Security

Built for the day the math breaks.

Anything written to Solana is public and permanent. Encrypt it with today's elliptic curves and a large enough quantum computer opens it later. qwire is built so that day doesn't matter.

The threat: harvest now, decrypt later

An attacker doesn't need a quantum computer today. They only need to copy the chain, which anyone can do, and wait. In October 2026 the US Government Accountability Office warned that failing to prepare for cryptographically relevant quantum computers could be catastrophic. Messages encrypted only with X25519 or other elliptic-curve schemes are exactly what such a machine would read first.

What qwire protects

PropertyStatusHow
Message textSealedX-Wing (ML-KEM-768 + X25519) and XChaCha20-Poly1305. Breaking it needs both lattices and curves broken.
Attached amountSealed + checkedSealed with the text and compared to the real transfer when opened.
Replay to other walletsBlockedSender and recipient addresses are bound into the key and the cipher.
Your secret keyLocal onlyDerived in your browser from a wallet signature. Never uploaded.

What stays public

qwire hides what you say, not that you said it. These are visible to everyone, as with any Solana transaction:

Who sent to whomPublicSender, recipient and time are on-chain.
Payment amountPublicThe SOL transfer itself is a normal transfer.
Message lengthPublicRoughly, from the number and size of parts.
Wallet signaturesEd25519Solana itself still signs with Ed25519. That protects authorship today, not against a future quantum forger.

What you trust

The browser code that encrypts, built on the audited @noble/post-quantum and @noble/ciphers libraries. Your wallet, which signs the key-derivation message. And Solana, which stores the envelopes. Not a qwire server, because no qwire server ever sees your data.