Your wallet address has no private key.
Not even we can derive one. Your funds are controlled by hash-based signatures, so there is no public key for a quantum computer to work backwards from.
A normal address is a public key. This one is made of hashes.
A large enough quantum computer can turn a public key back into its private key. Qorvex never puts a public key on-chain, so there is nothing to turn back.
A normal wallet
- Your secretprivate key
- Derived from it, and published on every spendpublic key = your address
- What a quantum computer can dopublic key → private key
Qorvex
- Your secret24 words → 1,024 one-time keys
- The address: the output of a hash, owned by a programhash(seed, root) → address
- What the chain ever seeshash values and a Merkle proof
Honest scope: Solana itself, the fee payer (Phantom) and the program's upgrade authority still use Ed25519. Qorvex removes the elliptic-curve key from your funds, not from the network around them.
Every send uses a key that is burned forever.
Your wallet holds 1,024 one-time keys. Each send signs with the next one and the blockchain cancels it, so it can never sign again. You always see which key is about to be spent and how many remain, and you rotate to a fresh set before they run out. The address never changes and no funds move.
Illustration: seven keys used.
Don't take our word for it. Check.
Each claim above maps to something you can verify yourself, live from the chain, on the Proof page.
- No private key exists for the addressVerify
The address is off the Ed25519 curve, and you can recompute it from the program and your public seed values.
- Nothing reversible is publishedSee the list
Exactly what goes on-chain, and why each piece is a hash output rather than an elliptic-curve public key.
- Keys cannot be reusedCheck
Your live key counter, read straight from the state account.
- Who can change the program, checked liveCheck
The program's upgrade authority, read live from the chain. You can always see here who, if anyone, is able to change it.
- Open sourceRead
The code, the tests and the threat model.