latch off the default
Nothing is different. Buy, sell and send like any other coin. Nobody can turn the latch on for you.
If AI or a quantum computer ever learns to crack Solana wallet keys, whoever cracks yours can take everything in it. Latch puts a second lock on this coin that a cracked key can't open. Turn it on, and your tokens stay put even if your wallet key doesn't.
program 8jAukWNHrzpaFe3cqMCnNF2aCJLWpHdLodBxFPmhuAmPdevnet · not yet immutable
for the technical · the precise version
Latch is a Token-2022 transfer-hook program. A holder opts in by committing, to a PDA seeded by their token account, the Merkle root of 2h Winternitz one-time public keys (W-OTS, w = 16, SHA-256, 67 chains; h = 10 by default). From then on, Token-2022's mid-transfer CPI into the hook requires a single-use authorization whose digest, SHA-256("qlh:xfer" ‖ mint ‖ source ‖ destination ‖ amount ‖ nonce), is recomputed from the live transfer and consumed on use. Authority over a latched balance therefore reduces to the one-wayness and second-preimage resistance of SHA-256, not to the discrete-log hardness of Ed25519. An ECDLP break, by Shor or by an undiscovered classical algorithm, yields signatures but not transfers.
This is the reviewed build, deployed on devnet at the address above and run against every finding of the review there. The pre-review program was closed.
the problem
On 7 October, Ethereum researcher Justin Drake warned that AI might find a shortcut for working out a wallet's private key from its public key, in months rather than the decades quantum computers were expected to take. Nobody has done it yet. But if it happens, every wallet whose public key is known can be emptied.
how it works
Nothing is different. Buy, sell and send like any other coin. Nobody can turn the latch on for you.
Selling or sending takes one code, which this site supplies for you along with one wallet approval. Buying never needs a code. Nobody else can move your tokens, even with your wallet key.
live · in your browser
Type a transfer and sign it with a one-time key. Your browser just made 1,024 of them with the same code the holder app uses; nothing leaves this page. Each of the 67 chains is SHA-256 applied over and over: the signer walks up to the digit of the transfer's digest, the checker walks the rest of the way, and every chain has to land on the key the fingerprint on chain commits to.
digest
scroll the picture sideways to see all 67 chains and the path to the root.
Then change the amount by one. The signed code stays put and the picture shows what a thief would need: every red chain has to run backwards, which means inverting SHA-256.
the attack
Say an AI shortcut, a quantum computer or a plain leak hands someone your wallet key. They can sign anything as you. Play the thief: below are the moves, run against the real program on devnet.
you hold the key for 94vgMa…cdze, the wallet from the run. reading its latch…
Each try is built as the real transaction, signed as that wallet, and run by devnet itself with signature checks off. Nothing is sent.
If you think your key leaked: send, don't sell. A sale pays SOL into your wallet, and whoever has your key can take it from there. Move the latched tokens to a fresh wallet first: the send is bound to that wallet, so nobody can redirect it.
Two things the latch can't fix: someone who gets your recovery words, or your device or backup file plus the passphrase, has your codes too, and the latch has to be on before keys can be cracked. After that, someone who can forge your key could turn on a latch of their own first.
use it · devnet
Connect a wallet to latch, send, sell and lift from this page. Or look any wallet up without connecting.
When latched: you enter the passphrase, this page signs with your next one-time key, and the wallet approves the three uploads and one transaction that authorizes and sends, so the authorization is used the moment it lands.
The pool is filled in with the devnet test curve. When latched, the sell is authorized to the pool's vault for exactly this amount first.
Buying never needs the latch. One wallet approval.
Your seed is generated and used only on this page. It is kept in this browser's storage, sealed with your passphrase, and backed up the way you choose: 24 words you write down, or a backup file. The server builds unsigned transactions from public data and never sees a key. Before your wallet is asked, this page checks each one against what you typed and refuses anything else; every transaction is signed by your own wallet. A browser is a weaker home for a seed than an encrypted file on your own disk, so large balances are better served by the command line. Try the run's wallet without connecting: .
proof · devnet · 2026-10-08 · 16:30 mdt
The whole flow, done for real on Solana's test network: launch the coin, buy, sell, turn the latch on, try to sell without a code (refused), then sell with one. Every line opens in Solana Explorer.
latch on: 256 one-time signatures registered3cXkwk…rPBg
transfer authorized with one-time key 02QQdjY…FNFX
authorized with one-time key 14yAQHY…rQ8e
details
| Account | Seeded by | Holds |
|---|---|---|
| Latch | Token account | Owner, Merkle root, height, next leaf, nonce |
| Auth | Token account | One pending digest and nonce, single use |
| Scratch | Token account | Signature upload buffer |
| Extra metas | Mint | Tells Token-2022 to hand the latch and auth accounts to the hook |
# Is my account latched, how many keys remain qlh status --mint MINT # Drop the latch: 1,024 one-time signatures qlh lock --mint MINT # Send or sell: authorizes first when latched qlh send --mint MINT --to WALLET --amount N qlh sell --mint MINT --pool POOL --amount N # Buying needs nothing special qlh buy --mint MINT --pool POOL --sol X # Lift the latch: spends one key qlh unlock --mint MINT
The client reads the live key index and nonce from the chain before every signature, so a stale local file cannot burn a key. Flags: --keypair, --rpc, --program, or the QLH_KEYPAIR, QLH_RPC and QLH_PROGRAM variables.
log