Concepts
Threat model
What an Ed25519 wallet assumes, why a published key is permanent, and what Shor and Grover change.
What a Solana wallet is
A Solana account is an Ed25519 keypair. The private key is a scalar . The public key is a point on Curve25519,
where is the curve’s base point. Recovering from is the elliptic-curve discrete logarithm problem. On classical hardware it costs about operations, which is why it holds today.
The address is the public key
A Solana address is not a hash of the key. It is the 32-byte encoding of itself. The moment an address appears on chain, whether it signed or only received, its public key is public, and it stays public. There is no later date at which you can decide to stop having published it.
Shor and Grover
Shor’s algorithm solves the discrete logarithm problem in polynomial time on a large enough quantum computer. It reads off . It does not weaken Ed25519. It removes it.
Grover’s algorithm is the quantum attack on a hash. For an -bit hash it finds a preimage in about evaluations instead of . For SHA-256:
A search is out of reach of anything physical. That asymmetry is the whole design. metaspace moves the one assumption from the first row of this table to the second.
| Primitive | Problem | Classical | Quantum |
|---|---|---|---|
| Ed25519 | Discrete logarithm on Curve25519 | Polynomial time (Shor) | |
| SHA-256 | Preimage | (Grover) |
What a multisig does and does not do
A multisig mitigates key theft, which is the common failure. It mitigates nothing here. Five Ed25519 keys fail the same way one does, at the same time, for the same reason. A hardware wallet protects the key from the computer, not from the mathematics. Moving funds to a fresh address publishes a fresh key as soon as the address is used.
What a vault does not protect against
- Theft of the seed. Whoever holds the twelve words holds the vault.
- A client that reuses a one-time key. See Rotation.
- A compromised client that signs a digest the owner did not intend.
- A bug in the verifier. Every property in Security model is conditional on the verifier being correct.