> For the complete documentation index, see [llms.txt](https://docs.tezos-homebase.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tezos-homebase.io/bunker-mode-for-your-treasury.md).

# Bunker mode for your treasury

Over the past days a number of well known people in the Tezos world and beyond have started saying out loud that elliptic curve signatures, the kind every wallet on Tezos uses today, might get weaker sooner than quantum computers arrive, because of what AI is doing to mathematics. Nobody knows if or when. Their advice is the same everywhere, and it is reasonable advice regardless: keep public keys hidden, rotate signers, and do not let a single key hold everything.

This page explains what that means for a DAO treasury on Homebase, what the contract already does for you, what it does not, and one thing you should check today.

### There is no key to steal

A Homebase treasury is not a wallet. Funds sit in a smart contract, a KT1 address, and a contract has no private key. Nothing an attacker could recover, now or after some breakthrough, lets them sign on behalf of the treasury, because the treasury never signs anything.

Funds leave the contract in exactly one way: someone creates a proposal, token holders vote on it during the voting period, it passes quorum, and after the delay the DAO defines, anyone can execute it. All of that happens on chain, in public, over days.

So what does an attacker get if they recover one member's key? That member's share of one vote. They cannot drain anything. If the compromised member holds a lot of voting power the DAO has a problem, but it is a problem the other members can see coming for days, not an empty treasury the next morning.

The guardian key, the address a DAO designates to cancel spam proposals, can drop a proposal. It cannot move funds either.

### The treasury does not have to migrate

The standard advice right now is to move funds to fresh addresses whose public key has never been revealed, and to be ready for a migration to post-quantum signatures. Tezos is already testing those: Quantumnet, launched in September 2026 by Nomadic Labs and Trilitech, runs ML-DSA signatures for accounts and hash-based signatures for consensus. It is an experiment, not a mainnet timeline, but the direction is set.

For a DAO this is simpler than for a wallet. When new signature schemes arrive, each member rotates their own key on their own schedule, from a wallet they control. The treasury address never changes and never moves. There is no coordinated migration of the funds, because the funds were never behind a key.

### The part only you can do: watch it

A delay only protects a treasury that someone is watching. A proposal that sits for five days unnoticed executes exactly like one that was reviewed.

Homebase now emails you when a proposal is created in your DAO, when voting is about to close, when it passes or fails, when it becomes executable or is about to expire, and when it is executed or dropped. Open your DAO's page on tezos-homebase.io, enter an email address in the alerts box, click the confirmation link in the email you receive. That is the whole setup. Every member who holds voting power should do it.

### What the contract does not protect

* A member who holds a voting majority on their own is still a single key. The fix is governance, not cryptography: spread the governance token.
* Your own voting key is still an elliptic curve key. The general advice applies to it: do not reuse addresses that have revealed their public key for large holdings, and be ready to rotate.
* The contract code is its own attack surface, like any contract. The current generation has run unchanged on mainnet for years and Homebase treasuries have secured roughly a quarter of a million dollars in assets since 2021.
* The admin role. See below.

### Check this today: who administers your DAO

Every Homebase DAO contract has an admin role. Its single power is to make the DAO transfer FA2 tokens it holds, including NFTs, through the `transfer_contract_tokens` entrypoint. It cannot move XTZ. The role exists so that whoever creates the DAO can set things up, and the intended end state is that the role is handed to the DAO itself, after which no key holds it.

DAOs created with Homebase since 2023 do this handover automatically during creation. Most of them completed it. A few did not, usually because the second transaction of the creation flow was rejected or lost, and every DAO created before 2023 still has the creator's key as admin. In both cases one key can move your tokens and NFTs without a vote. That is exactly the kind of exposure the current advice is about.

#### How to check

1. Open `https://tzkt.io/<your DAO address>/storage`. Your DAO address is the KT1 in your DAO's Homebase URL.
2. Find the `admin` field.
3. If it equals your DAO's contract address, you are done. The DAO administers itself.
4. If it is a tz1, tz2 or tz3 address, that key still holds the admin role. Continue below.

#### How to hand the admin role to the DAO

You need the wallet that currently holds the admin role. The transfer is one transaction and the DAO accepts it automatically when the new owner is its own address.

1. Open `https://tzkt.io/<your DAO address>/interact` (or the same contract on better-call.dev).
2. Connect the admin wallet.
3. Choose the `transfer_ownership` entrypoint.
4. In the `new_owner` parameter, enter your DAO's own address, the same KT1.
5. Send and confirm in your wallet.
6. Reload the storage page. `admin` now shows the DAO's address.

From that point no key can move the DAO's tokens. Only a passed proposal can.

If the admin wallet is lost, the role cannot be transferred. The practical answer is to move the DAO's token and NFT holdings to a new DAO through regular proposals, which the XTZ never needed anyway. Ask in the Homebase Discord if you are in that situation.

### In short

* Treasury funds sit behind a vote and a delay, not a key.
* Members rotate their own keys; the treasury never moves.
* Turn alerts on, so the delay is worth something.
* Check that the admin role belongs to the DAO, and hand it over if it does not.

Homebase is free and open source governance for the Tezos community.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.tezos-homebase.io/bunker-mode-for-your-treasury.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
