ARKUM
DocsCreate vault
How it works

Inside the vault.

Plain-language notes on the threat, the signature scheme and exactly what the arkum program checks.

The threat

Every Solana wallet is an ed25519 key pair. Its security rests on elliptic-curve math that ordinary computers can't solve. A large, error-corrected quantum computer running Shor's algorithm could. It would work out a private key from the public key, and every public key on Solana is already on-chain.

Nobody knows when such a machine will exist. The day it does is usually called Q-Day. Funds that move only with an ed25519 signature are exposed from that day on.

Why hashes

A hash function like SHA-256 turns any input into a fixed fingerprint that can't be run backwards. The best known quantum attack on hashes, Grover's algorithm, only gives a square-root speedup. Signatures built only from hashes have been studied for decades and are part of the post-quantum standards (SPHINCS+ / SLH-DSA).

Winternitz chains

An arkum key is 30 secret values. Each one is hashed 255 times to form a chain. The ends of all 30 chains are hashed together into one 32-byte root.

secret→ H →1→ H →2→ … →255⟶× 30 chains→ H →root

To sign, you hash the message and read its first 28 bytes as 28 numbers from 0 to 255. For each one you reveal that chain at that step. A verifier hashes each revealed value the remaining steps and checks the result folds into the root. Two extra checksum chains stop anyone from pushing chains further to forge a different message. Try it in the key lab.

What a vault is

A vault is an address derived from the root by the arkum program (a program-derived address). It holds SOL like any account, but no private key exists for it. The only thing that can move its SOL is the arkum program, and the program only does that when shown a valid hash signature for that exact root.

How a vault opens

  1. You choose an amount and a destination. Your browser picks your next fresh vault for whatever is left.
  2. Your browser signs (vault, destination, next vault, amount) with the vault's one-time key. 840 bytes.
  3. The arkum program walks every chain to the end on-chain, hashes the ends into a root and rebuilds the vault address. If it doesn't match, nothing moves.
  4. If it matches, the amount goes to the destination and everything else moves to your next vault. The old vault is left empty and its key is never used again.

The wallet that sends the transaction only pays the network fee. It has no power over the vault: change the amount or destination and the signature no longer matches.

Your secret

One 32-byte secret makes all your keys: vault #0, #1, #2 and so on, each with its own one-time key. Back it up once. My vaults finds your vaults again from the secret alone, on any device.

Trade-offs

  • Bigger signatures: 840 bytes instead of 64, and the program does thousands of hashes, so an unlock uses more compute than a normal transfer. The fee is still a fraction of a cent.
  • You hold the secret: lose it and the vault stays closed. There is no recovery.
  • The rest of Solana: a vault protects what's inside it. Your normal wallet still signs with ed25519.
  • Unaudited: the program hasn't been independently audited yet. Start small.