Protect my wallet

Launching on Ethereum soon

A quantum-resistant vault for your Ethereum

Every move needs your normal key and a one-time hash key made on your device. Quantum computers cannot forge the second one. No owner, no admin, no server: nobody can touch or block your vault.

per protected action 50 WINTERto leave no feeadmin keys noneworks without this site yes
scroll

Is your key already out there?

Every transaction a wallet sends puts its public key on chain, and a public key is all a quantum computer needs. Paste an address or ENS name to check. Your browser asks a public Ethereum endpoint directly: no sign-in, no wallet connection, nothing stored.

Try

Exposed

The address has ever sent a transaction, signed a token approval on chain, or deployed a contract. Its public key is public for good, and moving the funds is the only fix.

Not yet exposed

The address has only ever received. Its key is still hidden behind a hash, until the first time it sends.

the quantum canary

A bounty nobody should ever win

A public bounty for anyone who can break the cryptography protecting today's wallets. If anyone ever claims it, the whole world sees it on Ethereum the same day.

the bounty
50%

of every fee goes into the bounty. It starts growing when WINTER launches.

why it mattersAn alarm in public

Nobody can date the first machine that breaks a wallet key. A claim on the canary is the clearest signal anyone could get that ordinary keys are no longer safe.

how it growsHalf of every fee

500 WINTER for each new vault and 25 WINTER for each protected action, in the same transaction. No cap, no admin, no withdraw: only a valid claim moves it.

its limitsA detector, not a shield

Someone able to claim it might choose not to. Your vault does not rely on the alarm: it needs a hash key on every move, before and after.

The canary, in full
why now

The ice is thinner than it looks

Nobody can date the first machine that breaks a wallet key. What can be tracked is the published cost of doing it, and it keeps falling.

< 500,000
physical qubits to break the curve behind every Ethereum key, about ten times fewer than the previous best estimate.
Google Quantum AI with the Ethereum Foundation and Stanford, Mar 2026 [1]
minutes
per key once such a machine exists. Summaries of the paper quote about 18, or 9 with precomputation.
[1], summary [2]
2035
the year NIST disallows today's signature algorithms. Deprecation starts after 2030.
NIST IR 8547 [5]
The estimates and what is exposed, in depth
how it works

Approve once. Wait a few minutes. Done.

A protected action takes a few minutes, and the wait is the safety step: Ethereum records what you are about to sign before your device signs it, so a one-time key can only ever sign once.

  1. 1You approve

    You confirm the action once, shown in plain words, with the wallet you already use.

  2. 2Ethereum records it

    Your vault writes down exactly which action the next one-time key may sign. Written once, never changed.

  3. 3It settles

    About eight minutes, until Ethereum treats the record as final. This is what keeps your key safe.

  4. 4Sign and send

    Only then does your device make the one-time signature. The vault checks both keys before anything moves.

Watch a one-time signature form

A real one-time key signs a real transaction digest, then the check runs backwards to its public key. Computed in this tab.

digest ... checksum ... sign ... + verify ... = ... ...

The same keccak256 Ethereum uses. A new demo transaction every loop.

How it works, in depth

Small, simple, paid in WINTER

The vault contract itself charges the fee. Pay with ETH if you like: the app converts it in the same step.

create a vault1,000 WINTER

Once, in WINTER.

protected action50 WINTER

In WINTER, plus Ethereum gas: about $0.24 at today's gas.

exit and recoveryno fee

Never a WINTER fee, never anyone's permission. Gas only.

Pricing, in full
nobody in charge

No owner. No one to ask.

Your vault is a contract on Ethereum that nobody can change. Once it is out, it is out there: a community protocol with no owner, no admin and no off switch.

What you keep
  • Custody. Only your keys can move your funds.
  • An exit. Leave any time, without anyone's permission and without a fee.
  • A recovery key you hold, with a 30-day brake that only you can pull.
  • Your keys. They are made on your device and never leave it.
What you are trusting
What nobody can do
  • Touch or block your vault. No server is in the path of any action, exit or recovery.
  • Change the rules. No admin keys, no pause button, no upgrade.
  • Change the fee token. One setting at launch, locked forever after. It can never touch your funds.
  • Keep you in. If this website disappeared tomorrow, your vault would work exactly the same.
The risks that remain, plainly
exitsAlways a way out

Leaving never needs anyone's permission or a WINTER fee. The app ships with an exit page that talks to Ethereum directly and needs no server.

How leaving works
coming soonBusiness and Enterprise

Protection for teams, treasuries and the keys that run a protocol. Personal protection comes first.

Coming soon

Protect your wallet

A vault on Ethereum that only you can move, a key no quantum computer can forge, and a door you can always walk out of.