Solana DvP Gives Institutions an Open Program for Atomic Settlement

The Solana Foundation has released Solana DvP, an MIT-licensed escrow program for delivery-versus-payment that settles both legs of a trade in one transaction. J.P. Morgan gave input on institutional settlement practices, and the program is deployed on mainnet-beta and devnet.

Delivery-versus-payment is the rule that a security changes hands only if the payment for it does too. Institutions depend on it because the gap between the two legs is where a trade goes wrong, with one side having delivered and the other not yet paid. Traditional markets cover that gap with clearing houses and custodians, and the Foundation says the process ties up capital for one to two days. It says Solana DvP removes that counterparty risk and frees the capital in seconds.

The Foundation announced Solana DvP on October 6, 2026, and says J.P. Morgan's involvement was limited to that input. Institutions settling onchain have typically relied on custom programs, and Solana DvP is meant to be the shared one for tokenized assets that settle on Solana. The Foundation says the program is "ready for use with real funds" and is taking design partners ahead of a production release.

How Solana DvP works

Each trade is a program-owned SwapDvp account plus two escrow token accounts, one per leg. The record stores the two parties, the two mints, the amounts, an expiry, an optional earliest settlement time, the settlement authority, and a settlement destination for each side.

Anyone can create a trade, and CreateDvp moves no tokens. There is no funding instruction either. Each party sends a standard TransferChecked to its escrow from the wallet or custodian it already uses, so a custody provider doesn't have to integrate a DvP-specific call.

The program has six instructions.

Instruction

Signer

What it does

CreateDvp

Any payer

Creates the trade record and both escrows

SettleDvp

Settlement authority

Sends each leg to the other side's destination, refunds any surplus, and closes the trade

CancelDvp

Settlement authority

Refunds both escrows and closes the trade

RejectDvp

Either party

Refunds both escrows and closes the trade

ReclaimDvp

Either party

Returns the signer's own leg and leaves the trade open

RecoverDvp

Either party

Returns a deposit that arrived after the trade closed

The settlement authority is a third address named when the trade is created, such as a bank, custodian, or exchange. It is the only signer that can settle, it can't be one of the two parties, and it can't redirect the proceeds because both destinations are fixed in the record.

SettleDvp fails if either escrow holds less than the agreed amount, if the expiry has passed, or if the earliest settlement time hasn't arrived. Expiry can be set up to one year out. Reclaim, cancel, and reject still work after expiry.

Because anyone can create a record with any terms, the program guide tells each party to check the trade before funding it. Confirm the account is owned by the program and is 458 bytes, and that the parties, mints, amounts, timestamps, authority, and both destinations match what you agreed.

Which tokens can a trade hold?

A trade can use SPL Token or Token-2022 on each leg, in any combination, including wrapped SOL. The program checks mint extensions at creation and again at settlement.

  • Accepted. PermanentDelegate, Pausable, DefaultAccountState, TransferHook, MemoTransfer, ConfidentialTransfer, and MintCloseAuthority

  • Rejected. TransferFee, InterestBearing, ScaledUiAmount, and NonTransferable, which all fail with BlockedMintExtension

Issuers of tokenized securities keep their controls while tokens sit in escrow, so a freeze authority, a pause, or a permanent delegate can act on a leg during a trade. On a mint that freezes accounts by default, the escrow starts frozen and has to be thawed before it can be funded.

Audit, clients, and what's next

Cantina audited the program from May 21 to May 28, 2026, and its report lists 21 findings. All four medium-severity findings are fixed.

The program is written in no_std Pinocchio, and the repository ships Rust and TypeScript clients generated with Codama. It is upgradeable on both clusters.

Solana DvP is also available through the Markets module of the Solana Developer Platform, and there's a devnet demo that walks through a trade. The Foundation plans to add private settlement.

The Foundation is betting that a custodian who can fund a Solana DvP trade with a plain token transfer has no reason to commission a settlement program of its own. The integration work falls to the venue or agent acting as settlement authority, and it gets an audited program and generated clients to start from.