Protect my wallet
the quantum canary

A bounty nobody should ever win

A public bounty for anyone who can break the cryptography protecting today's wallets. It is a smart contract on Ethereum with no owner and no withdraw. If anyone ever claims it, the whole world sees it the same day.

the bounty
50%

of every fee goes into the bounty. It starts growing when WINTER launches.

A key that never existed

The bounty sits behind an ordinary Ethereum public key with one difference: it was made by hashing a public seed, so no private key for it was ever made. Nobody has it, including whoever deployed the contract.

todayUnclaimable

To claim, you must sign with that key. With today's computers, that means solving the problem every Ethereum wallet's safety rests on. Nobody can.

one dayA proof in public

A large enough quantum computer could work the private key out from the public one. Signing a claim proves exactly that, on chain, for everyone to check.

first claimTakes it all

The whole bounty goes to the first valid claim and the canary stays fired forever. The claim names the claimer's own address, so nobody can copy it and race them.

How it grows

Half of every fee goes into the bounty in the same transaction that pays it. The other half is burned. Nothing goes to anyone else.

each new vault500 WINTER

Half of the 1,000 WINTER creation fee.

each protected action25 WINTER

Half of the 50 WINTER action fee.

anyonetop it up

Anyone can add WINTER to the bounty directly. Nobody can take any out.

The bounty starts growing when WINTER launches. Before that, the app is free and the canary holds nothing. Paying with ETH adds a 20% convenience premium, split the same way: half burned, half to the bounty.

Why it matters

For everyone

Nobody can date the first machine that breaks a wallet key. The canary turns that unknown into a public event: if it fires, ordinary keys are no longer safe, and everyone knows at once.

For a vault

Nothing changes. A Wintergate vault already needs a one-time hash key on every move, so it is protected before the alarm, not because of it.

For the honest finder

Whoever gets there first has a public reward for saying so, instead of a reason to stay quiet.

its limits

A detector, not a guarantee

It can stay silent

An attacker does not have to claim it. Someone able to break keys could go after bigger wallets first, or never reveal it.

It measures one thing

It fires on a broken Ethereum key. It says nothing about bugs, stolen seeds or other risks.

Its size moves

The bounty is held in WINTER, so what it is worth in dollars moves with the market.

All the risks, plainly · The research behind the threat