Blockchain & Digital Assets / Solana Transaction

What you will do: Follow a Solana transfer from an Ed25519 keypair to an address, a formatted transaction and a signed message.

Worked example: The eight steps end with the signed message; the notes explain why an Ed25519 signature is a post-quantum liability and what would replace it.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Digital Assets

For your role

Developer / Engineer
Walk the nine steps from Generate Source Keypair: Ed25519 signing, the BIP39 and SLIP-0010 derivation notes and the signed message at the end show what a Solana client signs and where a post-quantum replacement would sit.
Researcher / Academic
The notes on each step explain why an Ed25519 signature is a post-quantum liability; compare the signed message with the Bitcoin flow to see what differs between EdDSA and ECDSA transactions.

Live HSM Mode Active

SoftHSM3 · PKCS#11 v3.2 · Rust · session open

STEP 1 OF 9

1. Generate Source Keypair

Generate an Ed25519 private key for the sender. Solana uses Ed25519 for high-performance, deterministic signatures with strong security guarantees.

Why Ed25519? Unlike Bitcoin's secp256k1 (ECDSA), Ed25519 uses EdDSA which is faster, more secure against side-channel attacks, and produces deterministic signatures (no random k value needed).

Demo vs Production Key Generation: This demo generates a raw Ed25519 seed directly via SoftHSMv3 C_GenerateKeyPair. Real Solana wallets (Phantom, Solflare, etc.) use a different flow:
1. User enters or generates a 12/24-word BIP-39 mnemonic
2. PBKDF2-HMAC-SHA512 derives a 64-byte root seed from the mnemonic + optional passphrase
3. derives the Ed25519 child key via path m/44'/501'/0'/0' using HMAC-SHA512 (hardened derivation only — standard BIP-32 does not support Ed25519)
The final 32-byte value is the same Ed25519 seed this demo generates directly. The cryptographic operations from step 2 onward are identical regardless of how the seed was derived. → For the full BIP-32/39/44 + SLIP-0010 derivation walkthrough, pick HD Wallet from the chain selector in this workshop.

Private Key
Ed25519 curve
Public Key
32 bytes
Base58
Direct encoding
Address
Base58 string
// SoftHSMv3 WebAssembly API
const { pubHandle, privHandle } = hsm_generateEdDSAKeyPair(
  hsm.module,
  hsm.sessionHandle,
  'Ed25519',
  false // non-extractable — private key stays in HSM
);
// Production wallets: BIP-39 → PBKDF2 → SLIP-0010(m/44'/501'/0'/0') → Ed25519 seed
TERMINAL OUTPUT
Click Execute to run this step.

No keys yet — click Execute to run the provisioning flow.

Try it

Why does the flow call Ed25519 a post-quantum liability?

Next step

Turn it into a plan: Deployment Playbook

This tool practises the Digital Assets module, phase 5 (Pilots & Migration); Deployment Playbook produces a deliverable of that phase.

Next in Blockchain & Digital Assets