Built to stay safe when quantum computers arrive.
Experts expect quantum computers to eventually break the math that protects today's crypto accounts. Agents sign constantly, so Astral gives them the new standards today.
Quantum-safe signatures
Every agent payment and every owner approval is signed with a post-quantum algorithm instead of the ECDSA used by most wallets, and verified on-chain.
Your key stays with you
Your key is encrypted in your browser with your password. Astral never sees it, nor your 24 words, nor any agent key.
Recovery contacts
Lose every device and the people you chose can together give control to a new one, after a delay during which you can cancel. They never see your key and can't move funds.
A recovery phrase you own
Like any self-custody wallet: your 24 words restore your account on any device. Keep them offline; Astral can't recover them.
In plain words
Wallets rely on ECDSA. It's secure against normal computers.
A large quantum computer could work out a private key from a public one.
Agent and owner keys use lattice math (ML-DSA) that quantum computers can't shortcut.
Security status
- Contracts: internal review, attack tests, fuzzing, invariants, static analysisDone
- Contract sources published and verified (Sourcify)Done
- ML-DSA verifier: Fireblocks' open-source code, checked against upstreamDone
- External audit of the contractsIn progress
Until the audit is published
Astral is in beta. Keep amounts small and limits tight: the limits, approvals and pause are enforced by the contracts either way.
