SOLANA MAINNETSLOT ...SIG WOTS-KECCAK · n=192 · w=256VAULT PROGRAM Shor…fuHZ
LIVE ON SOLANAHASH-BASED SIGNATURES

Post-quantum custody for every launch.

Creator fees settle into Winternitz vaults on Solana. No Ed25519 key can move them, so Shor's algorithm has nothing to break.

34 CHAINS · COMPUTED IN THIS BROWSER
Live signature
-
Message
-
Digest
-
Verifier work
-
Result
-

Launch registry

Every listed coin pays its creator fees into a Winternitz vault, verified on chain at launch.

Coins launched
0
PQ vaults opened
0
Fees under PQ custody
0.00 SOL
Graduated
0

The registry is empty.

Every coin listed here pays its creator fees into a Winternitz vault. Be the first.

Launch a coin

Verify it in your browser.

The trace on the right is not an animation of the idea. Your browser is deriving a one-time key, signing a withdrawal, and running the exact verifier the vault program runs on chain, every seven seconds.

Signature
816 B
Chains
32 + 2 checksum
Quantum security
2^96 (Grover)
On-chain cost
≈0.6M CU
Verifier traceLIVE
$ shorproof verify --key 0

What breaks on Q-Day, and what doesn't.

On Solana every address is a public key. Once a cryptographically relevant quantum computer exists, any Ed25519 key that has ever appeared on chain is recoverable. Hash functions only lose half their bits.

PrimitiveUsed forBest quantum attackAfter Q-Day
Ed25519Every Solana wallet and fee payerShor: private key from public key, polynomial timeBROKEN
WOTS chains, Keccak-256 at n=192Shorproof vault keysGrover preimage search: 2^192 → 2^9696-BIT
Keccak-256 digestSigned withdrawal messagesBHT collision search: 2^128 → ~2^85HOLDS
AES-256-GCMQuantum key sealed on deviceGrover key search: 2^256 → 2^128128-BIT

The custody path.

From the first trade to your wallet, a creator fee never sits under an Ed25519 key. Every step is a real instruction you can inspect on chain.

Typical launchpad

  • Fees paid to an Ed25519 wallet
  • Public key exposed forever
  • One broken key drains it

Shorproof

  • Fees paid to a keyless vault PDA
  • One-time keys, rotated per spend
  • Spending needs a hash-based signature
  1. 1
    create_v2pump.fun

    creator = your vault PDA, a program address with no private key

  2. 2
    tradepump.fun curve / PumpSwap

    every buy and sell accrues the creator fee for that address

  3. 3
    collect_creator_feekeeper or anyone

    permissionless; the only possible destination is the vault

  4. 4
    WithdrawSolShorproof program

    816-byte WOTS signature over amount, destination and next key

  5. 5
    rotateShorproof program

    nonce +1, next root installed; the used key can never sign again

On-chain verification.

Every vault open, verified withdrawal and fee collection, read straight from Solana.

Verification logprogram ShorAk…fuHZ

Generate your quantum key.

256 bits of entropy, encoded as 24 words, sealed with AES-256 in this browser. It never touches a server.

Open quantum vault