Post-quantum swapsanywhere to anywhere
Two parties trade directly, with no bridge, no oracle, and no key for a quantum computer to break.

Governments are taking quantum hackers seriously
US and European rules require critical industries like finance and networking to begin protecting themselves from quantum attacks by 2028.
How a swap settles
You can think of the protocol like trading wallets. Each wallet needs a shared key and a personal key. Once you reveal the shared key to claim your assets, your partner can now retrieve a copy to withdraw their half. No hackable bridge or oracle, just post-quantum goodness.
The pools are what get drained, and the contract is rarely what breaks: $292M left KelpDAO in April 2026 after a single off-chain verifier was fed a burn that never happened, per Chainalysis.
You address the offer to a Quip account you already know. It is signed intent, not a transaction: nothing is escrowed, no gas is spent, and either side can walk away for free.
If either side stops, the deadline passes and each asset returns to whoever committed it. Deadlines are asymmetric, so acting honestly is always the protected position.
Both sides settle, or neither does.
Making post-quantum swaps convenient
The Quip extension holds your post-quantum keys, signs each leg of a swap, and connects to dApps like the wallet you already use.



Making swap intents discoverable
Today you have to know your counterparty. Soon you will be able to post an offer to the Decentral Limit Order Book and let your match find you. Nothing is escrowed until a taker commits.
Explore a demoWhat is live, and what is next
Oak Security reviewed the QuipSwap contracts. The findings will be published shortly.
What you can swap
A swap can cross two chains, or stay on the same one.
- Native coinsThe chain's own coin
- ERC-20Fungible tokens
- ERC-721One of a kind
- ERC-1155Fungible and unique together
Common questions
Those hold classical keys, the kind a quantum computer is built to break. A Quip account wraps your classical keys with post-quantum keys, and QuipSwap is how that account reaches other chains without stepping outside its own protection.
It settles like an OTC trade rather than a pool trade: you name a counterparty, both sides escrow, and timed windows bound each stage. The extra steps remove the risk that someone steals the collateral behind your bridge or your liquidity pool.
A bridge holds your asset in a pool and issues a wrapped claim against it, which makes the pool worth attacking. Here each asset stays in a contract on its own chain, so custody never moves.
The locks are hash-based, and hashes stay hard for a quantum adversary. Signature checks happen in the Quip account layer, where post-quantum keys live.
Base today. Swaps cover native coins, ERC-20, ERC-721, and ERC-1155, and the protocol settles across two chains or the same one. More EVM chains are coming very soon, with SVM networks to follow.
Today you bring one: offers are link-addressed, so you agree terms with a specific person and send them the link. An order book where you can publish an offer and let a counterparty find you is coming soon.
The deadline passes and you reclaim your asset in full from the contract on your own chain. Deadlines are asymmetric, so acting honestly is always the protected position.
Yes, by Oak Security. The findings will be published shortly.


