Wallet connection is not authentication
Wallet Adapter connects compatible Solana wallets, including Phantom, Solflare and compatible Wallet Standard wallets. The server issues a one-use challenge bound to the site origin, network, wallet, session, random nonce, issue time and five-minute expiry. The wallet signs that exact text. The server verifies the Ed25519 signature and consumes the challenge atomically.
A successful login rotates the server session. Its seven-day cookie is HttpOnly, SameSite Strict and Secure in production; only a hash of the random token is stored in the database. Mutation routes enforce same-origin requests and bounded schemas. The private wallet key never leaves the wallet.
Switching or disconnecting a wallet must reconcile the server identity before protected actions resume. A connected address is not accepted as proof that a user controls that wallet.
One free sign-in message
A text-message signature authenticates the session. It does not authorize a transaction, transfer tokens, approve a delegate or grant permission to burn. The private key remains inside the wallet.
Starting and resuming a continuous run require no token balance, SOL payment, network fee or blockchain transaction. A session that expires may require another free sign-in message.
The run has no completion event, collectible, NFT, token reward, discovery drop or financial return.
A saved run belongs to the signed-in wallet
The backend derives the owner from the authenticated session. Starting a run creates or returns one saved record per wallet per configured network. It does not accept an arbitrary client-supplied address as ownership proof. Repeated requests and later sign-ins return that wallet’s existing run.
PostgreSQL stores the run ID, wallet, network, start time, running state and wallet-access mode. No payment receipt, token balance or blockchain finalization is required for this free-access record. The network label remains explicit and scopes the saved run.
The former quote and signed-transaction registration routes are closed with HTTP 410. Historical burn code and receipts remain separate for audit and recovery; they cannot enable a new paid launch or gate the current run.
Browser visualization, not a background job
The continuous field is procedural artwork rendered in the browser. Closing the page stops rendering; the database keeps the saved run. The elapsed timer measures time since that run began, not work performed, a completion percentage or progress toward a reward.
The field does not run on physical quantum hardware, prove quantum advantage, execute a continuously sampled server circuit, mine cryptocurrency or create an asset. The archived classical simulation is a separate retained v1 implementation.
Trust and operational limits
- The operator controls the website, public configuration and database. Review the sign-in text and site origin before signing; a compromised interface can misrepresent its own UI.
- Wallet signatures prove key control, not a unique human identity. A wallet address is pseudonymous, not anonymous. The site stores the address and the run start time to provide saved access.
- Rate limits and one-use nonces reduce replay and request spam. They are not comprehensive DDoS protection or Sybil resistance.
- Browser support, device performance, hosting and database availability can interrupt the experience. An unbounded run is an application mode, not a guarantee of permanent hosting or uptime.
- Maintain session security, database backups and historical verification keys. Automated checks are not an external security audit.
Archived v1 records
New discovery generation is closed. POST /api/mine returns HTTP 401 without authentication and HTTP 410 for authenticated requests. Historical records remain independently inspectable. Their canonical hash, derived rarity, procedural seed, trusted server signature and any existing Solana Memo commitment are separate checks.
A v1 signature proves that its signing key signed a record hash, not that the operator selected unbiased entropy, published every outcome or executed a physical quantum computer. Preserve historical signing keys and database backups when retaining record verification. Archived rarity probabilities are not probabilities of an output from the continuous run.
Audits
- EXTERNAL AUDITS
- NONE
- CUSTOM QEE PROGRAM
- NOT DEPLOYED
- PHYSICAL QUANTUM HARDWARE
- NOT USED
- OUTPUT OR REWARD
- NONE
Report a vulnerability
A security contact has not been configured. No audit or disclosure-response commitment is claimed.
Read the free wallet-access specification or the archived v1 verification method.