You want a wallet address that starts with your name, or a token mint that starts with the ticker. It is a real thing people do, the tool to do it ships with the Solana CLI, and the maths behind it fits on one line. Here is how the grinder works, how many tries a prefix costs, the two safety rules that matter, and the reason a matching prefix should never be mistaken for a matching address.
What an address is
A Solana address is 32 random bytes — a public key — written in base58. Base58 is the alphabet of digits and letters with four characters removed because they look like each other: zero, capital O, capital I and lowercase l. That leaves 58 characters, and 32 bytes come out as 43 or 44 of them.
There is no “choosing” an address. You generate a random private key, derive its public key, and look at the characters. A vanity address is a random key whose public key happened to start with what you wanted, found by generating keys until one does. The grinder is a loop.
Worth knowing: the smallest possible 44-character address is the one the tool keeps as a constant — a 2 followed by forty-three 1s. Not every string is reachable: a prefix that would decode to more than 32 bytes cannot exist, and the tool skips candidates above that bound before it bothers encoding them.
The grinder
The tool is solana-keygen grind. It takes three kinds of target, each as the pattern and a count of how many matching keys you want:
--starts-with xroot:1 — one key whose address begins with xroot.
--ends-with 1234:1 — one key whose address ends with 1234.
--starts-and-ends-with ab:cd:1 — both.
Add --ignore-case to accept any capitalisation of the letters, and --num-threads to use more cores. Every thread generates random keypairs, encodes the public key, and checks it against every target until the counts are filled. When a match is found the keypair is written to a file named after the address.
That is the whole algorithm. There is no shortcut, no table, no way to steer the key toward a prefix. Each try is independent and each has the same tiny chance.
The odds, in tries
Each character position in a base58 address is close to uniform over 58 values, so a case-sensitive prefix of n characters matches one key in 58ⁿ on average:
--ignore-case helps by roughly the number of letters in the prefix that have both cases: a five-letter all-alphabetic prefix with case ignored is about 2⁵ = 32 times cheaper — twenty million tries instead of 656 million.
How long that takes depends entirely on your hardware, and the tool shows its progress rather than promising a rate. The useful rule is the ratio: each extra character multiplies the work by 58, each case-insensitive letter divides it by about 2. Four characters is minutes on a laptop; six is a serious machine for a long time; eight is not a thing people do for a wallet.
Two safety rules
- Never use a website or a service to grind a key. Whatever generates the keypair holds the keypair. A vanity address from a web generator is an address someone else can empty, and the pattern of “cheap vanity address, drained later” is old. Run the tool yourself, on your own machine, offline if the key will hold anything.
- The output file is plain text.
solana-keygenwrites the keypair as a plain JSON array of bytes. If you generate with a recovery phrase and a passphrase, the passphrase protects the phrase, not the file — the tool’s own source describes the file as stored as insecure plain text. Treat the file the way you would treat a seed phrase written on paper, and note that the tool refuses--no-outfileunless you also asked for a mnemonic, so a key can never be generated with no recovery path at all.
The reason a prefix is not an identity
This is the part that matters more than the odds. If you can grind an address that starts with xroot, so can anyone else. Address poisoning attacks do exactly that: generate an address whose first and last characters match a victim’s real counterparty, send a dust transfer so it appears in the victim’s history, and wait for the victim to copy the lookalike from the list.
A vanity prefix on your own address makes you easier to recognise and easier to imitate in the same move. The defence is the same as for any address: verify the whole string, or a long enough suffix as well as the prefix, and never copy an address out of a transaction history. The grinder that makes vanity addresses possible is the grinder that makes the poisoning cheap.
Vanity Addresses: Questions People Actually Ask
How do I generate a Solana vanity address?
With the CLI: solana-keygen grind --starts-with PREFIX:1, optionally --ignore-case and --num-threads N. The tool generates random keypairs until one’s public key matches, then writes the keypair file.
How long does a vanity address take?
On average 58 to the power of the prefix length tries for a case-sensitive prefix: about 11 million for four characters, 656 million for five, 38 billion for six. --ignore-case divides that by roughly two per letter. Actual time depends on your hardware.
Are vanity addresses safe?
Only if you generate them yourself, offline, and guard the plain-text keypair file. Any service that generates the key for you holds the key. A vanity prefix also makes your address easier to imitate in address-poisoning attacks.
Can two wallets have the same vanity prefix?
Yes, and that is the risk. Anyone can grind a prefix. Verify the entire address, never just the start, before sending.
If you are going to do it
Run solana-keygen grind locally, with --ignore-case if the capitalisation does not matter to you, and keep the prefix to four or five characters unless you have the hardware for more.
Treat the output file as the key itself, because it is.
Tell the people who send you money to check the full address, not the start of it. Your prefix is the easiest part of your address to fake.
A familiar-looking prefix is exactly what drainers rely on — owner reassignment is one of them — and a keypair that must stay offline signs more safely with a durable nonce.
Constants read from the Agave validator source at commit beee69b958: keygen/src/keygen.rs and clap-v3-utils/src/keygen/mnemonic.rs. Flag names change between releases — check them against solana-keygen grind --help for the version you run.