Mixers hide the link. They don't hide the pattern.
Every mixer breaks the on-chain link between a deposit and a withdrawal. Analysts put it back together with what the mixer leaves behind.
Amounts match
A 0.5 ETH deposit followed by a 0.5 ETH withdrawal is not private. Round numbers are fingerprints.
Timing matches
Twenty minutes later, same amount, fresh address. Heuristics link it in one query.
Randomness replays
Pseudo-random delays come from a seed. Guess the seed, replay the generator, rebuild the schedule.
Four layers. One mask.
Start with the one that leaks the most on every other mixer: the pattern.
Quantum split
A 64-bit slice of a real IBM Quantum job decides how your amount shatters across the pools, in what order the parts leave, and how long each stays in flight. No seed, no generator, nothing to replay.
Outcome: amounts and timing stop being fingerprints.
Zero-knowledge pools
Fixed-denomination pools with a Poseidon Merkle tree. Unmasking proves one leaf is yours and reveals only its nullifier. Groth16, generated in your browser.
Outcome: no on-chain link, ever.
Post-quantum key file
Your notes are sealed to an ML-KEM-768 key file (FIPS 203) with HKDF and AES-256-GCM. The file stays shut the day elliptic curves fall.
Outcome: the claim on your coins survives the quantum era.
Relayer that can't steal
The proof binds the recipient and the fee. The relayer pays gas, releases each part when its delay elapses, and cannot redirect a cent. Down? Submit the proof yourself.
Outcome: a fresh address that never signed anything.
Not quantum-themed. Quantum-measured.
Every mask consumes bits read out of real qubits. The record is public, the job id is on your receipt, the split is deterministic from the bits: replay it yourself.
Measure
8 qubits in superposition, a Hadamard on each, 128 shots on IBM Quantum hardware. 1,024 bits, published as-is.
Slice
Each mask takes 64 bits at a rotating offset. The offset and the job id go on your receipt.
Shatter
One bit per large part decides whether it explodes into ten of the next pool, up to your tier's cap.
Shuffle
Six bits per swap drive a Fisher-Yates over the parts, so nothing leaves in size order.
Schedule
Six bits per part set its minutes in flight inside your tier's window. No two parts share a minute.
Masked in four steps.
Everything cryptographic runs in your browser. The relayer only ever sees a proof it cannot alter.
Key file
Generate an ML-KEM-768 key file. It never leaves your device. Lose it, lose the notes: that's the point.
Mask
Pick an amount. The quantum slice shatters it into parts, each deposited with a fresh commitment. Your notes come back sealed.
In flight
Parts sit in the pools with everyone's identical deposits. Nothing says which are yours or that they belong together.
Unmask
Open the file, name a fresh address. Your browser proves and the relayer releases each part on its quantum schedule.
Real pools. Real numbers.
What the pools hold, refreshed from Robinhood Chain every twenty seconds, and the last quantum job that split a mask.
Holders mask more.
No accounts, no subscriptions: the USD value of your $QMASK is your tier. It sets how finely your amount shatters and how long parts can stay in flight. The pools and the proofs are the same for everyone.
Free
free- • Up to 4 parts per mask
- • Flight window 30 min
- • 3 masks / 24h
- • Same pools, same proofs
Holder
≥ $20- • Up to 12 parts per mask
- • Flight window 2 h
- • 25 masks / 24h
- • Same pools, same proofs
Pro ⭐
≥ $100- • Up to 40 parts per mask
- • Flight window 6 h
- • 250 masks / 24h
- • Same pools, same proofs
Whale
≥ $1000- • Up to 120 parts per mask
- • Flight window 24 h
- • Unlimited masks / 24h
- • Same pools, same proofs
$QMASK launches on Karat, paired against HOOD on Robinhood Chain. The only contract that sets your tier will be printed here.
Questions trenchers ask.
Is the quantum part real or marketing?
Real. The job runs on IBM Quantum hardware, the full bitstring is published at /quantum/latest.json, and your receipt carries the job id and the slice offset. Rebuild the split from the bits and you get the same plan. Right now the record is a labelled dev fallback: the first hardware job replaces it before launch.
Can QuantMask see or steal my coins?
No. Notes are generated and sealed in your browser. The relayer only receives a Groth16 proof bound to your recipient and fee; it can submit it or not, it cannot change it. If the relayer is down you can submit the same proof yourself from any wallet.
What if I lose my key file?
Your sealed notes can't be opened and the parts stay in the pool forever. There is no recovery, by design: a recovery path would be a back door.
Why fixed amounts?
Identical deposits are what make a pool a crowd. The quantum split is how a free amount becomes a set of identical deposits without a recognisable pattern.
Why a token?
The token funds the relayer and the daily quantum jobs, and holders get finer splits and longer flight windows. It never gates the cryptography.
What doesn't it protect against?
Spending the unmasked ETH in a way that identifies you, reusing the same fresh address, a pool so empty you're the only depositor, and losing your key file.