Skip to content
Connect wallet

How Hashlock seals a coin

A launch puts the coin's creator fees and dev buy in a vault. Only a hash-based signature, checked by the vault program on Solana, can move them out. This page shows what happens and what you can verify.

A launch, step by step

You connect a Solana wallet (Phantom, Solflare, Backpack or any other). Every transaction is signed by your own wallet, in two prompts for a sealed launch.

  1. Create your vault

    Your browser generates a 24-word recovery phrase and turns it into 1,024 one-time keys (WOTS+ with SHA-256, in a Merkle tree 10 levels deep). You write the words down and confirm three of them. Only the tree's 32-byte root goes on chain, in a vault account the program creates for you. The phrase is never sent anywhere, including our server. You create a vault once and reuse it for every coin.

    If you would rather not keep a phrase, you can derive the keys from a wallet signature instead. That mode is labelled not post-quantum, because whoever controls that wallet key can rebuild the vault keys.

  2. Launch and record

    Your wallet approves the launch and its vault record in one prompt. The launch creates the coin on pump.fun and makes your dev buy, with your wallet as the creator. Once it lands, the vault program writes a launch record that links the coin to your vault, signed with your next one-time key.

  3. Seal it

    A second prompt locks pump.fun fee sharing for good: your share of creator fees () goes to your vault and to Hashlock's platform wallet. The same prompt moves the dev buy tokens into the vault. The coin page shows the Sealed badge once the launch record exists. Until this step lands, every page reminds you to finish it.

What gets sealed

Sealed: the creator's share of the coin's fees, in any quote pump.fun supports (SOL, USDC, tokenized stocks, pump coins), and the dev buy tokens.

Not sealed: Hashlock's share, which the flywheel spends.

Sealed

How a hash-based key works

Hash-based signatures rest on one assumption: that SHA-256 cannot be run backwards. No known quantum algorithm breaks that, which is why they count as post-quantum. Elliptic-curve keys like Ed25519 do not have that property.

One key is a set of hash chains

A WOTS+ secret key is 67 random values. Hash each one 15 times and the ends of those chains are the public key. To sign, the signer reveals a point partway along each chain, picked by the message. A verifier hashes from each revealed point to the end of its chain and checks the ends match. Revealing points for a second message would leak too much, so each key signs once.

Six of the 67 chains, each 16 steps long. The message decides where each signature point sits.

1,024 keys under one root

Your vault holds 1,024 one-time keys. Their public keys are hashed in pairs, then pairs of pairs, ten times, down to one 32-byte root. The vault stores only that root and the index of the next unused key.

A withdrawal carries the WOTS+ signature, the one-time public key's position in the tree, and the 10 hashes beside its path. The program rebuilds the one-time public key from the signature, hashes up the path, and compares the result with the stored root. If it matches and the key has not been used, the funds move and the index goes up by one.

Check it on Solscan

Every claim above sits in a public account. From any coin page, the Sealed badge links to the coin's vault. Then check these, in order.

The vault account
Owned by the Hashlock vault program. Its data holds the Merkle root, the tree height (10) and the next key index. A fresh vault shows index 0.
The launch record
An account of the same program that names the coin's mint, its fee-sharing config and the vault. It is what the Sealed badge reads.
The fee-sharing config
pump.fun's fee-sharing account for the coin. Its recipients are the vault (the creator's share) and Hashlock's platform wallet (, shown as basis points). It is locked, so nobody can change the split later.
The dev bag
The token account holding the dev buy. Its owner is the vault, not the creator's wallet.
Withdrawals
Each one is a transaction to the vault program. The key index rises by one per withdrawal, so you can count how many one-time keys a vault has spent.
The coin's metadata file also carries a WOTS+ signature over the launch, so tools that look for one find it. That file is not the proof. Nothing on chain reads it. The proof is the accounts above.

The flywheel and fees

Every coin on Hashlock feeds the flywheel: of its creator fees goes to one platform wallet. Every 15 minutes, or when a creator claims, Hashlock sweeps each coin's fees and spends its share.

A coin's creator fees

Each buy and each burn is a public transaction on the $HASHLOCK mint. Until $HASHLOCK is live, the share collects and waits. pump.fun's own trading fees apply as usual and are set by pump.fun.

Seal tokens you hold

You do not have to launch to use a vault. Open one and deposit any token you hold. Taking it out needs a WOTS+ signature from your vault keys, checked on chain, the same as a creator's fees.

The Q-day switch

A vault can name a successor mint for a coin it launched. The record is written on chain and shows on the coin page, so if Solana ever needs to move to post-quantum accounts, holders can see in advance where the coin is meant to go. Claiming a successor comes in a later release. The slot exists now so the record can be made early.

The program and your way out

Who can change the vault program. A program that can be upgraded could have its signature check replaced, so this is stated live:

If Hashlock is ever offline. Your vault does not depend on this site. The recovery page withdraws with only your 24 words, a Solana RPC and a wallet, and it can be saved to your disk as one file (download it).