Ethereum researchers call for a bunker mode as AI speeds up cryptanalysis. Read why it matters

Keep your tokens out of reach of quantum

Null moves your tokens into hash-locked pools on Solana. No private key controls a pool, so there is no key for a quantum computer or a new algorithm to recover. Your balance stays private and keeps earning.

Rates come from each pool's strategy, sourced from DefiLlama and Kamino. See all 224 tokens

Supported tokens

224 tokens.
One pool each.

From SOL and stablecoins to staked SOL, DeFi, DePIN and memes. Every token gets its own hash-locked pool, and the ones with a safe strategy earn yield.

Our thesis

Money with no key to steal.

Every Solana wallet is guarded by an elliptic curve, and its address is the public key itself. There is no unused address to hide behind. Anyone who can run the math backwards owns the account. Null removes the key from the picture. Pools answer to a hash, and hashes have no structure to attack.

0
private keys control a Null pool. Each pool is a program address that sits off the curve.
1
primitive authorizes every spend: a battle-tested hash function.
64 B
is all that guards a normal Solana or Bitcoin account: one curve signature.
14M+
Bitcoin addresses already hold funds behind an exposed public key, per Project Eleven.
How it works

Three moves into the bunker.

Your wallet signs once, on the way in. After that, your tokens live as a private note that only your hash keys can spend. Take out only what you need to use.

01

Deposit any SPL token

Send tokens from your wallet into the pool for that asset. This is the last time your wallet's curve key matters for these funds.

from 7xKX…q9Fd (Ed25519, last use)
to pool PDA ["pool", SOL]
amount 120.00 SOL
02

Hold a private note

You get a wrapped balance, nSOL, as a note in the pool's commitment tree. The chain sees a hash. Your yield accrues to the pool and to your note.

note H(asset, amt, owner, salt)
owner root of 1,024 one-time keys
onchain commitment only
03

Withdraw what you spend

Prove ownership with a hash-based proof and publish a nullifier. A relayer pays the fee, and the tokens land at a new address with no link to your deposit. The rest stays in the pool.

proof STARK (hash-only)
nullifier 3be1…07fa spent once
to new address, unlinked
The design

Built from hashes, end to end.

Signatures and proofs can already be built from hashes alone. Null uses them everywhere a key used to sit, and keeps curve cryptography only at the edges where Solana still requires it.

authorityPDA("pool", mint)
private keynone · off-curve
spend rulevalid proof + new nullifier
upgradeshash multisig + 14d timelock

Hash-locked pools

One pool per token. The program owns the vault through an address with no private key, so nothing exists to be recovered.

your notec1 · hidden among every note

Private notes

Balances live as commitments in a Merkle tree. Spending reveals a nullifier, never which note it came from.

SOLJito liquid staking · 4.82%
USDCKamino lending · 4.46%
PYUSDKamino lending · 4.67%
JUP, BONK, WIF…no strategy · 0%

Yield you can trace

Each pool runs one named strategy. Rewards flow back into the pool, so every note grows by the same rate.

keys per tree1,024 · each signs once

One-time hash keys

Your spending keys are Winternitz one-time keys under one Merkle root. Each signs once, then retires.

fee payerephemeral key · holds 0 tokens
authorizationhash proof bound to recipient
if fee key breaksnothing to take

Relayed spends

Solana needs a curve signature to pay fees. Null gives that job to a throwaway key that never holds your funds.

encrypted notes onchain0
self-depositsrederived from your secret
transferssent offchain, oversized params

Notes stay offchain

Nothing encrypted is written to the chain, so a future break in public-key encryption cannot reopen your history.

Why now

The people building the roadmaps are worried.

In the first week of October 2026, two of Ethereum's best-known researchers warned that AI-driven mathematics could break curve cryptography before quantum computers do.

mathematical superintelligence is upon us

Drake asked holders to plan a calm move to addresses that have never signed, and argued that elliptic curves carry more structure for AI to exploit than hashes do.

Justin DrakeEthereum Foundation researcher · Oct 7, 2026Coverage ↗
Hash-based > lattice-based, in those situations where hash-based is possible at all

Buterin warned that lattice schemes may also lose security to AI-assisted math, and recommended keeping encrypted notes off the chain and funds in unused addresses.

Vitalik ButerinEthereum co-founder · Oct 2026Coverage ↗

Quoted from public posts. Neither person is affiliated with Null or endorses it.

Compared

What guards your tokens.

Post-quantum wallets swap one structured problem for another. Null avoids structured assumptions wherever the chain allows it.

Normal walletLattice PQ walletNull
Spend authorized byEd25519 / ECDSA signatureML-DSA or Falcon signatureHash-based proof
Public key exposed onchainAlways. On Solana the address is the keyYes, once it signsNever. Only commitments and nullifiers
Mathematical structure an attacker can work withGroup law, pairings, FrobeniusLattice geometry (LWE, SIS)None known beyond generic search
Exposed to Shor's algorithmYesNoNo
Exposed to a new classical algorithmPlausiblePlausibleNeeds a break of the hash or a flaw in the proof system
Balance visible to the worldYesYesNo
Bunker mode

Move calmly. Move once.

Botched migrations can cost more than hacks. Null is one deposit per token, one private note, and withdrawals whenever you need them.