Hash-Based Signatures for Builders: SLH-DSA, XMSS, LMS and the Winternitz Vault

Updated | 4 min read | QUANTUM (QNT) community

Why builders like hash-based signatures

Most post-quantum signatures rest on newer math such as lattices. Hash-based signatures rest on the security of hash functions, which are well studied; see hash functions and quantum computers. The trade-off is size or state. There are two families.

Stateless: SLH-DSA (SPHINCS+)

NIST published FIPS 205, SLH-DSA, on August 13, 2024. It is based on SPHINCS+ and described as a stateless hash-based digital signature algorithm. Stateless means you can sign from several machines without tracking a counter, which makes it the safer default. The price is signature size: reported figures are 7,856 bytes for SLH-DSA-SHA2-128s and 17,088 bytes for the faster 128f set, with public keys of 32 to 64 bytes. See SLH-DSA explained.

Stateful: XMSS and LMS

XMSS and LMS are standardized by the IRTF and approved by NIST in SP 800-208. They give much smaller signatures than SLH-DSA, but the private key includes a counter that says which one-time key to use next. If a one-time key signs two different messages, an attacker can forge signatures. NIST treats them as special purpose, suitable where private key use can be carefully controlled, and requires key and signature generation to happen inside hardware modules that do not export secret key material. liboqs ships both XMSS and LMS at Tier 2 support, but remember its general production warning.

State management pitfalls

RFC 10033, an informational IETF document from 2026, collects the lessons. Its main points as I read them:

A practical rule: if you cannot name the single component that increments the counter and prove it cannot roll back, do not use a stateful scheme.

Winternitz one-time signatures in plain English

A Winternitz one-time signature (WOTS) turns a message hash into several small chunks. Each chunk corresponds to a chain of repeated hashing starting from a secret value. To sign, you reveal an intermediate point on each chain. A verifier hashes the remaining steps forward and checks that every chain ends at the published public value. Larger chunks mean shorter signatures but more hashing. The catch, as the vault README notes, is that each signature reveals roughly half the private key, so a key can safely sign once. See the signature comparison for how it ranks against the NIST picks.

How the Solana Winternitz vault works

The Solana Foundation says the Winternitz Vault was built by Blueshift, calls it one of the few quantum-resistant primitives in use on a major blockchain, and says it has been in place for over two years. The public code README (by Dean Little; The Quantum Insider covered the vault in January 2025) describes three steps:

  1. Open: generate a Winternitz keypair, hash its public key with Keccak256 to get a merkle root, and use that root as a seed for a program-derived address. That address is the vault, which holds lamports (SOL).
  2. Split: to spend, the owner signs a message naming the amount, a new destination vault and a refund address. The program recovers the public key from the signature, hashes it, and checks that it matches the vault's seed. It sends the amount, refunds the rest to a new vault, and closes the old one.
  3. Close: sign a message naming a refund address and the vault pays out its whole balance and closes.

Because a spend reveals half the key, the design closes the vault every time, so each key is used once. The README says the hash is a truncated Keccak256 giving 224-bit preimage resistance, kept short to fit Solana's instruction data and compute limits, while the merkle root uses the full 256 bits. The README also warns that the author is "a pretty good dev larping as a cryptographer", that security figures are the author's own claims, and that it shows no independent audit. Blueshift's own documentation pages could not be loaded for this guide, so this section relies on that README, the Foundation post and The Quantum Insider coverage. The Foundation's two-year claim is its own and I did not verify it independently. The vault is opt-in; it does not protect ordinary wallets. For the wider chain picture see Ethereum and Solana plans. This is education, not financial advice.

Sources and further reading

Reported as of 2026-10-09. Library versions, defaults and standards status change often, so check the primary documents and test on your own stack before relying on anything here. Nothing here is financial advice or a security audit. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every project, library, lab and chain named on this page.

Frequently asked questions

Why is a stateful hash-based signature risky?

If a one-time key is used for two different messages, an attacker can forge signatures. Rollbacks from backups or cloned virtual machines can cause this by accident.

Should I pick XMSS or LMS over SLH-DSA?

RFC 10033 says most applications should prefer stateless schemes. Choose stateful ones only with tight signing control and hardware that protects state.

Is the Solana Winternitz vault audited?

Its README says the code is used at your own risk and the page shows no independent audit. Treat it as an interesting design, not a guarantee.

Does the vault protect every Solana wallet?

No. It is an opt-in program that holds funds in vaults. Ordinary wallets are unchanged.

Share on X

Keep reading

All Quantum computing guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.