Quantum Shielddocs

Operating with no wallet

The vault is an ERC-4337 account. A hash-based signature is all an owner needs; no ECDSA key, no ETH.

Requiring a wallet to submit a post-quantum signature would put an elliptic curve key back in the path and make every account depend on holding ETH. The vault avoids both by being an ERC-4337 account itself, on the canonical EntryPoint v0.8.

One account for everyone

There is a single smart account: the vault. Every shielded account operates through it.

UserOperation fieldValue
senderthe vault
nonceopId << 64, where opId = keccak256(account, epoch, leaf) truncated to 192 bits
callDataexecute4337(opId)
signatureabi.encode(Op, hashSignature)
initCode, paymasterAndDataempty

Each operation uses its own nonce key, so operations of different accounts never queue behind each other.

Everything happens in validation

validateUserOp does the whole state transition:

  1. Decodes the Op and recovers the key and leaf from the hash-based signature.
  2. Checks that nonce and callData are the ones this operation determines, and that op.caller is the vault.
  3. Checks the gas limits against op.minCallGasLimit and the maximum cost against maxOpCostWei.
  4. Checks that op.gasFee is worth at least the network fee.
  5. Compares the recovered key with the account's key. A mismatch returns SIG_VALIDATION_FAILED and writes nothing.
  6. Applies the operation: leaf counter, key change, transfer, burn. An exit is escrowed.

Validation reads and writes only the vault's own storage: no price is read, no token moves, and the deadline is handed to the EntryPoint as validUntil. That keeps the operation inside the ERC-4337 validation rules, so standard bundlers carry it.

execute4337 then settles the escrowed exit: pays the tokens out, or hands them to the router to sell.

Gas is not signed

The hash-based signature covers the Op, not the UserOperation's gas fields. A wallet can estimate with a placeholder signature, and an operation priced too low is repriced and resent with the same signature and the same leaf. No leaf is ever spent on a fee bump.

This is safe because the two things a bundler could abuse are bounded by signed or immutable values:

  • minCallGasLimit is signed, so execution cannot be starved of gas.
  • The operation's maximum cost may not exceed maxOpCostWei (0.0005 ETH), an immutable of the vault.

Who pays

The EntryPoint charges the vault's deposit. The owner pays the vault a flat network fee in shares (op.gasFee):

  • Its value is maxOpCostWei at the price average, so the fee always covers the most an operation can cost.
  • Its token amount is recomputed at most once an hour (NETWORK_FEE_INTERVAL). The previous amount stays accepted, so an operation signed just before a change still passes.
  • The shares are burned and their tokens stay: the fee is a donation to every account.

The deposit is refilled by the harvester from trading fees, up to its target. The system funds its own gas.

The direct path

transact(op, signature) applies the same operation from a plain transaction. Anyone may submit it, or only op.caller if the operation names one; the submitter pays gas in ETH and no network fee is required. The app offers it as Any wallet.

On this page