Docs · Why quantum-safe▾
Overview

Why quantum-safe

Ethereum accounts are protected by ECDSA signatures. ECDSA is secure against today's computers, but not against a sufficiently large quantum computer. Winternitz moves your account to a signature scheme that stays safe.

What a quantum computer breaks#

A normal Ethereum account (an EOA) has one private key for life. Its public key becomes visible on-chain the first time the account sends a transaction, and it stays visible forever.

ECDSA's security rests on one assumption: that you cannot compute the private key from the public key. Shor's algorithm, running on a large enough quantum computer, can do exactly that. An attacker could then sign any transaction from that account.

This enables a harvest now, decrypt later attack: the public keys are already public today, so they can be collected now and used the day the hardware exists.

What it doesn't break#

Hash functions such as keccak256 are a different story. The best known quantum attack on them, Grover's algorithm, only speeds up brute force search. A 256-bit hash still offers about 128 bits of security against a quantum attacker, which remains far out of reach.

Signature schemes built only from hash functions therefore stay secure. Winternitz one-time signatures (WOTS) are the classic example, and the building block behind the hash-based signature standards chosen for the post-quantum era.

ECDSA (today's wallets)Winternitz (WOTS)
Built onElliptic curves (secp256k1)Hash functions (keccak256)
Quantum attackBroken by Shor's algorithmOnly weakened by Grover; ~128-bit security remains
Key useOne key for every transactionA fresh key for every transaction
Signature size65 bytes2,176 bytes (incl. next key)

Why act now#

On 27 September 2026, Vitalik Buterin published The cryptographic world computer, mapping Ethereum's path to 2030. Among the shifts it describes: transaction authorisation moving from a single classical signature toward quantum-safe signatures or zero-knowledge proofs, and upgrades after the Hegotá fork focusing on making the whole system quantum-resistant.

Vitalik had already described the endgame for a sudden threat. In How to hard-fork to save most users' funds in a quantum emergency (March 2024) he proposed disabling ordinary ECDSA transactions, letting users prove with a STARK that they know the hash preimage their key came from, and moving their accounts to smart-contract validation. Winternitz is a smart-contract account whose validation is already hash-based, so it does not depend on that rescue. The quantum emergency plan walks through the proposal with diagrams.

Protocol-level changes take years. Wallets do not have to wait. The Future work page describes how Winternitz plans to help existing addresses prepare.

How account abstraction makes it possible#

With ERC-4337, your account is a smart contract. The contract itself decides what counts as a valid signature. That means a wallet can switch from ECDSA to WOTS today, on any EVM chain that supports ERC-4337, without any change to Ethereum itself.

Winternitz uses the standard EntryPoint v0.7, so it works with existing ERC-4337 bundlers and infrastructure.

Scope

Only your account's authorisation becomes quantum-safe. Ethereum's consensus, the bundler's own transaction and the device that holds your seed are outside this project. See Security & scope.