skip to content
Network: mainnetX

SAVINGS YOUR WALLET KEY CAN'T MOVE ALONE.

Deposit SOL into a vault that only opens with a one-time key made from hashes. If ordinary wallet signatures are ever broken, your savings still need that second key.

CA

coming soon

the token address appears here at launch

wallet key alone: locked

Why a second key.

Every Solana wallet is an elliptic-curve key. A large enough quantum computer could work that key out from your public address and move everything it holds.

Hash functions don't have that weakness. So this vault asks for a signature built only from hashes, from a phrase that never touches your wallet.

two keyswhat each key can do

Your wallet key, next to the vault key.

Both sign transactions. Only one of them is built from hashes.

Comparison of the ed25519 wallet key and the hash-based vault key
Property ed25519 wallet key hash-based vault key
made froman elliptic curve (ed25519)hash functions only (SHA-256)
signsas many times as you likeexactly once, then the vault rolls
on chainthe full public key: your addressonly a hash of the public key
signature64 bytes784 bytes (28 hash chains)
large quantum computercould work the key out (Shor's algorithm)no known fast attack: forging still takes about 2^104 work, even with Grover
in this vaultpays fees, sends depositsthe only key that moves the funds

Neither key helps if someone gets your vault phrase: with it, they can withdraw. Is the phrase itself quantum-safe?

Create, deposit, withdraw.

Your normal wallet pays fees and sends deposits. Only your vault phrase can sign a withdrawal.

  1. 1. create a vault

    Your browser makes a 24-word vault phrase. Write it down, then type three of the words back to confirm.

  2. 2. deposit

    Send SOL from your normal wallet, as much as you like. Your wallet pays the fee.

  3. 3. withdraw

    Sign with the live key from your phrase. That key is spent, and what's left rolls into the next vault.

how the one-time keys work

key roll

Example* live

0.8420

vault address
9xQe..Vb4K
live key
#3
keys spent
3, no limit

keys #0 --> #1 --> #2 --> [#3 live] --> #4 next

Withdraw to watch the live key get spent and the rest roll into a fresh vault.

winternitz chain

Examplew=16

A key is a set of hash chains. Signing reveals one point on each chain. Anyone can hash forward from that point, so a checksum chain runs the other way, and every key is used once.

Revealed step 6 of 15 on the message chain, and step 9 on the checksum chain. Dashes after each point can be computed by anyone.

start

Create a vault.

Two minutes on mainnet: write down a vault phrase, deposit from your wallet, then try a withdrawal and watch the key roll.

create a vault
ctrl K
  • create a vault~/create
  • recover with phrase~/recover
  • my vault~/vault
  • deposit~/deposit
  • withdraw~/withdraw
  • how it works~/how-it-works
  • docs~/docs
  • is the phrase quantum-safe?~/docs/phrase-quantum-safety
  • faq~/faq
  • terms~/terms
  • home~/
  • connect walletwallet

connect a wallet

Your wallet pays fees and sends deposits. It can't move vault funds on its own.

Connecting shares only your public address. Your vault phrase never touches your wallet.