01 / SIGNATURES
Hash-based, not curve-based
WOTS signatures rely only on Keccak-256, the same hash Ethereum already trusts. No elliptic curves, nothing for Shor's algorithm to attack.
Winternitz is a quantum-safe smart wallet for Ethereum and its L2s, starting on Robinhood Chain. Every transaction is signed with a hash-based one-time key, so your assets stay yours after ECDSA falls.
TESTNET · SELF-CUSTODIAL · ERC-4337 · FUZZ-TESTED

128-bit
Post-quantum security
0
Signing keys ever reused
67
Hash chains per signature
2.1 KB
Signature size
Features
01 / SIGNATURES
WOTS signatures rely only on Keccak-256, the same hash Ethereum already trusts. No elliptic curves, nothing for Shor's algorithm to attack.
02 / ROTATION
Each key signs once, then it's gone.
03 / ADDRESS
Keys rotate behind a smart account. One address, on every EVM chain.
0x7a3F9c2E04bD6a1f58C3e7B90dA4f2c61e8591cE
04 / GAS
Gas per ETH transfer, benchmarked on-chain.
05 / RECOVERY
24 words restore your whole key tree.
06 / SWAP
Swap ETH, stablecoins and tokenised stocks through Uniswap v4, with the best route quoted on-chain. Approvals and swap are one operation, one key.
07 / SAFETY NETS
One-time keys need care. The wallet takes it for you.
08 / DEVELOPERS
The TypeScript SDK handles key generation, signing and the ERC-4337 bundler flow. Verifier contracts are open source.
Read the SDK docs →import { QuantumSafeWallet } from "@winternitz/sdk";
const wallet = await QuantumSafeWallet.load({ seed, ...d });
const tx = await wallet.send(
[{ to: "0x7a3F…91cE", value: parseEther("0.1") }],
bundler,
);
// signed with WOTS key #43, next key committedHow it works
Your seed expands into Winternitz key pairs using only Keccak-256. Keys never leave your device.
Each transaction walks 67 hash chains. Your ERC-4337 account verifies them on-chain before anything moves.
The used key is burned and the next one is committed in the same transaction. Your address never changes.
Chrome extension
The same quantum-safe account, in your browser toolbar or docked in Chrome's side panel. dApps connect to it like any other wallet.
Popup or side panel. Keep the wallet open next to the page while you trade.
Works with dApps. Standard EIP-1193 provider, discovered through EIP-6963.
Stock Tokens and ERC-20. Robinhood Stock Tokens listed by default; import any other token.
Approve everything. Every connection and transaction opens an approval window first.
v0.1 · Manifest V3 · Chrome 116+ · Brave, Edge, Arc

Security
ECDSA falls to Shor's algorithm. Hash functions don't: Grover's search only halves their strength. That is why hash-based schemes were among the first post-quantum signatures NIST standardised.
Vitalik Buterin's plan for a quantum emergency ends with Ethereum accounts moving to smart-contract validation. Winternitz is that kind of account, usable today.
Use cases
Cold storage
Harvest-now, decrypt-later attacks target exactly this: exposed public keys that sit on-chain for years. Winternitz never reuses a key, so there is nothing to harvest.
FAQ
Cryptography, costs, recovery and what changes for you.
Winternitz is a self-custodial smart wallet for Ethereum and its L2s that signs every transaction with a Winternitz one-time signature (WOTS), a hash-based scheme that stays secure against quantum computers.
Regular Ethereum accounts use ECDSA over secp256k1. A large enough quantum computer running Shor's algorithm could derive a private key from any public key already exposed on-chain. Hash-based signatures do not have that weakness.
No. Your address is a smart account that stays the same. Only the signing key behind it rotates, and the account tracks which key is next.
Yes, about 219k gas per transfer against 91k for an ECDSA smart account, mostly for verifying the 2 KB signature and carrying it in calldata. On L2s such as Robinhood Chain gas is cheap, and batching several calls into one operation spreads the cost.
You can move funds from any existing wallet into your Winternitz account. We deliberately do not import ECDSA keys, since that would carry the quantum risk with them. A guided migration and a quantum-readiness check are on the roadmap.
Your 24-word recovery phrase restores every key, in the web wallet, the extension or the command line. Write it down when you create the wallet: without it, the funds cannot be recovered.
Not yet. Winternitz is a testnet prototype: the contracts are unit-, fuzz- and differential-tested, but have not had a security audit. An independent audit comes before mainnet; until then, use test funds only.
Create a wallet on testnet today. Your address works right away, and mainnet follows an independent audit.