One Anchor program covers the Solana side, mirroring the EVM escrow and solver split. Deposits pay into an escrow, a program-derived account with seed escrow, and stay there until they settle past the deep-reorg check; refunds pay out of the same escrow with the program signing as its authority. The operator float lives in a plain treasury system account and its associated token accounts, and fulfillments are signed by the treasury key itself. Settled escrow funds move to the treasury through the release instructions. Prefer the router_address (program id) and treasury returned on the quote and by GetChains over these constants.

Deposit instructions

deposit_token transfers SPL tokens from the depositor’s token account into the escrow’s associated token account and emits Deposit with the amount actually credited, so transfer-fee mints are accounted at the escrow, not assumed. deposit_native transfers lamports to the escrow directly; the mint in its event is the default pubkey.
Invokes the aggregator program passed as swap_program with the caller-supplied accounts and data, then requires the escrow’s token account to have grown by at least min_bridge_out, emitting SwapDeposit with the credited amount. buildSvmSwapDeposit in the SDK assembles this transaction from the GetSwapInstructions payload; see Swap instructions.

Operator instructions

Restricted to the treasury signer, listed for completeness.
fulfill_token pays the recipient’s token account from the treasury and optionally transfers gas_drop lamports to the recipient, requiring the recipient to be credited the full amount. The refund variants pay the depositor back from the escrow, with the program signing as the escrow authority. The release variants move settled deposits from the escrow to the treasury and are submitted by the operator once the released amount crosses a per-token threshold.

Voucher redemption

Callable by anyone. The transaction must include an ed25519 verification instruction, before this one, over the voucher message (domain, chain, program id, id, mint, referrer, amount) signed by a registered voucher signer. A marker account derived from the id is initialized on redemption, so an id cannot be redeemed twice, and the amount is transferred from the treasury’s token account to the referrer’s via the program’s delegate authority PDA. See Referral program.

Events

The indexer matches Deposit and SwapDeposit against stored quotes by quote_hash. Native amounts carry the default pubkey as mint.

Errors