ML-DSA-65 · FIPS 204Post-quantum signaturesfor Solana.
Real ML-DSA keys, generated, signed and verified right here in your browser. The first quantum-resistant proof-of-concept on Solana — small enough that you can read every line of it.
The problem
Solana signs everything with Ed25519. It is fast, tiny and completely fine against classical computers. It is not fine against Shor's algorithm: a sufficiently large quantum computer derives the private key from the public key, and on a public ledger every spent address has already published its public key.
Nobody knows the date. That is exactly why the migration work should be boring, public and done early — "harvest now, decrypt later" applies to signatures too, because the keys are already out there.
The approach
Use ML-DSA-65, the NIST-standardised lattice signature scheme from FIPS 204 (formerly CRYSTALS-Dilithium). A user holds a post-quantum keypair alongside their normal Solana keypair, and binds the two by signing their Solana address with the post-quantum key.
solana address ──┐
├─► ML-DSA-65 sign ──► pq signature (3309 B)
pq secret key ──┘ │
▼
anyone verifies with the pq public key
(next step: anchor it on-chain)Step one is making that verifiable by anyone, with no trust in this website. That is what the demo does.
Proof, running live
Generate a real post-quantum keypair, sign a message, verify it — then break it on purpose and watch verification reject it.
The anchor transaction
The full ML-DSA-65 public key (1952 B) and signature (3309 B) over the contract address are written into Solana mainnet as memo transactions — not a hash, the whole thing. Pull them off the chain and verify locally; nothing here has to be trusted.
All payload transactions
- 123qeFQaQbR9auV84qsbMb8xJgyCN6aMRE4LkKp5BeYHTppBJ4gDrHoiaKaAdGT7EE9Rw2vNCvGMpv2dnEeuD1kP8
- 2tof4gU4mB3Hcm2vHq1CYAYhxYdX2wG7hBZAD9xJczniY5gsXnGoPxJpm1WHZDhemtenoHD9KFZg8XVdjQVdPyYv
- 3VRWxTmiyrikgkMTDDZvJszAvhWS4synYG5eLZ1b8KBGegX5MFp1yynaHmxbuqKyWEZSLqMgb7Xj5StcvMhNiUqV
- 42vFaUj5Te2fuCbh1uqsHLzpKYsBjX8ZdA7fw84rDwZRKc77gY8iFJiUi5h7oo2iRN4KcfUuCUrz4jBushzHpBj6w
- 535svcTKXUmZMxb8uify59m6NTWSJd6yagyTH4G77xeguL1SjxL3n8vudenL1Ej5emSx6qfryGcx6tvdDTJVcugik
- 65GHJWUy9G6g14cL658fxVnvQD1fQFMDKnC15jdPhKxdoYqoQSaQgfMw3Zo8KpEeYfdyXmvwj1TUZSqgJ5GoeGkX4
- 72XRa3jo8DEYUf6ZVHDUxLx6ggy1PuVwP5BPR7hJCGQqJhj4kPaBcrpxP2Z7aFTEXyphVUDjQ882jusrCzLR4Zr49
- 853j3pbZunSSEY2C3nEcqsCsy1mZaLcfunQLpTDcnbznoKiJZNdgQGpdPtQGcLzzrzicRiEkBD375nwHqZ4gBcA7r
- 94WnhsMwMiBm3SqasLeHovZHwcyyf38uE1Q2BG2oG3KNCG2oAVb9Uo5RFXQqEFFL6EuQobeh1oZmbNeDU2DUq2x3
- 102SeBXFfSRyBhQC79gjssAd7o7LdYXpeJMrxDCXz5LxXyV8YDps8tT8V1PHVAfCuW7y1sZWhf8wivdYxbmF4oSfGi
- 112vLLGqqSJXGD4fv8WZeeJuzTgQGErbnHsoSLPuBAAqLorcSL2U2bdGiVczawoFeDGLyp6QWfsoERtQiPezEeeKRN
- 12b48JpqhKeC7KfF7kZoYmdR2PBJpamumQ6i7t2ZCU4y6dk84RGjGWRyhF2z6DnH3rzjZmVi8T5R2vQKKQzBGsMeJ
- 1354M6Docp59NcbR7FFULk5xnTvjkRSRDtpdaAjGwkNDoveqCST8LvZBiAjmbrumYAzeDrJkqQWRJR9QH4aeq2b5Uy
- 144yfq9t51Wfhaz4UjAViQBfhBb672eFeoGSiWpRxVjvHZcU8YSXunnVg1eW9RYaLopnAH4mTLCPtrhjEHVQcwfdmE
- 154HMF8ejwpyaY5pE88o4gjBCvuxKKpAp28B3YxHhZAVHZGE9VQ5r2dqSeuhEhn4f5eJpdmbZTuMQFYcrjUgryodwp
- 163r9DrdQD3f2vT3bexBF4busozNSWdJ2Jn9qoqFRzHrL8UvFCrJCetuxrLyU5GMRDKgXqSSpvh2eNmJK16w6ceidA
- 174KvfPfXHQdzRK33FVpnBLrPYQ8S82KBp6spJw7y7Kun7nS1QoZrgx1WWMRwjyVtwbSMFV9KoVjMsZUoeCW84Y8uM
- 18uYQBU3yGamXn8LtZJpQxw7jSBvTQaF8136J5XQatSMBK6acLR6MdbpmY2gH4UKNC3NrnupaQURtNErErci31eSk
Token
FAQ
- Is Solana broken today?
- No. Ed25519 is safe against every computer that exists right now. The concern is a future, large, fault-tolerant quantum computer running Shor's algorithm, which would recover a private key from a public key. Any address whose public key has been exposed on-chain would be at risk.
- So what does this actually do?
- It brings a NIST-standardised post-quantum signature scheme (ML-DSA / Dilithium, FIPS 204) into the Solana world, starting with a fully verifiable browser implementation. Every key, signature and verification on this page is real — no mock, no server.
- Why should I believe it works?
- Don't believe it — check it. Copy the public key, message and signature from the demo, and verify them yourself with any FIPS 204 implementation. Tamper with a single byte and watch verification fail.
- Why are the signatures so big?
- Lattice signatures trade size for quantum resistance: ~3.3 KB versus 64 bytes for Ed25519. That size is the main engineering challenge for putting them on-chain, and it's what the next phase is about.
- What is next?
- Anchoring a post-quantum signature to a Solana transaction, so a wallet can prove control of an address with a quantum-safe key. The page will link the transaction when it's live.
- Who made this?
- One dev, nights and weekends, in the open. If something is wrong, open an issue — being corrected is cheaper than being confidently wrong.