AmericanFortress proposed a scheme to protect crypto wallets from quantum threats

cryptonews.ruPubblicato 2026-07-29Pubblicato ultima volta 2026-07-29

Introduzione

AmericanFortress has published a preprint detailing ZKPoSP, a cryptographic scheme designed to protect hierarchically deterministic (HD) cryptocurrency wallets from potential quantum attacks without requiring users to change their addresses. The proposed scheme replaces classical digital signatures with non-interactive zero-knowledge (NIZK) proofs, aiming to maintain compatibility with existing address formats. The company also introduced the QBIP32 scheme, intended to generate a signing scalar, a separate quantum-resistant proof, and a chain code in a single function call. According to the authors, QBIP32 can be applied to various elliptic curves of prime order, including secp256k1 and Ed25519. The post-quantum security of the scheme is described as "conjectured," relying on the quantum resistance of the underlying hash functions and NIZK proofs. However, for the scheme to function in a given blockchain network (like Bitcoin, Ethereum, or Solana), nodes would need to support verification of these new proofs instead of standard signatures—a capability currently not implemented. An implementation in Rust using RISC Zero reportedly takes 12–13 seconds to generate a proof and 9–10 milliseconds to verify it. The publication follows other industry efforts to address quantum threats, including reports from Galaxy on vulnerable assets, new hardware wallets like the PQ1, and consortiums like the Bitcoin Security Consortium pledging funding for post-quantum cryptography research. T...

Company AmericanFortress published a preprint on ZKPoSP — a cryptographic scheme for protecting hierarchical deterministic wallets from potential quantum attacks without changing addresses.

According to the authors' design, ZKPoSP allows preserving the existing address format while replacing the classical signature with a non-interactive zero-knowledge proof (NIZK).

AmericanFortress also described the QBIP32 scheme. It is designed to generate a signature scalar, a separate quantum-resistant witness, and a chain code within a single function call. The authors claim that QBIP32 can be applied to different elliptic curves of prime order, including secp256k1 and Ed25519.

In the preprint, the post-quantum security of the scheme is described as assumed. According to the document, it relies on the resilience of hash functions and NIZK proofs against quantum adversaries. However, for the scheme to work in a specific network, nodes must support verifying such proofs instead of standard signatures. Neither Bitcoin, Ethereum, nor Solana currently do this.

AmericanFortress implemented the constructions in Rust using RISC Zero. According to the authors, creating a signature proof takes about 12–13 seconds, while verification takes about 9–10 ms.

Quantum & After. Question No.2: How are blockchains preparing for the "quantum" era?

In a March report, Galaxy company indicated that Project Eleven estimates approximately 7 million $BTC, or about $470 billion at prices at that time, as potentially vulnerable. This referred to addresses whose public keys have already been disclosed on-chain.

On July 28, Freedom Factory introduced the PQ1 hardware wallet for Ethereum and EVM-compatible networks. In a press release, the company stated the use of SPHINCS+C10 and ERC-4337 smart accounts.

On July 23, Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy, and Strategy announced the launch of the Bitcoin Security Consortium. Participants promised to collectively allocate $15 million over three years to developers and researchers working on the long-term security of Bitcoin, including post-quantum cryptography.

On July 21, Galaxy launched a nearly identical program to prepare the first cryptocurrency for potential threats from quantum computers. Up to $5 million will be directed in grants to developers and researchers.

Earlier, the Stellar Development Foundation presented its document, and the Algorand Foundation also published a roadmap. Nicolas B. Consigny, lead of the Kohaku project at the Ethereum Foundation, proposed a solution called SPHINCS-, which would allow securing wallets without conducting a hard fork.

Recall that in May, AmericanFortress presented a post-quantum signature scheme to protect existing crypto assets, including "dormant" wallets from the Satoshi era with 1.1 million $BTC. The new publication differs by focusing on hierarchical deterministic wallets and describing ZKPoSP/QBIP32 as a general mechanism for different curves and networks.

Will Quantum Hackers Steal Satoshi Nakamoto's Billions?
end-content

Domande pertinenti

QWhat is the main cryptographic scheme proposed by AmericanFortress in the preprint, and what does it aim to protect?

AAmericanFortress proposed the ZKPoSP (Zero-Knowledge Proof of Signature Possession) scheme. It aims to protect hierarchically deterministic wallets from potential quantum attacks without requiring a change of wallet addresses.

QAccording to the article, what do existing blockchains like Bitcoin and Ethereum lack to implement the proposed quantum-resistant scheme?

AExisting blockchains like Bitcoin, Ethereum, and Solana currently lack support for node-level verification of the new non-interactive zero-knowledge (NIZK) proofs that would replace standard digital signatures to enable the proposed scheme.

QWhat are the reported performance metrics for the ZKPoSP scheme implemented in Rust using RISC Zero?

AAccording to the authors, creating a signature proof takes about 12–13 seconds, while verifying a proof takes about 9–10 milliseconds.

QWhat specific type of wallets did the March Galaxy report highlight as potentially vulnerable to quantum attacks, and what was the estimated value at risk?

AThe Galaxy report highlighted addresses whose public keys have already been exposed on-chain as potentially vulnerable. It estimated that roughly 7 million BTC, worth about $470 billion at the time, were at risk.

QBesides ZKPoSP, what other scheme is described by AmericanFortress for generating quantum-resistant components, and what is a key feature of it?

AAmericanFortress also described the QBIP32 scheme. A key feature is that it can generate a signing scalar, a separate quantum-resistant witness, and a chain code within a single function call, and it can be applied to different elliptic curves of prime order like secp256k1 and Ed25519.

Letture associate

Trading

Spot
活动图片