Protect my wallet

how it works

Two keys sign. Ethereum makes sure one of them signs only once.

Your device holds both keys. Your vault on Ethereum checks both, and keeps the public record that stops a one-time key from ever signing twice. No server sits in between.

One protected action, start to finish

What happens when you send from your vault.

Your device normal key + one-time hash key keys never leave it Your vault on Ethereum 1. record the action 2. settle, about 8 min 3. check both keys nobody else in the path Funds move fee taken first then your action public, final approve execute

Two transactions, minutes apart. The app does both for you after one approval.

  1. 1You approve

    The app shows the action in plain words. You approve it once with your normal wallet. That approval names the exact action and the one-time key that may sign it.

  2. 2The vault records it

    The app sends a small first transaction. Your vault writes down "this one-time key may sign this action, and nothing else". A record can be written once and never changed.

  3. 3The record settles

    The app waits until Ethereum treats the record as final, about eight minutes. It does not touch the one-time key before then.

  4. 4Sign and execute

    Your device makes the one-time signature for the recorded action. The vault checks your approval, the hash signature and the record, takes the fee, then runs your action.

Anyone may send either transaction for you, so a stuck one can always be re-sent. Gas is paid by your own wallet, or by a small gas key the app keeps that can pay but can authorise nothing.

Why it takes minutes, not seconds

A one-time key is safe only if it signs one thing, ever. Signing before the record is final could, in a rare chain reorganisation, leave room for a second record. So the app waits, and you choose how long.

SettingWaits forTypical action, end to endWhen to use it
Safe (default)Ethereum's "safe" block, about 8 minutes8 to 15 minutesEverything. A safe block has never been reverted on Ethereum.
Fast3 blocks, about 36 secondsabout a minuteSmall amounts only. A deep reorg plus a restore from an old backup could, in theory, reuse a key.
Strict"finalized", about 15 minutesabout 16 minutesLarge moves, if you want the strongest finality Ethereum offers.
Private by default

The app sends the first transaction through a private relay, so it does not sit in Ethereum's public waiting room. You can switch to the public mempool if you prefer.

A deadline you sign

Every action carries a two-hour deadline and the highest fee you are willing to pay. If either is passed, nothing moves and the next action uses a fresh key.

Why "sign once" is the whole game

A hash-based one-time key reveals part of itself each time it signs. One signature is safe. Two signatures on different messages let a forger mix the revealed parts into a third.

The everyday trap

A transaction is dropped, the app retries with new details and the same key. That is two signatures. Nothing malicious happened, and the key is now forgeable.

What the vault does about it

The record on Ethereum names one action per key, for good. The app signs only what the record says, so a retry re-sends the same bytes, and a second device simply takes the next key.

Watch a signature form

67 chains, 16 steps each: sign plus verify is always exactly 1,005 hashes.

digest ... checksum ... sign ... + verify ... = ... ...

Computed in this tab with keccak256, the hash Ethereum uses.

One chain, walked by hand

To sign a digit you publish the value that many steps up the chain. Anyone can walk forward to check it. Nobody can walk back.

\[\sigma_i = c^{\,b_i}(sk_i),\qquad c^{\,15-b_i}(\sigma_i) \stackrel{?}{=} pk_i\]

One chain, step by step

...

signer hashes
0
verifier hashes
0

Try to forge it

Pushing a chain forward is free, so a forger could raise any digit. The signature also signs a checksum that runs the other way, so every raised digit forces another chain backwards.

\[C = \sum_{i=1}^{64} (15 - b_i) \in [0, 960]\]

Try to cheat the signature

real keccak256
Digest and its 67 digits

...

checksum \(C\)
...
verify hashes
...
verdict
...

Each key set holds about a thousand one-time keys. Before they run out, the app moves your vault to a fresh set in one ordinary protected action.

The fee, inside the contract

Every protected action is paid in WINTER: the vault contract will not accept a protected signature without its WINTER fee.

Protection credit

Your vault holds some WINTER. Each protected action pays 50 WINTER from it, a fixed amount that never changes. Top it up with ETH in one step.

Exits are free

Starting or finishing an exit, a recovery, cancelling a recovery, or moving everything to your exit address never costs a WINTER fee and never reads the fee contract.

Where it goes

Half of every fee is burned on chain, for good. The other half is added to the public canary bounty, in the same transaction. Nothing goes to anyone else.

Until WINTER launches, creating a vault and protected actions are free. Vaults made before the launch start paying from the launch on. Pricing · WINTER

Leaving, and getting back in

You never need anyone's permission, a server or a fee to leave. The exit page talks to Ethereum directly and can be saved and run from your own computer.

move everything outEvacuate

One fee-free action sends your ETH and the tokens you list to the exit address you chose when you made the vault. It needs your keys, and it can only ever pay that address.

seven daysThe escape hatch

Start an escape with your keys. Seven days later your vault no longer needs the on-chain record for each action. It exists for the worst days; the wait stops a thief from rushing it.

lost keysRecovery

A separate recovery key, kept apart from everything else, can hand the vault to new keys after 30 days. Anyone who starts it is visible on chain, and you can cancel it with your keys.

a new phoneRestore

Your recovery kit or master seed rebuilds your keys, and the vault itself tells the app which one-time keys are used. No backup file has to be up to date for your keys to stay safe.

The quantum alarm

A bounty sits on a public key made by hashing, so its private key never existed. Only someone able to break today's wallet keys can claim it. The bounty grows with every vault and every protected action: half of every fee goes into it, 500 WINTER for each new vault and 25 WINTER for each protected action. There is no cap, no admin and no withdraw: the whole bounty goes to the first valid claim.

Your vault

Always needs the hash key on every move, so the alarm changes nothing for it. You are protected before the alarm, not because of it.

Everyone else

Claiming the bounty is public. It is the clearest signal anyone could get that ordinary wallet keys are no longer safe.

Its limits

An attacker does not have to claim it. The canary is a detector, not a guarantee.

what you are trusting

Plainly

Nobody can take funds

Every move needs your normal key and your one-time hash key. Nobody else holds either, and no contract has a way around them.

Nobody can block you

No server is in the path of any action, exit or recovery. Your app needs a public Ethereum connection and your own gas, nothing else.

No admin

No owner, no pause, no upgrade. One fee-token setting at launch, locked forever after; it can never touch your funds.

Recovery with a brake

Your recovery key can replace lost keys after 30 days. You can cancel any recovery you did not start.

Your app

The record on Ethereum is the rulebook; the app must follow it, and it is built and tested never to sign outside it.

One hard assumption

That the hash function cannot be reversed. Quantum computers only halve its strength, to about 2128.

The risks that remain, written down honestly