metaspace
Concepts / Threat model

Concepts

Threat model

What an Ed25519 wallet assumes, why a published key is permanent, and what Shor and Grover change.

What a Solana wallet is

A Solana account is an Ed25519 keypair. The private key is a scalar aa. The public key is a point on Curve25519,

A=a⋅B,A = a \cdot B,

where BB is the curve’s base point. Recovering aa from AA is the elliptic-curve discrete logarithm problem. On classical hardware it costs about 21262^{126} operations, which is why it holds today.

The address is the public key

A Solana address is not a hash of the key. It is the 32-byte encoding of AA itself. The moment an address appears on chain, whether it signed or only received, its public key is public, and it stays public. There is no later date at which you can decide to stop having published it.

Shor and Grover

Shor’s algorithm solves the discrete logarithm problem in polynomial time on a large enough quantum computer. It reads aa off AA. It does not weaken Ed25519. It removes it.

Grover’s algorithm is the quantum attack on a hash. For an nn-bit hash it finds a preimage in about 2n/22^{n/2} evaluations instead of 2n2^{n}. For SHA-256:

2256  ⟶  2128.2^{256} \;\longrightarrow\; 2^{128}.

A 21282^{128} search is out of reach of anything physical. That asymmetry is the whole design. metaspace moves the one assumption from the first row of this table to the second.

PrimitiveProblemClassicalQuantum
Ed25519Discrete logarithm on Curve25519≈2126\approx 2^{126}Polynomial time (Shor)
SHA-256Preimage22562^{256}≈2128\approx 2^{128} (Grover)

What a multisig does and does not do

A multisig mitigates key theft, which is the common failure. It mitigates nothing here. Five Ed25519 keys fail the same way one does, at the same time, for the same reason. A hardware wallet protects the key from the computer, not from the mathematics. Moving funds to a fresh address publishes a fresh key as soon as the address is used.

What a vault does not protect against

  • Theft of the seed. Whoever holds the twelve words holds the vault.
  • A client that reuses a one-time key. See Rotation.
  • A compromised client that signs a digest the owner did not intend.
  • A bug in the verifier. Every property in Security model is conditional on the verifier being correct.