is the phrase quantum-safe?
Short answer: as far as anyone knows, yes. The phrase only ever goes through hash functions, and it has enough randomness to stay out of reach of quantum search. Here is each reason in plain words, and the one thing it can't protect against.
Only hash functions, from phrase to key
#01Quantum computers are a threat to elliptic-curve keys, the kind every Solana wallet uses (ed25519). They aren't known to break hash functions in the same way.
Your vault phrase becomes keys through hash functions only: the standard BIP39 step (PBKDF2-HMAC-SHA512) turns the words into a seed, then SHA-256/HKDF makes one key per index. The path never touches an elliptic curve, and the phrase never makes an ed25519 key.
24 words --PBKDF2-HMAC-SHA512--> seed --SHA-256 / HKDF (i)--> key #i
(hash) (hash)
no elliptic curve anywhere on this pathThat's also why the vault phrase must not be a Solana wallet phrase. A wallet phrase makes elliptic-curve keys; the vault phrase is kept apart from them on purpose.
256 bits of entropy
#0224 words carry 256 bits of randomness: 2^256 possible phrases. The best known quantum attack on a hash (Grover's algorithm) only takes the square root of the work. That still leaves about 2^128 tries, far more than any computer, classical or quantum, can run.
The quantum attack that does break keys quickly (Shor's algorithm) works on elliptic curves, not on hashes. It has nothing to grab on this path.
Only hashes go on chain
#03The vault's address and the program's records hold a hash of the one-time public key, never the key itself. There is nothing on chain for an attacker to work backward from.
A withdrawal reveals one one-time signature, once. That key is then spent: the funds have already moved to the next vault, under a key that hasn't been revealed.
One key, one message
#04A one-time key must never sign two different messages: two signatures together can leak enough to forge a third. So if a withdrawal fails, the app retries with the exact same signed message (same amount, recipient and next vault), or moves on to the next key index. It never signs something new with a key that has already signed.
No upgrade backdoor
#05A Solana program can have an upgrade key, and that key is an ordinary elliptic-curve key. Whoever held it could replace the program, so on a quantum day it would be a backdoor to every vault.
On devnet the program stays upgradeable while it's being built. On mainnet the upgrade authority is revoked once the launch checks pass, and the program can never change again.
What it doesn't protect
#06- Limit: Someone who steals the phrase itself, through malware, phishing or a photo of your backup, can withdraw. Quantum or not, the phrase is the key.
- Yes: The fee payer is a normal wallet, but it can't change where funds go: the recipient is inside the message the phrase signs.
And the vault protects only what's inside it.