No wallet key can empty a Q-Account.
- Money out needs a Winternitz signature.
- Hash-based: Shor's algorithm does not apply.
- Each key signs once, then rotates.
- Trading stays one click.
- //Q-Accounts_
- //Quantum_signatures_verified_on_chain_
- //Factory_
- 0xab7d...0bdA ↗
- //Owner_
- None
Read from the factory contract every 15 seconds. It has no owner and holds nothing.
Wallet keys break. Hashes hold.
Every EVM wallet signs with ECDSA on secp256k1. Once a wallet has sent one transaction, its public key is on chain, and a large enough quantum computer running Shor's algorithm could work the private key out of it.
A Q-Account does not use ECDSA at all. Its signatures are chains of keccak-256 hashes. The best known quantum attack on a hash is Grover's search, which leaves 128 bits of security: out of reach.
ECDSA, secp256k1
- //Quantum_attack_
- Shor
- //Recovers_the_key_
- Yes
- //Public_key_exposed_
- After 1st transaction
Winternitz, keccak-256
- //Quantum_attack_
- Grover
- //Security_left_
- 128 bits
- //Key_exposed_
- Spent on use
Same family as SLH-DSA, the hash-based signature standard NIST published in 2024 (FIPS 205).
One withdrawal, step by step.
- S.01
The digest
The batch you sign (the calls, the chain, the account, the key number, a gas floor and the hash of your next key) is hashed into 32 bytes.
- S.02
67 positions
Those 32 bytes are 64 hex digits, each from 0 to 15. Three more digits are a checksum: the sum of what the 64 leave out. Raising any digit lowers the checksum.
- S.03
The signature
Your key is 67 secret values. Each one is hashed as many times as its digit says. The 67 results are the signature: 2,144 bytes.
- S.04
The check
The contract hashes each word the rest of the way, to 15 steps, then hashes the 67 ends together. That must equal the key the account stores.
- S.05
The rotation
The key is now spent. The digest already named the next key, so the account switches to it in the same transaction. A key never signs twice.
Trade in one click. Withdraw with the quantum key.
Speed and safety get different keys. A session key, made in your browser for up to 30 days, opens and closes positions for the Q-Account. Everything that moves money out takes a one-time quantum-resistant signature, and the contract checks it.