The first quantum-resistant primitive on Solana
Dean Little publishes the Winternitz vault, a program that holds SOL behind a hash-based one-time signature. It needs no protocol change. Source on GitHub.
QuantumPepe is an ordinary memecoin launched on pump.fun. What is new is where it can live. Holders can move their tokens into a vault on Solana whose only key is a hash-based one-time signature. There is no elliptic-curve key for a quantum computer to break.
The vault program is open source and lives at . Deposits are plain token transfers. Withdrawals are verified on chain by walking Keccak-256 hash chains, not by checking a curve signature.
Every Solana wallet is an Ed25519 key pair. The public key is the address, and it is visible to everyone. Ownership of a token is nothing more than the ability to produce an Ed25519 signature for that address. Shor's algorithm, run on a large enough quantum computer, computes the private key from the public key. That breaks Ed25519, and with it every token account on the chain.
Solana itself is working on this. Anza has published its plan for a post-quantum transition, and a proposal to add a Falcon signature syscall was opened in 2026 and then paused until there is more demand. In the meantime the network, the validators and every wallet still sign with Ed25519. The only working post-quantum primitive on Solana today is a hash-based vault, and until now it held SOL, not tokens.
QuantumPepe takes that primitive and applies it to a memecoin. The token itself is normal, so it trades everywhere. The vault is what makes it different.
| Token in a normal wallet | Token in a QuantumPepe vault | |
|---|---|---|
| What proves ownership | An Ed25519 signature from the wallet's private key | A Winternitz one-time signature: 34 chains of Keccak-256 hashes |
| What is public | The public key, on chain, forever | Only a hash of the public key. The key itself is revealed once, at the moment it is spent |
| What a quantum computer would need | Run Shor's algorithm on the public key | Invert a 176-bit hash. Grover's algorithm gives only a square-root speedup, so this stays out of reach |
| Who can move the tokens on Q-day | Whoever computes the key first | Only the holder of the one-time secret |
| How you deposit | Any token transfer to the vault's associated token account. No special wallet needed | |
A vault is a program-derived address. Its only seed is the hash of a Winternitz public key, which is 34 values that each sit at the top of a chain of 256 Keccak-256 hashes. The private key is the 34 starting points of those chains. Tokens sent to the vault's associated token account are held by the program, and nothing else on the chain can sign for that address.
To withdraw, the holder hashes the message that describes the withdrawal: the amount, the destination account, the account that receives the remainder and the account that receives the closed vault's rent. Each byte of that digest tells the program how far up a chain to climb. The signature reveals the chain elements at the matching heights, the program climbs the rest of the way, hashes the 34 tops together and checks that the result is the vault's own seed. Two extra chains carry a checksum, so no one can take a real signature and climb further to forge a different message.
A Winternitz key is used once. Spending it reveals part of the private key, so the program closes the vault in the same transaction and the remainder moves to a fresh vault with a fresh key. The animation below runs the real algorithm on a random message.
Q-day is the day a quantum computer breaks elliptic-curve cryptography at practical cost. Nobody knows the date. What is known is the shape of that day on Solana: every public key on the chain becomes a private key for whoever runs the machine, and tokens in ordinary wallets belong to the fastest attacker. Exchanges, market makers and holders all sign with the same broken curve.
Tokens in QuantumPepe vaults do not move, because a vault is not a key. It is a hash. The chain was already the most valuable thing a quantum computer could attack, and on that day the only coins that stay where their owners put them are the ones that never depended on the curve. That is the position QuantumPepe holders are in before anyone else on Solana.
Dean Little publishes the Winternitz vault, a program that holds SOL behind a hash-based one-time signature. It needs no protocol change. Source on GitHub.
A post-quantum transaction prototype runs on a Solana testnet. It is a prototype, and mainnet still signs everything with Ed25519.
Anza describes how Solana can migrate signatures. A proposal to add Falcon-512 verification to the protocol, SIMD-0461, is closed in June 2026 to wait for demand. Anza's post. The proposal.
The QuantumPepe vault program extends the hash-based design from SOL to any SPL token, with a checksum against forgery and support for Token-2022. Holders can move in and out with a normal wallet paying the fees.

Your quantum key is a 32-byte secret that never leaves this browser. Every vault you open is derived from it, so one backup covers all of them. A normal wallet only pays transaction fees. It never controls the tokens.
Withdrawing takes two transactions: the first creates the receiving accounts, the second carries the hash-based signature. After a withdrawal the spent vault is closed and any remainder sits in the next vault, under a fresh key.
The backup is the secret in base58. Anyone with it controls every vault derived from it. Store it offline. The site keeps a copy in this browser's local storage only.
Phantom signs the fee and the deposit. It is an Ed25519 key, so it is not quantum-safe, and it does not need to be: it never holds the vaulted tokens.
A throwaway Ed25519 key kept in this browser. Send it a little SOL for fees. On mainnet you also need the tokens in this key's account to deposit from it.
Create or import a quantum key to see your vaults.
Sends tokens from the fee payer's token account to the selected vault. Anyone can deposit into a vault address; it is just a transfer.
The remainder of the selected vault moves to the next unused vault. Two transactions: prepare accounts, then the hash-based signature.
The numbers below are read from the chain when this page loads, through public RPC endpoints, and nothing here is cached or typed in by hand. A vault is only as safe as the program that guards it, so the program must be immutable: an upgrade authority that is a normal key would be a quantum key. Check that the upgrade authority reads "none".