explainer · updated 9 Oct 2026
pqc.market does not survive Q-day. Here's why, and what does.
pqc.market says you can "launch coins that survive Q-day". Its hash-based signatures are fine, and it now has a real on-chain vault. Where it falls short is where the vault's keys come from, who can rewrite the vault, and everything that still sits outside it. Below is what a quantum attacker gets, where pqc.market breaks, what it gets right, and how winterpad differs.
A vault keyed from your wallet
Launches, coins, creator fees and the "pqc wallets" are controlled by ed25519 keys. Their quantum vault does check a hash-based signature on-chain, but its keys are derived from a wallet signature (plus an optional passphrase), and one ed25519 key can rewrite the vault program.
A vault the chain enforces
Value sits in program-owned accounts that have no private key at all. The program releases it only for a hash-based signature that it verifies on-chain. The hash keys come from a random seed and never from a wallet.
What a quantum attacker actually gets
Shor's algorithm recovers an elliptic-curve private key from its public key. On Solana the public key is the address, published from the day the account exists. Unlike a never-spent Bitcoin address, there is no hash in front of it. So "Q-day" for a Solana user means the attacker can sign anything that key could sign: transfers, token approvals, authority changes, and messages to websites.
SHA-256 is different. The best known quantum attack (Grover) only square-roots the work. A second preimage still costs about 2128, so hash-based signatures hold. The question is never whether WOTS is secure. It is what a WOTS signature actually controls.
Where pqc.market breaks
- 01The vault's keys come from your wallet. Their docs: vault seeds are HKDF of the identity seeds, and the identity is derived from a fixed message your wallet signs. ed25519 signatures are deterministic, so anyone who recovers the wallet key produces the same bytes and re-derives every vault key. Their docs say it plainly: a post-quantum attacker who recovers a wallet-only identity's wallet key "could also derive the vault keys".
wallet public key --Shor--> wallet private key wallet private key --sign(fixed msg)--> same 64 bytes as yours same 64 bytes --HKDF--> identity seeds --HKDF--> vault keys --> vault drained
- 02The passphrase fix can be guessed offline. A vault's address is derived from the hash of its one-time public key, and it is public on-chain. An attacker holding your wallet key tries passphrases on their own machines (one scrypt at N=215 per guess) until a derived vault address matches one of yours. Security becomes "however strong your passphrase is", not 2128.
- 03One ed25519 key can rewrite the vault. Their vault program (
DNsPfPec…cg9F) is upgradeable. Its upgrade authority, read on-chain on 9 Oct 2026, isESobDnh3…fMJi, an ordinary ed25519 key. After Q-day, whoever forges it can replace the program and empty every vault at once, whatever keys or passphrases users chose. - 04The vault can't trade. It holds and withdraws. To buy or sell on pump.fun, value has to go back to an ed25519 wallet, where Shor can take it.
- 05Everything outside the vault is ed25519. Coins sit in normal wallets, every coin's creator fees go to the platform's treasury wallet, and the "dual-signed" pqc wallets are ed25519 keypairs. Their docs say the post-quantum half "does not stop a forged transfer from executing".
- 06Identity keys are policed by a database. One-time use of identity leaves (launch attestations, logins) is enforced by their server's leaf ledger. A compromised server can allow reuse. Vault keys are different: see below.
What they got right: their vault has no ed25519 spend path, verifies WOTS on-chain, and enforces one-time use on-chain (each spend retires the vault address and moves the rest to a fresh one). Launch attestations are verifiable from IPFS with SHA-256 alone. That's real progress. The gaps are the key derivation, the upgradeable program, and the value that never enters the vault.
How winterpad does it
The design rule: no ed25519 key may ever be able to move value. Solana still needs an ed25519 fee payer for every transaction. That's unavoidable, so winterpad makes the fee payer worthless to an attacker.
| Thing | pqc.market | After Q-day | winterpad | After Q-day |
|---|---|---|---|---|
| SOL and coins in the vault | Vault PDA, WOTS verified on-chain | keys re-derived from the wallet (or passphrase guessed) | The vault's purse (a PDA: no private key), WOTS+Merkle verified on-chain | safe |
| Vault key seed | derived from a wallet signature (+ optional passphrase) | re-derived / guessable | 32 random bytes + recovery code | unknown to attacker |
| Who can rewrite the vault program | one ed25519 upgrade key | forged, every vault drained | none: the upgrade key was removed on 9 Oct 2026 (--final) | no key exists |
| One-time key rule | vault: on-chain; identity: server database | vault ok; identity: server's word | on-chain: leaf must exceed the last one used | enforced |
| Trading on pump.fun | from an ed25519 wallet only | wallet drained | From the vault: only a keyless "trade" PDA holding that one trade ever signs for pump.fun | one trade at most |
| Creator fees | platform treasury wallet | stolen | pump.fun creator = your purse; claimed by permissionless sweeps | safe |
| Coins outside a vault | ed25519 wallet | stolen | ed25519 wallet (deposit them to protect them) | stolen |
| Fee payer key | is the wallet | drains all | Pays fees only; can't change any signed field | loses gas money |
How a vault spends
withdraw 3 SOL to X, valid until T, and hashes it together with the program id and the vault address.Rules the chain enforces: a vault's leaves must strictly increase, so a signature that never landed dies when a later one lands. The last leaf of every tree can only sign a rotation to a new tree, so a vault can never run out of keys. Every signature names its expiry and its exact accounts. A signature for one vault, action, amount, recipient or tree can't be reused for any other.
Your coins can stay on pump.fun
Deposit is a plain transfer to your vault's purse, for SOL or any coin. From the vault you can buy and sell on pump.fun's curve, trade on PumpSwap after the coin graduates, or launch a pump.fun coin whose creator fees flow into the vault. pump.fun never gets the purse's signature. Each trade goes through a separate keyless trade account that holds only that trade and is emptied back into the vault in the same instruction. Afterwards winterpad checks that the minimum you signed for actually arrived.
pump.fun's four programs can be upgraded by one ed25519 key. We tested a hostile replacement: with a slippage bound the trade reverts and nothing is lost; with no bound it can take that one trade, never the rest of the vault. What no vault can protect is the liquidity inside pump.fun's own curve or pool.
The test that matters
The suite simulates Q-day literally. The attacker is handed a copy of the victim's wallet keypair, which is exactly what Shor gives them. The victim's wallet is also the fee payer and the buffer writer.
BadSignature.BadSignature every time. Submitted unchanged, it only does what the victim signed.LeafUsed. Replaying a landed one: LeafUsed.BadSignature.36 Rust tests in LiteSVM, run against the REAL mainnet pump.fun, PumpSwap and pump fees programs (read-only copies), plus 840 JS checks. Signatures from the JS signer, an independent Rust signer and the on-chain verifier are byte-identical. A signed action costs about 100k–240k compute units.
The control experiment rebuilds pqc.market's design inside the same program: a vault whose hash keys come from a wallet signature. The attacker re-derives the keys and drains it. The same attacker, against a vault seeded from a random number generator, gets BadSignature.
Honest limits
- Locked for good. winterpad's mainnet program (
CepWbpci…kxa1) has no upgrade key since 9 Oct 2026. Nobody can change it, including us. That also means bugs can't be patched: a fix would be a new program, and moving to it would be your choice. - Solana itself. Validator vote and identity keys are ed25519. An attacker able to forge a supermajority of stake could attack consensus. No app can fix that; it needs a protocol migration. winterpad removes the per-user target, which is the cheap one.
- Value outside a vault is unprotected. SOL is exposed until it's deposited, and coins sent to an ordinary wallet are exposed again.
- Liquidity inside pump.fun isn't yours to protect. After Q-day, pump.fun's upgrade key could be forged and its curves and pools drained. Your coins stay in your vault, but there may be nothing to sell them into.
- Issuer keys. A Token-2022 coin with a permanent delegate or freeze authority can still be moved or frozen by its issuer, in any account, a vault included. pump.fun coins have neither.
- Signatures are public before they execute. They sit in the buffer for a few seconds. That's harmless for withdrawals, since everything is bound. For buys and sells the slippage limit is the defence against front-running.
- Not done yet: an external audit, and Metaplex metadata for coins on winterpad's own curve.
- Back up your recovery code. It is the only key to your vault. There is no reset and no backdoor, by design: a vault anyone could recover for you is a vault an attacker could too. The app won't let a vault take funds until you've proved you saved it.
- Client discipline. Never sign two different messages with one leaf. The client journals each leaf before broadcasting, and after restoring from the recovery code it skips ahead past the last leaf used on-chain.