Check your wallet
See how much of it a quantum computer could reach. You paste a public address, nothing else.
Check a wallet →no key. nothing to break.
Each launch ships with a creator vault sealed by hash-based signatures and an on-chain identity made of one-time keys. Holders can set an exit that triggers the instant the canary wallet moves.
in plain words
See how much of it a quantum computer could reach. You paste a public address, nothing else.
Check a wallet →Set an automatic exit. If the alarm goes off, your coins move into your own vault before anyone else can reach them.
Set an exit →Keep ETH and coins in a vault that has no key to steal. You hold the only backup.
Open a vault →Your coin starts with its own vault and a signed identity, so holders can see the fees are locked away from day one.
Start a launch →act one
A wallet address is computed from a secp256k1 public key, and that key is published the moment you send your first transaction. For now it costs you nothing. Turning a public key back into its private key is far beyond any classical machine.
act two
Balances, transfers and public keys are copied to thousands of nodes and kept for good. Nobody has to crack them this year. They only have to keep the data and wait.
act three
Once a quantum computer is large enough to run Shor's algorithm, a public key is all it needs to compute the private one. Any wallet that has signed even once can be emptied.
act four
A NULLKEY vault is not controlled by an elliptic-curve key. Its ETH and tokenized stocks move only with a Winternitz signature built on keccak-256, and Shor's algorithm has nothing to say about hashes.
under the hood
Each vault is a contract balance filed under the hash of a Winternitz public key. Spending means revealing one point on every keccak-256 chain, and the message you sign decides which points. No curve is involved, so Shor's algorithm has no target.
the alarm
The canary is a wallet holding ETH whose private key was destroyed at creation. Ordinary computers cannot spend from it. If the balance ever drops, a private key has been worked out from a public one.
Set an auto-bunker and your exit sits ready, approved but not sent. When the canary goes, it executes and your stocks land in a hash-locked vault. Prefer not to wait? Bunker mode seals everything with a single hold.
A wallet whose private key no longer exists. Only a quantum computer, or a copy of the key that should not exist, could move its ETH.
the footage so far
surveillance
An AI agent follows quantum computing news day and night. Developments that matter are logged, and genuine progress shifts the q-day estimate. Launches, vaults and sweeps on NULLKEY show up in the same feed.
Everything in this panel is invented to show how a coin page will look. Real coins appear here after launch.
final reel
Pick a name, a ticker and an image, then hold the button. The coin opens on Robinhood Chain against a tokenized stock, and its vault and identity are created in the same step.
hash-only signatures go back to leslie lamport in 1979. the idea is old. the reason to use it is new.
launch
Pick a name, a ticker and an image, then hold the button. The coin opens on Robinhood Chain against a tokenized stock, and its vault and identity are created in the same step.
The shield score opens at 35 and rises as creator fees reach the vault and more holders move behind vaults of their own.
This backup is the only way to move what the vault holds. Lose it and the asset is lost.
coins
The more of a coin's value that sits behind hash-based keys, the higher it ranks.
price after each trade · ETH per coin · read from chain
Creator fees routed to the dev vault.
An open dev vault.
Share of the largest holders with a vault of their own.
scan
Enter an address. The scanner looks at what it holds and how long its public key has been visible, then estimates how much would be within reach on q-day.
The score is a heuristic from 0 to 99. It is not a measured probability of theft.
bunker
Set an auto-bunker and your exit sits ready, approved but not sent. When the canary goes, it executes and your stocks land in a hash-locked vault. Prefer not to wait? Bunker mode seals everything with a single hold.
ETH at a wallet whose private key was destroyed when it was made. If its balance drops below the baseline, canaryDead() returns true for everyone in the same block.
Kill the canary on this page only and watch what an armed escape does. Nothing leaves your browser.
Save this backup. A lost backup means a lost asset.
fire(...) pulls the approved tokens into your vault. Disarm removes the escape route on chain.Don't wait for the signal. One hold moves everything you approve into your hash-locked vault now.
tech
Quantum-resistant, not quantum-proof. Here is what the system does, the parameters it uses, and where its limits are.
Wallets on Robinhood Chain use secp256k1. Shor's algorithm breaks that on a large enough quantum computer. Q-day is the hypothetical moment when the attack becomes practical.
The system rests on hash functions instead of an elliptic curve. Grover search is assumed to halve the security bits, so 192-bit preimage resistance works out to about 2^96 under that model. NIST standardised SLH-DSA (FIPS 205); NULLKEY uses a Winternitz one-time signature over keccak-256, not that standard.
A vault id is keccak-256 over 34 chain ends. There is no private key in the elliptic-curve sense. The checksum chains stop forgery, each key signs once, and a used vault forwards its remainder to a named successor.
| chains | 34 (32 message + 2 checksum) |
|---|---|
| value size | 24 bytes |
| max steps | 255 (w = 256) |
| signature | 816 bytes |
A developer gets 32 one-time keys under a merkle tree, in the style of XMSS (RFC 8391). The root is registered on chain for the token. Every update spends a new leaf; the contract rejects reuse and a 33rd update. A valid signature proves who signed, not that the content is true.
Launches go through Karat, a launchpad built on Uniswap v4. Your browser generates the vault key and the identity tree locally. If a launch fails midway a token may already exist, so check your wallet history before trying again.
It needs a public address and nothing else. The score runs from 0 to 99 with these weights: value 58%, history 18%, activity 12%, token count 12%.
The canary is an ETH wallet whose private key was destroyed. If its balance falls below the baseline, canaryDead() returns true. With an auto-bunker armed, fire(...) can pull the approved tokens into your vault and nowhere else. A dead canary alone does not prove how a key was obtained.
Vaults protect only what is inside them. A lost vault backup is a lost asset. The q-day clock is an estimate, not a guarantee. Code and tests are not an audit. Verify contract addresses and a confirmed deposit before you put real value in.
A real Winternitz key with the spec's parameters. Sign a message, verify it, then try to cheat.