Quantum vault
Keep SOL and tokens where a quantum computer, or a broken elliptic curve, cannot reach them: behind hash-only signatures that come from your 12 words.
Connect a wallet to start
Any Solana wallet works (Phantom, Solflare, Backpack…). It only signs what you approve; its keys never leave it, and Sotto never holds your funds.
- 1
Connect
Pick your wallet below.
- 2
Unlock
Create or open your 12-word zip key, kept encrypted on this device.
- 3
Go
Zip, unzip, speak. Your wallet asks before anything moves.
This is the Devnet preview: set your wallet to Devnet too (Phantom: Settings, Developer settings, Testnet mode, Solana Devnet). On mainnet it shows no balance and warns about the transaction.
Quantum-resistant by construction, and how to check
- No elliptic curve guards the vault. Only a hash-based signature can move what it holds: Winternitz (WOTS) over Keccak-256 with a checksum and SPHINCS+-style tweaked hashes, 224-bit values. The best known quantum attack on a hash, Grover's search, still needs about 2112 steps.
- Keys from hashes only. Each vault's key comes from your 12 words through PBKDF2-SHA512 and HKDF-SHA256; nothing about it ever touches a curve.
- One key, one spend, enforced on-chain. A spent vault can never sign again; what is left moves to the next vault, and anything sent later to a spent one can only go on to its successor.
- Your wallet only pays the fees. Its key cannot move the vault's funds, so a broken wallet key costs at most its own SOL.
Check it yourself
solana-verify get-program-hash 7toWPxm835gpEZMi6A3QTdZwJBmqUWL4RjL4qgVxNgsF returns d7b8a1c4606d3679e757959c88e320833c2daf3e10b7b0142243eb0e163d6502, the hash of solana-verify build --library-name pq_vault run on the source this site publishes: the bytes on chain are that code, nothing else.
Tested: unit and property tests of the signature (two different messages' digit vectors are never comparable, so no signature can be turned into another), integration tests with forgery attempts, a stateful fuzzer, and end-to-end runs on devnet. The browser signer is checked byte for byte against the program's.
We say quantum-resistant, not quantum-proof: no one can prove a hash will never fall, and two pieces still rest on elliptic curves until they are retired, the program's upgrade key (below) and Solana's own transaction signatures, which Solana is planning to replace.