pqp
// documentation

PQP docs

Overview

PQP (Post Quantum Pad) is a Solana token launchpad built on Meteora's Dynamic Bonding Curve (DBC). Every token starts on a bonding curve, trades instantly, and moves automatically into a permanent Meteora DAMM v2 pool once it raises enough SOL.

On top of that, PQP adds a creator attestation signed with post-quantum cryptography, so anyone can check who launched a token, even against a future quantum attacker.

How PQP works

creator wallet ──► PQP launch form
        │             │  validate fields
        │             │  build metadata (+ proof hash)
        ▼             ▼
   sign tx ◄── Meteora SDK: createPool / createPoolWithFirstBuy
        │
        ▼
 Solana ──► DBC pool (bonding curve) ──threshold──► DAMM v2 pool

Meteora DBC launch lifecycle

1. Create: one transaction creates the token mint and its DBC pool, using PQP's shared config account. The mint key is generated in your browser and used once.

2. Trade: anyone can buy and sell against the curve. The price follows the curve set in the config account.

3. Graduate: when the SOL in the curve reaches the migration threshold, the pool migrates to Meteora DAMM v2 and trading continues there (and through Jupiter).

Bonding curves

DBC stores price as a square root in Q64.64 fixed point. PQP converts it like this:

price (SOL per token) = (sqrtPrice / 2^64)^2 × 10^(tokenDecimals − 9)
progress              = quoteReserve / migrationQuoteThreshold
market cap            = price × total supply

Graduation into DAMM v2

When progress reaches 100%, a migrator moves liquidity into a DAMM v2 pool. LP tokens are split and locked according to the partner and creator LP percentages in the config. Locked LP can't be withdrawn, so liquidity stays permanent. PQP detects this from the pool's isMigrated flag and switches the trade panel to the live market.

Creator and partner fees

Every trade pays a fee set by the config account (a base fee, plus an optional dynamic fee). The fee is split between the creator and the partner (PQP):

creator share = tradingFee × creatorTradingFeePercentage / 100
partner share = tradingFee − creator share

The Launch page shows these values read live from the chain, never typed in by hand.

Post-quantum threat model

A large enough quantum computer could forge Ed25519 signatures from a public key. A forger could then pretend to be a well-known creator. PQP's goal is provenance: proving that a launch came from a specific creator identity, using signatures that are believed to resist quantum attacks.

Quantum identity

Your quantum identity is derived in your browser from a deterministic wallet signature over a fixed, domain-separated message. You can add an optional passphrase to make it stronger. The private key never leaves your browser and is never sent to a server.

seed      = SHA-256("PQP/identity/v1" || walletSignature || passphrase?)
keypair   = WOTS+ leaves → Merkle tree   (or ML-DSA keypair)
identity  = Merkle root, anchored on Solana with a Memo transaction

Signature schemes

WOTS+ with a Merkle tree: hash-based one-time signatures. Each launch uses one leaf, and a used-leaf ledger stops a leaf from being used twice.

ML-DSA (FIPS 204): a reusable lattice-based signature, used for repeated attestations.

All hashing is SHA-256 with a domain-separation prefix per purpose.

Launch attestations

digest = SHA-256("PQP/launch/v1" || mint || name || symbol || imageHash
                 || creator || dbcConfig)
proof  = { scheme, identityRoot, leafIndex, authPath, signature, digest }

Metadata structure

{
  "name": "Example",
  "symbol": "EXM",
  "image": "ipfs://…",
  "description": "…",
  "extensions": { "twitter": "…", "telegram": "…", "website": "…" },
  "pqp": { "version": 1, "proofHash": "…", "proofUri": "ar://…" }
}

Verification

The verifier fetches the token's metadata, rebuilds the launch digest, checks the post-quantum signature and Merkle path in your browser, confirms the identity root's on-chain anchor, and checks that the pool belongs to PQP's config. Possible results: Verified, Invalid, Metadata changed, Identity mismatch, Signature reused, Pool mismatch, or Unable to verify.

Wallet security

PQP never asks for your seed phrase or private key. Every transaction is tested against the network first and then signed in Phantom, Solflare, or Backpack. Check the amounts in your wallet before you approve.

Smart-contract addresses

network          mainnet-beta
DBC program      dbcij3LWUppWqq96dh6gJWwBifmcGfLSB5D4DuSMaqN
DAMM v2 program  cpamdpZCGKUy5JxQXB4dcpGPiikHawvSWAd6mEn1sGG
quote mint       So11111111111111111111111111111111111111112
PQP config       (not configured yet)

SDK examples

import { DynamicBondingCurveClient } from "@meteora-ag/dynamic-bonding-curve-sdk";
const dbc = DynamicBondingCurveClient.create(connection, "confirmed");

// all PQP launches
const pools = await dbc.state.getPoolsByConfig(PQP_CONFIG);

// buy 0.5 SOL of a token
const tx = await dbc.pool.swap({
  owner, pool, amountIn: new BN(0.5e9), minimumAmountOut,
  swapBaseForQuote: false, referralTokenAccount: null,
});

Honest security limitations

PQP attestations give quantum-resistant provenance and creator attestations. They do not make Solana accounts, SOL balances, or Meteora transactions quantum-resistant. Solana still enforces Ed25519 signatures on-chain.

Bonding-curve tokens are high-risk. Being verified proves who launched a token, not that it's worth anything.