QuantumPOS
Solana mainnet-beta · live

The quantum-safe
transaction layer
for Solana.

Send and receive SOL through Winternitz vaults. Your funds sit behind a one-time, hash-based signature that a quantum computer can’t forge, and the key rotates on every transfer. Recipients are just Solana addresses.

No wallet needed to look around: Launch App opens the live layer on mainnet.

Phantom not detected — install it →

One permanent vault

Your vault address is derived from your first key's hash and never changes. Share it once and receive into it forever.

Keys rotate on every spend

Each transfer is authorised by a one-time Winternitz signature that also commits to the next key. Old signatures stop working instantly.

Send to any Solana address

Recipients with a vault receive vault-to-vault, so the SOL stays quantum-protected. Any other address receives native SOL.

quantum_safety.scope → Funds held in your Winternitz vault can only move with a one-time hash-based signature. Shor’s algorithm has no public key to attack. Research-grade: the program is upgradeable, the server holds the encrypted one-time keys, and the Phantom fee payer is still Ed25519. Real mainnet SOL.

// how it works

One vault. One-time keys. Every transfer rotates.

Each transfer runs in three steps, and you approve all of them once in Phantom. First we make sure the destination exists. Then the vault checks a Winternitz signature and moves the SOL. Finally the SOL is delivered as native SOL if the recipient is a plain wallet.

Phantom

Pays fees

Your vault

Wrapped SOL, PDA

WOTS spend

816-byte signature

Recipient vault

or native wallet

nonce n → sign(keccak(“WNTR:XFER” | vault | n | src | dst | amt | pkₙ₊₁))

verify: 34 chains walked, hash == pkₙ

rotate: pk ← pkₙ₊₁, nonce ← n+1

01

Open your vault

We generate a Winternitz key and derive a permanent vault address from its hash. Phantom pays a one-time rent of under 0.003 SOL to create it on mainnet.

02

Receive into it

Anyone can pay you through your link or QR code. The SOL is wrapped into the vault's token account, and only a Winternitz signature can ever move it.

03

Sign once

To send, a one-time signature covers the nonce, source, destination, amount and the hash of the next key. Change any byte and the program rejects it.

04

Key rotates in place

The vault swaps to the next key in the same instruction. Your address never changes, and every old signature stops working for good.

05

Deliver

Send to another vault and the SOL stays quantum-protected. Send to a plain wallet and it is unwrapped and delivered as native SOL.

// why this matters

Post-quantum security, without waiting for the base layer.

The quantum threat

Shor's algorithm recovers an Ed25519 private key from its public key, and every Solana wallet reveals its public key the first time it signs. So data harvested today can be cracked later.

Hash-based, not curve-based

Winternitz signatures rely only on Keccak-256 preimage resistance. The 24-byte chains give about 192-bit classical and 96-bit quantum security, and Grover's algorithm only halves the exponent.

Checksum-hardened WOTS

There are 32 message chains plus 2 checksum chains. Raising any message byte lowers the checksum, so a forger would have to walk a hash chain backwards, which can't be done.

The address is a commitment

The vault PDA is ["vault", first_pk_hash]. The address you share is a cryptographic commitment to the key that opened it.

Everything is in the digest

Nonce, source, destination, amount and next key are all hashed before signing. A signature authorises exactly one transfer of exactly one shape.

Honest scope

The vault program is open source and live on mainnet, and it is upgradeable. Your one-time keys are held encrypted on our server. The fee payer, Phantom, still uses Ed25519. This is research-grade software.

Program details, byte layouts, test vectors and threat model.