PrototypeTestnet launch on Robinhood Chain. See the roadmap

The wallet
quantum can't
break.

Winternitz is a quantum-safe smart wallet for Ethereum and its L2s, starting on Robinhood Chain. Every transaction is signed with a hash-based one-time key, so your assets stay yours after ECDSA falls.

TESTNET · SELF-CUSTODIAL · ERC-4337 · FUZZ-TESTED

Winternitz wallet showing ETH and Robinhood Stock Token balances
Ethereum✦Robinhood Chain✦Base✦Arbitrum✦ERC-4337✦EntryPoint v0.7✦Keccak-256✦WOTS w=16✦CREATE2✦Uniswap v4✦Ethereum✦Robinhood Chain✦Base✦Arbitrum✦ERC-4337✦EntryPoint v0.7✦Keccak-256✦WOTS w=16✦CREATE2✦Uniswap v4✦

128-bit

Post-quantum security

0

Signing keys ever reused

67

Hash chains per signature

2.1 KB

Signature size

Features

Everything a wallet does. Nothing a quantum computer can forge.

01 / SIGNATURES

Hash-based, not curve-based

WOTS signatures rely only on Keccak-256, the same hash Ethereum already trusts. No elliptic curves, nothing for Shor's algorithm to attack.

w = 1667 chainskeccak256

02 / ROTATION

Zero key reuse

Each key signs once, then it's gone.

key #41BURNED
key #42BURNED
key #43ACTIVE
key #44QUEUED

03 / ADDRESS

Same address forever

Keys rotate behind a smart account. One address, on every EVM chain.

0x7a3F9c2E04bD6a1f58C3e7B90dA4f2c61e8591cE

04 / GAS

Gas, measured

Gas per ETH transfer, benchmarked on-chain.

ECDSA91k gas
WOTS219k gas

05 / RECOVERY

One seed, every key

24 words restore your whole key tree.

1. ••••••2. ••••••3. ••••••4. ••••••5. ••••••6. ••••••7. ••••••8. ••••••9. ••••••

06 / SWAP

Trade Stock Tokens

Swap ETH, stablecoins and tokenised stocks through Uniswap v4, with the best route quoted on-chain. Approvals and swap are one operation, one key.

You pay0.01 ETH
You receive0.1161 NVDA
RouteETH → USDG → NVDA

07 / SAFETY NETS

No surprises

One-time keys need care. The wallet takes it for you.

  • Stuck transaction? A recovery key replaces it; no key ever signs twice.
  • Fee before you sign Expected and maximum, with room left in your balance.
  • Plain-language approvals “Approve unlimited USDG” instead of 68 hex bytes.

08 / DEVELOPERS

Post-quantum in a few lines

The TypeScript SDK handles key generation, signing and the ERC-4337 bundler flow. Verifier contracts are open source.

Read the SDK docs →
import { QuantumSafeWallet } from "@winternitz/sdk";

const wallet = await QuantumSafeWallet.load({ seed, ...d });
const tx = await wallet.send(
  [{ to: "0x7a3F…91cE", value: parseEther("0.1") }],
  bundler,
);
// signed with WOTS key #43, next key committed

How it works

Three steps. Every transaction.

01

Generate

Your seed expands into Winternitz key pairs using only Keccak-256. Keys never leave your device.

02

Sign

Each transaction walks 67 hash chains. Your ERC-4337 account verifies them on-chain before anything moves.

03

Rotate

The used key is burned and the next one is committed in the same transaction. Your address never changes.

Chrome extension

One click from
any dApp.

The same quantum-safe account, in your browser toolbar or docked in Chrome's side panel. dApps connect to it like any other wallet.

  • Popup or side panel. Keep the wallet open next to the page while you trade.

  • Works with dApps. Standard EIP-1193 provider, discovered through EIP-6963.

  • Stock Tokens and ERC-20. Robinhood Stock Tokens listed by default; import any other token.

  • Approve everything. Every connection and transaction opens an approval window first.

v0.1 · Manifest V3 · Chrome 116+ · Brave, Edge, Arc

app.example.xyz
A dApp open in Chrome with the Winternitz wallet docked in the side panel

Security

No curves.
Just hashes.

ECDSA falls to Shor's algorithm. Hash functions don't: Grover's search only halves their strength. That is why hash-based schemes were among the first post-quantum signatures NIST standardised.

Vitalik Buterin's plan for a quantum emergency ends with Ethereum accounts moving to smart-contract validation. Winternitz is that kind of account, usable today.

ECDSA walletWinternitz
Built on✕ Elliptic curves (secp256k1)✓ Hash functions (Keccak-256)
Quantum attack✕ Broken by Shor's algorithm✓ Only weakened by Grover, still 128-bit
Key reuse✕ Same key for every transaction✓ Fresh key for every transaction
Exposed public key✕ Visible after first spend✓ Burned after it signs

Use cases

What are you protecting?

Cold storage

ETH you plan to hold for a decade.

Harvest-now, decrypt-later attacks target exactly this: exposed public keys that sit on-chain for years. Winternitz never reuses a key, so there is nothing to harvest.

  • ✓Fresh key after every spend
  • ✓One seed restores every key
  • ✓Address usable before deployment

FAQ

Questions

Cryptography, costs, recovery and what changes for you.

01What is Winternitz?+

Winternitz is a self-custodial smart wallet for Ethereum and its L2s that signs every transaction with a Winternitz one-time signature (WOTS), a hash-based scheme that stays secure against quantum computers.

02Why do I need a post-quantum wallet?+

Regular Ethereum accounts use ECDSA over secp256k1. A large enough quantum computer running Shor's algorithm could derive a private key from any public key already exposed on-chain. Hash-based signatures do not have that weakness.

03Do I get a new address every transaction?+

No. Your address is a smart account that stays the same. Only the signing key behind it rotates, and the account tracks which key is next.

04Is it more expensive than a normal wallet?+

Yes, about 219k gas per transfer against 91k for an ECDSA smart account, mostly for verifying the 2 KB signature and carrying it in calldata. On L2s such as Robinhood Chain gas is cheap, and batching several calls into one operation spreads the cost.

05Can I import my existing wallet?+

You can move funds from any existing wallet into your Winternitz account. We deliberately do not import ECDSA keys, since that would carry the quantum risk with them. A guided migration and a quantum-readiness check are on the roadmap.

06What happens if I lose my device?+

Your 24-word recovery phrase restores every key, in the web wallet, the extension or the command line. Write it down when you create the wallet: without it, the funds cannot be recovered.

07Has it been audited?+

Not yet. Winternitz is a testnet prototype: the contracts are unit-, fuzz- and differential-tested, but have not had a security audit. An independent audit comes before mainnet; until then, use test funds only.

Be ready before
Q-Day.

Create a wallet on testnet today. Your address works right away, and mainnet follows an independent audit.