ARKUM
DocsCreate vault
Key lab

Sign with hashes.

This is the exact signature the arkum program checks on-chain, running for real in your browser. Make a one-time key, sign a message, then try changing the message and watch verification fail. Nothing leaves this page.

1 · One-time keyno key yet
Secret seed–Root–
hidden part of a chainrevealed by the signaturechecksum chains
2 · Sign a message
3 · Verifyanyone can do this with only the root
What you're seeing
  1. Your key is 30 chains. Each starts at a secret value and is hashed 255 times. The ends of all chains are hashed into one root. A vault's address is made from that root, nothing else.
  2. Signing walks each chain part of the way. How far depends on the message's hash, so every message reveals a different pattern.
  3. A verifier finishes each chain and checks it reaches the root. Change one character and it doesn't.
  4. The two yellow checksum chains stop anyone from walking chains further to forge a new message.
Why one-time

Every signature reveals part of each chain. Sign two different messages with the same key and an attacker learns enough to forge others. That's why a vault rotates to a fresh key on every unlock. Try signing twice here to see the warning.

Numbers
Chains30Steps per chain255HashSHA-256 (28-byte chains)Signature840 bytesRoot32 bytes