Introduction
Shorline is a vault on Base with a built-in early warning for quantum attacks on secp256k1, the elliptic curve behind every Ethereum and Base account. It has three parts: the Canary, a bounty that can only be claimed by breaking secp256k1; the Vault, which holds deposits under two locks; and the Failsafe, which switches the vault from signature exits to hash exits the moment the Canary is claimed.
The threat
An Ethereum account is a secp256k1 key pair. The address is a hash of the public key, and the public key becomes visible on chain the first time the account signs a transaction. Shor's algorithm, run on a large fault-tolerant quantum computer, recovers a private key from a public key in polynomial time. When that machine exists, every account that has ever sent a transaction is exposed.
Hash functions such as keccak256 are not broken by Shor. The best known quantum attack on them, Grover's algorithm, only reduces a 256-bit preimage search to roughly 2^128 work.
The Canary
The Canary is a secp256k1 public key C whose discrete log nobody knows. It is derived by hashing a published seed sentence onto the curve (try-and-increment on keccak256(seed, counter) until the result is a valid x coordinate). Because the point is produced by a hash, no one could have chosen it with a known private key.
canary.claim(to, v, r, s)
require ecrecover(keccak256("SHORLINE CANARY", to), v, r, s) == address(C)
pay the bounty to `to`
vault.fire() // same transaction, same block
A valid signature for C is a proof that someone computed its private key. The bounty pays whoever produces it, and the same call fires the vault.
The Vault
Each deposit records the owner, the amount, and a commitment:
commitment = keccak256(secret, payee, depositId)
While the failsafe is armed, the owner asks to withdraw, waits 2 days, then withdraws to any address. The 2 days are the tripwire window: if the canary dies before they end, the request dies with it, so a thief who forged an owner signature has to wait in public. The commitment is never used and never revealed while armed, and the owner can replace it at any time.
The Failsafe
The failsafe has exactly one input: the Canary's claim. There is no admin, no vote and no oracle. Once fired it stays fired. After it fires:
- Signature-based withdrawals and commitment changes revert.
- An exit is a reveal of
(secret, payee, depositId)that hashes to the stored commitment. - The vault pays
payee, whoever sends the reveal. Someone who copies the reveal from the mempool can only make the payment go where the owner already chose.
$SHORE
$SHORE is a B20 asset on Base: 1,000,000,000 supply with a hard cap set at creation, minted once, then the mint role is renounced. The team holds none. A share of the supply is locked in the Canary as its bounty. The token does not control the failsafe and gives no one power over deposits.
Limits, plainly
- The Canary only sings if the attacker wants it to. A quantum attacker may skip the bounty and go after larger targets quietly. The Canary is an early warning, not a guarantee of one.
- Your secret is your last key. Lose it and, after the failsafe fires, your deposit cannot leave. Store it offline, like a seed phrase.
- The payee must be safe on the day. If the payee is an ordinary account whose public key is already exposed, a quantum attacker could take funds after they arrive. Commit to an address that has never sent a transaction, or a future post-quantum account.
- A false trip is possible only by breaking the curve. A classical break of secp256k1, or a leaked key from the derivation, would also fire the vault. Both would be emergencies anyway.
- Smart contracts can have bugs. Unaudited code can lose funds.
Glossary
- secp256k1: the elliptic curve used by Ethereum and Base accounts.
- Shor's algorithm: a quantum algorithm that solves the discrete logarithm problem, recovering private keys from public keys.
- Grover's algorithm: a quantum search that speeds up hash preimage attacks quadratically, not exponentially.
- Nothing-up-my-sleeve point: a curve point derived from a public seed by hashing, so its private key is unknown to everyone.
- B20: Base's native token standard, issued through a factory precompile.