BUNKER
DocsCreate bunker
A proposed bunker solution for Solana

Lock your SOL behind hashes.

Bunker Protocol is a proposed vault for Solana where withdrawals are authorized by hash-based signatures instead of the elliptic-curve keys every wallet uses today. Hash functions are expected to hold up when quantum computers arrive. Today's wallet signatures are not.

BUNKER CONSOLERUNNING IN YOUR BROWSER
Bunker vault door

    
WOTSWinternitz one-time signatures
SHA-256the only assumption: hashes are hard to reverse
1 KEY = 1 USEevery withdrawal rotates to a fresh key
DEVNET SOONproposal stage, not on mainnet yet
How a bunker works

Four steps. No curves.

A bunker only ever stores a hash. To open it you prove you know what that hash came from.

01

Generate

Your browser creates a secret and hashes it, again and again, into one 32-byte commitment. The secret never leaves your device.

02

Seal

You deposit SOL into a bunker that only knows the commitment. No public key that a quantum computer could attack.

03

Unlock

To withdraw, you sign the exact withdrawal with a one-time signature. The program re-hashes it and checks it lands on the commitment.

04

Rotate

Every unlock also commits to your next key. A used key is worthless, so a revealed signature can't be replayed or reused.

Why it matters

Wallet vs bunker

Every Solana wallet signs with ed25519. A large enough quantum computer running Shor's algorithm could recover a private key from its public key. Hash-based signatures don't have that weakness.

Normal wallet (ed25519)Bunker (hash-based)
Security rests onElliptic curve mathHash functions only
Quantum computersBroken by Shor's algorithmOnly a square-root speedup (Grover)
Public key on-chainVisible foreverOnly a hash commitment
Key reuseSame key for lifeOne key per withdrawal, then rotate
Signature size64 bytes~2 KB (the price of safety)
not launched

The $BUNKER token

Roadmap

Where we are

PHASE 0 · NOWProposal

Design, site and the in-browser key lab.

PHASE 1Devnet

Bunker program on devnet. Create, seal, unlock, rotate.

PHASE 2Audit

Independent review of the program and the signing code.

PHASE 3Mainnet

Bunkers open on mainnet, starting with deposit caps.

Key lab

Sign with hashes

Make a one-time key, sign a message and verify it, all in your browser.

OPEN →
Docs

How it works

The threat, Winternitz chains and how a bunker unlocks.

READ →
Risks

Read first

This is a proposal. Nothing is audited or live on mainnet yet.

READ →