Don't trust.
Verify.
Every Qatze signature can be checked right here, by your own browser. No server involved.
Six signatures made by the official XMSS reference code (C, by the RFC 8391 authors). Our JavaScript and our contract must accept every one of them, byte for byte.
A real signature over a message. Change one character of the message or one bit of the signature, and it falls apart.
Signature · 2,500 bytes · one-time key
Paste the transaction hash of any Qatze box opening on Robinhood Chain. We read it from the chain and redo the check here.
Try
What is checked
67 hash chainsThe signature reveals a point on each chain. Hashing up to the end gives the one-time public key.
One leafThose 67 values fold into one leaf of a tree of 1,024 one-time keys.
Ten steps upThe ten neighbours in the signature lead to the root. The box stores that root.
SHA-256 onlyNo curve, no factoring. Nothing Shor's algorithm can attack. About 1,800 hashes per check.