What Pixel Kingdom Wars puts on Solana — payments, Land Deeds, KEEP and weekly balance roots — versus the game server, with devnet addresses and checks.
On this page
- Quick facts
- On chain vs. on the game server
- The shardkeep-core program
- 1. Route SOL payments
- 2. Keep an entry receipt
- 3. Post weekly balance roots
- Admin instructions
- What each purchase does on chain
- The shardkeep-distributor program (not in use)
- Land Deeds (Metaplex Core)
- The KEEP token and custody
- Coming with onchain gameplay
- Addresses at a glance
- Who holds the keys
- Security posture in brief
- How to check on an explorer
- See also
Pixel Kingdom Wars is a server-authoritative game that uses Solana for a small, clear set of things: taking SOL payments, holding your Land Deed as an NFT, moving the KEEP token in and out, and publishing a weekly proof of player balances. Everything else — your base, army, raids and SHARDS — lives on the game server, and this page shows where the line is and how to check it yourself.
Everything here runs on Solana devnet. Devnet SOL and KEEP are test-net tokens with no real value, and there is no mainnet deployment.
Quick facts
- Two Anchor programs:
shardkeep-core(live: SOL payment router, entry receipts, weekly balance roots) andshardkeep-distributor(deployed but not in use). shardkeepis the project's original working name; it survives in the program, IDL and database names. The game is Pixel Kingdom Wars.- Land Deeds are Metaplex Core NFTs in one collection, minted by the server after a verified land payment.
- KEEP is a classic SPL token with 9 decimals; in-game balances are ledger entries, and deposits and withdrawals are ordinary token transfers.
- The program splits routed SOL 40% / 35% / 25% between liquidity, dev and ops treasuries; some purchases go 100% to liquidity by direct transfer.
- The server sets prices. The program routes whatever it is sent; an underpayment is accepted on chain but grants nothing in the game.
- No third-party audit has been completed. Devnet only.
On chain vs. on the game server
| On Solana (devnet) | On the game server |
|---|---|
SOL payment routing and entry receipts (shardkeep-core) | Base layouts, buildings, timers, Keep level |
| Weekly Merkle root of player KEEP balances | SHARDS, Mines, the Gold Forge, armies, heroes, items |
| Land Deed NFTs and their collection (Metaplex Core) | Quests, clans, chat, mail, market listings |
| The KEEP token; deposits and withdrawals | Raid snapshots, battle simulation, settlement, replays |
| The unused distributor program | Sign-in, rate limits, anti-cheat, ledger accounting |
Gameplay never reads the NFT. Whether you can be attacked, what you produce and what you own in the game are server state, so nothing you do to a deed in your wallet protects your base.
The shardkeep-core program
Program ID (devnet): mYYQFnpyGofG31y5oJkiKVmNwifbSXBMnQ5aUgQkL6b
This is the program your wallet talks to when you buy land, extra builders, raid energy or shields. It does three jobs.
1. Route SOL payments
Every payment instruction sends SOL from your wallet to three treasury accounts in one transaction, using the split stored in the program's Config. The treasuries are fixed in Config, so a client cannot swap in its own addresses; rounding dust goes to the liquidity leg.
Each payment emits a PaymentMade event (wallet, kind, amount, reference). The game server waits for the transaction to be finalized and only then grants the purchase.
| Instruction | Who signs | What it does |
|---|---|---|
pay_entry | you | One-time first-land purchase. Creates your Player receipt; a second call fails on chain. |
buy_sink(kind, amount) | you | Repeatable payment tagged with a kind (energy, shield, builder, extra deed and so on). |
buy_builder, buy_expansion | you | Older paths; the current game does not use them. |
2. Keep an entry receipt
pay_entry creates a Player account from your wallet address, created once and never again, so each wallet has exactly one entry receipt. The server also uses it as a fallback proof that you paid.
3. Post weekly balance roots
Once a week (Monday 00:10 UTC) the server snapshots every player's in-game KEEP balance, builds a Merkle root and posts it with post_root. Each EpochRoot account is written once and never changed. The public GET /por endpoint shows coverage, and a signed-in GET /por/proof returns your own inclusion proof.
Admin instructions
set_paused blocks all payments; propose_admin / accept_admin hand the admin key over in two steps. The program has no price-change instruction — the land price on chain can only change through a program upgrade.
What each purchase does on chain
| Purchase | On-chain path | Price (devnet SOL) | Where it goes |
|---|---|---|---|
| First land | pay_entry | 0.2 | split |
| Another deed | buy_sink | 0.2 | split |
| Builders 2–6 | buy_sink | 0.5 to 3 | split |
| Raid energy ×1 / pack ×6 | buy_sink | 0.03 / 0.09 | split |
| Shield +12 h | buy_sink | 0.05 | split |
| Warzone shield | direct transfer + buy_sink | 10 | 50% to liquidity directly, the rest split |
Some purchases skip the program and are plain SOL transfers with a reference key:
| Purchase | Price (devnet SOL) | Where it goes |
|---|---|---|
| Land expansions | 0.15 to 3 | 100% liquidity |
| Mine upgrades to L5 … L20 | 0.5 … 3.2 | 100% liquidity |
| Gold Forge upgrades to L2 … L20 | 0.1 … 1 | 100% liquidity |
| Item market | the seller's price | 95% to the seller, 5% fee; one buyer-signed transaction |
The shardkeep-distributor program (not in use)
Program ID (devnet): 6Tgc32nfuEDwvVQii47eLKZXeu39evzG5142UheuxpKU
A one-claim Merkle distributor built for a possible future token event. It is deployed but switched off: no distributor account exists for KEEP, it holds no funds, and nothing in the game calls it. Gameplay rewards do not come from it.
Land Deeds (Metaplex Core)
Collection (devnet): 56RemMwZRxL7xMMV8TbiErZX2YfrnuY65x3t7sTQxKrT
- Minted exactly once. The deed's address comes from your base's stable id, so a retried transaction can never make a second deed.
- Transferable. Each deed carries an admin freeze switch for emergencies; it is not engaged.
- Living metadata. Name
Land Deed · xxxx…yyyy, symbolDEED. The picture is your base; traits (Location, Realm, Tile, Keep Level, Buildings, Land, Founded) are rebuilt from the game. - 5% royalty, honoured by marketplaces. A direct wallet-to-wallet transfer pays nothing.
- A deed carries the whole base — never the wallet's KEEP or SOL, identity or clan.

Full details: Land Deeds and realm tiles.
The KEEP token and custody
KEEP mint (devnet): 5GQh8Dg2BFtH3Yso5drRA2K8omw46m3KAQrhH3TMpWJC
KEEP is a classic SPL token (not Token-2022) with 9 decimals. Your in-game KEEP is a balance on the game's ledger; the payout custody wallet holds the reserve.
- Deposit = an ordinary SPL transfer to the game's custody wallet with a reference account.
- Withdraw = the custody wallet sends KEEP back to your wallet. Fee 2% (kept on the game's books, not burned on chain), minimum 500 KEEP.
- The weekly balance roots are the public check that the ledger adds up.
The 1,000,000,000 fixed-supply model with revoked authorities is the intended mainnet design; today's devnet mint still has its mint and freeze authorities. See Deposits, withdrawals and 2FA.
Coming with onchain gameplay
Addresses at a glance
All addresses are from the published devnet registry (infra/devnet.addresses.json).
| What | Address (devnet) |
|---|---|
| shardkeep-core program | mYYQFnpyGofG31y5oJkiKVmNwifbSXBMnQ5aUgQkL6b |
| shardkeep-distributor program | 6Tgc32nfuEDwvVQii47eLKZXeu39evzG5142UheuxpKU |
| Core Config PDA | AEtsnqdSXDwGDBeovnD9XoutQmNptcPWC8ygieZSkKHH |
| KEEP mint | 5GQh8Dg2BFtH3Yso5drRA2K8omw46m3KAQrhH3TMpWJC |
| Land Deed collection | 56RemMwZRxL7xMMV8TbiErZX2YfrnuY65x3t7sTQxKrT |
| Treasury | Address (devnet) |
|---|---|
| Liquidity (40%, plus all direct transfers) | A1ja8GwrTM2KvS4tKJJaVaLk57xJeehuk2F9Exbz82QA |
| Dev (35%) | 5sYVCRd1onSre8EKujE5vDKa9KeF2KuJvPA3rpRonfif |
| Ops (25%) | fCTc8TgJCvHUkn1aaME2gDcs69LpgtVXq1rmBSvS3Bx |
For developers — program-derived accounts:
- shardkeep-core:
Config=["config"];Player=["player", wallet];EpochRoot=["root", epoch as u64 little-endian]. - shardkeep-distributor:
Distributor=["distributor", mint]; vault authority =["vault"];ClaimStatus=["claim", distributor, claimant].
Who holds the keys
- Setting up either program requires its current upgrade authority, checked on chain.
- After that,
shardkeep-coreis run byConfig.admin(pause, post roots, two-step admin handover). - Admin, custody and deed keys are kept out of the repository.
- No third-party audit has been completed.
Security posture in brief
Every program change keeps: overflow checks in release builds; a signer on every authority; typed accounts with owner and discriminator checks; canonical PDA seeds; create-once receipts and roots; fixed treasury and mint constraints; multiply-before-divide basis-point maths; an event for every value movement; and adversarial tests (wrong signers, swapped treasuries, duplicate entries, pause bypass, forged Merkle proofs).
On the server: every payment is checked at finalized before anything is granted, payment events are only trusted from shardkeep-core's own execution, and custody transactions are saved before they are sent so a retry resends identical bytes.
How to check on an explorer
- Open Solana Explorer or Solscan and switch to Devnet.
- Paste a program ID above.
- After a land purchase, open your transaction: it should show three SOL transfers to the treasuries above — for 0.2 SOL: 0.08 / 0.07 / 0.05 — and a
PaymentMadeevent. - Paste the KEEP mint or the collection address to browse; your own deed is under your wallet's assets.
