Seal
Your vault key grows 30 secrets. Each one is hashed 255 times. The ends fold into one root, and the root becomes the vault's address. No private key exists for it.
Sign
To move funds you reveal one point on each chain. Where each point sits is decided by the message itself: the amount, the recipient and the vault the rest rolls into.
Verify
The program walks every chain the rest of the way, on chain. Around 4,000 SHA256 steps. If they land on the root, it opens. If a single byte is off, it stays shut.
Reborn
A key opens its vault once, then it retires. Whatever you did not send is reborn in a fresh vault under a brand new key, in the same transaction. The jellyfish trick, on chain.
It never dies.It starts over.
Turritopsis dohrnii is the jellyfish that cheats death: hurt it and it turns back into a polyp and grows up again. Your vaults work the same way. They hold SOL, USDC or any token behind SHA256 hash chains instead of the ed25519 key a quantum computer is coming for, and every spend retires the key and rebirths what is left under a brand new one.
Your address is your public key.It has been since day one.
On Solana the address you hand out is the public key itself. Today that is fine. Shor's algorithm, run on a large enough quantum computer, turns a public key back into the private key. Researchers put the bill for a 256 bit curve at roughly 2,330 logical qubits. AI is speeding up the labs building them. Nobody can tell you the date. Everyone agrees on the direction.
Harvest now, drain later: an attacker does not need the machine today. Every public key that ever touched the chain is already sitting in the ledger, waiting.
It ages backwards.So does every vault.
One jellyfish has found a way around death. Scroll through its life and watch what your funds do at each stage.
- 01 · medusa
Alive, drifting
An adult jellyfish, a few millimetres across, pulsing through open water.
vault Your SOL or tokens sit behind 30 hash chains. No private key exists for a quantum computer to recover.
- 02 · cyst
It pulls everything in
Hurt, starved or old, it stops swimming and collapses into a ball of cells.
vault You spend. The one time key signs your exact amount and recipient, once, and is spent for good.
- 03 · polyp
It goes back to the start
The ball settles on the sea floor and grows into a polyp, the stage every jellyfish begins as.
vault The program walks every chain on chain, around 4,000 SHA256 steps. One wrong byte and it stays shut.
- 04 · medusa again
Reborn
New jellyfish bud off the polyp. Same animal, a brand new life. It can do this again and again.
vault The recipient is paid and whatever you kept is reborn in a fresh vault under a brand new key.
Thirty chains.One life per key.
Every other wallet ages.This one starts over.
Who is exposed.Who is reborn.
QuestionsStraight answers.
Is my money quantum safe in a vault?
The vault itself is. It is an address with no private key, and the only thing that opens it is a Winternitz signature built from SHA256 hash chains. The best known quantum attack on that only halves the bits, which leaves about 112 bits of security. Anything still sitting in a normal wallet is not covered.
What about the wallet I connect?
Your connected wallet pays network fees and sends funds in. It never controls a vault. If its key were broken tomorrow, it could not move a single lamport out of one.
Why does a vault only open once?
Winternitz keys are one time keys. Signing two different messages with the same one leaks enough to forge a third. So every spend retires the key and moves what is left to a fresh vault under the next key in the same transaction. You never see the difference, you just see a new vault.
What if I lose my 24 words?
Then nobody can open your vaults, including us. The words are made in your browser and never reach a server. Write them down offline. You can keep them on one device under a lock code and restore every vault on any device from the words alone.
What does it cost?
Network fees only. A spend briefly rents a small staging account and hands the rent back when it closes. Token spends may open token accounts for the recipient and the next vault, which costs the usual Solana rent.
Which tokens can I seal?
SOL and any SPL or Token 2022 token. Each vault holds one asset, so a wallet with five tokens worth protecting gets five vaults, all from the same 24 words.
When is Q day?
Nobody knows. Estimates for a machine that breaks a 256 bit curve keep moving closer, and every public key that ever touched the chain is already recorded. Sealing costs a network fee and unsealing is one click, so there is little reason to wait for a date.
Hedge against Q day.It costs a network fee.
Nobody knows the day a machine breaks ed25519. Everyone exposed on that day finds out together. Seal what you cannot afford to lose now and unlock it in one click whenever you want.
Q DAY scannerWhat a quantum computer would see.
Your bunkerVaults only hash chains can open.
The boardExposed on one side. Sealed on the other.
How it worksNo magic. Just hashing.
The problem
Every normal Solana wallet is an ed25519 key. Its safety rests on one assumption: that nobody can work backwards from a public key to a private key. Shor's algorithm breaks that assumption on a large enough quantum computer. On Solana your address is your public key, so every wallet is already showing the thing an attacker would need.
The vault
A TURRITOPSIS vault is an address the program owns, derived from the root of a Winternitz one time key. Winternitz signatures are made of hash chains. Breaking one means reversing SHA256, and the best known quantum attack on that (Grover) only halves the bits, which leaves about 112 bits of security on the 224 bit digests used here.
Moving funds
You choose an amount and a recipient. Your browser signs that exact message with the vault's chains, and two transactions go out together: one stages the first half of the signature, the next carries the second half, verifies all 30 chains on chain, pays the recipient and moves everything left into a fresh vault under the next key. One approval in your wallet covers both.
Your vault key
24 words make every vault key you will ever use. They are generated in your browser and never leave it. Lose them and the vaults cannot be opened by anyone, including us. You can keep them on this device under a lock code, and you can restore every vault on any device from the words alone.
What it costs
Network fees only. A spend briefly rents a small staging account and hands the rent back when it closes. Token spends may create token accounts for the recipient and the next vault, which costs the usual Solana rent.
Why a jellyfish
Turritopsis dohrnii is a jellyfish about the size of a fingernail clipping. When it is starved, hurt or old, it does not die. Its cells reorganise, it sinks back into a polyp, and it grows into a young jellyfish again. A one time key works like that: it is used once, then everything it held carries on under a new one. Nothing ever reuses a key, so nothing ever gets old enough to attack.
Honest notes
Your connected wallet still pays fees with a normal signature. That key never controls the vault: a broken fee key cannot move a single lamport out of it. Each vault holds one asset. The program is open source; read it before you trust it.