
QUANTUMDESK
Post-quantum crypto API · Solana launches · not audited
qv> security --report
Quantum Security
No 'Quantum Safe' badge until verifiable requirements pass
Wallet signature (Ed25519): signs ordinary Solana transactions. It is NOT post-quantum secure.
Vault authorization (ML-DSA-65 (FIPS 204)): a separate key that will authorize withdrawals once verified by the on-chain program. Public key 1952 bytes, signature 3309 bytes.
Each authorization binds domain, cluster, program, vault, mint, amount, destination, nonce and expiry.
- [OK] Local ML-DSA test suite (valid, tampered, replay, expiry, wrong key)
- [--] On-chain verifier test suite — not built
- [--] Compute-unit benchmark — not run
- [--] Audit — none
Post-quantum withdrawal authorization does not make Solana itself quantum-resistant. It does not protect consensus, ordinary wallet accounts, RPC infrastructure or other smart contracts.
- On-chain vault program (Anchor/Rust) is not deployed — it must be built and deployed to Devnet outside this app builder.
- On-chain ML-DSA verification is unproven on Solana: a 3,309-byte signature exceeds a single 1,232-byte transaction and verification cost vs. the 1.4M compute-unit limit is not yet benchmarked.
- No independent cryptographic or smart-contract audit has been performed.
- Key recovery design is not reviewed — losing the post-quantum seed means losing withdrawal authority once a vault exists.