Account Discriminators
Discriminators identify which struct type owns an account's byte layout. They block type confusion attacks where a malicious account is interpreted as the wrong type.
Search across all documentation pages
Discriminators identify which struct type owns an account's byte layout. They block type confusion attacks where a malicious account is interpreted as the wrong type.
if data[..8] != Account::DISCRIMINATOR { return Err(ProgramError::InvalidAccountData); }When to reach for this:
pub const VAULT_DISC: [u8; 8] = *b"vault___";
pub fn load_vault(data: &[u8]) -> Result<Vault, ProgramError> {
if data.len() < 8 || data[..8] != VAULT_DISC { return Err(ProgramError::InvalidAccountData); }
Vault::deserialize(&mut &data[8..]).map_err(|_| ProgramError::InvalidAccountData)
}What this demonstrates:
SHA256("account:TypeName")[:8] in 0.32.1.
Pick unique constants; document in IDL.
// Include disc in SPACE: 8 + body| Alternative | Use When | Don't Use When |
|---|---|---|
| Owner-only typing | Single account type per program | Multi-type programs |
| Version byte only | Simpler | Weaker type safety |
| Anchor auto disc | Default | Native manual |
Anchor convention; native can differ if consistent.
Usually prepended manually or Anchor wrapper.
Yes first write.
Zero entire data.
Anchor includes account names.
Not security boundary - layout match matters.
Token program has own layout - different.
Use version field after disc.
LiteSVM negative test.
Anchor internal - reproducible.
Export constants for clients.
Valid bytes but avoid all-zero ambiguity.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026