Protect my wallet

Research · the threat model

How close is a machine that breaks secp256k1?

Nobody can date a cryptographically relevant quantum computer. What can be tracked is the published cost of the attack, which keeps falling, and the size of machines being built, which keeps rising. Wintergate is built for the gap between those lines closing without notice.

Published resource estimates

Shor's algorithm computes the discrete logarithm \(q\) from \(Q = qG\) in polynomial time. The question is the constant: how many error-corrected (logical) qubits, how many non-Clifford gates (Toffolis), and how many physical qubits once error correction is paid for.

Estimates for ECDLP-256 against machines built

Drag to scrub; playing sweeps 2017 to 2026.

...

YearSourceLogicalToffoliPhysicalAssumptions
2017Roetteler, Naehrig, Svore, Lauter [3]2,330~1.3 × 1011not given\(9n + 2\lceil\log_2 n\rceil + 10\) qubits and \(448 n^3 \log_2 n + 4090 n^3\) Toffolis at \(n = 256\)
2022Webber et al. [10]n/an/a13M (1 day), 317M (1 h)surface code, 1 µs cycle, 10-3 physical error
2023Litinski [4]n/a~5 × 107~6.9Mphotonic, non-local links; not like for like with planar superconducting
2026Chevignard et al., EUROCRYPT 2026 (as summarised in [2])~1,100> 1011n/afewer qubits, many more gates
Mar 2026Google Quantum AI, EF, Stanford [1]1,200 / 1,45090M / 70M< 500,00010-3 physical error, 1 µs cycle, 10 µs reaction time; runtime minutes (about 18, about 9 primed [2])

Built machines for scale: IBM Condor, 1,121 physical qubits (Dec 2023); Google Willow, 105 physical qubits with below-threshold error correction (Dec 2024). Chip counts are not error-corrected qubits and not comparable one to one; they are plotted only to show the gap in orders of magnitude.

From logical to physical: a textbook model

The physical count is where the estimates moved most. A standard back-of-envelope for a rotated surface code of distance \(d\) uses a logical error rate per logical qubit per code cycle of

\[p_L(d) \approx A \left(\frac{p}{p_{\text{th}}}\right)^{(d+1)/2},\qquad A \approx 0.1,\ p_{\text{th}} \approx 10^{-2}\](1)

The whole computation must fail with probability at most \(\varepsilon\). With \(Q\) logical qubits alive for \(N_c\) code cycles:

\[Q \cdot N_c \cdot p_L(d) \le \varepsilon,\qquad N_c = \frac{T \cdot d}{f},\qquad n_{\text{phys}} \approx o \cdot Q \cdot 2(d+1)^2,\qquad t_{\text{run}} = N_c \cdot t_c\](2)

where \(T\) is the Toffoli count, \(f\) the Toffolis completed per \(d\) cycles (parallelism), \(o\) an overhead factor for routing and magic-state factories, and \(t_c\) the code cycle. Solve for the smallest odd \(d\):

Surface-code sizing

textbook model, not Google's architecture
log scale; threshold at 10-2
code distance \(d\)
...
\(p_L(d)\)
...
physical qubits
...
runtime per key
...
vs Mar 2026 estimate (< 500k)
...
physical qubits vs \(p\) (log-log)current \(p\)500,000

With the defaults this model lands at a few million physical qubits and a runtime in the tens of minutes: the same order as the pre-2026 estimates. The March 2026 figure of under 500,000 comes from a detailed architecture and circuit model this sketch does not reproduce; read the gap as the reason the headline number fell, not as a disagreement. What the model shows reliably is the shape: halving \(p\) buys a smaller \(d\), and the qubit count falls with \((d+1)^2\).

What is exposed on Ethereum

An Ethereum address is \(\texttt{keccak256}(pk)[12{:}32]\), a hash of the public key. The key itself appears only when the account signs: \((r, s, v)\) plus the message lets anyone recover \(pk\) with ecrecover.

AccountPublic key on-chain?Exposure to a CRQC
EOA that has sent any transactionyes, recoverable from every signatureat rest key recoverable any time, funds movable
EOA that only ever receivedno, only its hashon first spend safe until it signs
Safe / multisig of ECDSA ownersyes, owners have signedat rest needs threshold many keys, minutes each
EIP-7702 delegated EOAyesat rest the key can still sign and re-delegate
Wintergate vaultECDSA key yes, hash key only as a hashnone known every move also needs a one-time hash signature (a 256-bit preimage)

On-spend attacks matter little; at-rest ones matter most. An on-spend attack recovers the key from a transaction in flight and races a replacement in before inclusion. Ethereum has a public mempool and 12-second blocks, while the estimate is minutes per key, so an on-spend attack needs a transaction left pending for longer than the attack takes: rare, and closed off by sending through a private relay. The attack that matters is on keys already exposed at rest, which is every account that has ever sent a transaction.

\[\Pr[\text{on-spend success}] = \Pr[t_{\text{key}} < t_{\text{inclusion}}] \approx 0 \quad\text{for } t_{\text{key}} \sim 10^{3}\,\text{s},\ t_{\text{inclusion}} \sim 10^{1}\,\text{s}\](3)

Deadlines set by others

Aug 2024FIPS 203/204/205 Mar 2026< 500k qubits estimate 2029Google PQC target [2] 2030NIST: deprecated 2035NIST: disallowed Jan 2036Optimism ECDSA sunset Ethereum: post-quantum accounts are on the research roadmap; no ECDSA sunset date published as of the research date.
Deadlines. Sources: NIST IR 8547 [5], Google whitepaper and summary [1][2], bex.co on Optimism [6].

The risks Wintergate itself still carries

No design removes every risk. These are the ones that remain in Wintergate Personal on Ethereum, what limits each, and what you can do. Better to read them here than to discover them.

RiskWhat could happenWhat limits it
After quantum computers break ordinary keys: key burningSomeone who can forge your normal key still cannot move your funds, but in two narrow ways could use up some of your one-time keys: by copying a record you send through Ethereum's public mempool, and through the neighbouring key each record reveals (at worst half of one key set).The app sends records through a private relay by default. Nothing can move funds without your hash key, and the seven-day escape always lets you out. A stricter key layout that removes the neighbour leak is possible in a later version.
The fast settingIn fast mode the app signs after 3 blocks. A rare deep chain reorganisation, together with a restore from a backup older than the signature, could let one one-time key sign twice.Safe mode (about 8 minutes) is the default and has no known case on Ethereum. Fast mode is offered for small amounts only, with a plain warning.
What a hardware wallet showsYour approval is a signature over a fingerprint of the action. A hardware wallet screen shows that fingerprint, not the recipient and amount.The app shows the action in plain words before you approve. Check it there. A version that puts the full action on the hardware screen costs a little more gas per action and is under review.
Slow recoveryWith only your recovery key, taking back a vault takes 30 days. Cancelling a recovery also clears the recovery key, so you must set a new one.The wait is what stops a thief who steals your recovery key. You can cancel any recovery you did not start, fee-free, and the app sets the new key in the same flow.
Your appSoftware that ignores the rule (sign only what the vault has recorded, once it is final) could expose a key. No contract can stop a device from broadcasting a signature.The rule is enforced in the app with tests, and the public record on Ethereum lets anyone check that no key was ever recorded twice.
The one fee-token settingA single-use key names WINTER at launch. If it were stolen before then, the thief could name another verified launch of the same kind, so fees would be due in that token and paid actions would fail. If it were lost, Wintergate would stay free forever.It can never touch funds or stop an exit, it works once, and the contract accepts only a verified launch with an ETH or USDC price. A fixed deployment would replace it, and you would leave fee-free.
The fee amountThe fee is a fixed number of WINTER (1,000 WINTER to create, 50 WINTER per action). What it costs in ETH or dollars moves with the WINTER market price, up or down, and nobody can change the amount.There is no price feed or average to manipulate. The app shows the token amount and a live ETH estimate before you approve, and the most you agreed to pay is signed into every action. Exits never need WINTER.
A bug in the contractsNobody can patch your vault: the contracts have no owner and no upgrade.Repeated adversarial reviews. If an issue is ever found, a notice goes on the security notices page and in the app; you move out with an ordinary action or the exit page, and a fixed version is a new deployment.
Outside the vaultFunds outside your vault, tokens whose issuers use exposed keys, and Ethereum's own rules are beyond any wallet's reach.Keep what you want protected inside the vault. Read the risk disclosures.

A no-server exit page ships with the app: it talks to Ethereum directly, can be saved and run from your own computer, and lets you evacuate, escape or recover without any server.

Found a flaw? There is no private inbox: Wintergate has no owner to write to. Nobody can patch a vault, so what protects users is knowing in time to move. Publish your finding with its proof, on chain or tagging @WinterGateHQ on X, so everyone sees it at once. If you can break the cryptography that protects ordinary wallets, the canary bounty is yours to claim on chain, in public.

Protect my wallet How Wintergate answers it