Quantum-grade privacy · Robinhood Chain

Mask your coins. Let quantum decide the rest.

Deposit into the pool. A real quantum computer decides how your amount shatters and when each part leaves. Unmask on a fresh address nobody can link to you, with proofs generated on your device.

Built on NIST post-quantum standards, Groth16 proofs and IBM Quantum hardware.

split by none (dev fallback) · job dev-5aa38a… · 0110 1100 0001 0111
Built on standards, not promises.
NIST FIPS 203 · ML-KEM-768Groth16 over BN254Poseidon Merkle · depth 20IBM Quantum · 8 qubits × 128 shotsAES-256-GCMHKDF-SHA256Robinhood Chain · 4663Circom 2Zero-knowledge unmaskFixed denominationsNIST FIPS 203 · ML-KEM-768Groth16 over BN254Poseidon Merkle · depth 20IBM Quantum · 8 qubits × 128 shotsAES-256-GCMHKDF-SHA256Robinhood Chain · 4663Circom 2Zero-knowledge unmaskFixed denominations
The hidden leak

Mixers hide the link. They don't hide the pattern.

Every mixer breaks the on-chain link between a deposit and a withdrawal. Analysts put it back together with what the mixer leaves behind.

Amounts match

01

A 0.5 ETH deposit followed by a 0.5 ETH withdrawal is not private. Round numbers are fingerprints.

Timing matches

02

Twenty minutes later, same amount, fresh address. Heuristics link it in one query.

Randomness replays

03

Pseudo-random delays come from a seed. Guess the seed, replay the generator, rebuild the schedule.

What QuantMask does

Four layers. One mask.

Start with the one that leaks the most on every other mixer: the pattern.

Quantum split

A 64-bit slice of a real IBM Quantum job decides how your amount shatters across the pools, in what order the parts leave, and how long each stays in flight. No seed, no generator, nothing to replay.

Outcome: amounts and timing stop being fingerprints.

Zero-knowledge pools

Fixed-denomination pools with a Poseidon Merkle tree. Unmasking proves one leaf is yours and reveals only its nullifier. Groth16, generated in your browser.

Outcome: no on-chain link, ever.

Post-quantum key file

Your notes are sealed to an ML-KEM-768 key file (FIPS 203) with HKDF and AES-256-GCM. The file stays shut the day elliptic curves fall.

Outcome: the claim on your coins survives the quantum era.

Relayer that can't steal

The proof binds the recipient and the fee. The relayer pays gas, releases each part when its delay elapses, and cannot redirect a cent. Down? Submit the proof yourself.

Outcome: a fresh address that never signed anything.

Read the docs
Quantum, in the tech

Not quantum-themed. Quantum-measured.

Every mask consumes bits read out of real qubits. The record is public, the job id is on your receipt, the split is deterministic from the bits: replay it yourself.

001

Measure

8 qubits in superposition, a Hadamard on each, 128 shots on IBM Quantum hardware. 1,024 bits, published as-is.

002

Slice

Each mask takes 64 bits at a rotating offset. The offset and the job id go on your receipt.

003

Shatter

One bit per large part decides whether it explodes into ten of the next pool, up to your tier's cap.

004

Shuffle

Six bits per swap drive a Fisher-Yates over the parts, so nothing leaves in size order.

005

Schedule

Six bits per part set its minutes in flight inside your tier's window. No two parts share a minute.

Latest measured jobdev fallback · awaiting the first hardware run
job dev-5aa38a6a · 8 qubits · 128 shots · 2026-10-10T01:21:51.522761+00:00
01101100 00010111 01000110 00010000 01100100 11101001 01000011 01100001 11101010 01011001 00100111 10000101 01011111 01110111 00101100 11010010 11011011 10111100 10111010 00111100 00001110 00101111 10001111 00010010 00000000 10001110 11010011 11011010 10001000 11111010 11110110 01011011 11011101 00110000 00001011 10100000 01001100 01110101 00001111 00001110 … full record →
Your stack, verified

Built on standards you can audit.

No invented crypto. NIST post-quantum, Groth16, Poseidon and the circuits are in the open. Verify the proof, replay the split, open the envelope with your own key.

ML-KEM-768ML-DSA-readyGroth16PoseidonCircom 2IBM QiskitviemCloudflare Workers
How a mask works

Masked in four steps.

Everything cryptographic runs in your browser. The relayer only ever sees a proof it cannot alter.

01

Key file

Generate an ML-KEM-768 key file. It never leaves your device. Lose it, lose the notes: that's the point.

02

Mask

Pick an amount. The quantum slice shatters it into parts, each deposited with a fresh commitment. Your notes come back sealed.

03

In flight

Parts sit in the pools with everyone's identical deposits. Nothing says which are yours or that they belong together.

04

Unmask

Open the file, name a fresh address. Your browser proves and the relayer releases each part on its quantum schedule.

On-chain, right now

Real pools. Real numbers.

What the pools hold, refreshed from Robinhood Chain every twenty seconds, and the last quantum job that split a mask.

0
Masks in the pools
0.000 ETH
ETH currently masked
0
Bits measured in the last job
0
Pools · 0.1 / 0.01 / 0.001 ETH
pre-launch · pools not deployed yetlast job …job id …
$QMASK

Holders mask more.

No accounts, no subscriptions: the USD value of your $QMASK is your tier. It sets how finely your amount shatters and how long parts can stay in flight. The pools and the proofs are the same for everyone.

Free

free
No $QMASK needed
  • • Up to 4 parts per mask
  • • Flight window 30 min
  • • 3 masks / 24h
  • • Same pools, same proofs
Start masking

Holder

≥ $20
in $QMASK, any wallet
  • • Up to 12 parts per mask
  • • Flight window 2 h
  • • 25 masks / 24h
  • • Same pools, same proofs
Start masking

Pro ⭐

≥ $100
in $QMASK, any wallet
  • • Up to 40 parts per mask
  • • Flight window 6 h
  • • 250 masks / 24h
  • • Same pools, same proofs
Start masking

Whale

≥ $1000
in $QMASK, any wallet
  • • Up to 120 parts per mask
  • • Flight window 24 h
  • • Unlimited masks / 24h
  • • Same pools, same proofs
Start masking

$QMASK launches on Karat, paired against HOOD on Robinhood Chain. The only contract that sets your tier will be printed here.

Common questions

Questions trenchers ask.

Is the quantum part real or marketing?

Real. The job runs on IBM Quantum hardware, the full bitstring is published at /quantum/latest.json, and your receipt carries the job id and the slice offset. Rebuild the split from the bits and you get the same plan. Right now the record is a labelled dev fallback: the first hardware job replaces it before launch.

Can QuantMask see or steal my coins?

No. Notes are generated and sealed in your browser. The relayer only receives a Groth16 proof bound to your recipient and fee; it can submit it or not, it cannot change it. If the relayer is down you can submit the same proof yourself from any wallet.

What if I lose my key file?

Your sealed notes can't be opened and the parts stay in the pool forever. There is no recovery, by design: a recovery path would be a back door.

Why fixed amounts?

Identical deposits are what make a pool a crowd. The quantum split is how a free amount becomes a set of identical deposits without a recognisable pattern.

Why a token?

The token funds the relayer and the daily quantum jobs, and holders get finer splits and longer flight windows. It never gates the cryptography.

What doesn't it protect against?

Spending the unmasked ETH in a way that identifies you, reusing the same fresh address, a pool so empty you're the only depositor, and losing your key file.

Ready to mask?

Your coins, everywhere and nowhere.

Three pools, one key file, a real quantum computer in the loop. No account, no pitch, no pressure.