Winternitz
THE FIRST QUANTUM-PROTECTION TOKEN ON SOLANA

Every asset a project ever accumulates, guarded by a signature Shor cannot forge and Grover cannot brute-force in the lifetime of the universe.
The day quantum arrives, this is the only thing on Solana still standing.

Built for the day the maths breaks.

The first quantum-protection token on Solana. Locked liquidity is table stakes; any launchpad can burn an LP. None of them can sign without elliptic curves.

Nobody has done this

No Winternitz vault has ever run on Solana. Ours does, today, and every transaction is linked below.

Signed by hashes

Supply and treasury answer to a hash-based signature. Shor's algorithm has nothing here to break.

Every key dies once

A key signs a single time and the vault rotates in the same instruction. Reuse does not weaken it. It fails.

Still an ordinary token

A standard SPL token that trades anywhere. The cryptography sits underneath. Nothing to adapt.

The day the quantum computer arrives.

A working quantum computer breaks Ed25519, the signature every ordinary token relies on. Here is what happens to a normal token that day, and what happens to this one. Both columns are checkable in an explorer right now.

  Every other token, quantum day A Winternitz token, quantum day
Supply Anyone who cracks the Ed25519 mint key prints unlimited tokens. Untouched. No mint authority exists to crack.
Liquidity Anyone who cracks the LP owner key drains the pool. Untouched. The locked LP has no owner key to crack.
Fees and treasury Anyone who cracks the wallet key empties years of savings. Untouched. Guarded by a hash chain Shor cannot invert.
Your holdings Anyone who cracks your wallet takes everything in it. Move them into a Winternitz vault and the same crack finds nothing.
The verdict Every line above falls at once. The token is a carcass. Every line above still stands. There was never a key to take.

Why it holds. Ed25519 keeps a secret that its public key mathematically implies; Shor's algorithm draws the line between them. A hash chain keeps no such secret. The vault's public key is the far end of 255 hashes, and walking back even one step means inverting a hash, which is the one thing quantum computers barely help with. Grover halves the exponent and stops there.

Why the rest is safe too. The reserves and the locked liquidity are not guarded by a better key. They are guarded by no key: program addresses on Solana are derived deliberately off the elliptic curve, so no private key for them exists to be found. Put together, an attacker holding a working quantum computer would look at this token and find nothing with a lock on it.

A signature you can only use once.

That sounds like a defect. It is the entire defence, and it is why this survives the machine that breaks everything else.

Every ordinary Solana account is guarded by Ed25519. Its security rests on one bet: that nobody can work backwards from a public key to the private key. A quantum computer running Shor's algorithm makes that walk backwards trivial. Not faster , trivial. Every key ever published becomes a key anyone can forge.

Hashes have no such door. The best a quantum computer can do against a hash is Grover's algorithm, which halves the exponent: 192 bits of security become 96. Still 79,228,162,514,264,337,593,543,950,336 attempts. So we build the signature out of nothing but hashes.

σ secret never shown signature published public key on chain the message says: walk m steps anyone can walk the remaining 255 − m one chain of 255 hashes · a signature uses 34 of them at once
  1. The chain. Start from a secret and hash it 255 times. The far end is the public key, published for all to see. Nobody can walk back towards the secret, because that would mean inverting a hash.
  2. The signature. The message decides how far along to stop. You reveal that one link. A verifier hashes it the remaining number of times and checks it lands exactly on the public key. It fits: the message chose the distance, and only the holder of the secret could have reached that point.
  3. The catch, and the trick. Show two links on the same chain and a forger can interpolate between them. So the key dies on first use, and every signature carries the hash of its successor. The vault rotates in the same instruction, before the money moves. Reuse does not weaken the signature; it fails, because the key it would be checked against no longer exists.
  Ed25519 This vault
Rests onelliptic curveshash preimages
Quantum attackShor recovers the key outrightGrover, halves the exponent, 96 bits left
Key reuseunlimited, by designonce, enforced by rotation
Signature size64 bytes816 bytes
Cost to verifyfree, the runtime does it695,337 compute units

The price is honest and it is on that last row: signatures thirteen times larger, and half a transaction's compute budget spent walking hash chains. That is what it costs to hold an authority that does not depend on elliptic curves staying hard.

One vault, every asset a Solana project holds. Audited line by line against a quantum computer.

One vault. Every treasury, every mint, every DAO signer, every fee stream, every upgrade key. Anything worth signing for, in the years before quantum lands and the years after. We hand you the addresses and dare you to check.

What holds value Verdict Why
Reserves on the curve no key exists Held by a program address, which is derived off the elliptic curve on purpose. There is no private key, so Shor's algorithm has no target.
Liquidity after graduation no key exists 100% permanently locked. Locked, not burned: nobody can withdraw it and the fees it earns still go somewhere. To us, and then out again.
Supply of a launched token no key exists The mint is immutable from creation. No authority survives, so there is nothing to steal and nobody, including us, can ever print more.
Everything the project holds forever Winternitz vault Trading fees from every token launched here, the treasury the team owns, and the address that collects from every locked LP for as long as this launchpad exists. Add years of accumulation and this is where the real money lives. A quantum computer with a working Shor engine looks at this vault and finds nothing to break.
Authority over any token launched here Winternitz vault Any project on this launchpad can put its own mint authority, its own multisig, its own treasury behind the same vault. One signature scheme protects every asset a Solana project ever accumulates, from year one to year twenty.
Anything else worth signing for Winternitz vault The vault runs arbitrary programs on Solana under a one-time signature: DAO votes, cross-program calls, custody of NFTs, upgrade authorities on other contracts. Whatever you need signed years from now, this signs.
Meteora's upgrade key not our layer The curve and pool programs can be replaced by their multisig, and a multisig is still elliptic curves underneath. Not ours to fix, so we name it: JADaUV8kv…feuCVLd
Our own upgrade key not our layer Upgradeable while the code is young, and we publish the key rather than hide it. It gets burned the day the code is final: EFQJ3sPa…m4NbxaeU. It gets burned when the code stops changing.
Your own wallet not our layer That is what a Solana account is. No token can change it, and any project telling you otherwise is lying to you.

Read the table and it says this: the money sits where no key can reach it, and the income sits behind a signature no quantum computer can forge. Everything left on that list is the rest of Solana, the same for every token that has ever existed. On the parts that are actually ours, we are further than anyone on this chain.

Where the idea comes from. Dean Little published solana-winternitz-vault, the first Winternitz vault written for Solana, and it is the reason anyone knows this is possible here. That program guards lamports and cannot touch tokens, so ours is written from the scheme rather than forked: it adds the cross-program calls that let a vault be a mint authority, a treasury and a launchpad's fee collector. The signature scheme is the same well-known one, and we would rather point at the shoulders we are standing on than pretend we invented hash-based signatures.

Next comes our own curve with its upgrade key burned, so that no key exists anywhere in the stack at all. Audited first, because code that can never be patched had better be right, and paid for out of the fees this one is already earning.

The road to a post-quantum Solana.

Every step is the same vault, wearing a different hat. No dates, because we ship when it works. In order of what we hit first.

Quantum-safe wallet with in-browser signing 01 · next Generate the 24 words, sign transfers straight from the web, watch the key rotate on chain. A Phantom that a quantum computer cannot empty.
DAO signer 02 Replace a multisig with a rotating hash key. Every proposal signs once and the key that voted it dies. A stolen seed cannot vote for the DAO ever again.
Treasury vault for projects 03 Put a project treasury behind the vault instead of a hot wallet. Movements need a fresh signature; nothing on a laptop can drain it.
Upgrade authority as a service 04 Any Solana program can hand its upgrade key to a vault. Your contract survives a quantum break of the whole chain.
Time-locked vaults 05 Vest a founder allocation or a partner grant behind a schedule that only the vault can unlock. No hot key that anyone can compromise midway through.
NFT custody for collectors 06 Send a Metaplex asset to a vault. It stays there until a one-time signature moves it. Wallet drainers stop working.
Signed messages under Winternitz 07 Sign a note with a key that cannot be forged. A message from a project years from now still verifies as theirs.
Our own curve, immutable 08 Replace the Meteora curve with one whose upgrade key is burned. The last elliptic-curve key in the whole stack disappears. Audited before it ships, because there are no second chances with immutable code.
Winternitz SDK 09 A library any Solana project can drop in to put their own mint, treasury or upgrade key behind the vault. Everyone on Solana gets to skip the quantum apocalypse.
Quantum Launchpad · the first on Solana

Launch a token whose keys outlive the maths.

Free to launch, liquidity locked forever when it graduates, and the address every fee is paid to is a Winternitz vault instead of a keypair. The curve is Meteora's, battle-tested and unchanged. What is ours is the part that holds the money.

Open the launchpad
1.5% fee40 SOL to graduateLP locked 100%free to create

Live on mainnet. Here is the receipt.

Every address below is live. Open them in an explorer and read the transactions yourself: with cryptography, that is the only kind of claim worth making.

$WINTERNITZ, the official token
3SJZcESxBMGvfRHu2DX6LeewMeFX586hc3hM1ZMQUANT
The vault calling another program
3WkCjvg6…tF4oBBFc
A quantum-signed mint
5aKThPDm…P77WYZey
816bytes long, the size of one hash-based signature that fits in a single transaction
695,337calculations to check one signature, half of what a Solana transaction is allowed to spend
9 out of 9attempts to forge a signature, all rejected by the chain
2192guesses a quantum computer would need to break one key, more than the atoms in the universe
Launchpad fee
1.5% total: 0.8% platform, 0.4% creator, 0.3% Meteora
Graduation
40 SOL, half of what pump.fun asks
Liquidity at graduation
100% permanently locked, nobody can pull it
Launching a token
free
Fees are paid to
a Winternitz vault, not a keypair

We tried to rob it nine different ways. Sending the same signed transaction twice. Signing with a key that had already been used. Signing with a key the vault never knew. Changing the amount after signing. Changing who receives the money. The chain rejected every single attempt, and anyone can rerun the lot with one command and watch it happen.

And the vault is not tied to one token. It can drive any program on Solana, each call authorised by a signature that covers the target, every account and every byte of the instruction. That is how it collects a launchpad's trading fees: the address Meteora pays has to sign, and here signing means a hash chain rather than a key in a file. It is the first wallet on this chain that a quantum computer cannot empty.

Read the audit for the parts we do not control, named one by one.

Standing on someone else's work, and saying so

Dean Little wrote the first Winternitz vault for Solana. That program guards lamports and cannot touch tokens, so ours is written from the same scheme rather than forked: it adds the cross-program calls that let a vault hold a mint authority, a treasury and a launchpad's fees. The signature scheme is the well-known one. We would rather point at the shoulders we are standing on than pretend we invented hash-based signatures.

github.com/blueshift-gg/solana-winternitz-vault →
Winternitz · the post-quantum standard of Solana Launchpad · Audit · Proof Prior art (Blueshift) · Our source · Program on mainnet