The idea
What a quantum computer does to a wallet, and why a key made of hashes is out of its reach.
A wallet is a math problem
An Ethereum address is the hash of a public key, and the public key is a point on the secp256k1 curve. Signing proves you know the number behind that point. Anyone who can go from the point back to the number can sign as you.
On a classical computer that takes about 2128 operations. On a quantum computer, Shor's algorithm does it in polynomial time. Nothing about the chain changes on that day: a transaction signed with a recovered key is a valid transaction.
Two facts make this worse than it sounds:
- The public key is public. Every transaction a wallet has ever sent reveals it. An address that has signed once has its problem posted on-chain permanently.
- The target does not expire. A balance that sits behind a published key can be attacked whenever the machine exists. There is no need to intercept anything in real time.
A hash is not a math problem
A hash function has no structure to exploit. The best quantum attack on it is Grover's search, which only takes a square root off the work: keccak256 keeps 128 bits of security against a preimage search on a quantum computer. That is the same margin elliptic curves give against classical computers today.
Signatures can be built from hashes alone. The idea is as old as public-key cryptography (Lamport, 1979; Merkle, 1979; Winternitz), and it is the family standards bodies chose for long-term security: XMSS (RFC 8391, NIST SP 800-208) and SPHINCS+ (standardized as SLH-DSA, FIPS 205).
Quantum Shield uses this family, built on the hash the EVM already runs natively: keccak256.
From one signature to an account
A hash-based key can sign safely once. The construction turns that into an account in three steps:
A one-time key
67 secret values, each hashed 15 times in a chain. The ends of the chains are the public part. To sign, you reveal each chain at a position chosen by the message: nobody can walk a hash chain backwards, and a checksum stops anybody walking it forwards into another message.
A tree of them
256 one-time keys are the leaves of a Merkle tree. The root, bound to a public seed, is a 32-byte key. A signature names its leaf and carries the path from that leaf to the root.
An account
The vault stores the key and a counter. Each signature uses the next leaf; the vault refuses any leaf it has passed. Before the leaves run out, one signature installs the next key. The account keeps its name and its balance.
The result behaves like a wallet (a recovery phrase, a balance, send and sell buttons) and contains no elliptic curve anywhere between the secret and the funds. See the signature scheme for the full construction.
What stays public
Quantum Shield is about who can sign, not about privacy. Accounts, balances and movements are readable on-chain, as with any token. What changes is that a published account name gives an attacker nothing to compute a key from.