Add capability. Keep the asset intact.

pWrap derives a quantity-backed Token‑2022 representation W for an existing Solana mint U. U stays unchanged. Capabilities attach to W.

U → W representationSelected · USDC
USDC markU · USDCExisting mint
pWrapWrap · Unwrap
USDC markW · USDCToken‑2022 representation
USDC markUnderlying U held

The selected asset carries through every protocol stage.

U Existing mint W Token‑2022

Protocol properties

One boundary.
Four properties.

01

Deterministic

For one U and destination token program, pWrap derives one W and one escrow.

02

Quantity-backed

The deterministic escrow must hold at least as much base U as total W supply.

03

Reversible by design

Unwrap burns W and debits U from escrow when current U rules and account state permit delivery.

04

Non-invasive

pWrap does not modify U’s mint or authorities. W has independent on-chain state.

The protocol sequence

01 / 03

Start with the asset that already exists.

pWrap leaves U unchanged. U plus the destination token program derive the relationship identity.

Derivation · U + destination program → W + escrow
UnderlyingU · USDC
USDC markU · USDC

U anchors the deterministic relationship.

02 / 03

Cross a visible representation boundary.

Wrap moves U into escrow and mints W equal to the net base amount credited. In one atomic transaction, Unwrap burns X W and debits X U from escrow; current U rules determine recipient delivery.

Solvency · exact escrow base U ≥ total W supply
Public boundaryWrap / Unwrap
USDC markU · USDCExisting mint
pWrapWrap · Unwrap
USDC markW · USDCToken‑2022 representation
USDC markUnderlying U held

Public entry and exit.

03 / 03

Use W as the capability surface.

W owns independent on-chain state. Token‑2022 capabilities attach there—not to U. Applications expose supported W capabilities.

Identity · one relationship, two mint addresses
RepresentationW · USDC
USDC markW · USDC
AddressDeterministic W
Token programToken‑2022
StateIndependent from U

Token‑2022 state lives on W.

From primitive to product

pWrap creates the boundary. Applications create the experience.

The protocol creates a quantity-backed W. Token‑2022 supplies capabilities on W. Applications turn those capabilities into user-facing flows.

01
pWrap

Representation

pWrap derives W and escrow. CreateMint, Wrap, and Unwrap are public pWrap instructions.

CreateMintWrapUnwrap
02
Token‑2022

Capability

Confidential Transfer is the first capability on the default W. Confidential deposit, apply, transfer, and withdraw occur separately through Token‑2022 on W.

Confidential depositApply pending balanceConfidential transferConfidential withdraw
03
Applications

Experience

Wallets and payment products can turn those capabilities into useful flows. These are product experiences, not pWrap instructions or guarantees.

Move to PrivateView private balanceSend privately

The boundary stays explicit. Integrations can verify the U/W relationship, escrow, W supply, and current authority state on-chain. Each product must separately review the assets and extensions it chooses to support.

Live deployment evidence

Mainnet program live. Verifiable on-chain.

The upgradeable pWrap program is executable at the same address on Solana Mainnet and Devnet. Mainnet is the production program deployment; Devnet remains available for integration testing. The clusters share an address, not state or authority.

LiveProduction program

Solana Mainnet

Production program deployment

Program address
Initial slot440,055,335
LiveIntegration testing

Solana Devnet

Test-cluster program deployment

Program address
Initial slot484,920,383
ProgramData · same literal, separate cluster accounts
Execution stateExecutable on both clusters
Trust boundaryEach cluster has an independent upgrade authority

Deployment proves executable code at this address—not support for an asset. No Mainnet asset relationship is currently operator-authorized. Permissionless third-party creation does not imply product support.