how it works
Two keys sign. Ethereum makes sure one of them signs only once.
Your device holds both keys. Your vault on Ethereum checks both, and keeps the public record that stops a one-time key from ever signing twice. No server sits in between.
One protected action, start to finish
What happens when you send from your vault.
Two transactions, minutes apart. The app does both for you after one approval.
- 1You approve
The app shows the action in plain words. You approve it once with your normal wallet. That approval names the exact action and the one-time key that may sign it.
- 2The vault records it
The app sends a small first transaction. Your vault writes down "this one-time key may sign this action, and nothing else". A record can be written once and never changed.
- 3The record settles
The app waits until Ethereum treats the record as final, about eight minutes. It does not touch the one-time key before then.
- 4Sign and execute
Your device makes the one-time signature for the recorded action. The vault checks your approval, the hash signature and the record, takes the fee, then runs your action.
Anyone may send either transaction for you, so a stuck one can always be re-sent. Gas is paid by your own wallet, or by a small gas key the app keeps that can pay but can authorise nothing.
Why it takes minutes, not seconds
A one-time key is safe only if it signs one thing, ever. Signing before the record is final could, in a rare chain reorganisation, leave room for a second record. So the app waits, and you choose how long.
| Setting | Waits for | Typical action, end to end | When to use it |
|---|---|---|---|
| Safe (default) | Ethereum's "safe" block, about 8 minutes | 8 to 15 minutes | Everything. A safe block has never been reverted on Ethereum. |
| Fast | 3 blocks, about 36 seconds | about a minute | Small amounts only. A deep reorg plus a restore from an old backup could, in theory, reuse a key. |
| Strict | "finalized", about 15 minutes | about 16 minutes | Large moves, if you want the strongest finality Ethereum offers. |
The app sends the first transaction through a private relay, so it does not sit in Ethereum's public waiting room. You can switch to the public mempool if you prefer.
Every action carries a two-hour deadline and the highest fee you are willing to pay. If either is passed, nothing moves and the next action uses a fresh key.
Why "sign once" is the whole game
A hash-based one-time key reveals part of itself each time it signs. One signature is safe. Two signatures on different messages let a forger mix the revealed parts into a third.
A transaction is dropped, the app retries with new details and the same key. That is two signatures. Nothing malicious happened, and the key is now forgeable.
The record on Ethereum names one action per key, for good. The app signs only what the record says, so a retry re-sends the same bytes, and a second device simply takes the next key.
Watch a signature form
67 chains, 16 steps each: sign plus verify is always exactly 1,005 hashes.
Computed in this tab with keccak256, the hash Ethereum uses.
One chain, walked by hand
To sign a digit you publish the value that many steps up the chain. Anyone can walk forward to check it. Nobody can walk back.
One chain, step by step
...
- signer hashes
- 0
- verifier hashes
- 0
- -
- 0
Try to forge it
Pushing a chain forward is free, so a forger could raise any digit. The signature also signs a checksum that runs the other way, so every raised digit forces another chain backwards.
Try to cheat the signature
real keccak256Digest and its 67 digits
...
- checksum \(C\)
- ...
- verify hashes
- ...
- verdict
- ...
Each key set holds about a thousand one-time keys. Before they run out, the app moves your vault to a fresh set in one ordinary protected action.
The fee, inside the contract
Every protected action is paid in WINTER: the vault contract will not accept a protected signature without its WINTER fee.
Your vault holds some WINTER. Each protected action pays 50 WINTER from it, a fixed amount that never changes. Top it up with ETH in one step.
Starting or finishing an exit, a recovery, cancelling a recovery, or moving everything to your exit address never costs a WINTER fee and never reads the fee contract.
Half of every fee is burned on chain, for good. The other half is added to the public canary bounty, in the same transaction. Nothing goes to anyone else.
Until WINTER launches, creating a vault and protected actions are free. Vaults made before the launch start paying from the launch on. Pricing · WINTER
Leaving, and getting back in
You never need anyone's permission, a server or a fee to leave. The exit page talks to Ethereum directly and can be saved and run from your own computer.
One fee-free action sends your ETH and the tokens you list to the exit address you chose when you made the vault. It needs your keys, and it can only ever pay that address.
Start an escape with your keys. Seven days later your vault no longer needs the on-chain record for each action. It exists for the worst days; the wait stops a thief from rushing it.
A separate recovery key, kept apart from everything else, can hand the vault to new keys after 30 days. Anyone who starts it is visible on chain, and you can cancel it with your keys.
Your recovery kit or master seed rebuilds your keys, and the vault itself tells the app which one-time keys are used. No backup file has to be up to date for your keys to stay safe.
The quantum alarm
A bounty sits on a public key made by hashing, so its private key never existed. Only someone able to break today's wallet keys can claim it. The bounty grows with every vault and every protected action: half of every fee goes into it, 500 WINTER for each new vault and 25 WINTER for each protected action. There is no cap, no admin and no withdraw: the whole bounty goes to the first valid claim.
Always needs the hash key on every move, so the alarm changes nothing for it. You are protected before the alarm, not because of it.
Claiming the bounty is public. It is the clearest signal anyone could get that ordinary wallet keys are no longer safe.
An attacker does not have to claim it. The canary is a detector, not a guarantee.
Plainly
Every move needs your normal key and your one-time hash key. Nobody else holds either, and no contract has a way around them.
No server is in the path of any action, exit or recovery. Your app needs a public Ethereum connection and your own gas, nothing else.
No owner, no pause, no upgrade. One fee-token setting at launch, locked forever after; it can never touch your funds.
Your recovery key can replace lost keys after 30 days. You can cancel any recovery you did not start.
The record on Ethereum is the rulebook; the app must follow it, and it is built and tested never to sign outside it.
That the hash function cannot be reversed. Quantum computers only halve its strength, to about 2128.