Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Website
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Slate)
  • No Skin
Collapse
AntiQua

AntiQua

  1. Home
  2. Technology
  3. Why Post-Quantum? The Threat is Real

Why Post-Quantum? The Threat is Real

Scheduled Pinned Locked Moved Technology
post-quantumcryptographyml-dsaml-kemsecurity
1 Posts 1 Posters 38 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • BlythexB
    BlythexB
    Blythex
    wrote on last edited by Blythex
    #1

    Almost every blockchain in use today secures your coins with elliptic-curve signatures (ECDSA or EdDSA). They are fast, compact and safe against every computer we have today. Against a large quantum computer running Shor's algorithm, they are not safe at all.

    AntiQua was designed from day one on the assumption that this threat is not hypothetical โ€“ it's a matter of when. Here is what that means in practice. ๐Ÿ‘‡


    ๐Ÿ” What a quantum computer actually breaks

    Not everything in a blockchain is equally at risk. The real problem is signatures, not hashing:

    Building block Used for Quantum attack Impact
    ECDSA / EdDSA Signing transactions Shor's algorithm โŒ Broken โ€“ the private key can be computed from the public key
    RSA, ECDH Encryption, key exchange Shor's algorithm โŒ Broken
    SHA-256, SHA-3 Hashing, addresses, mining Grover's algorithm โš  Weakened โ€“ effective security roughly halved (256 โ†’ ~128 bit), still considered safe
    AES-256 Symmetric encryption Grover's algorithm โš  Weakened the same way, still considered safe

    In plain words: whoever controls a large enough quantum computer can derive your private key from your public key โ€“ and sign transactions as if they were you.


    โŒ› Why "not yet" is not a good excuse

    1. Public keys live on-chain forever.
    On most blockchains, your public key becomes visible the moment you spend from an address โ€“ and it stays in the chain history permanently. Every coin behind an exposed public key is a target the day a capable quantum computer exists. That includes millions of coins already sitting in such addresses today.

    2. Migrating a live blockchain takes years.
    Switching the signature scheme of an existing network needs consensus, new wallets, exchange support โ€“ and every single holder moving their funds. Coins whose owners lost their keys or stopped paying attention can never be moved to safety.

    3. The standards are already here.
    In August 2024, NIST published the first post-quantum standards: FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA). NIST's transition plan proposes to deprecate quantum-vulnerable algorithms like RSA and elliptic-curve cryptography after 2030 and disallow them after 2035. The rest of the industry is starting its migration now.

    4. Attackers can wait.
    "Harvest now, decrypt later" is not science fiction: data and public keys collected today can be attacked the day the hardware is ready.


    ๐Ÿ›ก How AntiQua handles it

    AntiQua doesn't bolt post-quantum cryptography onto an old design. It is the design:

    Layer AntiQua uses Standard
    ๐Ÿ” Signatures ML-DSA-87 FIPS 204 ยท NIST security category 5
    ๐Ÿ”‘ Key encapsulation ML-KEM-1024 FIPS 203 ยท NIST security category 5
    #โƒฃ Hashing SHAKE-256 FIPS 202 (SHA-3 family)
    ๐Ÿ” Seed phrases AIP-39 our own post-quantum mnemonic standard
    โ› Proof of Work RandomX CPU-friendly, ASIC-resistant mining

    NIST security category 5 is the highest level NIST defines: breaking it must be at least as hard as brute-forcing a key for AES-256.

    And because post-quantum signatures are there from the genesis block, there is no legacy signature scheme to migrate away from โ€“ no future hard fork just to become quantum-safe.


    โš– The honest part: where the cost is โ€“ and how we contain it

    Post-quantum security isn't free. The keys and signatures are much larger than what Bitcoin or Ethereum use:

    Public key Signature
    ECDSA (secp256k1) 33 bytes ~72 bytes
    ML-DSA-87 2,592 bytes 4,627 bytes
    AntiQua combined key (ML-DSA-87 + ML-KEM-1024) 4,160 bytes โ€“

    A naive design would store all of that forever, on every node. AntiQua doesn't. Signatures are expensive once โ€“ on the wire and when a block is first accepted. After that, the network works with hashes, compact commits and checkpoints.

    โœ… Verify once, then commit compact

    When a block is connected, every transaction is verified in full โ€“ including its ML-DSA signature. What gets written to the ledger afterwards is a compact record: the 32-byte transaction hash, inputs, outputs and amounts โ€“ without signature and public key. The Merkle root and the block header hash bind that record to the verified original. Full and light nodes therefore store the proof of validation, not the proof itself.

    ๐Ÿ›ฐ Commitments instead of bodies in gossip

    Block announcements carry transaction commitments โ€“ again 32 bytes per transaction. The full block with all signatures only goes to a subset of verifying nodes, or to whoever explicitly requests it.

    ๐Ÿšฉ Checkpoints instead of re-checking history

    • UTXO snapshots every 5,000 blocks record the state hash, total coin supply and UTXO root. A starting node syncs from the latest snapshot โ€“ checking proof of work, Merkle roots and transaction hashes โ€“ instead of re-verifying every historical signature.
    • Finality checkpoints every 100 blocks are signed by miners and confirmed by a quorum. Once a height is finalized, reorganisations before it are locked. That's a handful of large signatures for finality โ€“ not millions of transaction signatures on disk.

    ๐Ÿ›ก Why this stays secure

    The check always happens before anything is discarded: a compact record is only valid because the full transaction was accepted first. Archive nodes keep the complete bodies, so anyone who needs the original โ€“ for an initial sync or a wallet โ€“ can fetch it and verify it again against the committed hash.

    In short: post-quantum signatures cost bandwidth and CPU once. Storage stays lean. And even if it didn't: storage gets cheaper every year โ€“ a stolen private key never gets un-stolen.


    ๐Ÿ’ฌ Let's talk

    Questions, doubts, counter-arguments? That's exactly what this category is for. Happy to go deep on any part of the stack โ€“ ask away ๐Ÿ‘‡

    Want more? Read how AIP-39 keeps your seed phrase quantum-resistant, or check our Security Audit History.

    โ€” Blythex

    1 Reply Last reply
    1

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better ๐Ÿ’—

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    antiqua-blockchain.com ยท Legal notice ยท Privacy ยท Community guidelines
    ยฉ 2026 AntiQua ยท Post-quantum blockchain
    • Login

    • Don't have an account? Register

    • Search
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Website
    • Search