Securing digital assets for the post-quantum era

The Quantum Threat to Blockchains - 2026 Report Now available ⬇️
19
29
115
29,526
The latest from the Project Eleven blog by @furkanakal Almost everything a blockchain does comes down to checking signatures. Balances, transactions, consensus votes... Strip away the machinery and a node spends its day asking one question over and over. Does this signature verify under that public key? There's no encryption protecting your coins. What protects them is that only you can produce a valid signature for your key. Today, that is done by four schemes: ECDSA, Schnorr, EdDSA, and BLS. They look like four independent choices, but as we'll see, they're really four versions of the same bet. This post kicks off our post-quantum signing series, and the goal is to build the foundation: what a digital signature actually is, how each of the four works, what they cost, and why a single quantum algorithm eventually retires all of them at once. Continue reading: projecteleven.com/blog/post-…
1
5
30
2,697
Quantum & Privacy Day 🫡🔥🚀 Apply to attend: luma.com/jtof4o9b
Founder of @Zcash and Chief Product Officer at Shielded Labs, @zooko, will be at Quantum & Privacy Day. Zcash launched in 2016 and brought zero-knowledge cryptography to production. October 8 | Tower Club, Singapore Join us in Singapore: luma.com/jtof4o9b
6
3
29
2,199
👀👀👀
Is your wallet post-quantum? @conordeegan, CTO and co-founder of @projecteleven, joins Quantum & Privacy Day. His work focuses on the post-quantum key management wallets depend on. October 8 | Tower Club, Singapore Apply to attend: luma.com/jtof4o9b
6
5
34
2,597
Proud to support Quantum & Privacy Day with @QuantusNetwork and @NEARProtocol 🫡 Apply to attend: luma.com/jtof4o9b
Quantus
1
3
33
5,233
Project Eleven retweeted
We’re excited to welcome @projecteleven to Quantum & Privacy Day this October. Project Eleven are leaders building post-quantum security and migration infrastructure for digital assets. October 8 | Tower Club, Singapore Apply to attend: luma.com/jtof4o9b
3
3
33
4,457
More progress on quantum means we need more progress on making crypto post-quantum.
Today at #IEEEQuantumWeek, NVIDIA introduced CUDA-Q Logical, a new orchestration layer in the open source CUDA-Q platform for designing and testing fault-tolerant quantum computing applications. ⬇️ nvidianews.nvidia.com/news/n…
4
2
14
5,123
Excited for this one! Quantum & Privacy Day during Token2049 Singapore with @QuantusNetwork and @NEARProtocol 🤝
.@apruden08, CEO and co-founder of @projecteleven and Chairman of @aleoHQ, takes the stage at Quantum & Privacy Day. Google Quantum AI’s paper on quantum risks to blockchain cryptography acknowledges Alex Pruden for discussions on the quantum vulnerabilities of cryptocurrencies. He’ll join the conversation on keeping money private and digital assets secure through the post-quantum transition. October 8 | Tower Club, Singapore Register to join us in Singapore: luma.com/jtof4o9b
3
1
26
2,822
One of the coolest open research efforts in crypto right now. ECDSA.fail is showing what happens when you turn quantum cryptanalysis into a public, competitive research problem. Great work by @eigenlabs/@yukonresearch!
The first full paper on ECDSA.fail is on arXiv In March, Google Quantum AI reported a more efficient quantum circuit for a core step in breaking the signatures behind Bitcoin and Ethereum. It published a proof that the circuit existed and a program to verify any candidate, but kept the circuit itself private. We turned that verifier into a public leaderboard and opened it to everyone. Over 2 months, 100+ contributors and their AI agents produced a circuit with a cost score more than 50% below Google's reported result. The live leaderboard has since moved to 62% ahead. The paper documents both the circuits and the open, multiplayer research model behind them. That model is now @YukonResearch. And the challenge is still open.
5
58
2,851
2028 timeframe. 26 days for each 256 bit break. Let's get to work.
The first complete, end-to-end fault-tolerant resource estimate for running Shor’s algorithm—the team used IonQ’s Walking Cat architecture to demonstrate how a specific application can be optimized for a trapped-ion quantum computer. This work concludes that a 20,000-physical-qubit IonQ quantum computer, once developed, is expected to be able to break secp256k1, the 256-bit elliptic curve used by blockchain technology such as Bitcoin, in just under 26 days. This architectural and resource-estimation study is consistent with IonQ's publicly stated roadmap, which targets systems with the relevant capabilities in the 2028 timeframe. Watch Chris Ballance share the full view in our livestream today, September 8, at 12:30 PM ET → investors.ionq.com/events-an… Read the announcement → ionq.com/news/ionq-publishes… Read the full paper → ionq.com/blog/the-first-full… #IonQ #QuantumIsNow #QuantumComputing #WalkingCat
4
2
34
2,661
Project Eleven retweeted
We reviewed the reference implementation of Threshold ML-DSA against the paper and found that a requirement the security model enforces had no counterpart in the code: the state of a signing attempt must be used at most once. The API allowed the same round-one randomness to produce responses under two different challenges. Two responses from the same randomness subtract to z − z′ = (c − c′) · s an equation in the party's secret share. This is analogous to nonce reuse in Schnorr. We opened a PR, and after discussion with Guilhem Niot at PQShield on the right design, the fix was merged on September 5. Signing state now moves forward one round at a time, is consumed on use, and the randomness is zeroized. The repository is an academic proof of concept, but for a new construction the reference code ends up being the practical spec. This one has already been reimplemented in other languages. We have since spoken to those teams and helped audit their state handling. Full write up by yours truly: projecteleven.com/blog/key-r…
4
10
62
2,792
We found a key-recovery flaw in the reference implementation of the first fully ML-DSA-compatible threshold signature scheme. Reusing signing state could expose a signer’s secret share and, in some settings, the aggregate signing secret. We worked with @PqShield to fix it before the pattern propagated further. @conordeegan explains what we found, why it matters, and how it was fixed: projecteleven.com/blog/key-r…
3
7
36
2,513
A friendly reminder that sending bitcoin back to your same address makes your address quantum vulnerable.
5
5
44
3,349
Project Eleven retweeted
so the Liquid hackers returned 3,400 BTC and kept 598.5 BTC (~$47m). They’ve called themselves white hats throughout this whole saga. Maybe Blockstream agreed to them keeping the 15%, maybe they didn’t. We don’t know yet. What’s arguably more interesting is what “white hat” hacking really means as AI makes serious vulnerability discovery accessible to a much larger group of people. Historically, the people capable of finding a subtle bug in something like Elements were usually security researchers. There are established norms around what you do next: disclose it, don’t take the money, agree a bounty, etc. AI increasingly separates the capability from those norms and I think we’ve probably underestimated how much security has relied on the two coming together. To get good enough to find really hard bugs, you generally spent years inside security, cryptography or open-source communities. Along the way you didn’t just learn how to find them. You also picked up the norms, built a reputation you cared about, and had professional relationships you probably didn’t want to burn. In other words, responsible disclosure hasn’t only worked because we’ve built good incentives for researchers (arguably most of the time the monetary incentives are crap or non-existent). It’s also worked because the population capable of finding these bugs was unusually selected. AI breaks that selection effect. If the capability becomes cheap and widely available, the norms don’t automatically come with it. That’s a pretty fundamental change to a security model which, it turns out, relied on social infrastructure more than we probably realised.
3,400 BTC looks to be on the way back 🔥 mempool.space/address/bc1qdl…
7
10
39
5,076
🚨👀 The Liquid Network hackers appear to have sent 3,400 BTC to Blockstream, keeping ~600 BTC for themselves Is 600 BTC ($50 million USD) a fair white hat reward?
3,400 BTC looks to be on the way back 🔥 mempool.space/address/bc1qdl…
2
3
15
2,503
Let’s dive in to the Liquid Network hack. Set a reminder to join! nitter.net/i/spaces/1nJOLQkmjpwxR
1
3
15
2,195
Crypto. AI. Quantum. The next decade belongs to all three.
Crypto. AI. Quantum. The next decade belongs to all three.
6
7
41
3,976