Why quantum-safe
Ethereum accounts are protected by ECDSA signatures. ECDSA is secure against today's computers, but not against a sufficiently large quantum computer. Winternitz moves your account to a signature scheme that stays safe.
What a quantum computer breaks#
A normal Ethereum account (an EOA) has one private key for life. Its public key becomes visible on-chain the first time the account sends a transaction, and it stays visible forever.
ECDSA's security rests on one assumption: that you cannot compute the private key from the public key. Shor's algorithm, running on a large enough quantum computer, can do exactly that. An attacker could then sign any transaction from that account.
This enables a harvest now, decrypt later attack: the public keys are already public today, so they can be collected now and used the day the hardware exists.
What it doesn't break#
Hash functions such as keccak256 are a different story. The best known quantum attack on them, Grover's algorithm, only speeds up brute force search. A 256-bit hash still offers about 128 bits of security against a quantum attacker, which remains far out of reach.
Signature schemes built only from hash functions therefore stay secure. Winternitz one-time signatures (WOTS) are the classic example, and the building block behind the hash-based signature standards chosen for the post-quantum era.
| ECDSA (today's wallets) | Winternitz (WOTS) | |
|---|---|---|
| Built on | Elliptic curves (secp256k1) | Hash functions (keccak256) |
| Quantum attack | Broken by Shor's algorithm | Only weakened by Grover; ~128-bit security remains |
| Key use | One key for every transaction | A fresh key for every transaction |
| Signature size | 65 bytes | 2,176 bytes (incl. next key) |
Why act now#
On 27 September 2026, Vitalik Buterin published The cryptographic world computer, mapping Ethereum's path to 2030. Among the shifts it describes: transaction authorisation moving from a single classical signature toward quantum-safe signatures or zero-knowledge proofs, and upgrades after the Hegotá fork focusing on making the whole system quantum-resistant.
Vitalik had already described the endgame for a sudden threat. In How to hard-fork to save most users' funds in a quantum emergency (March 2024) he proposed disabling ordinary ECDSA transactions, letting users prove with a STARK that they know the hash preimage their key came from, and moving their accounts to smart-contract validation. Winternitz is a smart-contract account whose validation is already hash-based, so it does not depend on that rescue. The quantum emergency plan walks through the proposal with diagrams.
Protocol-level changes take years. Wallets do not have to wait. The Future work page describes how Winternitz plans to help existing addresses prepare.
How account abstraction makes it possible#
With ERC-4337, your account is a smart contract. The contract itself decides what counts as a valid signature. That means a wallet can switch from ECDSA to WOTS today, on any EVM chain that supports ERC-4337, without any change to Ethereum itself.
Winternitz uses the standard EntryPoint v0.7, so it works with existing ERC-4337 bundlers and infrastructure.
Scope
Only your account's authorisation becomes quantum-safe. Ethereum's consensus, the bundler's own transaction and the device that holds your seed are outside this project. See Security & scope.