Skip to content
LAMPORT

Guide · Paper

How $LAMPORT protects itself.

Start with the plain-English guide. When you want the proofs, switch to the paper.

1.What $LAMPORT is

$LAMPORT is the first Solana token that protects itself. Every transfer runs through a transfer hook that checks for a second, quantum-proof key, so even if someone steals your wallet key, through a hack, a leaked seed phrase or a future quantum computer, they still can’t move your bag. You hold it like a vault and trade it like any other memecoin.

The short version: $LAMPORT is a Solana token with a bodyguard built in, a transfer hook that blocks any transfer without your quantum-proof second key, so a stolen wallet key can’t touch your bag.

2.One key opens everything

Today a Solana wallet has one key. Whoever has it can move everything, however they got it: a phished seed phrase, a malicious approval, a screenshot in the cloud, an AI-found math shortcut, or one day a quantum computer. The chain checks the signature, not the person.

3.A rule the token carries everywhere

$LAMPORT is a Token-2022 token with a transfer hook. Every time anyone moves it (a send, a sell, a swap, a drainer’s sweep), Solana automatically asks the Lamport hook “is this allowed?”. If the hook says no, the whole transaction fails. Nothing moves.

4.Arming adds a second lock

When you arm your bag, your browser creates a second key built only from hashes (quantum computers can’t fake it) and registers its public part with the hook. From then on your $LAMPORT needs two things to move: your wallet signature and proof from the second key.

Lock 1 · wallet signature (ed25519)
Lock 2 · second-key proof (hashes)
→
The hook checks both
→
both present → transfer passes
signature only → blocked
Fig. 1 — Two locks. The wallet key alone no longer opens an armed bag.

5.Daily use

You click Send or Swap as usual. The app attaches the second-key proof for you in two quick steps: it announces the transfer, waits about two seconds, then reveals the proof and moves the tokens. One button, both steps.

6.If your wallet key is stolen

The thief can sign, but can’t produce the proof. The hook sees a wallet signature without second-key proof and rejects the transfer. Because the second key is kept separate from your seed phrase, this already protects you from ordinary seed-phrase leaks and drainers today, not just from future quantum computers.

7.The Quick Key: one-time passwords that check themselves

Your everyday second key is a stack of one-time passwords. A secret is hashed thousands of times and only the final result is registered. Each transfer reveals the link just before it, and the hook hashes that link once to check it matches. Hashes are one-way, so nobody can work backwards from what is public to what comes next.

The two steps (announce, then reveal) stop anyone from copying a password mid-flight: by the time a link is visible, it has already been used. Try it yourself in the Quick Key toy.

8.The Master Key

The Master Key is a heavier quantum-proof signature (WOTS/XMSS) with 1,024 one-time uses, kept for rare actions: turning protection off, resetting the Quick Key when it runs low, and cancelling a recovery. You will rarely touch it, so keep its backup somewhere safe and separate.

9.If you lose your second key

You can disarm with only your wallet, but it takes 7 days, and your second key can cancel it at any time during those 7 days. That means a thief with only your wallet key can start the clock, and you can stop it.

Day 0 · request with wallet keyDays 0–7 · cancel with Quick or Master KeyDay 7 · protection off
Fig. 2 — The 7-day recovery. Either second key can cancel until the timer runs out.

10.Trading still works

Liquidity pools are program-owned accounts with no private key, so the hook lets them through. That means buying works from any app. Holders who haven’t armed trade like any normal token, and armed holders sell through the $LAMPORT app, which adds the proof to the swap automatically.

11.The honest limits

  • Unarmed holders are as exposed as with any token. Protection is opt-in.
  • Armed transfers take one extra quick step (about two seconds).
  • Someone with a leaked wallet key can still burn armed tokens (burns don’t trigger hooks), though they can never take them.
  • The protection covers $LAMPORT only. SOL and other tokens in the same wallet are not protected (yet).
  • If your wallet key is stolen and you have lost both second-key backups, you can’t stop a recovery request. Keep the backups.

12.What’s next

The Lamport Hook standard lets any new token plug in the same hook, with one arming setup protecting every Lamport-hooked token you hold. Armored wrappers turn SOL, USDC or any SPL token into a hook-protected qSOL or qUSDC, 1:1. And $LAMPORT becomes the platform token: fees from hooked launches and wrappers feed buybacks.

$LAMPORT is not affiliated with or endorsed by Leslie Lamport.