Project
Roadmap
Where Winternitz is, and where it is going: from a working prototype to a quantum-safe wallet on Ethereum and its L2s. Stages move when their blockers clear, not on fixed dates.
- Shipped
A working quantum-safe wallet
The prototype from the original plan, and more.WOTS signatures on ERC-4337TypeScript signer and Solidity verifier, differential- and fuzz-tested; a new key for every transaction.Web wallet, CLI and Chrome extensionEncrypted seed, 24-word recovery phrase, auto-lock, side panel, dApp connections.Recovery keyA stuck transaction is replaced without any key signing twice.Fee estimate before signingExpected and maximum network fee, with room kept for it in your balance.Swaps and Stock TokensUniswap v4 routing for ETH, stablecoins and tokenised stocks, one key per swap.Readable activityWhat each operation did, funds received, USD values and plain-language dApp approvals.Multi-chain readySame contract and account addresses on Robinhood Chain, Ethereum, Base and Arbitrum (Sepolia). - Now
Live on testnets
Everything above, running on real networks.Deploy and verify the contractsRobinhood Chain Testnet first, then Ethereum, Base and Arbitrum Sepolia, verified on Blockscout.On-chain proofThe five-transaction test and the gas benchmark on a live testnet, with explorer links.Hosted bundlerSend without a browser wallet relaying, through an ERC-4337 bundler.Demo videoCreate, fund, send, swap and recover, start to finish. - Next
Priorities
The five things that matter most next, in order. Their designs are described in Future work.1. XMSS and message signingMany WOTS keys under one Merkle root: dApp logins, permits and ERC-1271, with cheaper transactions.2. ERC-7579 validator moduleQuantum-safe signatures as a module for existing smart accounts such as Safe, Kernel and Nexus.3. PaymasterPay gas in USDC or USDG, or have it sponsored: no ETH needed to start.4. Quantum readiness and migrationCheck whether an address is exposed, move to safety, or prepare it with EIP-7702.5. Independent auditContracts, journal and extension, with a public report and a bug bounty before mainnet.Continuous integration and Web StoreEvery change tested end to end; one-click install and updates for the extension. - Later
Mainnet and beyond
Following Ethereum's path to quantum safety.Mainnet launchRobinhood Chain, Ethereum and its L2s, after the audit.Cheaper verificationOther values of w, ZK-aggregated signatures per bundle, and an Arbitrum Stylus verifier.New post-quantum schemesSLH-DSA, and lattice signatures once the EVM can verify them cheaply, through the same validator module.Several accounts and devicesSeparate accounts from one recovery phrase, and safe use of one seed on several devices.
Prototype status#
The project started as a six-week prototype in seven phases. The key milestone is the first successful testnet transaction at the end of Phase 4. This section tracks that plan.
Phases#
| Phase | Output | Status |
|---|---|---|
| 0. Research | Design notes: WOTS parameters, ERC-4337 flow | Done |
| 1. WOTS library | Key generation, signing, verification in TypeScript, with unit tests | Done |
| 2. Verifier contract | Solidity library with differential and fuzz tests | Done |
| 3. Account and rotation | QuantumSafeAccount, CREATE2 factory, replay tests | Done |
| 4. CLI and testnet | CLI to create a wallet, check balances and send; testnet deployment | Deploy pending |
| 5. Web UI | Create a wallet, send, key rotation history | Done |
| 6. Benchmark and docs | Gas vs ECDSA, README, demo video | Video pending |
Beyond the original plan: the Chrome extension, swaps, the recovery key and multi-chain support (see Shipped above).
Success criteria#
| Criterion | Status |
|---|---|
| At least 5 consecutive transactions, a new key each time | Local & fork Verified on Anvil and an Anvil fork of Robinhood Chain Testnet; live testnet after deployment |
| Replayed signatures are always rejected | Done |
| A signature changed by even one bit is rejected (fuzz-tested) | Done |
| TypeScript library and contract agree in differential tests | Done |
| Gas per transaction measured and compared with ECDSA | Done |
Deliverables#
| Deliverable | Status |
|---|---|
| Repository with TypeScript library, Solidity contracts, CLI and UI | Done |
| Verified contract addresses on the testnet | Pending deployment |
| Gas benchmark report | Done |
| README with architecture diagram | Done |
| Demo video, 3 to 5 minutes | To record |