Seal
Your bunker key grows 30 secrets. Each one is hashed 255 times. The ends fold into one root, and the root becomes the vault's address. No private key exists for it.
Sign
To move funds you reveal one point on each chain. Where each point sits is decided by the message itself: the amount, the recipient and the vault the rest rolls into.
Verify
The program walks every chain the rest of the way, on chain. Around 4,000 SHA256 steps. If they land on the root, it opens. If a single byte is off, it stays shut.
Roll
A key opens its vault once. Whatever you did not send moves to a fresh vault under a brand new key, in the same breath.
Seal it.Nothing gets in.
A hedge for your SOL and tokens against Q day. If a quantum computer, or an AI that finds a faster attack, ever cracks the curve behind Solana wallets, every exposed balance can be drained at once. A TARDIGRADE vault never touches that curve. It opens with SHA256 hash chains and nothing else.
Your address is your public key.It has been since day one.
On Solana the address you hand out is the public key itself. Today that is fine. Shor's algorithm, run on a large enough quantum computer, turns a public key back into the private key. Researchers put the bill for a 256 bit curve at roughly 2,330 logical qubits. AI is speeding up the labs building them. Nobody can tell you the date. Everyone agrees on the direction.
Harvest now, drain later: an attacker does not need the machine today. Every public key that ever touched the chain is already sitting in the ledger, waiting.
Thirty locks.Zero curves.
Built for the machinesthat are coming for your keys.
Who is exposed.Who is sealed.
Hedge against Q day.It costs a network fee.
Nobody knows the day a machine breaks ed25519. Everyone exposed on that day finds out together. Seal what you cannot afford to lose now and unlock it in one click whenever you want.
Q DAY scannerWhat a quantum computer would see.
Your bunkerVaults only hash chains can open.
The boardExposed on one side. Sealed on the other.
How it worksNo magic. Just hashing.
The problem
Every normal Solana wallet is an ed25519 key. Its safety rests on one assumption: that nobody can work backwards from a public key to a private key. Shor's algorithm breaks that assumption on a large enough quantum computer. On Solana your address is your public key, so every wallet is already showing the thing an attacker would need.
The vault
A TARDIGRADE vault is an address the program owns, derived from the root of a Winternitz one time key. Winternitz signatures are made of hash chains. Breaking one means reversing SHA256, and the best known quantum attack on that (Grover) only halves the bits, which leaves about 112 bits of security on the 224 bit digests used here.
Moving funds
You choose an amount and a recipient. Your browser signs that exact message with the vault's chains, and two transactions go out together: one stages the first half of the signature, the next carries the second half, verifies all 30 chains on chain, pays the recipient and moves everything left into a fresh vault under the next key. One approval in your wallet covers both.
Your bunker key
24 words make every vault key you will ever use. They are generated in your browser and never leave it. Lose them and the vaults cannot be opened by anyone, including us. You can keep them on this device under a lock code, and you can restore every vault on any device from the words alone.
What it costs
Network fees, plus rent for a permanent one-byte spent marker after each successful spend. The temporary staging account rent is returned when it closes. Token spends may also create recipient and next-vault token accounts, which require the usual Solana rent.
Security status
The vault source has had an internal static code review, not a formal third-party audit. Mainnet vault actions through this site remain disabled until an independent audit is complete and the deployed program is verified immutable. Direct SOL or token transfers bypass the site gate and may be unrecoverable.
Honest notes
Your connected wallet still pays fees with a normal signature. That key never controls the vault: a broken fee key cannot move a single lamport out of it. Each vault holds one asset. The program is open source; read it before you trust it.
Terminal
Live scans and vault activity, with direct command access.