Send and receive SOL through Winternitz vaults. Your funds sit behind a one-time, hash-based signature that a quantum computer can’t forge, and the key rotates on every transfer. Recipients are just Solana addresses.
No wallet needed to look around: Launch App opens the live layer on mainnet.
Phantom not detected — install it →Your vault address is derived from your first key's hash and never changes. Share it once and receive into it forever.
Each transfer is authorised by a one-time Winternitz signature that also commits to the next key. Old signatures stop working instantly.
Recipients with a vault receive vault-to-vault, so the SOL stays quantum-protected. Any other address receives native SOL.
// how it works
Each transfer runs in three steps, and you approve all of them once in Phantom. First we make sure the destination exists. Then the vault checks a Winternitz signature and moves the SOL. Finally the SOL is delivered as native SOL if the recipient is a plain wallet.
Phantom
Pays fees
Your vault
Wrapped SOL, PDA
WOTS spend
816-byte signature
Recipient vault
or native wallet
nonce n → sign(keccak(“WNTR:XFER” | vault | n | src | dst | amt | pkₙ₊₁))
verify: 34 chains walked, hash == pkₙ
rotate: pk ← pkₙ₊₁, nonce ← n+1
We generate a Winternitz key and derive a permanent vault address from its hash. Phantom pays a one-time rent of under 0.003 SOL to create it on mainnet.
Anyone can pay you through your link or QR code. The SOL is wrapped into the vault's token account, and only a Winternitz signature can ever move it.
To send, a one-time signature covers the nonce, source, destination, amount and the hash of the next key. Change any byte and the program rejects it.
The vault swaps to the next key in the same instruction. Your address never changes, and every old signature stops working for good.
Send to another vault and the SOL stays quantum-protected. Send to a plain wallet and it is unwrapped and delivered as native SOL.
// why this matters
Shor's algorithm recovers an Ed25519 private key from its public key, and every Solana wallet reveals its public key the first time it signs. So data harvested today can be cracked later.
Winternitz signatures rely only on Keccak-256 preimage resistance. The 24-byte chains give about 192-bit classical and 96-bit quantum security, and Grover's algorithm only halves the exponent.
There are 32 message chains plus 2 checksum chains. Raising any message byte lowers the checksum, so a forger would have to walk a hash chain backwards, which can't be done.
The vault PDA is ["vault", first_pk_hash]. The address you share is a cryptographic commitment to the key that opened it.
Nonce, source, destination, amount and next key are all hashed before signing. A signature authorises exactly one transfer of exactly one shape.
The vault program is open source and live on mainnet, and it is upgradeable. Your one-time keys are held encrypted on our server. The fee payer, Phantom, still uses Ed25519. This is research-grade software.