zmr
docsvaultmechanismreservereleasesprogramx

the monero releases

every sell of zmr pays a creator fee, and that fee is destined for holders rather than for the reserve. when the accumulated sell side fees cross the release threshold, the sell that crossed it is the trigger, and the release happens at that moment. the sol is swept into native xmr through near intents and split pro rata among every eligible holder, sent to the monero subaddress each of them registered.

there is no schedule, no snapshot hour and no claim step. a release is a consequence of a sell, and the balances that decide the split are read at the slot the triggering sell confirmed in.

fieldvalue
release threshold
minimum holding
release count
total swept to monero
xmr delivered
registrations

releases

each row is one release. the trigger signature is the sell that caused it. the sol swept is the amount pulled from the sell side of the fee vault. the intent hash is the near intents settlement that turned it into xmr, and the transaction proof lets a recipient confirm their own payment without revealing it to anyone else.

trigger signaturesell sizesol sweptintent hashxmr deliveredrecipientsproof

eligibility

a wallet is eligible for a release when two things are true at the trigger slot. it holds at least the minimum holding written in the program config, and it has a valid registration. everything else about the wallet is irrelevant, including how long it has held, when it bought and whether it has ever sold before.

the wallet that triggered the release is measured after its own sell has settled, so selling the whole position to trigger a release pays out nothing to the seller.

share_i = xmr_delivered × balance_i ÷ Σ balance_j over all eligible j

registering a subaddress

registration happens on solana, not on this site. send one transaction from the wallet that holds the token containing a single memo program instruction whose utf8 text is the prefix followed by your monero subaddress. the rest of the transaction does not matter, and a zero lamport transfer to yourself is enough to carry the memo.

zmr:xmr:<subaddress>
bytes 0 to 7, prefix, literal "zmr:xmr:"zmr:xmr:8bytes 8 to 102, subaddress, 95 characters, first character always 8total 103 bytes, utf8, one memo program instruction, any transaction

the keeper reads memos from wallets holding the token, checks that the subaddress begins with 8 and is 95 characters, and stores a hash of it against the wallet. only the hash is ever stored, and only the hash is ever shown. sending a later memo from the same wallet replaces the earlier registration.

registrations

the table lists wallets with a valid registration, the memo transaction that created it and the slot it was recorded at. the subaddress column is a hash, which is enough to confirm your own entry and not enough for anyone to pay you, or to link you to a payment.

walletmemo signaturesubaddress hashslot

privacy

a monero subaddress cannot be linked on chain to the wallet that registered it, to any other subaddress, or to the payment that reaches it. a holder can verify their own payment with the transaction proof for the release and their own view key. nobody else can see that they were paid, how much they were paid, or that the payment had anything to do with this token.