Quantus mainnet · real ML-DSA keypairs · exact upstream address derivation · 100% client-side
Forge keys the quantum era deserves
Generate genuine ML-DSA-65 / ML-DSA-87 post-quantum keypairs right here in your browser — then watch this page derive your qz… address with the exact algorithm the Quantus CLI uses: the 1,952-byte public key hashed through the Poseidon2-Goldilocks sponge into a 32-byte account ID, SS58-encoded with prefix 189. Verified byte-for-byte against the upstream crates' own test vectors. Inspect any address, sign and verify messages, print a paper card. Your keys never leave this tab — there is no server to send them to.
Derivation verified against qp-dilithium-crypto 0.6.1 (account-ID rule) and qp-poseidon-core 3.1.0 (permutation + sponge test vectors), Sept 30 2026. ML-DSA by the audited @noble/post-quantum implementation of FIPS 204.
⚒ Key Forge
Pick a parameter set and forge. Randomness comes from your OS cryptographic RNG (crypto.getRandomValues) — the same source the CLI uses. Key generation, hashing, and address encoding all run locally in this page.
No keypair yet. The forge is cold.
Takes about a second. Watch the derivation pipeline run: lattice keygen → Poseidon2 account hash → SS58 address.
The backup file is raw key material. Store it encrypted and offline. Anyone with this file owns the address.
How this address was derived (the exact upstream pipeline)
- Keygen: ML-DSA keypair from 256-bit OS randomness, per FIPS 204 (NIST's post-quantum signature standard).
- Account ID:
hash_bytes(public_key)— the rule inqp-dilithium-crypto'sIdentifyAccount for DilithiumSigner— wherehash_bytesis theqp-poseidon-corePoseidon2 sponge over the Goldilocks field (width 12, rate 8, 8 external + 22 internal rounds), producing a 32-byte account ID. - Address: standard SS58check with Quantus prefix 189 (that's why every address starts with
qz), blake2b-512SS58PREchecksum. - This page's implementation is validated against the crates' own published test vectors — permutation outputs, sponge digests, and a live mainnet address round-trip — 45/45 green in
tests/run-tests.mjs.
🔍 Address Inspector
Validate any Quantus address — checksum, prefix, and account ID — or go the other way, from a 32-byte account ID to its qz… address. Same SS58check rules the CLI enforces.
Paste an address above.
The account ID is what the chain actually stores; the address is just its SS58 costume.
✒ Sign & Verify
Feel what a post-quantum signature actually is. Sign a message with your forged key — then verify it. Notice the size: a single ML-DSA-65 signature is 3,309 bytes, which is exactly why Quantus built native transaction aggregation. Verification needs only the public key.
Forge a keypair above first — signing needs a secret key.
Anyone can verify — no secret needed. That's the whole point of signatures.
🃏 Paper Card
A printable receive card for your forged address: QR code plus the address in full. The secret key is never printed — this card is safe to share, stick on a mining rig, or hand to someone who owes you QTC.
—
Tip: print to PDF and keep it with your records. For cold storage of the actual key, use the encrypted backup download from the forge — stored offline — or import the address as a watch-only wallet in quantus-cli.
🛡 Security, honestly
This tool does real cryptography, and real cryptography deserves straight talk.
- Your keys never leave this tab. There is no backend, no analytics beacon, no network call anywhere in this app — open DevTools and watch: the Network tab stays silent.
- Randomness is OS-grade. Key material comes from
crypto.getRandomValues, the same system CSPRNG browsers reserve for TLS keys. - But this is builder tooling, not audited wallet software. The derivation math is verified against upstream test vectors, and ML-DSA comes from an audited library — but the page around it hasn't had a security audit. Treat forged keys as experimental: great for learning, testing, and small amounts.
- For meaningful funds, use the official quantus-cli. Before funding any address forged here, sanity-check it: decode it in the Inspector above and compare against the CLI's output for the same key.
- Backups are your responsibility. If you download a secret-key backup and lose it, the funds are gone — no password reset exists on any blockchain. Store backups encrypted, offline, in two places.
- Beware the clipboard. Malware that watches clipboards for crypto addresses is real. When pasting an address to receive funds, verify the first and last 6 characters match.