Docs · Roadmap▾
Project

Roadmap

Where Winternitz is, and where it is going: from a working prototype to a quantum-safe wallet on Ethereum and its L2s. Stages move when their blockers clear, not on fixed dates.

  1. Shipped

    A working quantum-safe wallet

    The prototype from the original plan, and more.
    WOTS signatures on ERC-4337
    TypeScript signer and Solidity verifier, differential- and fuzz-tested; a new key for every transaction.
    Web wallet, CLI and Chrome extension
    Encrypted seed, 24-word recovery phrase, auto-lock, side panel, dApp connections.
    Recovery key
    A stuck transaction is replaced without any key signing twice.
    Fee estimate before signing
    Expected and maximum network fee, with room kept for it in your balance.
    Swaps and Stock Tokens
    Uniswap v4 routing for ETH, stablecoins and tokenised stocks, one key per swap.
    Readable activity
    What each operation did, funds received, USD values and plain-language dApp approvals.
    Multi-chain ready
    Same contract and account addresses on Robinhood Chain, Ethereum, Base and Arbitrum (Sepolia).
  2. Now

    Live on testnets

    Everything above, running on real networks.
    Deploy and verify the contracts
    Robinhood Chain Testnet first, then Ethereum, Base and Arbitrum Sepolia, verified on Blockscout.
    On-chain proof
    The five-transaction test and the gas benchmark on a live testnet, with explorer links.
    Hosted bundler
    Send without a browser wallet relaying, through an ERC-4337 bundler.
    Demo video
    Create, fund, send, swap and recover, start to finish.
  3. Later

    Mainnet and beyond

    Following Ethereum's path to quantum safety.
    Mainnet launch
    Robinhood Chain, Ethereum and its L2s, after the audit.
    Cheaper verification
    Other values of w, ZK-aggregated signatures per bundle, and an Arbitrum Stylus verifier.
    New post-quantum schemes
    SLH-DSA, and lattice signatures once the EVM can verify them cheaply, through the same validator module.
    Several accounts and devices
    Separate accounts from one recovery phrase, and safe use of one seed on several devices.

Prototype status#

The project started as a six-week prototype in seven phases. The key milestone is the first successful testnet transaction at the end of Phase 4. This section tracks that plan.

Phases#

PhaseOutputStatus
0. ResearchDesign notes: WOTS parameters, ERC-4337 flowDone
1. WOTS libraryKey generation, signing, verification in TypeScript, with unit testsDone
2. Verifier contractSolidity library with differential and fuzz testsDone
3. Account and rotationQuantumSafeAccount, CREATE2 factory, replay testsDone
4. CLI and testnetCLI to create a wallet, check balances and send; testnet deploymentDeploy pending
5. Web UICreate a wallet, send, key rotation historyDone
6. Benchmark and docsGas vs ECDSA, README, demo videoVideo pending

Beyond the original plan: the Chrome extension, swaps, the recovery key and multi-chain support (see Shipped above).

Success criteria#

CriterionStatus
At least 5 consecutive transactions, a new key each timeLocal & fork Verified on Anvil and an Anvil fork of Robinhood Chain Testnet; live testnet after deployment
Replayed signatures are always rejectedDone
A signature changed by even one bit is rejected (fuzz-tested)Done
TypeScript library and contract agree in differential testsDone
Gas per transaction measured and compared with ECDSADone

Deliverables#

DeliverableStatus
Repository with TypeScript library, Solidity contracts, CLI and UIDone
Verified contract addresses on the testnetPending deployment
Gas benchmark reportDone
README with architecture diagramDone
Demo video, 3 to 5 minutesTo record