$LAMPORT Solana Token-2022 Est. 1979
A bodyguard on every transfer.
$LAMPORT is a Solana token with a bodyguard built in: a transfer hook that blocks any transfer without your quantum-proof second key, so a stolen wallet key can’t touch your bag.
Every transfer passes the hook. Thieves don’t.
Hook telemetry
Supply armed
Transfers checked
Theft attempts blocked
- I.Keys can be stolen.
- II.Hashes can’t be reversed.
- III.So we hooked the token.
§1The problem
One key opens everything.
Today a Solana wallet has exactly one key. Whoever holds it, by any route, can move everything in it. The chain checks the signature, not the person.
- Threat ATomorrow
Quantum computers
Every Solana wallet signs with ed25519, an elliptic-curve scheme. A large enough quantum computer running Shor’s algorithm recovers the private key from the public address. No hack needed, just physics.
- Threat BAny day
AI math breakthroughs
Elliptic-curve security rests on one hard problem. If a new algorithm, human or machine-found, takes a shortcut through it, every key on the curve becomes guessable at once.
- Threat CToday
Seed-phrase drainers
A fake airdrop, a poisoned link, a screenshot in the cloud. Drainers sweep wallets every day, and the chain can’t tell your signature from theirs.
Three different attacks, one result: a valid signature on a transfer you never made. $LAMPORT makes that signature not enough.
§2Mechanism
The hook that says no.
A transfer hook is a rule the token carries everywhere. Every time anyone moves $LAMPORT, Solana asks the hook “is this allowed?”. If the answer is no, the whole transaction fails.
Holder
- ✓ wallet sig
- ✓ Quick Key proof
Thief (stolen key)
- ✓ wallet sig
- ✕ proof
- armed?yes
- proof?yes
Recipient
waiting
Error: LamportArmed. Whole transaction reverted.
Step 1
A transfer arrives.
Someone signs a $LAMPORT transfer: a send, a sell, a swap or a drainer’s sweep. Before Token-2022 moves a single unit, Solana calls the Lamport hook.
Step 2
The hook asks one question.
Is the sending account armed? Pools and program vaults have no private key, and unarmed holders chose no protection: both pass straight through, like any token.
Step 3
Armed, with proof: it passes.
An armed holder’s transaction carries the next link of their Quick Key, revealed earlier in the same transaction. The hook checks it with a single hash and lets the transfer through.
Step 4
Stolen key, no proof: it fails.
A thief holding your wallet key can sign, but can’t produce the link. The hook returns LamportArmed and the entire transaction reverts. Nothing moves.
§3The Quick Key
One-time passwords that check themselves.
Your everyday second key is a secret hashed thousands of times. Only the final result, the anchor, is registered. Each transfer reveals the previous link; the hook hashes it once and checks it. Hashes are one-way, so nobody can work backwards.
In the app the chain has 10,000 links. Only the last one, the anchor, is ever published.
The hook stores only
…
- 1 Announce
- 2 Reveal + check
Hook decisions
Press Send. The hook hashes the revealed link once and compares it with the anchor.
Theorem 1 (Unstealable). Without the preimage of the anchor, no transfer from an armed account passes the hook.
Proof sketch. SHA-256 is preimage-resistant, so the next link can’t be computed from the anchor, and the announce-then-reveal order means a link seen in flight is already spent. ∎
Two quick steps. The app first announces a sealed commitment to the transfer, waits about two seconds, then reveals the link and moves the tokens in the same transaction. Anyone who copies the link is too late.
The Master Key is a heavier hash-based signature (WOTS / XMSS, 1,024 one-time uses) kept for rare actions: turning protection off, resetting the Quick Key, recovery.
§4Markets
Why trading still works.
The hook guards people, not pools. It checks one thing about the sender, then gets out of the way.
Pools have no private key.
A liquidity pool is owned by a program, not a person. Nobody can steal a key it doesn’t have, so the hook lets every pool transfer through. Buying $LAMPORT works from any app, any aggregator, any time.
Unarmed holders trade normally.
If you never arm, $LAMPORT behaves like any token. You keep the choice, and the risk that comes with it.
Armed holders click once.
When you sell or swap from an armed bag, the app inserts the Quick Key reveal before the swap instructions. One button, two quick steps, same price.
lamport_hook :: Execute · for every transfer
- 1Is the sender a program account with no private key (a liquidity pool, a vault)?no ↓ next checkyes → Allowpool account
- 2Does the sending token account have no Armor registered?no ↓ next checkyes → Allowunarmed holder
- 3Did this same transaction reveal the next Quick Key link for this account, covering this amount?no ↓ next checkyes → Allowarmed, valid proof
- Otherwise → BlockError LamportArmed. The whole transaction reverts.
§5Comparison
Their hook writes a diary of every transfer. Ours locks the door.
| Property | $LAMPORT | Vault-style protection | Record-only hooks | A normal token |
|---|---|---|---|---|
| Can a thief with your wallet key move it? | No (when armed) | Not while it stays in the vault | Yes, and it gets logged | Yes |
| Can you trade it on DEXes? | Yes, straight from your wallet | Withdraw first, then it is exposed | Yes | Yes |
| Where does the protection live? | In the token itself, on every transfer | In a separate contract you deposit into | Nowhere. It writes a diary | Nowhere |
| Survives a quantum break of ed25519? | Yes, hash-based second key | Only if the vault uses hash-based keys | No | No |
| Stops a drainer with your seed phrase? | Yes, the second key isn’t in your seed | While deposited | No | No |
| Everyday effort | One click; proof attached for you | Deposit and withdraw | None | None |
Record-only hooks log transfers for analytics or compliance; they can’t refuse one. Protection applies to armed accounts; unarmed $LAMPORT behaves like a normal token.
§6The Bounty Wallet
Here’s my private key. Try to take my bag.
One wallet, its private key published for anyone to use, holding armed $LAMPORT and no SOL. Every attempt to move the bag hits the hook. Every attempt is on the scoreboard.
Take a shotPrivate key (published)
…
- Attempts
- …
- Successful
- …
Waiting for the next attempt…
§7The name
Why “Lamport”?
Every Solana user already holds lamports. The network’s smallest unit (1 SOL = 109 lamports) is named after Leslie Lamport, the computer scientist whose work on distributed systems underpins the consensus behind modern blockchains.
Fewer people know the other thing he did in 1979: he showed how to sign a message using only a hash function. Reveal one of two secrets for each bit of the message; anyone can hash what you revealed and check it against your public key. No elliptic curves, nothing for a quantum computer to break. It is the ancestor of every hash-based, quantum-resistant signature scheme in use today.
He also created LaTeX, which is why this page is set like a paper: in Computer Modern, the typeface of a million proofs. $LAMPORT takes his 1979 invention and builds it into Solana’s token standard. The idea comes home.
1979
Lamport one-time signatures
Sign with nothing but a hash function.
1979
Merkle trees
One public root for many one-time keys.
1981
Hash-chain passwords
Lamport again: one-time passwords from a hash chain. Today’s Quick Key.
1989
Winternitz chains
Hash chains make the signatures short.
2018
XMSS (RFC 8391)
A standard stateful hash-based scheme.
2024
SLH-DSA (FIPS 205)
NIST standardises hash-based signatures for the quantum era.
$LAMPORT is not affiliated with or endorsed by Leslie Lamport. We use his name the way Solana does: as a tribute.
§8Future work
What’s next.
Today the hook guards one token. The same idea can guard everything you hold.
- 1Protect every holder
The Lamport Hook standard
Any new token can plug in the same hook at launch. One arming setup protects every Lamport-hooked token you hold.
“Others prove who launched a coin. Lamport protects who holds it.”
- 2qSOL · qUSDC · q-anything
Armored wrappers
Deposit SOL, USDC or any SPL token and get qSOL or qUSDC back 1:1, protected by the Lamport hook. The real assets sit in a program account that has no private key.
“Your stablecoins, with a bodyguard.”
- 3Fees → buybacks
$LAMPORT as the platform token
Fees from hooked launches and wrappers feed $LAMPORT buybacks. The more the hook protects, the more it earns.
“The bodyguard gets paid.”
§9The token
$LAMPORT
Hold it like a vault. Trade it like a memecoin. Buying works from any app: the seller is a pool, and pools pass the hook.
Token address
Coming soon- Standard
- Token-2022 + TransferHook
- Decimals
- 6
- Supply
- Fixed at mint
- Mint authority
- None (revoked at launch)
- Freeze authority
- None
- Hook authority
- None (hook frozen)
- Transfer fee
- None
- Programs
- Immutable after audit
§10Questions
Five things people ask first.
What is a transfer hook?
A transfer hook is a rule a Token-2022 token carries everywhere. Every time anyone moves the token (a send, a sell, a swap, a drainer’s sweep), Solana automatically calls the hook program and asks: is this allowed? If the hook says no, the whole transaction fails.
Most tokens use hooks for fees or game mechanics. $LAMPORT uses its hook for security.
What happens if someone steals my wallet key or seed phrase?
If your $LAMPORT is armed, they can’t move it. The hook sees a wallet signature with no second-key proof and rejects the transfer. That covers a phished seed phrase, a malicious approval, a wallet drainer, or a future quantum computer that can forge wallet signatures.
Move your other assets and your SOL to safety, then disarm and re-arm your $LAMPORT from a new wallet at your own pace.
Do I have to arm?
No. Unarmed holders trade and transfer $LAMPORT like any normal token, and the hook lets them through. Arming is how you turn the protection on for your own bag.
If you don’t arm, you are exactly as exposed as with any other token. That’s the honest trade-off.
What if I lose my second key?
You can disarm with only your wallet, but it takes 7 days. During those 7 days, the second key can cancel the request at any time. A thief who has only your wallet key can start the timer, and you can stop it.
Keep the encrypted backup files you download while arming. They are separate from your seed phrase on purpose.
Can I still trade on DEXes?
Yes. Liquidity pools are program-owned accounts with no private key, so the hook lets pool transfers through. That means buying always works, from any app.
Unarmed holders sell anywhere. Armed holders sell through the $LAMPORT app (or any integration that attaches the proof), which adds the second-key step to the swap automatically.