What a shelter is, and what it is not.
In October 2026 Justin Drake asked the industry to plan for “bunker mode”: the day the signature schemes behind crypto wallets stop being safe, whether a quantum computer gets there first or an AI finds a shortcut through the math. On Solana that bites hard. An address is its ed25519 public key, so there is no hiding a key that has never been used. If the curve falls, every wallet falls with it.
Shelter is a small, honest answer: put value somewhere no curve key can reach.
The shelter
A shelter is an account owned by the Shelter program at a program-derived address. Program addresses have no private key at all, so there is nothing to steal, crack or phish. The program moves funds out for one reason only: a valid Winternitz one-time signature.
- Winternitz signatures are built from SHA-256 and nothing else: 30 hash chains of 255 steps. Breaking one means inverting SHA-256. Shor’s algorithm does not apply, and no discrete-log shortcut helps.
- Each key signs once. Every signature also names the hash of the next key, so the shelter rotates on every spend and a used key is worthless.
- All keys come from one 24-word secret that only your browser ever sees. The server sees key hashes and finished signatures.
- Spending takes two steps:
authorizechecks the signature on chain and records the exact action;executecarries it out. Anyone can submit either, so we pay the fees for you. The signature is the authority, not the fee payer.
Coins
Every coin launched here is a Meteora Dynamic Bonding Curve pool. In the launch transaction the pool’s creator seat is handed to the coin’s shelter, and the program refuses to open the shelter unless the pool sends every trading fee and all graduated liquidity to it, in SOL, with a fixed supply and no freeze authority.
| Trading fee | 1% or 2%, chosen at launch (99% for the first 20 seconds, so snipers pay the shelter) |
|---|---|
| Who collects | Anyone. The engine does it every few minutes; the fees are unwrapped into plain SOL inside the shelter |
| Split | 80% stays in the coin’s shelter for its creator, 20% goes to the Shelter platform shelter |
| Graduation | At about 85 SOL raised, to Meteora DAMM v2. 100% of the LP is locked forever and its fees keep flowing to the shelter |
| Creator withdraws | With the 24 words saved at launch, to any address, no wallet needed |
What it does not do
- It cannot save Solana from itself. Validators, the token program and every user wallet still use ed25519. If the curve breaks for real, the chain itself needs a fix, which is Anza’s job, not ours. A shelter is the part of your value that no cracked key can move while that happens.
- The coin itself is still a normal SPL token. Holding the coin in your Phantom wallet is exactly as safe as Phantom. Put it in a personal shelter if you want it behind a hash key.
- Lose the words, lose the shelter. There is no recovery, no admin and no backdoor. That is the point.
- One key, one message. Signing two different withdrawals with the same key number would weaken it. This site remembers what each key signed and will only ever resend that.
- Fees waiting inside Meteora are Meteora’s risk until collected, which happens every few minutes.
- Upgradeable until frozen. The program’s upgrade key is itself an ed25519 key. Before real money goes in, the program is made immutable; until you see that on Solscan, treat it as experimental.
- Tokens with transfer hooks cannot be withdrawn from a personal shelter. Use plain SPL tokens and SOL.
The numbers
| Signature | WOTS, w = 256, SHA-256 truncated to 224 bits, 28 message + 2 checksum chains, 840 bytes |
|---|---|
| Security | about 112 bits against a quantum attacker (Grover), more classically |
| Verification | on chain, about 600–700k compute units, in one transaction |
| Program | bnkrjkAEPr2FwddcjqDfpTKmbER5wr81cXvT1p8R295 |