Post-quantum signatures
ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) replace elliptic-curve signatures, but they're 30 to 100 times larger. We study hybrid constructions with Ed25519 and how to fit them within on-chain size and compute limits.
We don't invent new cryptography. We take standardized, peer-reviewed algorithms and do the hard engineering of combining, testing and deploying them where real money and real data live.
Each area has a lead, a written problem statement and a public research note planned. Status is updated as work moves forward.
ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) replace elliptic-curve signatures, but they're 30 to 100 times larger. We study hybrid constructions with Ed25519 and how to fit them within on-chain size and compute limits.
Every connection between our apps, devices and servers uses hybrid X25519 + ML-KEM-768 (FIPS 203). If either scheme holds, the session key stays secret, which shuts down harvest-now-decrypt-later attacks.
Keys are generated and used in shares across several devices. Signing needs a quorum, like 2 of 3, and no single device ever reconstructs the full key, not even during setup.
Machine-checked proofs that parsers, state machines and key-handling code do exactly what the spec says, and nothing else. We focus proofs where a bug would mean lost funds.
Post-quantum algorithms are newer and their implementations less battle-tested. We measure timing, power and electromagnetic leakage on real hardware and harden code with masking and redundancy checks.
Solana accounts use Ed25519, and an account's public key is its address. A large quantum computer could derive the private key from it. We research hash-based vaults and rotation flows that let holders move to safety before that day.
Shor's algorithm breaks the math behind elliptic-curve and RSA cryptography outright. Grover's algorithm only weakens symmetric ciphers and hashes, so doubling key length restores the margin. The real danger is timing: encrypted data and on-chain public keys can be collected now and attacked later.
| Primitive | Used for | Quantum attack | Impact | Our response |
|---|---|---|---|---|
| Ed25519 / ECDSA | Wallet and transaction signatures | Shor | Broken: private key recoverable from public key | Hybrid with ML-DSA; hash-based vaults for long-term holdings |
| X25519 / ECDH | Session key agreement | Shor | Broken: recorded traffic can be decrypted later | Hybrid X25519 + ML-KEM-768 on every connection |
| RSA-2048 | Legacy certificates, key wrapping | Shor | Broken | Not used anywhere in our stack |
| AES-256 | Data at rest and in transit | Grover | Weakened to roughly 128-bit, still secure | Keep AES-256-GCM; never use 128-bit keys |
| SHA-256 / SHA-3 | Hashing, commitments, Merkle trees | Grover | Preimage margin reduced, still secure at 256-bit output | Keep 256-bit outputs; basis for SLH-DSA vaults |
Construction, security argument and test vectors for a signature that is valid only if both components verify.
Transaction size, compute units and fees for ML-DSA and SLH-DSA verification, compared with Ed25519.
Adversaries, assets and timelines, including harvest-now-decrypt-later and exposed public keys.
Distributed key generation, share refresh and recovery without ever assembling a full key.
Moving funds behind one-time hash signatures and the operational trade-offs that come with them.
Power and EM measurements on our prototype signing device, before and after masking.
Security claims are only worth something if others can check them. Nothing reaches users until it has been through each stage below.
What we're protecting, from whom, and what success looks like in measurable terms.
A written design precise enough for someone else to implement independently.
Open-source implementation with test vectors that match the spec.
Fuzzing, fault injection and side-channel measurement by our own red team.
Independent auditors and academic reviewers get full access and publish their findings.
Note, code, test results and audit report released together.