Dead man's switch · SPL delegates · Solana

A wallet that
hands itself down.

Stash is a dead man's switch for Solana wallets. Check in now and then. If you go quiet for long enough, your tokens go to the people you chose. They stay in your own wallet until then, and nobody holds your keys.

  • Tokens stay in your wallet
  • One transaction to arm
  • Rules open source
A pixel squirrel sits in a forest at night, holding acorns, with rows of buried acorn stashes along the ground and a second squirrel walking toward them.
Preview: the Stash program for Solana is specified, not built yet. Everything on this page runs locally in your browser.
day0
active
Check in every 60 days. 14 days of grace.
still here!
Day 0

Arm

One transaction. Your tokens do not go anywhere: the squirrel just starts watching them.

Day 40

Check in

A tiny transaction to yourself. The clock restarts from zero.

Weeks of silence

Nothing moves

Winter comes. The wallet still works as usual, and nobody can touch what is in it.

Day 100

Grace

The interval ran out. Still nothing moves, and a single check-in would undo it.

Day 114

Open

Anyone can send one call. The heirs take their shares: no keeper, no company, no permission.

60% to the first heir, 40% to the second. Same rules as the specified program.
Scroll to let time pass
The clock

Drag the days. Watch it open.

This is the real rule engine, the one the program is specified to follow, running in your browser. Move the slider to change how long the owner has been silent.

The Stash squirrel guarding its acorns
active

The demo wallet holds 10 SOL, split 60 / 40.
Why it exists

Every other answer asks you to give something up.

A seed phrase in a drawer

One piece of paper, one point of failure. Nobody knows it exists, or everybody does. Either way it is not a plan.

A custodian or a lawyer

Now someone else can hold your keys, or your instructions, and you have to trust them for years.

A vault program

Everything has to leave your wallet and sit in a program. You cannot use it like before, and a bug in it is a bug in everything you moved.

Stash keeps your tokens where they are.

On Solana a token account can name a delegate: someone allowed to move a set amount, and only that. Stash is that delegate, and it is specified to move nothing until you have been silent for the time you chose. Until then you sign with the same key, spend the same way, and nothing was deposited anywhere. SOL itself cannot be delegated, so it has its own small vault you can empty at any time.

How it works

Arm it. Check in. Or hand it down.

1

Arm

One transaction creates your switch account with your heirs, their shares and your two timers, and approves the Stash authority as a delegate on the token accounts you choose.

2

Check in

Every so often, sign a tiny transaction that restarts the clock. A wallet app, a script or the planned CLI can all send it.

3

Hand down

If you stay silent through the interval and the grace period, the switch opens. Anyone can then send distribute and the program moves the tokens to each heir. No keeper, no company, no permission.

active

You are here

You checked in within the interval. Nothing can move. The wallet works as usual.

grace

Last call

The interval ran out. Nothing can move yet. One check-in puts everything back to active.

open

Handed down

Anyone can send distribute. The heirs get their shares. If you come back before it is called, a check-in still closes it.

What is under it

A delegate, not a custodian.

Solana's token program lets an owner approve a delegate on a token account: it can move up to an amount you set, and nothing else. Stash uses that, with a program-derived authority as the delegate.

your token account, before
owner:    you
delegate: none
amount:   5,000 USDC
after arming
owner:    you   // still you
delegate: Stash authority   // a PDA, no private key
allowed:  up to the approved amount
amount:   5,000 USDC   // never left
  • Owner actions (arm, check in, disarm) need your signature. Nobody else can change your switch.
  • Opening the switch is open to anyone, but the program refuses until the clock says so.
  • Leaving is one revoke per token account. The delegate is gone.
the program interface (specified, not built)read the spec
arm(interval, grace, heirs[])
  // creates your switch account (a PDA of your wallet),
  // stores heirs, shares and timers, starts the clock
check_in()
  // owner only: last_check_in = now
disarm()
  // owner only: closes the switch account, refunds its rent
deposit_sol(lamports) / withdraw_sol(lamports)
  // the optional SOL vault: owner only, any time
distribute()
  // anyone, only after interval + grace:
  // splits each covered token account and the SOL vault
  // between the heirs, last heir takes the remainder
406bytes in the switch account
11rule tests that pass
0admin keys, by design
In practice

What each step does on chain.

This is the planned flow. The rules behind it are real and tested; the program that will enforce them on Solana is not deployed yet, so nothing here has been sent to a cluster.

1

Arm

One transaction: create the switch account (rent of about 0.0037 SOL, refunded when you close it), store the plan, approve the delegate on each token account you want covered.

2

Check in

A transaction that only you can sign and that costs a few thousandths of a cent in fees. It sets last_check_in to the cluster's clock.

3

Hand down

After interval + grace, anyone sends distribute with the token accounts and the heirs' token accounts. Large wallets need a few transactions because Solana limits their size.

What it can't do

Small on purpose. Here are the edges.

What the design guarantees

  • The program moves nothing before the switch opens. The delegate only acts inside distribute, and that refuses until the clock says so.
  • Only your signature can arm, check in, disarm or touch the SOL vault.
  • Shares are basis points that must add up to exactly 100%, fixed when you arm.
  • Rounding never leaves dust: the last heir takes the remainder, all in integer token units.
  • You can cut the delegate off at any time with a normal revoke on the token account.
  • No owner, no admin, no upgrade authority, no fee and no token inside the program (it is specified to be deployed immutable).

Things you should know

  • If you forget to check in, your heirs get the tokens. That is the product. Pick an interval you will actually keep.
  • SOL cannot be delegated, so SOL you want covered lives in the optional vault. Everything else stays in your wallet.
  • A token account holds one delegate at a time. Approving Stash replaces any other delegate on it.
  • Heirs need a token account for each token. The caller of distribute pays for creating missing ones.
  • NFTs are not distributed in the first version, and neither are tokens with transfer hooks or frozen accounts.
  • The program is specified, not built. Only the rules engine exists and is tested. It will need an audit before it holds anything that matters.
Who it is for

Anyone who holds more than they can explain to a stranger.

Long-term holders

Your family should not need to guess a seed phrase to inherit what you built.

Small teams

A treasury wallet that keeps working if the one person who controls it disappears.

Travelers

Out of reach for months? Set a long interval and a trusted heir as a safety net.

The careful

You do not plan to need it. That is the point of a switch.

Questions

The honest answers.

Do my tokens move when I arm it?

No. Arming creates a small switch account and approves a delegate on the token accounts you pick. The tokens stay where they are and you keep spending them as usual. Only SOL in the optional vault is held by the program.

What if I check in late, during the grace period?

The check-in works and the clock restarts. Grace is exactly for this: the owner can still come back until the moment the switch opens. Even after it opens, a check-in closes it again as long as nobody has called distribute yet.

Who presses the button when the time comes?

Anyone. The heirs, a friend, a bot. distribute is open to every address and does nothing before the switch opens, so there is no company or keeper you depend on. The playground shows what it will pay.

Can Stash move my tokens, or can its authors?

The design says no. The program has no admin function and no upgrade authority. The delegate only acts inside distribute, which waits for your silence, and you can revoke it yourself at any time. That is the specification: the program itself is not built yet.

Why a different design from the EVM version?

A Solana wallet cannot run contract code the way an EIP-7702 account can. What Solana offers instead is the token delegate, which is exactly the right size for this job: it can move tokens up to a set amount and nothing more.

Is it live?

No. The rules are written and tested in JavaScript and you can play with them in the playground. The Solana program is specified in the docs but not built, deployed or audited. This page says so at the top and will tell you when that changes.

Put something aside for later.

Try the whole thing in your browser. No wallet, no signing, nothing to install.

$STASHCommunity coin on Solana: address to be announced. It will be posted here and on @GuardWithStash first. Token page.