Skip to content
Qrypto

How it works

Two signatures, one account

Qrypto is a smart account, an Ethereum contract that checks both signatures. Every transfer needs ECDSA and hash-based SPHINCS-C13 signatures over the same transaction. Breaking the standard key alone cannot authorize it.

Standard key

ECDSA

Post-quantum key

SPHINCS-C13

Why the second signature matters

A sufficiently capable quantum computer could recover an Ethereum private key from its public key by breaking ECDSA, the standard signature scheme.

Hardware wallets protect where a key is stored. ECDSA-only multisig adds more keys. Neither changes the signature mathematics.

One phrase restores both keys

Your 24-word recovery phrase derives both keys separately and restores the same wallet address. Save and confirm it before receiving funds. The password only encrypts this device's wallet.

What this protects

Protection applies to the account's authorization, not Ethereum's consensus or token contracts. Anyone with the recovery phrase controls the wallet. Signing happens in your browser, so a compromised device or malicious site code can expose both keys.

Qrypto is experimental and unaudited. Its SPHINCS-C13 variant differs from NIST-standard SLH-DSA. These references explain the design; they are not an audit or endorsement of Qrypto.

Research and source code

Opening your wallet...