SHORLINE
X ↗
CANARY: ALIVE · FAILSAFE: ARMED

The quantum tripwire vault on Base
QUANTUM SIDECLASSICAL SIDE

Every wallet on Base is guarded by one hard problem. The day a quantum computer solves it, the guard is gone, and nobody announces that day. Shorline puts a canary on the line: a reward nobody can claim without breaking that problem. If the canary dies, the vault seals every exit behind a lock a quantum computer cannot pick.

The story

Shor's line

I · 1994

In 1994 Peter Shor showed that a large enough quantum computer could find a private key from its public key. Not guess it. Compute it. The curve that protects Ethereum and Base, secp256k1, is exactly the kind of problem his algorithm eats.

II · THE QUIET DAY

Nobody will tweet the day it happens. The first machine big enough will be expensive, secret and patient. Its owner will not empty a wallet in public on day one. The first sign may be a balance that moves when its owner was asleep.

III · THE MINE

Miners used to carry a canary underground. The bird felt the gas first. When it stopped singing, everyone walked out while they still could. The warning was the whole point.

IV · THE SHORELINE

Shorline draws a line between two worlds. On the quantum side, the wave. On the classical side, the flat calm line that Base runs on today. The canary sits exactly where they meet. As long as it sings, the classical world holds. If it falls, the vault does not wait to be told twice.

How it works

Three parts. One tripwire.

01 · THE CANARY

A bounty only Shor can claim

A public key built so that nobody knows its private key: not the team, not anyone. A reward sits behind it. The only way to sign for it is to solve the discrete log on secp256k1.

02 · THE VAULT

Two keys for every deposit

Your normal wallet key for every day, and a hash commitment for the day after. Hashes are the part of cryptography quantum computers do not break.

03 · THE FAILSAFE

It fires by itself

The moment the canary's reward is claimed, the vault stops trusting signatures. From that block on, the only way out is to prove the hash secret, to an address you committed in advance.

Why it matters

A warning with teeth

NO ORACLE

No one decides quantum day. The chain does, the instant a valid signature for the canary key appears.

NO ADMIN SWITCH

The failsafe has no off button and no on button. Only the canary can trip it.

NO MIGRATION RACE

Your escape route is committed before anything happens. On the day, you only have to walk out.

BUILT ON BASE

Cheap enough to commit, check and exit for everyone, not just the whales.

The Canary

Nobody holds its key

The canary is a public key with no owner. It is made by hashing a public sentence onto the curve, so the point is fixed for everyone to check, and its private key was never generated by anybody. Signing for it means computing that private key from scratch. Today that is impossible. After Shor, it is a weekend.

NOTHING UP THE SLEEVE

The seed sentence is published. Anyone can hash it to the curve and get the same point. If the team knew the key, the math would show it could not have.

THE BAIT

A share of $SHORE sits locked behind the key. Whoever signs for it takes it. Claiming it is how the world finds out.

THE TRIP

The claim transaction is the tripwire. The same call that pays the bounty flips the vault into failsafe, in one block.

Try it

Trip the wire

A simulation, in your browser. Nothing here touches the chain. Press the button and watch what the vault does on the day the canary falls.

canaryALIVE
failsafeARMED
signature exitsOPEN
hash exitsSTANDBY
block0
The Vault

Deposit today. Exit on any day.

The vault holds what you put in it, and answers to two locks. The everyday lock is your wallet. The emergency lock is a hash secret you commit when you deposit, together with the address it must pay. Click a state to see what each lock can do.

STATE 1

ARMED

Canary alive. Deposit with your wallet; withdraw after a 2-day window that dies with the canary. Your hash commitment waits, unused.

STATE 2

FIRED

Canary claimed. Signature withdrawals stop in the same block. Nobody, including a quantum attacker holding your key, can sign your funds out.

STATE 3

EXIT

Reveal your hash secret. The vault pays the address you committed at deposit, and only that address. Seeing the secret in the mempool does not help a thief.

WHY HASHES

The lock Shor can't pick

Shor's algorithm breaks curves. Against a good hash, the best known quantum attack (Grover's) only halves the security: a 256-bit hash still leaves 128 bits, far out of reach.

WHY THE ADDRESS IS COMMITTED

No front-running the escape

If the secret alone unlocked the funds, anyone who saw it could race you. Because the payee is inside the commitment, the secret only ever pays where you said, months before.

The token

$SHORE

$SHORE is a B20 asset, Base's native token standard, created through the B20 factory. It is the bait in the canary and the stake in the line: the bigger the bounty, the louder the canary sings.

On chain: 850,000,000 in the pool, 150,000,000 in the Canary. The team holds none, and no wallet holds any role over the token.

Specification

On the record

NameShorline
Ticker$SHORE
StandardB20 asset, created by the Base B20 factory precompile
ChainBase mainnet (8453)
Supply1,000,000,000, hard cap set at creation
Mint roleUsed once for the full supply, then renounced on chain
Team allocationNone
MarketUniswap on Base, $SHORE / ETH
$SHORE0xB200000000000000000000Fac65bc132E65332e4
Canary0xD3a865a2DC23bC5C0fe8c20aDd768A95E1615c97
Vault0x0166ce810C62B5D623f85c20597a81c7Ba23E6AE
Admin rolesNone. The token was created admin-less: nobody can mint, pause or change it

Introduction

Shorline is a vault on Base with a built-in early warning for quantum attacks on secp256k1, the elliptic curve behind every Ethereum and Base account. It has three parts: the Canary, a bounty that can only be claimed by breaking secp256k1; the Vault, which holds deposits under two locks; and the Failsafe, which switches the vault from signature exits to hash exits the moment the Canary is claimed.

Shorline is live on Base. $SHORE 0xB200000000000000000000Fac65bc132E65332e4, Canary 0xD3a865a2DC23bC5C0fe8c20aDd768A95E1615c97, Vault 0x0166ce810C62B5D623f85c20597a81c7Ba23E6AE. The contracts have not been audited: do not deposit more than you can afford to lose.

The threat

An Ethereum account is a secp256k1 key pair. The address is a hash of the public key, and the public key becomes visible on chain the first time the account signs a transaction. Shor's algorithm, run on a large fault-tolerant quantum computer, recovers a private key from a public key in polynomial time. When that machine exists, every account that has ever sent a transaction is exposed.

Hash functions such as keccak256 are not broken by Shor. The best known quantum attack on them, Grover's algorithm, only reduces a 256-bit preimage search to roughly 2^128 work.

The Canary

The Canary is a secp256k1 public key C whose discrete log nobody knows. It is derived by hashing a published seed sentence onto the curve (try-and-increment on keccak256(seed, counter) until the result is a valid x coordinate). Because the point is produced by a hash, no one could have chosen it with a known private key.

canary.claim(to, v, r, s)
  require ecrecover(keccak256("SHORLINE CANARY", to), v, r, s) == address(C)
  pay the bounty to `to`
  vault.fire()          // same transaction, same block

A valid signature for C is a proof that someone computed its private key. The bounty pays whoever produces it, and the same call fires the vault.

The Vault

Each deposit records the owner, the amount, and a commitment:

commitment = keccak256(secret, payee, depositId)

While the failsafe is armed, the owner asks to withdraw, waits 2 days, then withdraws to any address. The 2 days are the tripwire window: if the canary dies before they end, the request dies with it, so a thief who forged an owner signature has to wait in public. The commitment is never used and never revealed while armed, and the owner can replace it at any time.

The Failsafe

The failsafe has exactly one input: the Canary's claim. There is no admin, no vote and no oracle. Once fired it stays fired. After it fires:

  1. Signature-based withdrawals and commitment changes revert.
  2. An exit is a reveal of (secret, payee, depositId) that hashes to the stored commitment.
  3. The vault pays payee, whoever sends the reveal. Someone who copies the reveal from the mempool can only make the payment go where the owner already chose.

$SHORE

$SHORE is a B20 asset on Base: 1,000,000,000 supply with a hard cap set at creation, minted once, then the mint role is renounced. The team holds none. A share of the supply is locked in the Canary as its bounty. The token does not control the failsafe and gives no one power over deposits.

Limits, plainly

Read this section before you deposit anything, when the vault is live.
  • The Canary only sings if the attacker wants it to. A quantum attacker may skip the bounty and go after larger targets quietly. The Canary is an early warning, not a guarantee of one.
  • Your secret is your last key. Lose it and, after the failsafe fires, your deposit cannot leave. Store it offline, like a seed phrase.
  • The payee must be safe on the day. If the payee is an ordinary account whose public key is already exposed, a quantum attacker could take funds after they arrive. Commit to an address that has never sent a transaction, or a future post-quantum account.
  • A false trip is possible only by breaking the curve. A classical break of secp256k1, or a leaked key from the derivation, would also fire the vault. Both would be emergencies anyway.
  • Smart contracts can have bugs. Unaudited code can lose funds.

Glossary

  • secp256k1: the elliptic curve used by Ethereum and Base accounts.
  • Shor's algorithm: a quantum algorithm that solves the discrete logarithm problem, recovering private keys from public keys.
  • Grover's algorithm: a quantum search that speeds up hash preimage attacks quadratically, not exponentially.
  • Nothing-up-my-sleeve point: a curve point derived from a public seed by hashing, so its private key is unknown to everyone.
  • B20: Base's native token standard, issued through a factory precompile.
FAQ

Questions from the shoreline

Is quantum day coming soon?

Nobody knows, and that is the point. Estimates range from years to decades. Shorline does not bet on a date. It reacts to evidence, the first time a key that nobody owns is signed for.

Can the team trigger the failsafe?

No. The failsafe has no admin and no switch. The only thing that fires it is a valid signature for the Canary key, which requires solving the discrete log on secp256k1.

Could the team secretly know the Canary's key?

No. The key is derived by hashing a published sentence onto the curve. Anyone can repeat the derivation and get the same point, and nobody can choose a hash output to land on a key they already hold.

What happens to my deposit if nothing ever happens?

Nothing. While the Canary is alive the vault behaves like a plain vault: you deposit and withdraw with your wallet, and your hash commitment is never used.

What is a B20 token?

B20 is Base's native token standard. Tokens are created through a factory precompile instead of a custom contract, which gives them a standard, predictable implementation.

Where is the contract address?

$SHORE is 0xB200000000000000000000Fac65bc132E65332e4. The Canary is 0xD3a865a2DC23bC5C0fe8c20aDd768A95E1615c97 and the Vault is 0x0166ce810C62B5D623f85c20597a81c7Ba23E6AE, all on Base. They are only ever posted here and by @shorlinevault on X. Ignore any other address, and ignore DMs.