A vault for Ethereum where the only thing that moves money is a hash preimage.
No elliptic curves. No lattices. No public key to break.
Structure is attack surface.
Hashes have none.
Factoring went from 2n/2 to 2O(n1/3) because people kept finding structure.
What finds it next won't be people.
If AI brings 50 years of math in 2,
what's left standing?
Every public-key scheme is built on a trapdoor with exploitable structure: group theory for elliptic curves, short vectors for lattices. Each one has survived because nobody has yet found the next trick, not because no trick exists. A hash is designed to have exactly no structure to find.
An ECDSA address exposes its public key the first time it signs anything on-chain. prelode lets you keep funds behind a key that never signs an Ethereum transaction, never exposes a point on a curve, and spends by revealing a hash preimage once.
"It's much more likely that a mathematical object has exactly no exploitable structure, like hashes are intended to, than that a mathematical object has exactly ~3 forms of exploitable structure and not some secret fourth form we have not yet discovered."Vitalik Buterin, on AI-accelerated math and lattice riskSee the full construction ↘
- group law
- point counting (Schoof)
- pairings
- unknown fourth structure?
- short vectors (SVP, LWE)
- ring / module algebra
- decades of sieving tricks
- unknown next structure?
- no algebra to exploit
- no trapdoor
- breaking it ≈ P = NP territory
- pad rounds, not bytes, if worried
One seed. One root.
One preimage per spend.
Winternitz one-time signatures, a Merkle tree, and a contract that checks nothing else.
One 32-byte seed derives 2^height one-time secret keys. Each secret is 67 chains of keccak256, 15 steps long; the chain ends are hashed into a leaf, the leaves into a Merkle root. The root is the only public thing. Nothing about it is a curve point or a lattice vector: it is 32 bytes of hash output.
Type anything.
Watch it become a signature.
Every bar below is a real keccak chain length, computed in your browser from the digest of your message.
d = keccak256(chain ‖ vault ‖ nonce ‖ calls)
The digest binds the signature to one chain, one vault, one nonce and the exact calldata. A relayer can submit it, but cannot change a byte.
m0..63 = nibbles of d · m64..66 = checksum
Sixty-four 4-bit chunks plus a 3-chunk checksum of Σ(15 − mi), so an attacker can't lower one chunk without raising another.
σi = fmi(ski) · verifier: f15−mi(σi) = pki
The signer walks each chain mi steps and reveals where it got to. Going further is easy; going back is a preimage. The contract finishes the walk, hashes the 67 ends into a leaf and checks the Merkle path to your root.
gas ≈ 165k · calldata ≈ 2.7 KB · one leaf per spend
The vault contract has no owner, no upgrade path and no ECDSA fallback. A key file is a seed plus a counter; a spent counter must never roll back. If a key file leaks, rotate: a new root replaces the old one through the vault itself.
Good questions.
Clear answers.
Is this "post-quantum"?+
It is hash-only, which is the stronger claim. Quantum computers get a square-root speedup on hashes at most, and there is no known or suspected structure for an AI to find in keccak256. Lattice schemes are post-quantum on paper, but they carry algebraic structure that the next two years of math could degrade.
Why not just use a fresh address?+
A fresh address is safe until the first time it signs. The moment you spend, the public key is on-chain and the clock starts. A prelode vault lets you spend repeatedly without ever publishing an ECDSA public key. Use the scanner to see which of your addresses are already exposed.
Who pays gas if my key never signs a transaction?+
Anyone. The signed bundle authorises exactly one set of calls, so a random burner, a friend or a public relayer can submit it and gain nothing. Your signing key stays offline and hash-only.
What does "one-time" mean in practice?+
Each leaf of your tree can be used once. Reusing one leaks part of the secret. The key file tracks a counter and the contract tracks a spent bitmap, so the tooling never reuses a leaf even if the file lags. A height-10 tree gives 1,024 spends; rotate to a fresh root before it runs out.
Can I do a multisig?+
Yes. A vault takes up to 32 roots and a threshold. Each signer reveals their own one-time signature, confirmations are gathered offchain, and one relay submits them. There is no ECDSA signer anywhere in the path to degrade to.
Should I migrate today?+
Nobody serious is telling you to scramble. Botched migrations lose more money than hacks. prelode lets you fund a vault address before deploying it, test with dust, and keep the relay step separate from the signing step, so the move is boring on purpose.