Roto
Roto logo

Post-quantum backups. Minimal exposure.

Roto. Built for the quantum era.

Quantum computers need your public key to attack it. Roto keeps it hidden, uses it once, and moves on. Your backup is locked with NIST post-quantum encryption.

How Roto shrinks your quantum risk

  • Hidden until spent

    Your public key stays behind a hash until you sign. Nothing for a quantum computer to target while your funds sit still.

  • One spend, then gone

    After signing, funds sweep to a fresh key and the old one is retired. The exposure window shrinks to a single transaction.

  • Quantum-resistant backups

    Your seed is encrypted with ML-KEM-768 (NIST FIPS 203) plus X25519. Data stolen today can't be decrypted by a quantum computer tomorrow.

For the full technical details, read the threat model.

Five layers, one signature

  1. Step 1

    Key lives inside a sealed module

    Private key d never leaves.

  2. Step 2

    Every signature gets a fresh nonce k

    Erased right after.

  3. Step 3

    Signs in constant time

    Timing and power traces don't reveal the key.

  4. Step 4

    Use each key only a short time

    A watcher rotates to a new child key if something looks risky.

  5. Step 5

    Backups use two different cryptos

    X25519 + ML-KEM-768, so one broken assumption doesn't open the seed.

Where trust lives

The watcher sees only public data (r, s, timestamps, counts). It can trigger a rotation but can never sign.

AttackerWants d, a reused k, or timing leaks
no d, no k
Roto SignerSealed key, fresh nonce, constant time
r, s, t
Watcher (untrusted)Reads public data, can only say rotate_now
signed tx
BlockchainSees one signature per key, then a new address
Attacker arrows are blocked at the signer. The signer sends public signature data to an untrusted watcher, and signed transactions to the blockchain.

What Roto gives you

  • Prevents easy key leaks from bad nonces or side channels
  • Limits how long a public key is exposed to classical and quantum attackers
  • Makes automated attacks much harder to train on
  • Post-quantum protected backups
  • Ready to switch to post-quantum signatures as chains adopt them

The big idea

Roto reduces what an attacker can collect today, uses each key for a short time, and keeps your real key safely inside.