Plain English first. Every byte after.
0 · What QPAD is (and isn’t)
QPAD launches Solana coins and seals who made them. You launch on pump.fun or Meteora from your own Phantom, or you bring a coin you already launched anywhere. Either way you sign a short record (mint, name, ticker, venue, pool, creator, time) with a key built only from SHA-256. A quantum computer can’t fake that signature.
What it isn’t: a seal does not make the token, its pool or any wallet quantum-proof. Solana itself still uses Ed25519 keys. If those are ever broken, a seal made before that day is strong public evidence of who the real creator was.
0.1 · Launching
- pump.fun: one transaction, pump.fun’s own create_v2 instruction. Your wallet is both the payer and the on-chain creator, so pump.fun pays every creator fee to you. The mint key is made in your browser. About 0.006 SOL.
- Meteora DAMM v2: two transactions in one Phantom prompt. A new token (1B supply, mint authority revoked, no freeze authority, immutable metadata), then a one-sided pool holding 100% of the supply with liquidity locked forever. The pool position belongs to you, so all trading fees (1 to 5%, your pick) are yours. About 0.035 SOL.
- QPAD fee: 0%. We never hold your keys and never sign for you. Every launch is simulated against mainnet before you sign.
0.2 · Sealing a coin you already launched
Paste the mint. We read the chain and accept your wallet only if one of these is true, strongest first: it launched the coin on QPAD; it is the creator in pump.fun’s bonding curve; it is the metadata update authority; it is the mint authority; or it paid for the mint’s very first transaction. Anyone else is refused. The record says which check passed.
1 · What is Q-Day?
Q-Day is the day a quantum computer becomes big and reliable enough to break the math that protects today’s wallets. It hasn’t happened. Estimates of the machine it needs keep shrinking, and the machines keep growing. Nobody can honestly give a date.
2 · Why Solana wallets are exposed
A Solana address is an Ed25519 public key. Ed25519 is safe against normal computers, but Shor’s algorithm on a large quantum computer can recover a private key from its public key. Since every Solana address is a public key that’s already public, every wallet is in the same spot. (Program-derived addresses are the exception: they have no private key at all.)
3 · What a hash-based signature is
The picture: imagine 67 ladders, each 15 rungs tall. Only you know what’s at the bottom of each ladder. Everyone knows what’s at the top. To sign, you climb each ladder part of the way and show where you stopped. The message decides how high you stop on each one. Anyone can finish the climb and check they reach the known tops. Nobody can climb down, so nobody can sign a different message.
What actually happens: each “rung” is one SHA-256 hash. The message’s SHA-256 fingerprint is split into 64 hex digits (0 to 15), plus 3 checksum digits, giving 67 numbers. For chain i, the signature reveals the secret hashed di times. The verifier hashes it 15 − di more times and must land on the public chain end. The checksum stops anyone from raising digits by hashing forward, since raising one digit forces a checksum digit down, which needs a hash to be reversed. This is a Winternitz one-time signature (WOTS, w = 16).
Why quantum doesn’t help much: breaking it means reversing SHA-256. The best known quantum trick (Grover’s algorithm) only halves the security level, from about 2256 to about 2128 work. That’s still far out of reach.
4 · One-time keys, 256 of them
Each ladder set can sign only once: two signatures from one key reveal enough rungs to forge a third. So your browser makes 256 of them and joins them in a Merkle tree, a binary tree of hashes 8 levels tall. The single hash at the top (the root) is your post-quantum public key. A signature carries the key number, the 67 revealed values, and the 8 sibling hashes needed to climb from that key to the root.
We keep a public ledger of used keys and refuse any key that has signed something else. Your browser also remembers which keys it has used, and burns a key before it signs.
5 · Where your keys come from
No new seed phrase. Phantom signs this fixed message once. Ed25519 signatures are deterministic, so the same wallet always gets the same 64 bytes back. Those bytes (plus an optional passphrase, stretched with scrypt) go through HKDF-SHA256 to make a secret seed and a public seed. The secret seed never leaves your tab. We never see the signature.
QPAD key derivation v1 Signing this creates your one-time quantum-safe signing keys, inside this browser only. It is not a transaction and costs nothing. Your private key is never shared. Only sign this exact message on QPAD. Wallet: <your address>
6 · What you sign
One readable record, signed twice: by your wallet (Ed25519, binding today) and by your next unused one-time key (SHA-256, binding after Q-Day). The record lists the mint, name, ticker, venue, pool, your wallet, how we verified you as creator, the launch transaction (for coins launched here), the Solana slot and time of the check, and your post-quantum root. Our server signs the checked record with a secret key (an HMAC) before you sign it, so nobody can seal a coin they didn’t pass the creator check for.
7 · How anyone verifies a seal
- Hash the record text with SHA-256 → 67 digits.
- Finish all 67 chains from the revealed values to step 15.
- Hash the 67 chain ends together → the one-time key.
- Climb 8 levels with the sibling hashes → a root.
- It must equal the root written in the record. Also check the Ed25519 wallet signature, which is valid today.
Every coin proof page runs this in your browser, and the tamper test shows a single changed character failing. You can also check a seal without us: qpad_verify.py uses only Python’s hashlib.
python3 qpad_verify.py <mint address>
8 · Honest limits
- It’s proof, not protection. Solana still only checks Ed25519. A seal can’t stop a Q-Day attacker from moving tokens or faking new signatures with a cracked Ed25519 key. It gives strong evidence of who launched the coin, and when, for any recovery or migration that might come later.
- Time is a record, not magic. The seal includes the Solana slot of the creator check (it can’t be from before that) and our server’s receipt time. Seal early.
- Wallet-only keys can be re-made. After Q-Day, whoever cracks your wallet could re-derive your post-quantum keys and make new seals. They can’t change your earlier, dated seal. A passphrase closes this gap.
- 256 seals per identity. Plenty for every coin you’ll launch. The meter shows how many are left.
9 · Exact parameters
| Hash | SHA-256, n = 32 bytes |
|---|---|
| One-time scheme | WOTS, w = 16, 64 + 3 = 67 chains |
| Tree | Merkle, height 8, 256 keys |
| Signature | 4 + 67×32 + 8×32 = 2,404 bytes |
| Public key | root ‖ public seed, 64 bytes |
| Hash calls | F(seed, ADRS, x) = SHA-256(public seed ‖ 32-byte address ‖ x) |
| ADRS | type | key | chain | step | height | index | 8 zero bytes (u32, big-endian) |
| Seeds | HKDF-SHA256(wallet signature ‖ scrypt(passphrase)), salt “QPAD/seed/v1” |
| Passphrase | scrypt N = 2¹⁵, r = 8, p = 1 |
| Q-ID | “q1” + base58(SHA-256(tag ‖ public seed ‖ root)[0..20]) |
| Tested | byte-for-byte against an independent Python implementation, plus tamper and forgery tests |