Savings with no private key.
Null is a protocol for holding Solana tokens where no private key can reach them. You deposit any SPL token into that token's pool. In return you hold a wrapped balance, such as nSOL, as a private note. Pools put their assets to work in one named yield strategy, and you spend or withdraw with proofs built only from hash functions.
The idea is simple. Today's wallets are safe only as long as nobody can turn a public key back into a private key. Null takes the private key out of the design. A pool is a program address with no key at all, and ownership of a note is proven with hashes, which have no algebraic structure for a quantum computer or a clever new algorithm to exploit.
Why now
On October 7, 2026, Ethereum Foundation researcher Justin Drake asked the industry to start planning a calm, controlled bunker mode. His concern was not quantum computers. He argued that AI-driven mathematics might find a fast classical way to recover private keys from elliptic-curve public keys, and that the worst case could arrive in months rather than years. He pointed to OpenAI's release of 722 machine-produced mathematical results as the trigger.
mathematical superintelligence is upon usJustin Drake, post on X, October 7, 2026 (reported by The Block)
Drake's practical advice was to move funds to addresses whose public keys have never been revealed, starting with large holders, without rushing. He favoured going all-in on hash-based cryptography as the way back out of bunker mode.
Vitalik Buterin added a second warning the same week. Lattice schemes such as ML-DSA, the main post-quantum replacement, may also lose concrete security as AI accelerates mathematics. His analogy was factoring: decades of work on the number field sieve took RSA from naive exponential cost to sub-exponential cost, which is why RSA keys are hundreds of bytes long. He asked whether curves and lattices hide similar shortcuts that machines will find first.
Hash-based > lattice-based, in those situations where hash-based is possible at allVitalik Buterin, October 2026
How Null maps to that advice
| Advice | From | What Null does |
|---|---|---|
| Keep funds where no public key is exposed | Drake, Buterin | Pools are program addresses with no private key. Notes reveal no key. |
| Prefer hash-based signatures and proofs | Drake, Buterin | Spends use WOTS+ keys and hash-based STARK proofs. No curves, lattices or pairings inside. |
| Keep encrypted notes off the chain | Buterin | Null writes no ciphertext onchain. Notes are rederived or delivered offchain. |
| Be paranoid about lattice parameters | Buterin | Where encryption is unavoidable, Null uses hybrid encryption at the largest parameter set. |
| Confirm multisig actions offchain | Buterin | Governance gathers hash-based signatures offchain and submits one transaction. |
| Do not rush migrations | Drake, Buterin | One deposit per asset. No bridges, no new wallet software for the deposit itself. |
Null is not affiliated with either researcher, and neither has reviewed or endorsed it.
Threat model
Null plans for three kinds of attacker.
- Q-day. A large quantum computer runs Shor's algorithm and recovers any private key from its curve public key.
- AI-day. A new classical algorithm, possibly found by AI, does the same on ordinary hardware. Drake's working definition was key recovery in about a week on a large GPU cluster.
- Ordinary attackers. Bugs, phishing and stolen admin keys, which remain the most common way money is lost.
Why Solana holders cannot just use a fresh address
On Bitcoin and Ethereum, an address is a hash of the public key, so an unused address keeps the key hidden. That is the trick Drake recommends. On Solana, the address is the public key. Every Ed25519 account shows its key from the moment it exists, so there is no unused-address hiding place. The only Solana accounts without a recoverable key are program-derived addresses, which are built to sit off the curve. Null keeps every token in one of those.
What one algorithmic idea can do
The chart shows the work needed to factor an RSA modulus, before and after the general number field sieve. The same key size lost most of its security to better mathematics, without any new hardware. This is the kind of jump Null assumes could happen to structured problems.
Sieve curve uses the heuristic cost LN[1/3, (64/9)1/3] with the o(1) term dropped, so values are estimates. The dashed line marks 128-bit security. At 2,048 bits the naive bound gives 1,024 bits of work and the sieve about 117.
What Null protects, and what it does not
| Asset | Q-day | AI-day | Notes |
|---|---|---|---|
| Tokens inside a pool | Safe | Safe | Needs a break of the hash function or the proof system. |
| Your note's privacy | Safe | Safe | No ciphertext onchain to decrypt later. |
| Tokens still in your wallet | At risk | At risk | Deposit them, or accept the risk. |
| Tokens after withdrawal | At risk | At risk | They land at a normal Ed25519 address. |
| Yield strategy positions | Inherited | Inherited | Depends on the strategy protocol's own admin keys. See Yield. |
Primitives
Every scheme below rests on some mathematical assumption. Curves and lattices rely on problems with rich structure, which is what makes them compact and also what an attacker studies. Hash-based schemes rely only on the hash being hard to invert or collide. Null's rule is to use hashes wherever Solana allows it.
Sizes from NIST FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA, the standard form of SPHINCS+) and the Falcon specification. WOTS+ shown with n = 32 bytes and w = 16 (67 chains). The striped bar is a hypothetical ML-DSA-44 grown tenfold, following Buterin's suggestion to multiply structured key sizes by ten for long-term safety.
Which hash
Null uses SHA-256 and BLAKE3, both of which Solana exposes as native syscalls. It deliberately avoids algebraic hashes such as Poseidon for v0. They make zero-knowledge proofs much cheaper, but they are built from field arithmetic, which is exactly the kind of structure this design is trying to stay away from. Proving costs more as a result, and Null accepts that cost.
| Primitive | Assumption | Known structure | Used in Null |
|---|---|---|---|
| Ed25519 / ECDSA | Discrete log on a curve | Group law, Frobenius, pairings on some curves | Only where Solana requires a fee payer |
| ML-DSA, Falcon | Module-LWE / NTRU lattices | Lattice geometry, ring structure | No |
| ML-KEM | Module-LWE | As above | Only for offchain note delivery, hybrid, largest parameters |
| WOTS+, SPHINCS+ | Hash preimage and second preimage | None known | Spend keys, governance |
| STARK (FRI) | Hash as a random oracle | None known | Spend and withdraw proofs |
Architecture
A deposit crosses the curve-keyed world exactly once. Everything inside the dashed boundary is controlled by hashes.
Arrows show the path of tokens. The fee payer signs transactions but never holds funds or authority.
Pools
Each SPL mint gets one pool. The pool's token account is owned by a program-derived address with the seeds ["pool", mint]. Program-derived addresses are chosen to lie off the Ed25519 curve, so no private key for them exists. The Null program moves tokens out only when it verifies a valid spend proof and a nullifier it has not seen before. Anyone can open a pool for a new mint. Pools without a strategy simply hold the tokens.
Notes
Your balance is a note: the commitment H(mint, shares, owner_root, salt) stored as a leaf in the pool's Merkle tree. A note records pool shares, not a token amount, so yield raises the value of every note at once without touching any of them. The wrapped symbol, such as nSOL, is the name for one share of that pool.
Hash keys
The note's owner is the Merkle root of 1,024 WOTS+ one-time public keys. Your bunker key, a 256-bit secret, generates them through a hash-based key derivation. Each spend must carry a WOTS+ signature over the spend's details from an unused leaf, checked inside the proof. This splits two powers: a device that knows your notes can show balances and build proofs, but only the holder of the signing keys can move funds. When a tree runs low, the app moves your notes to a fresh tree in the same transaction as a spend.
Passkeys and the Recovery Kit
Null does not use a seed phrase. When you create a bunker, your device generates a bunker key: 256 random bits that are only ever fed into hash functions. Grover's algorithm can at most halve that strength, which still leaves 128-bit security.
You use the key in two ways. Day to day, a passkey unlocks it. Null asks the passkey for a secret through the WebAuthn PRF extension, which the authenticator computes with HMAC-SHA-256. That secret encrypts your bunker key on the device with AES-256-GCM. Null never uses the passkey's own signature, which relies on elliptic curves, so nothing about your funds depends on it. For backup, the Recovery Kit is a printable page with the bunker key as 56 characters and a QR code. Restoring from it rebuilds the same key tree on any device.
Approvals add a second layer: a bunker set to 2 of 3 needs another device or person to sign off, so one unlocked phone cannot move funds alone.
Spending
A spend, transfer or withdrawal publishes a STARK proof that shows, without revealing which note is involved:
- The input note is a leaf under a recent tree root.
- The nullifier equals
H(note_secret, leaf_index), so the note can be spent only once. - A valid WOTS+ signature from the owner's key tree covers the recipient, amount, fee and relayer.
- Output shares plus the withdrawal equal the input shares.
A STARK proof is larger than one Solana transaction and needs more compute than one transaction allows. Null verifies it in stages: the proof is written to a buffer account across several transactions, and a final transaction checks the result and releases funds.
Relayers and fee payers
Solana requires an Ed25519 signature from whoever pays the fee. Null hands that role to a relayer or to a throwaway key the app creates for one transaction. Because the proof binds the recipient, amount and fee, the fee payer cannot change where the tokens go. If someone recovers that key, they find an empty account with no authority.
Note delivery
Following Buterin's advice, nothing encrypted goes onchain. Notes you create for yourself are rederived from your bunker key and the public tree, so they need no encryption. Notes you send to someone else travel offchain through a relay, encrypted with a hybrid of X25519 and ML-KEM-1024. If that encryption ever breaks, the attacker learns about one transfer, and still cannot spend it without the recipient's hash keys.
Privacy
Inside a pool, nobody can tell which note belongs to whom, how much it holds, or which deposit a withdrawal came from. Transfers between Null users happen entirely inside the pool. Your privacy grows with the number of notes in the pool, called the anonymity set.
What stays public
- Deposits: the wallet, the token and the amount.
- Withdrawals: the destination address, the token and the amount.
- Timing of every transaction and which pool it touches.
- Your IP address, if your RPC provider logs it.
Good habits
- Withdraw an amount that differs from what you deposited, and wait between the two.
- Withdraw to a new address each time, and use a relayer.
- Use your own RPC endpoint or a network privacy tool.
Yield
Each pool runs one strategy and holds the positions through its own program-derived address. Rewards are added to the pool, which raises the token value of one share. Rates below come from each strategy's own venue, via DefiLlama and Kamino.
| Pool | Strategy | APY | Liquidity | Source |
|---|---|---|---|---|
| nSOL | Liquid staking via the Jito stake pool | 4.82% | $1.13B | DefiLlama |
| nUSDC | Lending, Kamino Main Market | 4.46% | $123.1M | Kamino API |
| nUSDT | Lending, Kamino Main Market | 4.49% | $11.1M | Kamino API |
| nPYUSD | Lending, Kamino Main Market | 4.67% | $34.5M | Kamino API |
| nUSDG | Lending, Kamino Main Market | 4.36% | $40.9M | Kamino API |
| nJitoSOL, nmSOL | Held; staking yield accrues inside the token | 4.82%, 4.74% | — | DefiLlama |
| nJUP, nJTO, nRAY, nORCA, nPYTH, nWIF, nBONK | None, held for protection only | 0.00% | — | — |
Governance
The Null program's upgrade authority belongs to a governance address, not a person. Changing the program or a pool's strategy needs a threshold of SPHINCS+ signatures from the signers, verified onchain, followed by a 14-day timelock so holders can leave first. Signers collect signatures offchain and submit one transaction, so their individual keys never appear onchain.
Governance can pause deposits. It cannot pause withdrawals or move funds. The long-term plan is to remove the upgrade authority entirely once the code is audited and stable.
Limits
- The edges still use curves. The wallet you deposit from, the fee payer and your withdrawal address are ordinary Ed25519 accounts. Null protects what is inside the pool.
- Hash keys are stateful. Signing twice with one WOTS+ key leaks it. Using the same bunker key on two devices at once can cause reuse, so the app tracks used leaves onchain and refuses a leaf that is already marked.
- Passkey support varies. Deriving keys from a passkey needs the WebAuthn PRF extension, which recent Chrome, Edge and Safari support. Elsewhere the Recovery Kit is the only way in. Roaming security keys exchange the PRF secret with the browser over an elliptic-curve channel, so someone would have to record that local exchange and later break the curve to learn it.
- Proof costs. Hash-only STARKs are large and slow to verify on Solana.
- Small anonymity sets early on. Privacy is weak until pools hold many notes.
- Strategy risk. Yield depends on outside protocols and their keys.
- Hashes can fail too. A break of SHA-256 or BLAKE3 would break Null. Buterin noted that if worry about hashes grows, adding rounds is the first response. Null's hash choice can change through governance.
- Regulation. Privacy pools and yield products face legal scrutiny in many places. Check the rules where you live.
FAQ
Is Null quantum-proof?
Tokens inside a pool depend only on hash functions and hash-based proofs, which are not known to be weak against quantum computers beyond a square-root speedup that 256-bit hashes absorb. Nothing is proven secure forever, and the edges listed above still use curves.
Is nSOL a token I can trade?
Not as a normal SPL token. Turning it into one would put it back in a curve-keyed account, which defeats the point. nSOL is a share of the pool held as a note. You can send it privately to another Null user or withdraw the underlying SOL.
Why not 24 recovery words?
A seed phrase is just a secret written as words, and it is the thing most often phished. Null keeps the same strength, a 256-bit secret, but you unlock it with a passkey and back it up as a Recovery Kit you print and store offline.
What if I lose my phone?
Restore the bunker on another device from your Recovery Kit, then add a new passkey. If your passkey syncs through iCloud Keychain or Google Password Manager, your other devices can unlock it too.
What if I lose my Recovery Kit?
If your passkey still works, unlock your bunker and download the kit again from Settings. If you lose both, nobody, including the Null team, can recover your notes.
Can Null freeze my funds?
No. Governance can stop new deposits, but the program always accepts valid withdrawals.
Why Solana?
Solana's addresses expose public keys from day one, so its holders have the most to gain from a key-free design. Its native hash syscalls also make hash-based verification practical.
Sources
- The Block: Justin Drake calls for bunker mode planning (Oct 7, 2026)
- Decrypt: Ethereum researcher says AI may break encryption before quantum
- Blockonomi: Buterin warns AI could break lattice cryptography faster than expected
- TokenPost: Buterin warns AI could weaken lattice-based cryptography
- The Quantum Insider: Solana Winternitz vault (Jan 2025)
- NIST FIPS 204: Module-Lattice-Based Digital Signature Standard
- NIST FIPS 205: Stateless Hash-Based Digital Signature Standard
- Project Eleven: Bitcoin Risq List