Inside the bunker.
Plain-language notes on the threat, the signature scheme and how a bunker opens. This is a proposal: details can change before devnet.
The threat
Every Solana wallet is an ed25519 key pair. Its security rests on elliptic-curve math that ordinary computers can't solve. A large, error-corrected quantum computer running Shor's algorithm could. It would work out a private key from the public key, and every public key on Solana is already on-chain.
Nobody knows when such a machine will exist. The day it does is usually called Q-Day. Funds that move only with an ed25519 signature are exposed from that day on.
Why hashes
A hash function like SHA-256 turns any input into a fixed 32-byte fingerprint that can't be run backwards. The best known quantum attack on hashes, Grover's algorithm, only gives a square-root speedup, which a large enough hash absorbs. Signatures built only from hashes have been studied for decades and are part of the post-quantum standards (SPHINCS+ / SLH-DSA).
Winternitz chains
A Winternitz one-time key is a set of secrets. Each secret is hashed 15 times to form a chain. The ends of all chains are hashed together into one commitment.
To sign, you hash the message and read it as 64 digits from 0 to 15. For each digit you reveal that chain at that step. A verifier hashes each revealed value the remaining steps and checks the result folds into the commitment. Three extra checksum chains stop anyone from pushing chains further to forge a different message. Try it in the key lab.
How a bunker opens
- The bunker account stores your current commitment and balance. No public key.
- You build a withdrawal (amount, destination, nonce) and sign it with your one-time key, in your browser.
- The bunker program recomputes the chains on-chain and checks they reach the stored commitment.
- If they match, the SOL moves and the stored commitment is replaced by the next one you committed to.
Rotation
A Winternitz key is safe for one signature. Each one reveals part of every chain, and two signatures from the same key reveal enough to forge others. So every unlock carries the commitment for your next key. The used key is dead the moment it's used, and a revealed signature can't be replayed.
Trade-offs
- Bigger signatures: about 2 KB instead of 64 bytes, so unlocks cost more compute than a normal transfer.
- You hold the secret: lose it and the bunker stays closed. There is no recovery.
- The rest of Solana: a bunker protects what's inside it. Your normal wallet still signs with ed25519.
- Unaudited: nothing here has been audited yet. Don't treat the preview as a promise.

BUNKER