a second key your wallet can't forge.
Your vault only opens with a one-time signature made from your vault phrase. It's built from hash functions instead of the elliptic curves that wallets use. Here is how it works, in plain words.
Winternitz in plain words.
A hash function turns any input into a short fingerprint. Going forward is instant. Going backward, from a fingerprint to an input that makes it, is not possible with any known computer, quantum ones included.
A Winternitz key is built from that one-way street. Start with a set of random secrets. Hash each one over and over to make a chain. The end of every chain is public; the secrets at the start stay with you.
To sign, the message is cut into small digits. Each digit says how far along its chain to reveal. A verifier takes the revealed point, hashes it the rest of the way, and checks that it lands on the public end.
One problem: anyone can hash a revealed point forward, which would turn a small digit into a bigger one. So the signature also signs a checksum that goes down whenever the message digits go up. Making any digit bigger forces some checksum digit smaller, which means hashing backward. That's the part nobody can do.
winternitz chain
w=16A key is a set of hash chains. Signing reveals one point on each chain. Anyone can hash forward from that point, so a checksum chain runs the other way, and every key is used once.
Revealed step 6 of 15 on the message chain, and step 9 on the checksum chain. Dashes after each point can be computed by anyone.
Why one-time keys roll.
Each signature reveals points on the key's chains. One signature is safe. Two different signatures from the same key reveal points from both, and together they can be enough to forge a third. So a Winternitz key signs exactly once.
That's why every withdrawal does all of this in one Solana transaction:
- You sign one message with key #n: the amount, the recipient, the next vault's key hash and this vault's address.
- The vault program checks the signature.
- It sends the amount to the recipient.
- It moves the rest into the next vault, opened with key #n+1.
- It closes the old vault. Key #n is never used again.
vault #n vault #n+1 +---------------+ withdraw +---------------+ | key #n | ------------> | key #n+1 | | 0.8420 SOL | 0.1000 SOL | 0.7420 SOL | +---------------+ to you +---------------+ closed, key spent live
Every key comes from the same 24-word vault phrase: key #0, key #1, key #2 and on. One backup covers every vault you'll ever roll into. To recover, the app derives the keys in order and checks the chain for the live vault. There's no server and no account: the chain is the record.
If a withdrawal fails, the app retries with the exact same signed message, or moves on to the next key. It never signs two different messages with one key.
key roll
* live0.8420
- vault address
- 9xQe..Vb4K
- live key
- #3
- keys spent
- 3, no limit
keys #0 --> #1 --> #2 --> [#3 live] --> #4 next
Withdraw to watch the live key get spent and the rest roll into a fresh vault.
What the vault does and doesn't protect.
Read this before you deposit.
It protects against
- Yes: Someone who has your wallet's private key. They can't move vault funds.
- Yes: A future break of Solana's normal signatures (ed25519), for example by a quantum computer.
- Yes: The fee payer changing where funds go: the recipient is inside the signed message.
- Yes: Losing your device. The phrase recovers the vault anywhere.
It does not protect against
- Limit: Someone who steals the vault phrase itself: malware, phishing, a photo of the backup.
- Limit: Losing the phrase. Nobody can reset it, so the vault is gone.
- Limit: The rest of Solana. The vault does not make Solana itself quantum-proof.
Is the phrase itself safe from quantum computers? Read the answer
Try it on mainnet.
Create a vault, deposit a little test SOL, then withdraw and watch the key roll.