how it works.

The cryptography, launch flow and data readers behind qHOST on Robinhood Chain. Learn how wallet scans work, how coins are monitored, and what must be verified before relying on a vault.

in 1979 leslie lamport showed you can sign with nothing but a hash function. every vault here descends from that idea. a ghost leaves no key behind.

The threat

Every wallet on Robinhood Chain is a secp256k1 key pair. Your address is a hash of the public key, and the key itself is revealed the first time you sign anything. Security rests on one assumption: getting from the public key back to the private key is infeasible. For a classical computer it is.

In 1994 Peter Shor showed that a large enough quantum computer solves this kind of discrete-log problem in polynomial time. Resource estimates depend on the circuit, hardware and error correction. Logical qubits are not interchangeable with noisy physical qubits, and a hardware qubit count alone does not establish an ability to break a wallet key. The hypothetical point when an attack becomes practical is q-day.

Because the chain keeps everything forever, the risk starts now: attackers can harvest public keys today and decrypt later. Moving to a quantum-resistant key after q-day is too late for any key that was already exposed.

What survives q-day

Hash-based constructions avoid the elliptic-curve problem targeted by Shor's algorithm. Generic quantum preimage search is modeled with Grover's algorithm, which roughly square-roots the search work: a 192-bit preimage corresponds to about 2^96 search steps under that model. Collision resistance and implementation security require separate analysis. NIST standardized a hash-based signature scheme, SLH-DSA (FIPS 205), in 2024; qHOST's scheme is a Winternitz one-time signature over keccak-256, not that standard.

qHOST builds everything that has to survive q-day out of hashes.

Vaults

A Winternitz one-time signature (WOTS) turns a list of secrets into a signature by hashing each secret a number of times set by the message. qHOST uses 34 chains: 32 for the bytes of the message digest, 2 for a checksum. Each chain value is 24 bytes (192 bits), and each chain is at most 255 steps long (w = 256). A signature is 34 × 24 = 816 bytes.

The vault id is keccak-256 over the 34 chain ends. The QVault contract keeps balances per vault id, for ETH and for any ERC-20, which on Robinhood Chain means tokenized stocks. There is no private key for a vault. To withdraw, the contract re-hashes the signature to the end of each chain, hashes the ends, and checks the result matches the vault id. It pays the recipient the amount, and moves everything left to the next vault named in the signed message. The message digest binds the chain id, the contract, the vault, the token, the recipient, the amount and the next vault.

The checksum is what stops forgery. Revealing a chain at step d lets anyone compute later steps, so an attacker could push a byte of the message up. The checksum is the sum of 255 − d over all bytes, so raising any byte lowers the checksum, which would mean walking a checksum chain backwards through a hash. Nobody can.

One key, one signature. A spent vault refuses further withdrawals and forwards nothing; whatever remains of other tokens can be swept by anyone to its recorded successor.

Identity

A dev needs to sign more than once: updates, announcements, proof they still control the coin. So each dev gets 32 Winternitz keys under a Merkle tree, the construction behind XMSS (RFC 8391). The root is written to the QIdentity contract in the launch flow, bound to the token address.

Each signed update uses the next unused leaf and carries its path to the root. Anyone can check it with hashes alone: recover the leaf's public-key hash from the signature, climb the tree with the siblings, compare to the root on chain. The contract refuses a leaf twice, and refuses a 33rd update.

A valid update proves that its message was signed with a hash-based leaf belonging to the published identity root. It does not automatically prove that the announcement is true, that a token is a good investment, or that its creator still controls every related account.

Launches

The coin launch is built on Karat, the Uniswap v4 launchpad of Robinhood Chain. Name, ticker, picture, and the tokenized stock to pair against. Your wallet signs the transactions; nothing private is sent to qHOST. The pool opens against that stock with a fixed supply and liquidity that cannot be pulled.

In the same flow, your browser mints a fresh vault key, whose hash becomes the coin's dev vault, and an identity tree, whose root is registered on chain against the new token. Creator fees are claimed from the token in the pair asset and can be swept into the vault from the Vault page.

A multi-transaction launch is not one atomic operation. Token creation can confirm before the identity step fails. If the flow reports an error after submission, inspect the wallet history before starting a new launch. Blind retries can create another token.

Wallet scanner

Open Scan and paste a Robinhood Chain address. You do not need to connect a wallet, approve a signature or pay a fee to read an address. The scanner accepts a public address only; it never needs a recovery phrase, private key or vault backup.

It reads the ETH balance and the tokenized-stock balances from the chain, the transaction count, and the oldest outgoing transaction from the explorer as an estimate of how long the public key has been exposed. A wallet that has only ever received has not revealed its public key yet; that is scored lower until it signs.

The score is a heuristic between zero and 99, not a measured probability of theft. Its inputs weight value at 58 %, observed history at 18 %, activity at 12 % and token count at 12 %. These inputs are capped and transformed so a single large input does not grow without limit.

Canary + bunker

The canary is a wallet funded with ETH whose private key was destroyed when it was generated. The QBunker contract records its balance as a baseline. If the balance ever drops, canaryDead() returns true for everyone, in the same block, with no server in between.

Auto-bunker is the intended escape. You approve the bunker contract for the stocks you want saved and name the vault they should go to. Nothing moves. When the canary dies, anyone can call fire(you): the contract pulls the approved tokens and deposits them into your vault. It cannot send them anywhere else. Disarming clears the escape on chain.

Bunker mode moves your whole balance, minus a little for fees, into a fresh Winternitz vault in one go. The site locks down around you. Your vault stays sealed until you sign a withdrawal.

A signature involving the canary is a serious signal, but the signal alone does not establish how a private key was obtained. An implementation mistake, retained backup or compromised creation process could produce a similar observation. Treat the canary as an operational tripwire, not conclusive scientific evidence of a quantum breakthrough.

Honest limits

Quantum-resistant, not quantum-proof. Hash-based signatures are the most conservative choice we know of, but no one can promise what future math finds.

Vaults protect what is in them. The coins themselves are normal ERC-20 tokens, and tokens sitting in a regular wallet are behind secp256k1 like everything else on the chain. A chain-wide upgrade is what eventually protects every token.

Lose a vault backup and the assets in that vault are gone. There is no central password-reset service that can recreate a missing secret. Store a recoverable backup outside browser storage before relying on the vault.

The q-day clock is a watchtower estimate influenced by news. It is not a network upgrade schedule, an insurance promise, or proof that a wallet is safe until the countdown reaches zero. Decide how much value to expose using your own risk assessment, not a date displayed by the interface.

Source code and passing tests help reviewers inspect a design; they are not equivalent to an independent audit. Verify the contract addresses and a confirmed deposit before depositing real value.

Launch a coin →Explore vaults