In that case we are perfectly fine. We can distribute symmetric keys in a different way. Just run a hash 10,000,000 times and your public key will be the last result, while the private key will be the first input. Only you can reconstruct the other layers going backwards, as you “peel the onion” and you can use those numbers any way you want. My favorite application is to generate random numbers among untrusting participants by everyone revealing the next number and then using functions of that as seeds to an RNG. It can be used for tons of byzantine fault tolerant applications.
The only problem is that it seems to also have forward secrecy built in because once you’ve revealed the next onion layer, anyone could have constructed the transcript up to that point. So you can only be sure that the author signed something if you are sure they didn’t reveal the next private key to anyone else (to verify it).