Signed once. Exposed forever.
Every transaction you sign puts your public key on-chain for good. Zero Surface (z0s) shows what each address has exposed, reads the research on breaking elliptic curves as it lands, and holds SOL behind hash-based one-time keys.
Live on Solana mainnet: the exposure checker, the watch agent, and the hash-based vault.
Live from mainnet
Every tile reads live: well-known addresses through the real checker, the agent's latest digest, the vault program on Solana mainnet, and Jupiter prices.
A signature shows the key
A wallet address comes from a public key, and a public key from a private key. What keeps the private key secret is elliptic-curve math: easy in one direction, assumed infeasible in reverse.
On Bitcoin and Ethereum the address is a hash of the public key, so the key stays hidden until the address signs its first transaction. After that it is on-chain permanently. On Solana the address is the public key, visible from the start.
If that math were ever reversed, a visible public key would be enough to forge a signature. Hidden keys would buy time and visible ones would not. That is the whole argument behind "bunker mode".
Bitcoin / Ethereum
seed--hash-->private key--curve-->public key--hash-->address
hidden until the first signature, public after
Solana
seed--hash-->private key--curve-->public key = address
public from day one: the address is the key
Winternitz vault
seed--hash-->one-time key--hash-->merkle root--hash-->vault address
no curve step; each key signs exactly once
No attack has been demonstrated.
No break of ECDSA or Ed25519 has been published. The debate is about how much warning there would be. Last checked 9 Oct 2026.
How z0s works
Paid features are unlocked by burning z0s. Checking an address and withdrawing from a vault are always free.
Watch
An agent reads new cryptography papers, researcher statements, and Solana client releases, then posts what changed. Each item is marked proven, stated, or speculation, with its source.
/watch ->Measure
The exposure checker reads public chain data and tells you whether an address's public key is already visible, and why.
/exposure ->Shelter
The vault holds SOL behind checksummed Winternitz one-time signatures, with z0s's own program on Solana mainnet. Keys are made and used on your device.
/vault ->Fund
Creator fees from the token pay for independent audits, bounties, and tooling.
/fund ->
Reading on bunker mode
Crypto industry split over Justin Drake's AI warningWho agreed, who called it FUD, and why Solana's answer differs from Ethereum's.theblock.co ->
Ethereum researcher's "bunker mode" call sparks debate over whether AI math threatens crypto keysDrake's own wording, Buterin's caution about rushed migrations, and Lindell's rebuttal.unchainedcrypto.com ->
Quantum readinessSolana's three-step plan, the Falcon implementations in Anza and Firedancer, and where the Winternitz Vault fits.solana.com ->
Securing Solana against a powerful quantum adversaryWhere Solana depends on elliptic curves, and a prototype for moving an existing account to a new key without changing its address.anza.xyz ->
The z0s token
z0s launches on Pump.fun, paired with SOL. The contract address is posted on @usez0s first and appears at the top of this site; any token using this name elsewhere is not ours.
The token has one use: paid features are unlocked by burning it. Prices are set in dollars and converted to z0s when you pay. The full amount is burned.
Holding z0s does not protect your wallet, and the token itself sits in an ordinary Solana wallet like any other. We make no claim about its price.
Built for the day curves break
Resistant to an elliptic-curve break as long as the hash function holds.
No curve to break
Vault keys are Winternitz one-time signatures built only from Keccak. Shor's algorithm, the threat to ECDSA and Ed25519, has no curve to attack here; the best generic quantum attack leaves the chains at about 2¹⁰⁶ work.
A forgery, closed
The widely shared Winternitz vault signs without a checksum, so a signature can be stretched into a forgery. We demonstrated one, then added the standard checksum: a signed withdrawal fits no other.
Verified byte for byte
The program's source is public, and building it reproduces the binary on Solana mainnet exactly. Anyone can check it in two commands.
Keys stay with you
Your vault seed is made in your browser and never sent anywhere. Each key signs once, to the address you choose, and a withdrawal cannot be redirected.
Exposure, measured
Check any Bitcoin, Ethereum, or Solana address for a visible public key, free, with the evidence behind every verdict.
Evidence, not alarm
The watch agent labels new research proven, stated, or speculation, and links every item to its source.