Nobody has done this
No Winternitz vault has ever run on Solana. Ours does, today, and every transaction is linked below.
Every asset a project ever accumulates, guarded by a signature Shor cannot forge and
Grover cannot brute-force in the lifetime of the universe.
The day quantum arrives,
this is the only thing on Solana still standing.
The first quantum-protection token on Solana. Locked liquidity is table stakes; any launchpad can burn an LP. None of them can sign without elliptic curves.
No Winternitz vault has ever run on Solana. Ours does, today, and every transaction is linked below.
Supply and treasury answer to a hash-based signature. Shor's algorithm has nothing here to break.
A key signs a single time and the vault rotates in the same instruction. Reuse does not weaken it. It fails.
A standard SPL token that trades anywhere. The cryptography sits underneath. Nothing to adapt.
A working quantum computer breaks Ed25519, the signature every ordinary token relies on. Here is what happens to a normal token that day, and what happens to this one. Both columns are checkable in an explorer right now.
Why it holds. Ed25519 keeps a secret that its public key mathematically implies; Shor's algorithm draws the line between them. A hash chain keeps no such secret. The vault's public key is the far end of 255 hashes, and walking back even one step means inverting a hash, which is the one thing quantum computers barely help with. Grover halves the exponent and stops there.
Why the rest is safe too. The reserves and the locked liquidity are not guarded by a better key. They are guarded by no key: program addresses on Solana are derived deliberately off the elliptic curve, so no private key for them exists to be found. Put together, an attacker holding a working quantum computer would look at this token and find nothing with a lock on it.
That sounds like a defect. It is the entire defence, and it is why this survives the machine that breaks everything else.
Every ordinary Solana account is guarded by Ed25519. Its security rests on one bet: that nobody can work backwards from a public key to the private key. A quantum computer running Shor's algorithm makes that walk backwards trivial. Not faster , trivial. Every key ever published becomes a key anyone can forge.
Hashes have no such door. The best a quantum computer can do against a hash is Grover's algorithm, which halves the exponent: 192 bits of security become 96. Still 79,228,162,514,264,337,593,543,950,336 attempts. So we build the signature out of nothing but hashes.
The price is honest and it is on that last row: signatures thirteen times larger, and half a transaction's compute budget spent walking hash chains. That is what it costs to hold an authority that does not depend on elliptic curves staying hard.
One vault. Every treasury, every mint, every DAO signer, every fee stream, every upgrade key. Anything worth signing for, in the years before quantum lands and the years after. We hand you the addresses and dare you to check.
Read the table and it says this: the money sits where no key can reach it, and the income sits behind a signature no quantum computer can forge. Everything left on that list is the rest of Solana, the same for every token that has ever existed. On the parts that are actually ours, we are further than anyone on this chain.
Where the idea comes from. Dean Little published solana-winternitz-vault, the first Winternitz vault written for Solana, and it is the reason anyone knows this is possible here. That program guards lamports and cannot touch tokens, so ours is written from the scheme rather than forked: it adds the cross-program calls that let a vault be a mint authority, a treasury and a launchpad's fee collector. The signature scheme is the same well-known one, and we would rather point at the shoulders we are standing on than pretend we invented hash-based signatures.
Next comes our own curve with its upgrade key burned, so that no key exists anywhere in the stack at all. Audited first, because code that can never be patched had better be right, and paid for out of the fees this one is already earning.
Every step is the same vault, wearing a different hat. No dates, because we ship when it works. In order of what we hit first.
Free to launch, liquidity locked forever when it graduates, and the address every fee is paid to is a Winternitz vault instead of a keypair. The curve is Meteora's, battle-tested and unchanged. What is ours is the part that holds the money.
Open the launchpadEvery address below is live. Open them in an explorer and read the transactions yourself: with cryptography, that is the only kind of claim worth making.
We tried to rob it nine different ways. Sending the same signed transaction twice. Signing with a key that had already been used. Signing with a key the vault never knew. Changing the amount after signing. Changing who receives the money. The chain rejected every single attempt, and anyone can rerun the lot with one command and watch it happen.
And the vault is not tied to one token. It can drive any program on Solana, each call authorised by a signature that covers the target, every account and every byte of the instruction. That is how it collects a launchpad's trading fees: the address Meteora pays has to sign, and here signing means a hash chain rather than a key in a file. It is the first wallet on this chain that a quantum computer cannot empty.
Read the audit for the parts we do not control, named one by one.
Dean Little wrote the first Winternitz vault for Solana. That program guards lamports and cannot touch tokens, so ours is written from the same scheme rather than forked: it adds the cross-program calls that let a vault hold a mint authority, a treasury and a launchpad's fees. The signature scheme is the well-known one. We would rather point at the shoulders we are standing on than pretend we invented hash-based signatures.
github.com/blueshift-gg/solana-winternitz-vault →