BUNKER
DocsCreate bunker
Key lab

Sign with hashes.

An educational Winternitz-style signing demonstration, running for real in your browser. Make a one-time key, sign a message, then try changing the message and watch verification fail. Nothing leaves this page.

1 · One-time keyno key yet
Secret seed–Commitment–
hidden part of a chainrevealed by the signaturechecksum chains
2 · Sign a message
3 · Verifyanyone can do this with only the commitment
What you're seeing
  1. Your key is 67 chains. Each starts at a secret value and is hashed 15 times. The tops of all chains are hashed into one commitment. That's all a bunker stores.
  2. Signing walks each chain part of the way. How far depends on the message's hash, so every message reveals a different pattern.
  3. A verifier finishes each chain and checks it reaches the commitment. Change one character and it doesn't.
  4. The yellow checksum chains stop anyone from walking chains further to forge a new message.
Why one-time

Every signature reveals part of each chain. Signing different messages with one key undermines its one-time security assumption and can enable forgery. That's why a bunker rotates to a fresh key on every unlock. Try signing twice here to see the warning.

Numbers
Chains67Steps per chain15HashSHA-256Signature2,144 bytesCommitment32 bytes

Educational browser implementation. No seed is stored or uploaded. Generate a new key before signing a different message; this lab is separate from the proposed production verifier.