DEX–Solana Vault: operation and security
CoinRobot trades on Solana through Jupiter using a user-owned Vault Program account and a separate bot-wallet. The Vault holds the trading token accounts behind a program-derived authority (PDA); the bot-wallet submits automated trade calls and pays the transaction fees.
Read the complete CoinRobot trading flow for the common route from market data and strategy decisions to execution and balance monitoring.
Bot-wallet + SOL fee↑ trade callYour Solana Vault
Vault and bot-wallet: two separate roles
The Vault/PDA side holds trading capital. The separate bot-wallet signs CoinRobot's automated trade transactions, so network fees are charged to that wallet. The bot-wallet needs a small initial SOL balance. If SOL later becomes low and USDC is available in the bot-wallet, the robot can attempt to buy SOL automatically. Vault and bot-wallet balances are available from the Dashboard.
Terms and network details
- Vault account
- Program state storing owner, bot-wallet, Jupiter router and token allowlist configuration.
- Vault USDC deposit token account
- The associated token account that actually receives trading USDC.
- Bot-wallet
- Separate CoinRobot wallet that signs automated trade calls and pays SOL network fees.
- Jupiter
- The configured Solana router used by the Vault for approved swaps.
Your Solana integration addresses
Log in to display the addresses of your DEX-Solana Connector.This is the Solana Program Vault account. Do not send trading USDC to this address.
Log in to display the addresses of your DEX-Solana Connector.Send Solana-mainnet USDC here for the capital that the Plan may trade.
Log in to display the addresses of your DEX-Solana Connector.Send a small amount of SOL here for automated transaction network fees.
Log in to display the addresses of your DEX-Solana Connector.USDC for fee replenishment can be sent here. The robot may use it to buy SOL when needed. Trading capital belongs in the Vault USDC deposit token account, not here.
Your own addresses are not available yet. Log in, initialize and save a DEX-Solana Connector; the addresses will then appear here automatically.
Why the Vault is useful
The Solana Vault lets CoinRobot trade through a constrained program without requiring the owner's private key or seed phrase. The program limits the token accounts and Jupiter route that may be used and checks input spending and minimum output.
Why there is a separate bot-wallet
The bot-wallet is the transaction initiator for automated trading and therefore the place where Solana transaction fees are paid.
Withdrawal is separate from trading
The bot-wallet may initiate the supported aggregate withdrawal only back to the stored owner. Owner-only targeted withdrawals and Vault management remain under the owner signature.
- Connect Phantom/compatible wallet and initialize the Vault.
- Fund the displayed Vault USDC deposit token account with trading capital.
- Fund the bot-wallet with a small amount of SOL for initial fees; optionally keep USDC there for automatic SOL replenishment.
- Create and start a Plan. CoinRobot evaluates the strategy; the bot-wallet signs the transaction; the Vault invokes Jupiter for the approved swap.
- Monitor the Vault and bot-wallet balances on the Dashboard.
- When exiting, stop the Plan and use the withdrawal flow separately from the trade loop.
Permission model
| Operation | Owner | Bot-wallet | Boundary |
|---|---|---|---|
| Automated CoinRobot trade | No | Yes | Signed by the configured bot-wallet and constrained by allowed mints, expected Vault token accounts, the configured Jupiter router and input/min-output checks. |
| Withdraw all allowed assets to owner | Yes | May initiate | Receiver must be the stored owner. |
| Targeted token/native SOL withdrawal | Yes | No | Owner signature required. |
| Change bot/router/token allowlist; close Vault | Yes | No | Owner signature required. |
Technical note: the current program's require_bot_or_owner check also permits the owner to call trade directly. The table describes CoinRobot automation, where the bot-wallet signs automated trade transactions.
Verified Build program and public source
The deployed Solana program is a Verified Build. Its on-chain verification can be inspected in Solana Explorer, and the matching source is available in the public GitHub repository.
Approved router: the Vault stores and validates the configured Jupiter router/program.
initialize_vault(...) owner initializes Vault/PDA state
trade(...) constrained Jupiter swap
withdraw_all bot/owner may return allowed assets to owner
withdraw_token / withdraw_native owner-only targeted withdrawals
set_bot_address / update_routers owner-only configuration
add_token / remove_token owner-only mint allowlist management
close_empty_token_accounts / close_vault_account owner-only cleanup
public readers inspect Vault state and allowed mintsOperational security checklist
- Send trading USDC only to the displayed Vault USDC deposit token account, never to the Vault account itself.
- Keep a small SOL balance on the bot-wallet for initial automated transactions.
- Keep only the indicated fee reserve on the bot-wallet; trading capital belongs in the Vault token accounts.
- Verify the program ID, owner, bot-wallet, Jupiter router and allowed mints.
- Never share the owner seed phrase or private key; CoinRobot does not need it.
