Winternitz
Winternitz is a quantum-safe smart wallet for Ethereum and its L2s, starting on Robinhood Chain. It replaces ECDSA, the signature scheme almost every Ethereum wallet uses today, with Winternitz one-time signatures (WOTS), using ERC-4337 account abstraction.
Prototype
Winternitz is a testnet prototype. It has not been audited; an independent audit comes before mainnet. Until then, use test funds only.
In one minute#
- The problem. A large enough quantum computer can derive an ECDSA private key from its public key. Every public key that has ever signed a transaction is permanently visible on-chain, so funds held by those accounts would be at risk.
- The idea. Sign with a scheme that only relies on hash functions (keccak256), which quantum computers cannot meaningfully break. Winternitz signatures do exactly that.
- The catch. A Winternitz key is only safe for one signature. So every transaction also names the next key, and the account switches to it automatically.
- Why it works today. With ERC-4337 the signature check lives in your account contract, not in the protocol. No Ethereum upgrade is needed.
- Where it leads. Vitalik Buterin's plan for a quantum emergency ends with Ethereum accounts moving to smart-contract validation. Winternitz is that kind of account, usable today. The quantum emergency plan explains it step by step.
Your device
derives one-time key #n from the seed
Bundler / relayer
ERC-4337
EntryPoint v0.7
canonical
Your account
checks key #n, then stores #n+1
What you get#
| Component | What it does |
|---|---|
| Smart contracts | The account, a WOTS verifier and a CREATE2 factory, built with Foundry and fuzz-tested |
| TypeScript SDK | Key generation, signing, verification and a wallet client that refuses to reuse a key |
| Web wallet | Create a wallet in the browser; send ETH and tokens, swap Stock Tokens, and follow every operation in plain language |
| Chrome extension | A MetaMask-style wallet (popup or side panel) that any dApp can connect to, with readable approvals |
| CLI | Create a wallet, check balances, send and swap from the terminal |
| Benchmarks | Measured gas cost against a standard ECDSA wallet |
Where to go next#
Why quantum-safe→
What quantum computers break, what they don't, and why this matters for Ethereum now.
How it works→
Hash chains, one-time keys and automatic key rotation, explained step by step.
Getting started→
Create your first wallet on the web, in Chrome or from the command line.
Roadmap→
What is finished, what is next, and the five priorities after the prototype.
Project goal#
The goal of this project is to prove that a wallet with quantum-safe authorisation can be used on Ethereum today, and to measure what it costs. It was scoped as a roughly six-week prototype for one developer: an off-chain library, contracts, a CLI, a simple UI, a testnet deployment, and a gas benchmark against an ordinary ECDSA wallet.
The original plan targeted Sepolia. The project now starts on Robinhood Chain, an Arbitrum-based Layer 2 on Ethereum, and the same contracts run at the same addresses on Ethereum Sepolia, Base Sepolia and Arbitrum Sepolia.