Hash-locked SOL vaults on Solana
A vault with
no key to steal.
A bunker is a Solana account that holds SOL and has no private key. It opens only to a one-time hash-based signature made from your 24 words, checked on chain, then thrown away. No wallet, no elliptic curve, no one in the middle.
Signature, live
w = 256840 B
signature
30
hash chains
224-bit
SHA-256, truncated
0
private keys on the vault
1
use per key
3
transactions per release
01On chain now
getProgramAccounts, cached 60sBunkers open
--
accounts on chain
SOL held
--
across all bunkers
Program
reading
BuNKTm...jk5MZ4
Cluster
mainnet-beta
cached 60s
02How a release works
One signature. Three transactions. Then the key is gone.
A Winternitz signature is too large and too expensive to check in one Solana transaction, so a release is split into store, verify, and move. You sign once; the relay sends all three and pays the fees.
- 00
Sign
your browser
Your words derive one-time key k. The browser signs the bunker, key index, amount, destination, and the hash of key k+1. Nothing secret leaves the page.
- 01
Authorize
relay
The terms and the 840-byte signature are stored in a release record. One signer, one instruction, 1,223 of 1,232 packet bytes.
- 02
Verify
anyone
The program walks all 30 chains, about a million compute units, and checks they end at the key the bunker committed to. The key rotates to k+1.
- 03
Execute
anyone
Lamports move to the destination and the record closes. The key that signed is now public and worthless.
03Start
/bunker
Open a bunker
Generate 24 words, write them down, and commit key 0 on chain. Fund it from any wallet or exchange. Release whenever you want, to any address.
/launch
Launch a coin
Start a Meteora pool with a bunker as the fee recipient. Creator fees land somewhere no private key can reach. The pool module is in progress.