A normal Solana account has a keypair; a PDA is derived from program id plus seeds and deliberately falls off the ed25519 curve, so no private key exists. Only the owning program can 'sign' for it — which is how a program holds tokens, vaults and authority without a key anyone could lose or leak.
They double as deterministic storage: the address for 'user profile of wallet X' is computable offline from X, so no registry is needed. The recurring bug class is seed validation — if the program does not check the seeds it was given, it is signing for an account it did not mean to.
Related terms
Solana
A high-throughput, low-fee blockchain — thousands of transactions a second at fractions of a cent — built for applications that need speed.
Anchor
The Rust framework for Solana programs — generates the boilerplate and enforces the checks raw Solana development makes easy to forget.
SPL token
Solana's token standard — the shared program every fungible and non-fungible token on the chain uses, so wallets and apps speak one format.
The bench this belongs to
BlockchainSolidity on Ethereum, Polygon, Base and Arbitrum. Anchor programs on Solana. Written with tests first, because a redeploy is not a hotfix once value is on the line.
