11 MARKETSUSDG10 S GRIDNEXT FILL 00:10
//Q_ Q-AccountsQuantum-resistant

No wallet key can empty a Q-Account.

  • Money out needs a Winternitz signature.
  • Hash-based: Shor's algorithm does not apply.
  • Each key signs once, then rotates.
  • Trading stays one click.
//Q-Accounts_
//Quantum_signatures_verified_on_chain_
//Owner_
None

Read from the factory contract every 15 seconds. It has no owner and holds nothing.

//01_ One signature, checkedFig.Q1, sample digests
//02_ The threatPlain words

Wallet keys break. Hashes hold.

Every EVM wallet signs with ECDSA on secp256k1. Once a wallet has sent one transaction, its public key is on chain, and a large enough quantum computer running Shor's algorithm could work the private key out of it.

A Q-Account does not use ECDSA at all. Its signatures are chains of keccak-256 hashes. The best known quantum attack on a hash is Grover's search, which leaves 128 bits of security: out of reach.

//Your_wallet_

ECDSA, secp256k1

//Quantum_attack_
Shor
//Recovers_the_key_
Yes
//Public_key_exposed_
After 1st transaction
//A_Q-Account_

Winternitz, keccak-256

//Quantum_attack_
Grover
//Security_left_
128 bits
//Key_exposed_
Spent on use

Same family as SLH-DSA, the hash-based signature standard NIST published in 2024 (FIPS 205).

//03_ Step by stepFive steps

One withdrawal, step by step.

  1. S.01

    The digest

    The batch you sign (the calls, the chain, the account, the key number, a gas floor and the hash of your next key) is hashed into 32 bytes.

  2. S.02

    67 positions

    Those 32 bytes are 64 hex digits, each from 0 to 15. Three more digits are a checksum: the sum of what the 64 leave out. Raising any digit lowers the checksum.

  3. S.03

    The signature

    Your key is 67 secret values. Each one is hashed as many times as its digit says. The 67 results are the signature: 2,144 bytes.

  4. S.04

    The check

    The contract hashes each word the rest of the way, to 15 steps, then hashes the 67 ends together. That must equal the key the account stores.

  5. S.05

    The rotation

    The key is now spent. The digest already named the next key, so the account switches to it in the same transaction. A key never signs twice.

//04_ Two keys, two jobsTab.Q4

Trade in one click. Withdraw with the quantum key.

Speed and safety get different keys. A session key, made in your browser for up to 30 days, opens and closes positions for the Q-Account. Everything that moves money out takes a one-time quantum-resistant signature, and the contract checks it.

ActionSession keyQuantum key
Open and close positionsYes, for 30 days at mostYes
Withdraw USDGNoYes, and only this
Collect queue claimsNoYes
Claim paper rewardsNoYes
Authorise or revoke a session keyNoYes
Move anything the account holdsNoYes
//05_ LimitsPlain words

What it does not do.

L.01

The account, not the chain

A Q-Account resists a quantum attacker. Robinhood Chain itself (its sequencer and bridge) and the USDG issuer still sign with ECDSA. If those fall, a Q-Account does not save the chain.
L.02

The key lives in this browser

It never leaves your device, so malware on that device could read it. The 24 backup words are the only copy we cannot lose for you.
L.03

Lose the words, lose the account

Nobody can reset a Q-Account: not us, not your wallet. Clear the browser without the 24 words and the funds stay where they are, for good.
L.04

One device at a time

A one-time key must sign a single batch. The app keeps a signed batch until it lands and refuses to sign another; two devices signing at once could break that rule.
L.05

No external audit

The Q-Account contracts are tested (unit tests, fuzzing, and a fork of mainnet against the live exchange) but have not had an external audit.
015304567

Paper hands.
Quantum-resistant account.