Quantus mainnet · real ML-DSA keypairs · exact upstream address derivation · 100% client-side

Forge keys the quantum era deserves

Generate genuine ML-DSA-65 / ML-DSA-87 post-quantum keypairs right here in your browser — then watch this page derive your qz… address with the exact algorithm the Quantus CLI uses: the 1,952-byte public key hashed through the Poseidon2-Goldilocks sponge into a 32-byte account ID, SS58-encoded with prefix 189. Verified byte-for-byte against the upstream crates' own test vectors. Inspect any address, sign and verify messages, print a paper card. Your keys never leave this tab — there is no server to send them to.

ML-DSA-65 pubkey1,952 B
ML-DSA-87 pubkey2,592 B
Account IDPoseidon2 hash
SS58 prefix189 · qz…
Network callszero
Vector tests45/45 green

Derivation verified against qp-dilithium-crypto 0.6.1 (account-ID rule) and qp-poseidon-core 3.1.0 (permutation + sponge test vectors), Sept 30 2026. ML-DSA by the audited @noble/post-quantum implementation of FIPS 204.

⚒ Key Forge

Pick a parameter set and forge. Randomness comes from your OS cryptographic RNG (crypto.getRandomValues) — the same source the CLI uses. Key generation, hashing, and address encoding all run locally in this page.

No keypair yet. The forge is cold.

Takes about a second. Watch the derivation pipeline run: lattice keygen → Poseidon2 account hash → SS58 address.

🔍 Address Inspector

Validate any Quantus address — checksum, prefix, and account ID — or go the other way, from a 32-byte account ID to its qz… address. Same SS58check rules the CLI enforces.

Paste an address above.

The account ID is what the chain actually stores; the address is just its SS58 costume.

✒ Sign & Verify

Feel what a post-quantum signature actually is. Sign a message with your forged key — then verify it. Notice the size: a single ML-DSA-65 signature is 3,309 bytes, which is exactly why Quantus built native transaction aggregation. Verification needs only the public key.

Sign a message

Forge a keypair above first — signing needs a secret key.

Verify a signature

Anyone can verify — no secret needed. That's the whole point of signatures.

🃏 Paper Card

A printable receive card for your forged address: QR code plus the address in full. The secret key is never printed — this card is safe to share, stick on a mining rig, or hand to someone who owes you QTC.

QTC · Quantum Key ForgeML-DSA-65
Forge a keypair to generate the QR code
—
Receive-only · secret key stored separately

Tip: print to PDF and keep it with your records. For cold storage of the actual key, use the encrypted backup download from the forge — stored offline — or import the address as a watch-only wallet in quantus-cli.

🛡 Security, honestly

This tool does real cryptography, and real cryptography deserves straight talk.