Sign with hashes.
An educational Winternitz-style signing demonstration, running for real in your browser. Make a one-time key, sign a message, then try changing the message and watch verification fail. Nothing leaves this page.
–Commitment–- Your key is 67 chains. Each starts at a secret value and is hashed 15 times. The tops of all chains are hashed into one commitment. That's all a bunker stores.
- Signing walks each chain part of the way. How far depends on the message's hash, so every message reveals a different pattern.
- A verifier finishes each chain and checks it reaches the commitment. Change one character and it doesn't.
- The yellow checksum chains stop anyone from walking chains further to forge a new message.
Every signature reveals part of each chain. Signing different messages with one key undermines its one-time security assumption and can enable forgery. That's why a bunker rotates to a fresh key on every unlock. Try signing twice here to see the warning.
67Steps per chain15HashSHA-256Signature2,144 bytesCommitment32 bytesEducational browser implementation. No seed is stored or uploaded. Generate a new key before signing a different message; this lab is separate from the proposed production verifier.

BUNKER