Few-time signatures cap how many signatures a signer can safely issue. Jevil is, to our knowledge, the first post-quantum and transparent (setup-free) few-time signature scheme with a sharp key-recovery cliff: its cap is enforced by a single sharp threshold rather than a slow slope. Signatures one through are existentially unforgeable at approximately -bit classical security; at the -th the entire secret polynomial becomes publicly recoverable, achieving catastrop

Jevil: A Catastrophic-Failure-by-Design Signature Scheme
Nadim Kobeissi
