Docs · Introduction▾
Documentation

Winternitz

Winternitz is a quantum-safe smart wallet for Ethereum and its L2s, starting on Robinhood Chain. It replaces ECDSA, the signature scheme almost every Ethereum wallet uses today, with Winternitz one-time signatures (WOTS), using ERC-4337 account abstraction.

Prototype

Winternitz is a testnet prototype. It has not been audited; an independent audit comes before mainnet. Until then, use test funds only.

In one minute#

  • The problem. A large enough quantum computer can derive an ECDSA private key from its public key. Every public key that has ever signed a transaction is permanently visible on-chain, so funds held by those accounts would be at risk.
  • The idea. Sign with a scheme that only relies on hash functions (keccak256), which quantum computers cannot meaningfully break. Winternitz signatures do exactly that.
  • The catch. A Winternitz key is only safe for one signature. So every transaction also names the next key, and the account switches to it automatically.
  • Why it works today. With ERC-4337 the signature check lives in your account contract, not in the protocol. No Ethereum upgrade is needed.
  • Where it leads. Vitalik Buterin's plan for a quantum emergency ends with Ethereum accounts moving to smart-contract validation. Winternitz is that kind of account, usable today. The quantum emergency plan explains it step by step.

Your device

derives one-time key #n from the seed

signs↓

Bundler / relayer

ERC-4337

handleOps↓

EntryPoint v0.7

canonical

validate↓

Your account

checks key #n, then stores #n+1

Each transaction uses one key, and the account rotates to the next one by itself

What you get#

ComponentWhat it does
Smart contractsThe account, a WOTS verifier and a CREATE2 factory, built with Foundry and fuzz-tested
TypeScript SDKKey generation, signing, verification and a wallet client that refuses to reuse a key
Web walletCreate a wallet in the browser; send ETH and tokens, swap Stock Tokens, and follow every operation in plain language
Chrome extensionA MetaMask-style wallet (popup or side panel) that any dApp can connect to, with readable approvals
CLICreate a wallet, check balances, send and swap from the terminal
BenchmarksMeasured gas cost against a standard ECDSA wallet

Where to go next#

Project goal#

The goal of this project is to prove that a wallet with quantum-safe authorisation can be used on Ethereum today, and to measure what it costs. It was scoped as a roughly six-week prototype for one developer: an off-chain library, contracts, a CLI, a simple UI, a testnet deployment, and a gas benchmark against an ordinary ECDSA wallet.

The original plan targeted Sepolia. The project now starts on Robinhood Chain, an Arbitrum-based Layer 2 on Ethereum, and the same contracts run at the same addresses on Ethereum Sepolia, Base Sepolia and Arbitrum Sepolia.