hackquest logo

Qanary

Quantum-safe treasury accounts for Arbitrum: NIST post-quantum signatures verified by Stylus, a capped classical hot key, and an on-chain Q-Day tripwire.

Video

Hình ảnh dự án 1
Hình ảnh dự án 2
Hình ảnh dự án 3
Hình ảnh dự án 4

Công nghệ sử dụng

Solidity
Rust
Next
Arbitrum Stylus
Post-Quantum Cryptography
ERC-4337
ZeroDev
AWS KMS

Sự miêu tả

The problem

Every Ethereum-style account reveals its public key the first time it signs, and more than 65% of ETH already sits in accounts whose keys are public; a quantum computer that can solve the elliptic-curve discrete log turns those keys into private keys ("harvest now, forge later"). Regulators have set dates: Singapore's CSA handbook asks for migration plans by 31 March 2027 and quantum-safe new systems from 2028, MAS asks for quantum resilience before the end of this decade, and NIST plans to disallow ECDSA after 2035. Arbitrum has no post-quantum precompile planned, and the best Solidity verifiers for NIST signatures cost 0.64–1.55M gas per check.

What Qanary does

A Qanary treasury splits authority by risk. The cold tier is a post-quantum key (ML-DSA-44/65 from FIPS 204, or Falcon-512) that can live in a browser wallet or an AWS KMS HSM; only it can move funds above the cap, change modules, rotate keys or sign ERC-1271 messages. The hot tier is a classical key (ECDSA wallet or passkey) that spends through an executor with an allowlist and a leaky-bucket cap measured from real balance changes, so its worst-case loss is bounded. An ownerless tripwire registry posts bounties on nothing-up-my-sleeve keys on a ladder of curves (160, 192, 224 bits, then secp256k1 and P-256); a valid claim proves the discrete log fell, raises the threat level forever and shrinks, freezes or kills the classical tier of every subscribed account automatically.

How it works

Post-quantum verification runs in Arbitrum Stylus (Rust compiled to WASM) behind the ERC-7913 verifier interface: Falcon-512 ≈ 36k gas, ML-DSA-44 ≈ 110k, ML-DSA-65 ≈ 166k (cached execution on Nitro), 9–18x cheaper than the best Solidity verifiers and inside the ERC-4337 validation budget. The verifiers plug into ZeroDev Kernel v3.3 as an ERC-7579 root validator, into Safe as post-quantum ERC-1271 owners (a 9-of-12 council of PQ owners is tested on a fork of Arbitrum One), and into OpenZeppelin accounts directly. A TypeScript SDK builds accounts, signs with browser keys or AWS KMS, and self-bundles user operations.

Live proof

On 2 October 2026 the Arbitrum Security Council paused new Stylus activations on Arbitrum One and Nova. Qanary's four Stylus programs are live on ApeChain, an Arbitrum Orbit chain settling to Arbitrum One, and reproduce byte-for-byte with cargo stylus verify; Arbitrum One runs the same modules with a Solidity ML-DSA-44 verifier behind the same interface, and accounts move to Stylus with one rotateKey call when activations return. On both chains a treasury whose root key is an ML-DSA-44 key held in AWS KMS executed post-quantum transfers, and the refusals landed on-chain as failed transactions: hot spend over the cap (CapExceeded), a tampered post-quantum signature (AA24), and a hot spend after the drill tripwire fired (ClassicalFamilyBroken). A ladder rung (secp160r1) was claimed through the live Stylus ECDSA verifier. All 18 Solidity contracts are source-verified on Sourcify.

Quality

Rust verification core passes NIST ACVP and Falcon round-3 KAT vectors with negative controls and fuzzing; 292 Foundry tests including invariants, fork tests against real Kernel, Safe and USDG on Arbitrum One, and a Stylus-in-Forge suite with live signatures; an internal security audit (1 High, 2 Medium, 3 Low) with every finding fixed or documented before deployment. CLAIMS.md tags every public claim with how to reproduce it; SECURITY.md lists the honest limits.

Why Arbitrum

Stylus is what makes NIST-standard post-quantum verification affordable on-chain today, and Arbitrum's Security Council itself is a 9-of-12 ECDSA multisig — Qanary's PQ Safe owners are a drop-in path for it.

Links

Live app: https://qanary-amber.vercel.app
Code: https://github.com/RaYYeR220/qanary
Demo video: https://youtu.be/306lVmwHXPg
Every address and transaction: https://github.com/RaYYeR220/qanary/blob/main/PROOF.md
Judges guide: https://github.com/RaYYeR220/qanary/blob/main/JUDGES.md

Tiến độ hackathon

Built from scratch during the buildathon in a new repository (history starts in the event window):

  • Rust verification core (ML-DSA-44/65, Falcon-512) with NIST ACVP / round-3 KAT vectors, plus the weak-curve ladder

  • Four Stylus verifiers (ERC-7913) and the Solidity modules: QuantumValidator, HotTierExecutor, QuantumCanaryRegistry, KeyStore, Safe and OpenZeppelin adapters, factories

  • Solidity ML-DSA-44 fallback verifier for Arbitrum One after the Stylus activation pause

  • TypeScript SDK (browser keys, AWS KMS signer, self-bundled user operations) and the web app

  • Internal security audit with every finding fixed or documented

  • Live deployments with end-to-end runs on ApeChain (19 txs) and Arbitrum One (14 txs), all contracts source-verified on Sourcify

Trạng thái huy động vốn

Not raised; bootstrapped.

Trưởng nhóm
RRayyer
Liên kết dự án
Triển khai Hệ sinh thái
Arbitrum OneArbitrum One
Ngành
InfraDeFi