Gas & benchmarks
Quantum safety has a price. We measured it against the reference ERC-4337 ECDSA wallet (SimpleAccount), both on EntryPoint v0.7.
Summary#
ECDSA SimpleAccount | Winternitz | |
|---|---|---|
| ETH transfer, total transaction gas | 91,315 | 219,293 |
Signature verification only (validateUserOp) | 11,332 | 108,209 |
| Signature size | 65 bytes | 2,176 bytes |
Winternitz adds about 128,000 gas per transaction, roughly 2.4× an ECDSA wallet.
Full results#
Real handleOps transactions, one operation per bundle, measured on Anvil with current Ethereum rules (including the EIP-7623 calldata floor). "Total gas" is what the chain charges, including calldata.
| Scenario | ECDSA | Winternitz | Ratio |
|---|---|---|---|
| First transfer (deploys the account) | 305,547 | 392,107 | 1.28× |
| ETH transfer (mean of 10) | 91,315 | 219,293 | 2.40× |
| Batch of 3 transfers | 115,677 | 234,372 | 2.03× |
Deployment is relatively cheap because accounts are minimal proxies (EIP-1167), and batching spreads the fixed signature cost over several calls.
Where the gas goes#
Verification cost depends on the message digits: the higher a digit, the fewer hashes are needed to reach the end of its chain.
| Digest | Hash steps | Verification gas |
|---|---|---|
All 0xff (best case) | 45 | 26,337 |
| Random (typical) | ~510 | 82,326 |
All 0x00 (worst case) | 990 | 161,148 |
The rest comes from calldata (2,176 mostly non-zero bytes at 16 gas each, about 34k) and key rotation (two storage writes, about 6k).
On Robinhood Chain#
Robinhood Chain is an Arbitrum L2, so execution is cheap, but posting data to Ethereum is charged as extra gas. Measured on Robinhood Chain Testnet with Arbitrum's NodeInterface:
| Operation | L1 data component |
|---|---|
| ECDSA-sized operation | ~13,600 gas |
| Winternitz operation | ~102,600 gas |
Estimate: about 320k gas per Winternitz transfer vs about 105k for ECDSA. At the testnet's 0.02 gwei that is around 0.0000065 ETH per transfer. The data component moves with Ethereum blob prices.
Reproduce it
node sdk/scripts/benchmark.ts measures end-to-end gas on a chain; forge test --mc Benchmark -vv measures verification alone. On-chain Robinhood Chain numbers will replace the estimate once the contracts are deployed.
Ways to make it cheaper#
- Different
w. A largerwshortens the signature (less data) but needs more hashing. On an L2 where data dominates, that trade is attractive. - Many keys under one root (XMSS-style). Removes the rotation write per transaction.
- ZK aggregation. Prove many signature checks off-chain and verify one proof per bundle.
- Arbitrum Stylus. A verifier compiled to WASM could make the hashing far cheaper on Robinhood Chain.