Quantum Bunker

Docs

namevaluenote
hashSHA-256Solana sha256 syscall · EVM precompile 0x02
chain value28 bytesSHA-256 output truncated to its first 28 bytes
Winternitz w256one byte per digit
message digits28the 28-byte truncated message hash
checksumC = Σ(255 − dᵢ)over the 28 message digits, max 7,140, 2 bytes big-endian → 2 digits
chains3028 message + 2 checksum
signature840 bytes + 3230 × 28-byte chain values, plus the pubSeed
verify cap≤ 3,600 stepsΣ(255 − dᵢ) over all 30 digits; the client grinds a salt until it holds
chain step Fsha256(QM/wots/chain ‖ pubSeed ‖ i ‖ step ‖ x)[0:28]i and step are uint8
public toppkᵢ = chain(skᵢ, i, 0, 255)255 applications of F
key hashsha256(QM/wots/pk ‖ pubSeed ‖ pk₀ ‖ … ‖ pk₂₉)the only key material stored on chain
quantum margin~112-bit (estimate)224-bit chain values; Grover's search halves the exponent

From 24 words to key n

seedderivation
masterBIP-39 seed of the 24 words: PBKDF2-HMAC-SHA512, 2,048 rounds, empty passphrase (64 bytes)
bunkerSeedsha256(QM/bunker/seed ‖ master ‖ chainId u64 ‖ bunkerIndex u32) · chainId 101 Solana, 103 the devnet build, 4663 Robinhood Chain
keySeedₙsha256(QM/key/seed ‖ bunkerSeed ‖ n u32)
pubSeedₙsha256(QM/wots/pubseed ‖ keySeedₙ)
skᵢsha256(QM/wots/sk ‖ keySeedₙ ‖ i u8)[0:28] for i in 0..29

The signed message

fieldbytesencoding
tag9ASCII QM/msg/v1
chainId8uint64 big-endian · 101 (103 for the devnet build)
program32the bunker program id
vaultId8uint64 · from the registry PDA at creation
keyIndex n4uint32 · the key that signs
kind10 SOL · 1 SPL token · 4 rotate · 6 call · 2, 3, 5, 7 only rotate on Solana
asset32zero for SOL and rotations · the mint (kind 1) · the program called (kind 6)
amount16uint128: lamports or token units · 2⁶⁴−1 = all · 0 for kind 6
to32recipient (0, 1) · zero (4) · sha256(account count ‖ keys + flags ‖ data) (6)
nextKeyHash32keyHashₙ₊₁: the key this bunker rotates to
salt8uint64 · ground until the verify walk is ≤ 3,600 steps

kindwhat it authorizes
kind 0withdraw SOL to any address (the bunker keeps its rent floor)
kind 1withdraw an SPL token, classic or Token-2022 ($BUNKER is Token-2022)
kind 4rotate only: no payout, emergency re-key
kind 6one call signed by the bunker: the pump.fun fee claim, a stake, an unstake
kind 2 · 3 · 5 · 7verify and rotate, move nothing (EVM-only kinds)

Programs

bunkerMainnet id QMD7go…XfVSRb (reserved); its upgrade authority is burned before launch. Registry PDA ["registry"] counts bunkers and executions; each bunker lives at PDA ["bunker", key hash 0], so its address is known before it exists and no private key exists for it.
authorize · executeauthorize carries the 840-byte signature in one packet (1,198 bytes for SOL, 1,230 for tokens) and costs at most ~594k compute units at 3,570 steps. execute pays out for 5k–39k compute units and is retryable. Anyone may submit either; the signature is the authority.
bunker_stakeIts own program, so the vault program never changes. Stake $BUNKER into a bunker for 1, 7 or 30 days (weight 1.0 / 1.5 / 2.0). Two reward legs: $BUNKER from the staking allocation, and SOL from creator-fee distributions; claims pay both into the bunker. A bunker stakes and unstakes with kind-6 calls its words sign.

A curve breakAI-found math or a quantum computer that recovers Ed25519 or secp256k1 keys gets nothing: no curve key controls a bunker. A wallet or the relay only pays fees.
Exposed deposit walletsDeposits can come from any address, exposed or not. Withdrawals need the words, never that wallet's key.
Tampering in flightThe signature binds chain, program, bunker, key number, kind, asset, amount, recipient, next key and salt. A relay or a front-runner that changes one byte fails verification.
ReplayEvery accepted signature rotates the stored key hash to the committed next key. An old signature never opens the new key.
Cross-chain replayChain id and program are in every message, and seeds are chain-scoped: a Solana key never signs for Robinhood Chain.

Lost wordsNobody can recover a bunker without its 24 words. No admin, no reset, no support desk.
Stolen wordsAnyone holding the words can move everything out. Phishing, a photo, a cloud note or a clipboard manager is how that happens.
A compromised device or pageMalware that reads what you type, or a modified copy of this page, sees the words. Check the bundle, or run the app locally (bun install && bun dev).
Signing twice with one keyTwo different messages under one key number make a forgery cheap. This browser keeps a ledger and refuses; another device cannot see it, so never sign the same key number on two devices.
Issuer switchesCircle can freeze USDC and an SPL mint with a freeze authority or a permanent delegate can freeze or move its tokens; on Robinhood Chain, Robinhood and Paxos keep theirs. A bunker protects you from a broken key, not from the issuer.
Program bugsv1 is unaudited. Once its upgrade authority is burned no one can patch or rescue it, and no one can change it either.
A break of SHA-256The whole scheme rests on SHA-256 second-preimage resistance at 224 bits.
PrivacyEverything is public on chain. A bunker hides its key, not its balance or its history.

Solana · issuer switches

Circle can freeze USDC. Any SPL token whose mint keeps a freeze authority can be frozen, and a Token-2022 mint with a permanent delegate can move or burn tokens, in a bunker or out. SOL and coins whose mint and freeze authorities are revoked have no issuer switch. A bunker protects you from a broken key, not from the issuer.

Robinhood Chain · tokenized stocks

Robinhood can freeze, pause or burn any tokenized stock, in a bunker or out, and a beacon upgrade could add an allowlist to every stock token. Paxos can freeze USDG. ETH and plain memes have no issuer switch. A bunker protects you from a broken key, not from the issuer.

pump.fun · $BUNKER

pump.fun's admin key can reassign $BUNKER's creator, which sends the creator fees of later trades to the new creator; every fee earned before the admin acts stays payable only to the fee bunker, and anyone can push it in.

pump.fun · Bunker Mode coins

pump.fun's admin key can take a Bunker Mode coin over, which sends every creator fee not yet cranked into the bunker, and all later ones, to the new creator; what the bunker already holds stays, and mayhem-mode coins refuse the takeover.

Pons V2

The Pons V2 factory can reassign a coin's creator-fee recipient after a 3-day timelock (CREATOR_FEE_RECIPIENT_TIMELOCK = 259,200 s): fees stay in bunker mode unless Pons does that, with three days of notice on chain.

Creator fees

Distributed when the team triggers it; no schedule and no rate are promised; fees never pay holders who do not stake.

Code

Unaudited. The Solana program is immutable once its upgrade authority is burned; the Robinhood Chain contracts start with small deposit caps.

Ticker

Another Solana coin also trades as BUNKER. Only the mint published on the $BUNKER page is this one.

It canPay the fees of create, authorize and execute, so a words-only user never needs a wallet. It checks every signature against the bunker's current key before spending anything, and it is rate-limited per bunker and per address.
It cannotChange the amount, the asset or the recipient, or reuse a signature. At worst it refuses to send: the same transaction goes out from any wallet, and the bunker page has that button too.
Check itEvery execute is on Verify: the page runs this exact scheme in your browser.