QRDXDocs

Post-quantum cryptography

What quantum computers threaten, what ML-DSA-65 protects on QRDX, and what it does not.

The threat

Blockchains secure accounts with public-key signatures. Bitcoin and Ethereum use ECDSA over secp256k1, whose security rests on the elliptic-curve discrete logarithm problem.

  • Shor's algorithm, run on a large fault-tolerant quantum computer, solves discrete logarithms and factors integers in polynomial time. It would let an attacker compute a private key from a public key, and so forge signatures. Every account whose public key is known (in Ethereum, any account that has ever sent a transaction) would be exposed.
  • Grover's algorithm speeds up brute-force search quadratically. It roughly halves the security of hash functions and symmetric keys: a 256-bit hash still gives about 128-bit security, which remains sound.

No quantum computer today can run Shor's algorithm at a useful size. But keys and chains last decades, migrating a live chain's accounts is slow and contentious, and data recorded now ("harvest now, decrypt later") stays recorded. QRDX starts post-quantum instead of migrating later.

What QRDX uses

ML-DSA-65 (FIPS 204, formerly CRYSTALS-Dilithium3) for signatures, NIST security category 3. Its security rests on lattice problems (Module-LWE and Module-SIS) for which no efficient quantum algorithm is known. QRDX Wallet uses the @noble/post-quantum implementation, checked byte for byte against liboqs, which the node uses.

Hashes: keccak-256 for addresses and account ids, BLAKE2b-256 for exchange transaction hashes, BLAKE3 for state roots. All keep at least 128-bit security against Grover.

What is protected

Protected by ML-DSA-65
Consensusevery block and attestation; validators cannot use classic keys
The 0xPQ… accountexchange balances, orders, pools, perps positions, tokens; type-0x51 transfers and contract calls
Exchange transactionsevery one; a classic key cannot sign them

What is not

  • Classic 0x… accounts are still secp256k1. They exist for Ethereum compatibility. Keep value you want protected from quantum attacks in your 0xPQ… account.
  • Imported private keys: an account created from an imported classic key gets a post-quantum key derived from that classic key, so it is only as strong as secp256k1. QRDX Wallet labels these classical PQ. Create accounts from a recovery phrase.
  • Account ids are 20 bytes, for EVM compatibility, which gives about 80 bits of collision resistance (finding any two keys with the same id), the same as Ethereum. Taking over a specific existing account still requires forging an ML-DSA-65 signature, or a 160-bit second-preimage. See Accounts.
  • TLS, the relay and your device. Connections to nodes and the QRDX Connect relay use today's TLS, and a compromised browser or operating system can read keys while the wallet is unlocked.
  • Other chains. Assets bridged in later will be as safe as the chain and bridge they come from.

Sizes and costs

ML-DSA-65secp256k1
Public key1,952 bytes33 bytes (compressed)
Signature3,309 bytes65 bytes
Intrinsic gas for a transfer145,176 (type 0x51)21,000

Larger keys and signatures cost more bandwidth and storage; QRDX prices them in gas. On the exchange, operation gas is fixed per operation, so post-quantum signing adds no per-trade surcharge.

On this page