Revealed chain node Unrevealed chain node Merkle authentication path Exposed by chain reuse
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Hash-Based Signatures: WOTS+ Chains & Merkle Authentication Path

Post-quantum cryptography does not only mean lattices — hash-based signatures such as SPHINCS+ and XMSS get their quantum resistance from nothing more exotic than a one-way hash function. This simulator renders a real Winternitz one-time-signature scheme in 3D: eight private hash chains climb from seed to public top, a message's digits decide how far each chain gets revealed when you sign, and a Merkle tree of one-time keypairs compresses everything into a single public root. A built-in "force leaf reuse" demo shows, concretely, why these one-time chains must never sign two messages — and how much of the private key leaks when they do.