Vaults that
survive Q-day
Quantum-safe custody for Solana coins. Hash-based signatures, checked on-chain. Still trades on pump.fun.
Launch appExperience with headphones
Threat model
Q-day
Shor's algorithm turns a public key into a private key. On Solana every address is a public key. Every wallet, every signature, every admin key: forgeable on the same day.
pqc.market
A receipt
is not a vault
pqc.market signs your launches with hash-based keys and calls the coins Q-day proof. The signatures are fine. What they protect is nothing that holds value.
FLAW 01
Keys from your wallet
Its "post-quantum" keys are derived from an ed25519 wallet signature. Break the wallet and you rebuild every hash key.
FLAW 02
The chain never checks
Solana only verifies ed25519. Forge it and the coins move; the hash signature in a memo changes nothing. Their docs say so.
FLAW 03
Keys hold the money
Coins sit in ed25519 wallets, fees go to an ed25519 treasury, one-time keys are policed by their database.
The vault
No private
key
Your SOL and coins live in a program-derived address. No key exists for it. Funds move only with a WOTS + Merkle signature (SHA-256 only) that the program verifies on-chain. Keys come from 32 random bytes, never from a wallet.
VAULT
Tree root
1,024 one-time keys · strictly increasing · rotate at the last
PURSE
Holds everything
your SOL + every token account · deposit address · keyless
TRADE
One trade at a time
the only signer pump.fun ever sees · emptied in the same instruction
Markets
Still on
pump.fun
Deposit any coin. Buy and sell on the pump.fun curve, trade on PumpSwap after graduation, or launch a pump.fun coin whose creator fees flow into your vault. A hostile pump.fun upgrade can take one trade at most, and with a slippage bound it takes nothing.
Q-day, simulated
Nothing
moves
The attacker gets every ed25519 key you have: wallet, fee payer, buffer writer. Then they try everything. Tested against read-only copies of the real pump.fun programs.
36Rust tests vs the real pump.fun binaries
32security checks deleted one by one, every one caught
0SOL lost to hostile pump.fun with a slippage bound
2¹²⁸quantum work to forge a signature (Grover on SHA-256)
Preview
Create your
vault
Demo only. A vault exists once you create it in the launchpad: never send funds to these addresses before that.
Generate 32 random bytes in this browser and build 1,024 one-time keys (about a second). Nothing leaves this page.
—
—
—
—