Sanctum Infinity
The assessment is adverse. Direct on-chain queries have turned an evidence gap into an active concern. The Infinity controller’s upgrade authority is a single plain keypair, not a multisig. A prior draft’s ”11-member multisig” claim traced to the wrong Sanctum program. The audited fee model, a 90/10 reserve/fee-vault split, no longer matches the live V2 fee model, a 5% performance fee, despite an unchanged program ID. This appears to be an unaudited logic change deployed by that single key. INF is not a single-validator or single-manager LST. It is the LP token of Sanctum Infinity, a managed pool of SOL and many Solana LSTs that earns the basket’s staking return plus swap fees. That does solve fragmented exit liquidity, but it also replaces a clear choice of staking operator with exposure to a changing basket, Sanctum’s valuation adapters, and administrators with broad powers. The protocol has operated since 2024, publishes its code and three audits, and handled the 2025-10-10 LST stress without a reported loss. The reason for rejection is not whether the mechanism works. It is whether an adviser can review and monitor every material constituent and the people who can add, disable, reprice, rebalance, pause, or upgrade it.
- Research remains unresolved until the live Infinity V2 program, every calculator and privileged authority are identified and mapped to published reviews
- Any constituent LST added without a published audit, authority review, and admission rationale
- Any one external LST issuer exceeding 20% of Infinity NAV
- A constituent impairment or calculator error causing INF redemption value to fall more than 1% below reported intrinsic SOL value
- Pool operations paused for more than one Solana epoch
- A proposed-size INF-to-SOL exit costing more than 50 basis points through both direct redemption and the best secondary route
- A live Infinity v2 program or calculator not mapped to a published audit
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-16.
The research file
Mechanism and source of return
A user deposits SOL or an accepted LST and receives INF, a pro-rata claim on Infinity’s reserves. The controller values each LST in SOL through an on-chain calculator built for that asset, which reads the external staking program’s state. Users can swap one LST for another or burn INF to withdraw an available reserve asset. INF rises in value through the weighted staking return of the LST basket and through swap and withdrawal fees kept by the pool. It is both a staking wrapper and an AMM LP position.
The old Infinity documentation says swap-fee revenue was split 90% to reserves and 10% to protocol fee vaults. Sanctum’s 2026-03-17 V2 launch announcement says it scrapped that model and replaced it with a 5% performance fee on INF yield, along with slot-level reward distribution, multi-epoch yield smoothing, and a more concentrated, actively managed LST portfolio. The current technical docs still say that removing liquidity costs 20 basis points. V2 separately describes lower swap fees for partner LSTs and higher fees for non-partners. These are separate charges and should not be combined into one “10% fee” description.
At epoch end, the system stakes SOL above its target into selected top-performing LSTs. It restores SOL below the target by unstaking the worst-performing LSTs. This is an active allocation rule, and V2’s narrower basket gives the manager’s choices more weight. The public docs do not define “top” or “worst,” the target SOL formula, constituent caps, or the data window well enough to reproduce a future rebalance.
Constituents, valuation, and control
The controller stores an admin, rebalance authority, disable authorities, a pricing manager, and a fee beneficiary. The admin can whitelist or blacklist LSTs. Pricing settings determine input and output fees. The controller can pause all pool operations. The original public repository describes one admin and one rebalancing authority, not an index run by fixed public rules. Development has since moved to the public inf-1.5 repository, which confirms that the live system can still be upgraded and is not frozen.
Valuing each LST in SOL from its internal records avoids reliance on a thin spot market, but it also assumes that an external LST program’s accounting value can be realized. A compromised stake-pool authority, validator slashing, stale external state, high withdrawal fee, or faulty calculator can make face value differ from exit value. INF spreads operator risk only if weights have firm limits. Without them, it can hold a troubled LST while giving departing users SOL.
Security and incident record
Sanctum publishes Infinity reviews by Neodyme, OtterSec, and Sec3, along with open-source controller code. Audits reduce doubt about the code reviewed. They do not cover future constituents, custody of live authorities, external LST programs, or every later upgrade. Sanctum says Infinity launched in March 2024 and held more than 2 million SOL during its 2024 Wonderland campaign. The sources reviewed identified no exploit or loss of principal caused by Infinity.
The best disclosed stress evidence comes from 2025-10-10. Sanctum reports that INF supplied substantial SOL liquidity during a BNSOL depeg and earned a 26.12% annualized epoch return from fees. This is the issuer’s account, not an independent post-mortem, and an annualized two-day return is not a lasting yield estimate. It shows the intended response to a liquidity shortage. It does not show the loss that would result if a constituent’s recorded value were impaired rather than merely hard to trade.
Exit and liquidity waterfall
There are three different exits. A holder can redeem INF for an asset held by Infinity and pay the documented 20-basis-point withdrawal fee. The holder can sell INF or a received LST in secondary markets and accept the available depth and slippage. The holder can also rely on Sanctum’s broader router and Reserve. The Reserve supplies last-resort SOL liquidity after the router and Infinity and charges a dynamic 8-to-800-basis-point fee as its SOL balance falls. Its docs say retail deposits are closed, so it is a protocol-controlled backstop rather than capital owned by clients.
“No lockup” does not mean par liquidity. Available SOL can run out. Redemption can return an LST that the client must still sell or unstake. The pool can be paused, and stress fees rise when exit is most valuable. Approval requires executable aggregator and direct-redemption quotes at the proposed position size, plus a record at the same block of the SOL reserve share and the largest constituents.
Comparison and decision frame
Compared with mSOL, JitoSOL, or a carefully chosen single LST, INF offers more routing liquidity and fee income but gives up control over the validator program, constituent weights, and future admissions. Compared with a conventional index, it does not yet publish a rules-based benchmark, reconstitution schedule, and hard issuer caps that an outsider can reproduce. Compared with a simple SOL-LST AMM, its intrinsic-value calculators reduce price slippage but add adapter and admin risk across many external programs.
The decision is rejection, not postponement. The March 2026 V2 launch post describes the issuer’s design. It does not prove the live program, calculator set, authorities, or audit coverage. The confirmed on-chain single-key upgrade authority is a reason to reject, not merely missing evidence. Reopen only when a repeatable on-chain constituent report shows no unapproved LST, hard concentration limits are documented or imposed in operations, current authorities and upgrade controls are identified, and both direct and secondary exits at the proposed size remain within a written cost limit. Higher yield cannot offset a basket with no firm bounds.
Open questions and observable triggers
Correction, 2026-08-16: the prior update in this section cited Solana Compass for an 11-member-multisig upgrade authority, but described a different Sanctum program, its generic SPL stake-pool deployments, rather than the Infinity controller on which this entry depends. Direct on-chain queries against the Infinity controller program (5ocnV1qiCgaQR8Jb8xWnVbApfaygJ8tNoZfgPwsgx9kx, confirmed to match Sanctum’s own technical docs, which were independently reached during this pass through a headless browser after the prior pass’s automated fetch was blocked) show that its ProgramData account lists one upgrade authority address (47SND7bGKvNXrqfP1bjsLCbwTgZhFBzAgmZ42QSkRScz). The System Program owns the account, which has zero account data. It is a plain keypair, not an on-chain multisig program account. A Squads vault would be owned by the Squads program and carry parsed multisig data, and this account does not. On-chain data cannot show whether several people informally control the key off-chain. This finding is materially weaker than the entry previously recorded, not stronger, and it remains a live gap. Sanctum’s own docs, independently confirmed, also state that the Infinity program page was ”last updated 8 months ago” and still describes a 90/10 reserve/fee-vault split, the pre-V2 model. The March 2026 V2 announcement instead describes a 5% performance-fee replacement. Because the program ID is unchanged, the same audited program appears to have been upgraded in place by that single-key authority. No evidence shows that an independent audit covered the V2 fee-logic change. This makes the audit scope gap below more serious.
This pass did not independently decode the current pool state or full constituent weights. It also did not find a public admission policy that sets minimum audits, operator concentration, maximum withdrawal fee, slashing history, liquidity, or per-issuer caps. The link between the March 2026 INF v2 upgrade and the three published legacy audits (Neodyme, OtterSec, Sec3, confirmed still hosted at github.com/igneous-labs/sanctum-static as of 2026-08-16) still needs an audit scope map. This review did not confirm whether those reports cover the exact v2 deployment or an earlier version, and the fee-model finding suggests that they may not.
The tests for reopening are clear. Publish a machine-readable weekly snapshot of constituents and authorities. Cap any one external LST issuer at 20% of NAV. Maintain at least 10% immediately withdrawable SOL or show an exit at the proposed size below 50 basis points. Map every live program hash to an audit. Document the exact admission, removal, and rebalance rules. Any failed calculator, unannounced constituent addition, or pause beyond one Solana epoch should trigger immediate review.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Sanctum legacy Infinity architecture, fees, allocation and audits · primary · accessed 2026-08-15
Supports: legacy Infinity mechanism, legacy fee routing, calculator model, legacy audits - Sanctum legacy Infinity holder mechanism · primary · accessed 2026-08-15
Supports: legacy deposit and withdrawal, intrinsic-value swaps, 20-basis-point removal fee - Sanctum Reserve mechanism and dynamic fee · primary · accessed 2026-08-15
Supports: reserve exit waterfall, dynamic fee, protocol-controlled liquidity - Sanctum S legacy repository, authorities and verified program hashes · primary · accessed 2026-08-15
Supports: legacy controller roles, pause and pricing authorities, legacy program hashes - Sanctum inf-1.5 repository · primary · accessed 2026-08-15
Supports: current code lineage, upgrade-oriented implementation, calculator source - Sanctum Infinity launch, 2024-03-05 · primary · accessed 2026-08-15
Supports: legacy launch, pool purpose, historical scale - Sanctum Infinity 2025 performance review and October stress account · primary · accessed 2026-08-15
Supports: issuer-reported October 2025 stress, BNSOL liquidity, epoch fee return - Sanctum Infinity V2 launch commentary, 2026-03-17 · primary · accessed 2026-08-15
Supports: V2 launch claim, 5% performance fee claim, concentrated active basket claim
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Solana | Approved with limits | Governed, no freeze | no admin key can seize funds, but stake concentration and a sub-25 Nakamoto coefficient are the standing watch items. |
| Asset | Control | Who can freeze it |
|---|---|---|
| INF | No freeze key | Sanctum Infinity. A basket of Solana LSTs: you inherit the weakest constituent rather than choosing the strongest. |