$BUNKER is now live.
CA: 2WNiZqRefcndEA9c1T6A1bdie31pbBGdFQpyR52h9TWr
the first post-quantum token launchpad, supporting 8 cryptographic signature options including WOTS/XMSS, SPHINCS+, ML-DSA, Falcon, and hybrid Ed25519 + ML-DSA.
every token launched carries a permanent cryptographic receipt containing its proof of origin, independently verifiable even if traditional elliptic-curve signatures are eventually broken.
connect your Solana wallet, derive a post-quantum identity, and choose how your token is cryptographically signed.
https://t.co/p72cx3IQZN
no, https://t.co/BNZnY1sfeZ has its own cryptographic implementation, with hardened post-quantum identities and independently verifiable proofs of origin.
every creator derives a unique cryptographic identity using hash-based Winternitz signatures and a 256-leaf Merkle tree. each token launch is signed and permanently linked to that identity, allowing anyone to verify its origin using SHA-256 without relying on our servers.
I'm also working on onchain PQC vaults that require post-quantum signature verification before SOL or tokens can move, rather than simply attaching proofs to transactions.
Morning everyone, got some rest and back at it.
so far, I've made a lot of progress on the onchain program for PQC wallets and vaults.
the main focus has been implementing hash-based post-quantum signatures and making sure the Solana program can independently verify them before authorizing transfers of SOL or tokens.
I probably have another hour or so of testing before pushing the update and making PQC wallets and vaults available to everyone.
as far as I'm aware, this will be one of the first implementations on Solana where post-quantum cryptography is actually used to control the movement of funds, rather than simply attaching cryptographic proofs to transactions.
this is a significant difference from the PQC wallets currently available that still rely on traditional Ed25519 signatures for security. the vaults will require post-quantum authorization directly onchain, adding protection against potential future quantum attacks.
have been working tirelessly to finish up PQC wallets for https://t.co/BNZnY1sfeZ.
essentially, these will be quantum-resistant wallets that use onchain vaults to hold SOL and tokens, with hash-based post-quantum signatures required to authorize withdrawals rather than relying solely on traditional Ed25519 wallet security.
the goal is to make it possible for anyone to create a wallet that uses post-quantum cryptography to protect their assets without requiring changes to Solana itself.
should be out in the next hour or so, assuming the remaining tests go as planned.
as far as token launches go, everything is already cryptographically verifiable using post-quantum signatures. every launch carries a permanent proof of origin that can be independently verified.
the wallets are the next step, extending post-quantum cryptography beyond token creation to the actual protection of funds.
Still here building.
adding more post-quantum signature algorithms to expand the cryptographic options available for token launches, with more hash-based and lattice-based implementations currently being tested.
the goal is to support as many cryptographic standards as possible, with every launch carrying a permanent, independently verifiable proof of origin.
"Bunker" day is coming, and we will be the ones best positioned to survive it.
the goal is to make https://t.co/BNZnY1sfeZ the most comprehensive post-quantum token launchpad on Solana.
supporting as many cryptographic signature algorithms as possible, from hash-based signatures like WOTS/XMSS and SPHINCS+ to lattice-based algorithms like ML-DSA and Falcon.
every launch should have a permanent, independently verifiable cryptographic proof of origin, regardless of which algorithm is used.
as AI continues to advance, I think having access to different cryptographic approaches is going to become increasingly important.
there's still a lot more to build, and I'm going to keep expanding what's possible.
hey @toly, built a post-quantum launchpad https://t.co/BNZnY1sfeZ. would love to hear your thoughts on it.
anyone can connect their existing wallet, derive a hash-based identity, and launch tokens using 8 different cryptographic signature algorithms, including WOTS/XMSS, SPHINCS+, ML-DSA, and Falcon.
every launch carries a permanent cryptographic proof of origin that remains independently verifiable even if elliptic-curve signatures are eventually broken.
the entire idea is to make post-quantum cryptography accessible to anyone on Solana.
https://t.co/p72cx3IQZN
every token launched on https://t.co/BNZnY1sfeZ carries something that most tokens don't: a cryptographic record of its creation that can be independently verified years from now.
each launch is signed using a post-quantum signature algorithm, with the proof permanently attached to the token's IPFS metadata.
this means that even if the cryptography securing today's Solana wallets is eventually broken, the original launch attestation can still be verified against its registered post-quantum identity.
the token can trade, change hands, and move through the market, but its cryptographic proof of origin remains independently verifiable.
https://t.co/tHRRdDZi7L
everything seems to be running smoothly again.
fingers crossed.
looks like the instability was related to network issues with Railway, the hosting provider.
appreciate everyone's patience.
okay, the site is continuing to crash.
looking into what's causing the instability now. still working through a few issues with the server.
sorry for the interruptions, I'll post another update once everything is stable again.
okay, the site is continuing to crash.
looking into what's causing the instability now. still working through a few issues with the server.
sorry for the interruptions, I'll post another update once everything is stable again.
please, please, please read this.
AI is advancing at an unprecedented pace, and the possibility of it discovering mathematical breakthroughs that compromise today's cryptography is becoming increasingly difficult to ignore.
this isn't about quantum computers arriving tomorrow. it's about the possibility that AI discovers weaknesses in cryptographic systems we've trusted for decades.
billions of dollars in digital assets depend on these mathematical assumptions remaining secure.
https://t.co/BNZnY1sfeZ is the first post-quantum token launchpad where every launch is CRYPTOGRAPHICALLY signed using algorithms such as WOTS/XMSS, SPHINCS+, ML-DSA, and Falcon.
this means that even if AI eventually breaks elliptic-curve cryptography, the hash-based proofs attached to these launches remain independently verifiable without relying on traditional wallet signatures.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash.
Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase).
Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets.
IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster).
Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the ErdΕs unit distance conjecture was our warning shot.
Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time?
Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.)
Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once.
Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.
I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026).
Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS.
Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security.
The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
ok, looks like I was wrong about the caching bug.
the site appears to be getting hit with a DDoS attack, which is causing the outages some of you are experiencing.
adding cloudfare protection now to prevent this from happening again. everything should be back up and running shortly.
sorry for the inconvenience. guess some people really have nothing better to do.
Everything should be running smoothly again.
small caching bug that has now been fixed.
remember, before launching a token, you must first create your post-quantum identity through the vault.
connect your Solana wallet and sign a message to derive your unique hash-based identity, which is used to cryptographically sign your launches and generate independently verifiable proofs of origin.
no new wallet or seed phrase required.
create your identity here: https://t.co/llk6RQGgvc
Everything should be running smoothly again.
small caching bug that has now been fixed.
remember, before launching a token, you must first create your post-quantum identity through the vault.
connect your Solana wallet and sign a message to derive your unique hash-based identity, which is used to cryptographically sign your launches and generate independently verifiable proofs of origin.
no new wallet or seed phrase required.
create your identity here: https://t.co/llk6RQGgvc
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices.
(and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation)
So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be?
This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption.
And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety.
And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems.
For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
* Hash-based > lattice-based, in those situations where hash-based is possible at all
* For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ...
* For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
* If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**.
* For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money"
https://t.co/oVjwZog2lL
5 tokens launched so far, each with its own post-quantum cryptographic proof of origin.
every launch is signed using quantum-resistant cryptographic algorithms, with a permanent receipt containing the signature and verification data stored in IPFS metadata.
even if traditional elliptic-curve cryptography is eventually broken, these proofs remain independently verifiable without relying on the security of today's wallet signatures.
PQC uses post-quantum cryptographic proofs, but they don't make the token itself quantum-resistant.
on https://t.co/MGT2jRZSkX, every token launched carries a verifiable cryptographic receipt, with 8 different signature options including WOTS/XMSS, SPHINCS+, ML-DSA, and Falcon.
please take a minute to read through the docs.
there are so many use cases for a launchpad that allows anyone to create tokens with post-quantum cryptographic signatures and independently verifiable proofs of origin.
AI is advancing faster than most people realize, and the mathematical assumptions securing today's blockchains may not remain reliable forever.
this is the first step toward making post-quantum cryptography accessible to anyone launching tokens on Solana.
https://t.co/bmA9tAq8ho