ARKUM
DocsCreate vault
A post-quantum vault for Solana

Lock your SOL behind hashes.

arkum is a vault for Solana where withdrawals are authorized by hash-based signatures instead of the elliptic-curve keys every wallet uses today. Hash functions are expected to hold up when quantum computers arrive. Today's wallet signatures are not.

ARKUM CONSOLERUNNING IN YOUR BROWSER
Vault vault door

    
WOTSWinternitz one-time signatures, checked on-chain
SHA-256the only assumption: hashes are hard to reverse
1 KEY = 1 USEevery withdrawal rotates to a fresh key
…checking network
How a vault works

Four steps. No curves.

A vault only ever stores a hash. To open it you prove you know what that hash came from.

01

Generate

Your browser creates one secret. From it, each vault gets a one-time key: 30 hash chains, 255 steps each, folded into one 32-byte root. The secret never leaves your device.

02

Seal

The vault address is derived from that root. You send SOL to it like any address. No public key sits on-chain for a quantum computer to attack.

03

Unlock

To withdraw, you sign the exact amount and destination with the one-time key. The arkum program re-hashes the signature on-chain and checks it rebuilds the vault.

04

Rotate

Whatever you don't withdraw moves straight into your next vault, with a fresh key. A used key never guards money again.

Why it matters

Wallet vs Arkum

Every Solana wallet signs with ed25519. A large enough quantum computer running Shor's algorithm could recover a private key from its public key. Hash-based signatures don't have that weakness.

Normal wallet (ed25519)Arkum (hash-based)
Security rests onElliptic curve mathHash functions only
Quantum computersBroken by Shor's algorithmOnly a square-root speedup (Grover)
Public key on-chainVisible foreverOnly a hash, until the one unlock
Key reuseSame key for lifeOne key per withdrawal, then rotate
Signature size64 bytes840 bytes (the price of safety)
Roadmap

Where we are

PHASE 0Build

The arkum program, the app and the in-browser key lab.

PHASE 1Devnet

Open vaults with test SOL. Break it, report it.

PHASE 2Audit

Independent review of the program and the signing code.

PHASE 3Mainnet

Real SOL behind hash keys.

Key lab

Sign with hashes

Make a one-time key, sign a message and verify it, all in your browser.

OPEN →
Docs

How it works

The threat, Winternitz chains and how a arkum unlocks.

READ →
Risks

Read first

New, unaudited software. Your secret is the only way in.

READ →