Docs · Gas & benchmarks▾
Project

Gas & benchmarks

Quantum safety has a price. We measured it against the reference ERC-4337 ECDSA wallet (SimpleAccount), both on EntryPoint v0.7.

Summary#

ECDSA SimpleAccountWinternitz
ETH transfer, total transaction gas91,315219,293
Signature verification only (validateUserOp)11,332108,209
Signature size65 bytes2,176 bytes

Winternitz adds about 128,000 gas per transaction, roughly 2.4× an ECDSA wallet.

Full results#

Real handleOps transactions, one operation per bundle, measured on Anvil with current Ethereum rules (including the EIP-7623 calldata floor). "Total gas" is what the chain charges, including calldata.

ScenarioECDSAWinternitzRatio
First transfer (deploys the account)305,547392,1071.28×
ETH transfer (mean of 10)91,315219,2932.40×
Batch of 3 transfers115,677234,3722.03×

Deployment is relatively cheap because accounts are minimal proxies (EIP-1167), and batching spreads the fixed signature cost over several calls.

Where the gas goes#

Verification cost depends on the message digits: the higher a digit, the fewer hashes are needed to reach the end of its chain.

DigestHash stepsVerification gas
All 0xff (best case)4526,337
Random (typical)~51082,326
All 0x00 (worst case)990161,148

The rest comes from calldata (2,176 mostly non-zero bytes at 16 gas each, about 34k) and key rotation (two storage writes, about 6k).

On Robinhood Chain#

Robinhood Chain is an Arbitrum L2, so execution is cheap, but posting data to Ethereum is charged as extra gas. Measured on Robinhood Chain Testnet with Arbitrum's NodeInterface:

OperationL1 data component
ECDSA-sized operation~13,600 gas
Winternitz operation~102,600 gas

Estimate: about 320k gas per Winternitz transfer vs about 105k for ECDSA. At the testnet's 0.02 gwei that is around 0.0000065 ETH per transfer. The data component moves with Ethereum blob prices.

Reproduce it

node sdk/scripts/benchmark.ts measures end-to-end gas on a chain; forge test --mc Benchmark -vv measures verification alone. On-chain Robinhood Chain numbers will replace the estimate once the contracts are deployed.

Ways to make it cheaper#

  • Different w. A larger w shortens the signature (less data) but needs more hashing. On an L2 where data dominates, that trade is attractive.
  • Many keys under one root (XMSS-style). Removes the rotation write per transaction.
  • ZK aggregation. Prove many signature checks off-chain and verify one proof per bundle.
  • Arbitrum Stylus. A verifier compiled to WASM could make the hashing far cheaper on Robinhood Chain.