Brandable post-quantum addresses · 100% client-side
Forge a name into your address
Every Quantus address starts with qz… — the rest is random. Vanity Forge grinds real ML-DSA-65/87 keypairs right in your browser until your address starts with your project, your handle, or your word: qzkshot…, qzmint…, qz…MINT. Same audited FIPS-204 keygen and exact upstream address derivation as Key Forge — nothing is sent anywhere, keys never leave this page.
Design your vanity
Pick the characters you want. The readout below shows the exact grind math — expected attempts, median luck, and wall-clock at your machine's measured rate — before you spend a single keypair. One quirk of the chain to know up front: the SS58-189 prefix bytes pin the character right after qz to just seven possible symbols (j k m n o p q, unevenly likely) — the forge rejects anything else there instead of grinding forever.
Difficulty explorer
How the grind scales: the first character after qz is pinned to seven symbols (worst case: q at ~1-in-24); each further character multiplies the expected attempts by 58. Grinding is a geometric process — the median find lands at ~69% of the expected attempts, and one unlucky run in ten takes more than ~2.3× expected.
| Chars | Expected attempts | Median attempts | Expected time | Scale |
|---|
Benchmark your machine
Measures real keygen + address-derivation throughput on this device (120 keypairs per scheme, ~a minute or two). The difficulty times and forge ETAs use your measured rate from then on — saved in this browser.
No benchmark yet. ~2 minutes of number-crunching; the grind math gets honest after.
The forge
Grinds keypairs in batches and checks every address against your pattern. The page stays responsive; stop any time — attempts so far are never wasted, they're just draws from the same distribution.
Load a pattern above, then start the forge.
Vault
Every find lands here automatically. This is browser localStorage, not a vault — convenient, not secure. Export finds to Key Forge's paper card or a proper backup, then delete them here.
Forge safety
- A vanity prefix weakens nothing. The address is a Poseidon2 hash of the public key — hunting for a prefix is just re-rolling the hash. Key entropy is identical to a random address.
- Keys never leave this page. Keygen uses the OS CSPRNG via the audited noble FIPS-204 implementation; there are no network calls. Verify in devtools: the Network tab stays empty while grinding.
- Don't grind on machines you don't own. A VPS, a shared laptop, or a browser with sketchy extensions can exfiltrate the secret key. Forge on your own hardware.
- Back up before funding. Reveal the secret, copy it to your paper backup (Key Forge prints a receive card), then send funds. A vanity address with a lost secret is a donation to nobody.
- The vault is localStorage. Any site-level XSS or anyone with your browser profile can read it. Treat it as a clipboard with memory, not custody.
- Know when to stop. Four characters is a long weekend on a fast machine; five is months; six is a datacenter's problem. The difficulty table above is the honest version of "wen lambo".
- The third character is pinned — some patterns are impossible. The SS58-189 prefix bytes only allow j k m n o p q right after qz (with uneven odds: q is ~4× rarer than k). The forge tells you up front instead of grinding forever; every character after that is a fair 1-in-58 draw.
- Suffix mode is approximate. The trailing characters encode the SS58 checksum, which is derived from the account ID rather than drawn independently — the published suffix odds assume near-uniformity over many draws.
Sources
Address derivation: Quantus-Network/chain — qp-dilithium-crypto into_account() = hash_bytes(pubkey) (Poseidon2-Goldilocks, qp-poseidon-core) → SS58check prefix 189 (quantus-cli/src/cli/address_format.rs), verified against crate test vectors in Key Forge.
Keygen: vendored @noble/post-quantum FIPS-204 ML-DSA-65/87 implementation (same code Key Forge ships).
Difficulty math: geometric distribution over the 58-symbol base58 alphabet; median = ln 2 × expected; percentiles from 1 − (1 − 1/E)ⁿ. Unit-tested in tests/vanity.test.mjs.