Qrypto is a smart account, an Ethereum contract that checks both signatures. Every transfer needs ECDSA and hash-based SPHINCS-C13 signatures over the same transaction. Breaking the standard key alone cannot authorize it.
Standard key
ECDSA
Post-quantum key
SPHINCS-C13
One smart account
Both signatures required
A sufficiently capable quantum computer could recover an Ethereum private key from its public key by breaking ECDSA, the standard signature scheme.
Hardware wallets protect where a key is stored. ECDSA-only multisig adds more keys. Neither changes the signature mathematics.
Your 24-word recovery phrase derives both keys separately and restores the same wallet address. Save and confirm it before receiving funds. The password only encrypts this device's wallet.
Protection applies to the account's authorization, not Ethereum's consensus or token contracts. Anyone with the recovery phrase controls the wallet. Signing happens in your browser, so a compromised device or malicious site code can expose both keys.
Qrypto is experimental and unaudited. Its SPHINCS-C13 variant differs from NIST-standard SLH-DSA. These references explain the design; they are not an audit or endorsement of Qrypto.
How hash-based signatures can be verified directly on Ethereum.
Solidity verifiers, signers, parameter choices, and research limitations.
Babbush and colleagues examine the resources needed to attack elliptic-curve keys.
The specification that lets smart accounts define how transactions are authorized.
FIPS 205 specifies SLH-DSA, based on SPHINCS+. Qrypto's C13 variant is not this standard.
A pinned Solidity implementation of another SPHINCS variant, distinct from Qrypto's C13 verifier.