The quantum‑safe standard for value on Solana

Rotor protects your SOL, tokens and tokenized stocks with hash-based signatures that quantum computers can’t break, and a fresh key for every transaction.

SOL SPL tokens Token-2022 Tokenized stocks iOS & Android
How Rotor is quantum-safe

Built on math a quantum computer can’t reverse.

Rotor replaces the elliptic-curve keys every other wallet depends on with hash-based one-time signatures. Here’s the whole idea in four steps.

01
The problem

Your address is your public key.

Normal wallets derive a public key from a private key using elliptic-curve math. Going forward is easy and going back is impossible, for today’s computers.

Shor’s algorithm lets a large quantum computer go back. Because your address is published on-chain, anyone can collect it today and crack it the day that machine exists.

02
The fix

Sign with hashes, not curves.

Rotor uses Winternitz one-time signatures: chains of SHA-256 hashes. Your secret is the start of each chain; your vault stores only a fingerprint of where the chains end.

To sign, your phone reveals a point partway along each chain. The program finishes the chains and checks they land on the fingerprint. There is no curve and no group structure, so there’s nothing for Shor’s algorithm to grab onto.

03
One key, one signature

A fresh key for every transaction.

A one-time key must sign exactly once. So every Rotor transaction signs with the current key and, in the same step, switches the vault to the next one.

All keys come from your 24 words, so backup and recovery stay simple. On-chain reservations make sure two of your devices can never use the same key at once.

04
No key to steal

Your vault has no private key at all.

Funds live in a program-owned vault on Solana. There’s no elliptic-curve key behind it to crack, steal or phish. The only way in is a valid hash signature from your device.

Solana fees still need an ordinary key, so a tiny gas wallet pays them. It holds pocket change and has no power over your funds.

Built for the
quantum era

0
Private keys in your vaultFunds sit in a program-owned vault. There is no elliptic-curve key for a quantum computer to crack.
1
Fresh key per transactionEvery transfer is signed with a one-time key, which is then retired forever on-chain.
2128
Quantum operations to forgeSignatures rely only on SHA-256. Even Grover's algorithm leaves 128-bit security.
The quantum threat

Every normal wallet is already exposed

Quantum computers running Shor’s algorithm can turn a public key into its private key. On Solana your address is your public key, published for anyone to collect today and crack tomorrow. Rotor never relies on that math.

Regular walletRotor vault
Signature schemeEd25519 (elliptic curve)Winternitz one-time (SHA-256)
Shor's algorithmRecovers the private key from the addressDoesn't apply: no curve, no group structure
Public key on-chainYour address is your public keyOnly a hash commitment, rotated every send
Key reuseSame key for yearsEach key signs exactly once
If ed25519 breaksFunds can be takenVault funds stay locked to your hash keys

One quantum‑safe stack
for everything you hold

Start with the wallet today. Swap, cold storage and bridging are coming, all on the same quantum-safe vault.

Live

Rotor Wallet

A quantum-safe mobile wallet for SOL, tokens and tokenized stocks.

  • Quantum-resistant signatures. Every transfer is signed with a SHA-256 Winternitz one-time key.
  • Fresh key every time. Your key rotates on-chain after each send. Your address never changes.
  • Stocks & tokens. Live prices, charts and history for SOL, SPL, Token-2022 and xStocks.
  • Familiar & simple. 24-word or private-key backup, Face ID, light and dark mode.
Open Rotor Wallet
Coming soon

Rotor Swap

Swap any Solana token at the best route, straight from your vault. No hot wallet in between.

Quantum-safe: Each swap is signed as an intent with a one-time hash key, and the minimum output is enforced on-chain.
Coming soon

Rotor Cold Wallet

Air-gapped storage for long-term holdings. Keys are created and used offline, and you sign by scanning a QR code.

Quantum-safe: Offline and quantum-safe: no elliptic-curve key ever exists, even on the device.
Coming soon

Rotor Bridge

Move assets from Ethereum and other chains straight into a Rotor vault on Solana.

Quantum-safe: Bridged funds land directly in quantum-safe custody, never in an exposed hot wallet.
How it works

Three steps to quantum‑safe custody

1

A vault with no private key

Your funds sit in a program-owned vault on Solana. Nothing can move them except the Rotor program, and it obeys only your hash signature.

2

Sign with a hash, not a curve

Your phone signs each transfer with a Winternitz one-time signature built purely from SHA-256. It's verified on-chain, in the same transaction.

3

Rotate, every single time

The program retires the key you just used and switches to the next one. All keys come from your 24 words, so recovery stays simple.

Live on the web

Get Rotor Wallet

Create a quantum-safe vault in under a minute, right in your browser. Your recovery phrase is encrypted on your device and never sent anywhere. Mobile apps are coming soon.

Open web wallet Coming soon toApp StoreComing soon toGoogle Play

FAQs

What is Rotor?

Rotor is a self-custody wallet for Solana that protects your funds against quantum computers. Your SOL, tokens and tokenized stocks live in an on-chain vault that can only be moved with hash-based one-time signatures, never with an ordinary elliptic-curve key.

Why are normal crypto wallets at risk?

Almost every wallet today (Phantom, MetaMask, Ledger) signs with elliptic-curve cryptography. A large enough quantum computer running Shor's algorithm can derive the private key from a public key, and on Solana your address is your public key, so it's already visible to everyone.

How does Rotor keep funds quantum-safe?

Funds are held by a program-derived address that has no private key. The Rotor program only releases funds when it sees a valid Winternitz one-time signature, which relies purely on SHA-256 hashing. Quantum computers get no shortcut against it. After every transaction the vault switches to a fresh key, and the old one is retired forever.

What is the gas wallet?

Solana network fees still have to be paid by an ordinary key, so Rotor keeps a tiny separate gas wallet that holds only fee money. It has no authority over your vault: if it were ever compromised, the worst case is losing a few cents of fees.

Can I use my Rotor recovery phrase in Phantom or MetaMask?

No, and you shouldn't try. Other wallets can't produce Rotor's quantum-safe signatures, so they'd open an empty, different wallet. Only ever enter your recovery phrase or Rotor private key in Rotor.

What can I hold in Rotor?

SOL, any SPL or Token-2022 token, and tokenized stocks such as xStocks. Rotor shows logos and prices for verified tokens, and you can import any token by its mint address.

What happens if Rotor the company disappears?

Your funds live on the Solana blockchain, not with us. Your 24-word phrase deterministically recreates every key, so your vault can always be recovered with the open protocol and a compatible client.