I built a cold wallet you can make out of any USB stick. It's called qUSB, and it's quantum-proof
qusb.app
$qUSB
here's the problem in plain words
every Solana wallet today is protected by the same kind of math: elliptic curves, that includes Phantom, Backpack, your Ledger, all of them, y our public address is out in the open, and right now nobody can work backwards from it to your private key, normal computers would need longer than the universe has existed
big enough quantum computer changes that
there's a known algorithm, Shor's, that does exactly this: public key in, private key out, obody can tell you the date that machine shows up, ut when it does, every wallet built on curves is open, and moving your coins after the fact won't help if someone gets there first
so I built a wallet that doesn't use curves at all
qUSB signs with hashes instead, using Winternitz one-time signatures over SHA-256, hash-based signatures are the boring, well-understood kind of post-quantum crypto
quantum computer has no shortcut against them, with no curve, there's nothing for Shor to break
how it works:
1. take any USB stick from your drawer. No special hardware, no chip, no company
2. flash it with qUSB. It holds an encrypted keystore and the wallet program
3. run qusb init. You get 24 words and set a passphrase, and your keys are encrypted on the stick
4. qusb receive gives you a vault address. Send SOL to it from any wallet or exchange
5. to spend, you sign offline with the stick, then broadcast from any online computer, signed message is locked to one recipient and one amount, so the online machine can't redirect your funds
the vaults live on Solana, small open-source program called qvault checks the hash-based signature on-chain before any SOL moves, there's no admin key and no backdoor over your funds
lose the stick? everything comes back from your 24 words, someone steals the stick? without your passphrase they get encrypted noise
What it doesn't do (I'd rather you hear it from me):
- It's v1 and not audited yet
- each vault key signs exactly once, wallet handles this and moves your change to the next vault
- Fees and SPL tokens still use a normal Solana key, as every wallet today, keep only fee money there
- If the computer you sign on has malware, it can see your keys while you sign, use a machine you trust
the full threat model is in the repo
why a token?
I want qUSB to be the first serious open-source software with no financial dependency on anyone, no VC, no sales team, no paid marketing
$qUSB is how it gets funded: the creator fees pay me and it
that's it, he token gives no claim on anything, and the code stays open source whatever happens
If you've used SAM, you know I ship open source. This is the next one
code:
github.com/prfagit/qusb
qvault program: CnfS7soDNtZaJgshcU38tvDuK2zZZwFPAedRUdRm
read the code, plug it in
CA: 9NDY4jY5gqcNfDrZsKujtnuvH12pPG5FUGS5QmwZpump