards, rather than a report of a wallet exploit.
What it means here
Separate a published standard, a proposed migration, and a demonstrated attack when evaluating security headlines. They answer different questions and call for different actions.
Limits This source is labeled an initial public draft. It does not establish when a practical attack against a deployed Solana wallet will become possible.
Read primary source$HRDP
A token with a job to do.
The proposed service credit for checking more wallets, more often.
- Free
- Single checks, signed reports, verification, share cards + briefs
- Planned
- Credits for batch checks, scheduled checks + API access
Token not launched. Payment features are not active.
Working ticker. Holding a token does not strengthen wallet security.
Small scope. Real progress.
- 01
Check Live
Read-only wallet checks and sourced security briefs
- 02
Verify Live
Signed reports, local verification, and share cards
- 03
Expand Planned
Batch checks, scheduled checks, and API service credits
Methodology & privacy
What this version checks
Hardpoint requests account information, base token-account permissions from SPL Token and Token-2022, and up to 12 recent transaction references from the configured Solana mainnet data provider. It inspects up to 500 accounts per token program. Each report lists the available checks and their slots.
What a report cannot establish
We do not inspect mint-level authorities, Token-2022 mint extensions such as permanent delegates or transfer hooks, historical approvals, arbitrary programs, wallet sessions, or device security. No findings is not a guarantee of safety. An address reference does not prove that the address signed a transaction. Program-owned accounts and PDAs depend on their controlling program and authorities.
Signed reports and verification
You can download a report signed by Hardpoint using SLH-DSA, a hash-based signature scheme standardized in NIST FIPS 205. If signing is temporarily unavailable, the report is explicitly labeled unsigned. You can also try the signed fictional example. The verifier checks signatures against Hardpoint's published verification key. It detects changes to the signed contents and authenticates the report's signer; it does not establish that the data provider was correct, that every risk was checked, or that the wallet is safe. A saved report remains a dated snapshot.
Your address and data
The address you enter is sent to Hardpoint and its configured Solana data provider to run the check. Reports stay in the current page unless you copy or download them; we do not maintain a wallet database or watchlist in this version. Hosting and RPC providers may retain operational logs. No seed phrase, private key, wallet connection, or transaction signature is needed.
Files you select in the report verifier are checked in your browser; their contents are not uploaded. Share cards are also generated in your browser and hide the wallet address by default. Full report downloads include the address and findings, so review them before sharing. A share card is a visual summary, not a replacement for the signed report.
These are on-demand snapshots. Hardpoint does not continuously monitor, block transactions, hold assets, or certify post-quantum wallet security. Security briefs are manually curated and show a review date separately from their source's publication date. Data-provider availability and limits can delay a check.