Skip to content

z0s:/vault

no break shownCAnot live yetFollow @usez0s

Vault

live Unaudited, so each vault is capped at 0.1 SOL until an audit. Deposit only what you can afford to lose.

A hash-based vault for SOL: it holds funds behind a one-time Winternitz signature instead of an elliptic-curve key. Keys are made and used on your device and never reach a server. z0s's version adds the standard Winternitz checksum, which the widely-shared implementation leaves out, so a signed withdrawal cannot be re-used for another.

cost
Opening a vault through z0s: $3 of z0s burned, from the token launch (free until then). Withdrawing is always free.

Try the vault

Experimental. Unaudited. Read this first.

  • This program has not been audited. It can hold at most 0.1 SOL per vault while that is true.
  • Deposit only what you can afford to lose.
  • Your vault seed is shown once. We never see it or store it. Lose it and the funds are gone.
  • It shelters SOL behind a hash-based one-time signature. It is not a claim of safety.

Smart contract

mainnet
program id
solscan ->explorer ->
network
Solana mainnet-beta
build
Pinocchio 0.7, sBPF v3, 20,792 bytes, deployed in slot 454,723,739
source
github.com/z0s-app/z0s-vault ->

Public and MIT licensed. Building it reproduces the deployed binary byte for byte (sha-256 57bc3e6e8d72...).

verifier
checksummed Winternitz, 34 chains of 224-bit Keccak, one signature per key
upgrade authority
3mR7..YrKD upgradeable

The program is upgradeable: the authority key can replace its code. That is normal before an audit, and it means you are trusting that key. The plan is to make the program immutable once it is audited.

  • 0 openroot (32) + bump (1)

    Creates the vault account at the program address of its key's root, rent paid by the opener.

  • 2 closesignature (952) + bump (1)

    Recovers the root from a signature over the refund address, checks it derives this vault, sends the whole balance to refund, and closes the vault.

  • 1 splitsignature (952) + amount (8) + bump (1)

    Pays part of the balance and moves the change. In the program, not yet in the interface: its transaction is over Solana's size limit until address lookup tables are added.

A fork of Dean Little's solana-winternitz-vault (MIT) with one change: the signature scheme carries the standard Winternitz checksum. Full specification ->

  1. [1]

    Constructing Digital Signatures from a One Way Function

    L. Lamport · SRI International, 1979

  2. [2]

    A Certified Digital Signature

    R. Merkle · CRYPTO '89

    Credits the Winternitz improvement to R. Winternitz.

  3. [3]

    RFC 8391: XMSS, eXtended Merkle Signature Scheme

    A. Hülsing, D. Butin, S. Gazdag, J. Rijneveld, A. Mohaisen · IRTF, 2018

  4. [4]

    solana-winternitz-vault

    D. Little · GitHub, MIT

    The program the z0s vault forks.

  5. [5]

    z0s-vault

    Zero Surface · GitHub, MIT

    Builds to the deployed program, byte for byte.

  6. [6]

    Quantum readiness

    Solana · solana.com

How it works

  1. Open

    Burn $3 of z0s (from the token launch). Your device generates a one-time Winternitz key from your seed; the vault's address is a hash of its public half. You deposit up to 0.1 SOL.

  2. Withdraw

    You sign once to any address. The program recovers the key from the signature, checks it against the vault, and sends the whole balance. The key is then spent for good.

  3. Recover

    Every key comes from one seed plus a counter, so a new device rebuilds your vaults from the seed alone. Lose the seed and the funds are gone.