Agenda
Naive, pre-quantum secret sharing across dedicated decryptor committee?
Meeting Time: Wednesday, August 12, 2026 at 15:00 UTC (60 minutes)
Naive, pre-quantum secret sharing across dedicated decryptor committee?
Meeting Time: Wednesday, August 12, 2026 at 15:00 UTC (60 minutes)
The meeting focused on the design of an encrypted mempool, particularly the tension between post-quantum protection and key reveal optionality. Justin, Gottfried, Benedikt, Jan, Jannik, Anders, and Loring discussed whether to pursue a pre-quantum or post-quantum solution, with significant concerns raised about the engineering effort and scalability issues of post-quantum cryptography. The group debated the viability of using DKGs with KZG ceremonies, but concluded that quantum attacks would render such systems insecure. Jannik presented an alternative approach using an allow list for key publishing, which was seen as conceptually different from the trust graph in EIP-8105. The discussion also covered potential bribery and collusion attacks on keeper committees, and the difficulty of automating detection of such behavior. The participants acknowledged the need to reach a consensus on whether a non-post-quantum secure solution is acceptable, suggesting that client teams and the wider ecosystem should weigh in on this decision.
Justin opened the meeting and clarified that there was a scheduling error, which EF confirmed would be fixed on the backend. The main focus of the meeting was to discuss notes prepared by Yannick regarding an allowlist for key publishing, addressing the tension between post-quantum protection and key reveal optionality. Justin outlined his thoughts on using a DKG (Distributed Key Generation) built around the existing KZG ceremony to address the key optionality problem, though he noted concerns about quantum protection.
The team discussed the challenges of implementing a DKG (Distributed Key Generation) solution, particularly regarding quantum computer vulnerabilities. Justin proposed going down the pre-quantum path but later changed his mind, arguing that the project management perspective and potential money saved from mitigating MEV in the short term might not be more valuable than preparing for PQ day and solving sizing problems introduced by post-quantum crypto. The group explored the possibility of using a dedicated DKG facility as an EIP, with Jan explaining that Shudder uses a Bonnie Frankner IBM threshold IBE approach without batching, though there are some concerns about identity spaces when encrypting and sending payloads to others. The discussion concluded with an acknowledgment that the DKG and encryption scheme must be compatible, and the team began exploring the post-quantum attack surface, particularly regarding the trusted setup used by committees to validate their shares.
The team discussed quantum security vulnerabilities in threshold key generation (DKG) and encryption schemes. Benedikt explained that while threshold encryption schemes might be vulnerable to quantum computers, this isn’t as critical as the ability to forge transaction signatures. The discussion focused on KZG-based DKG protocols, where Benedikt clarified that quantum computers could break the binding of KZG commitments once, allowing classical recovery of tau values. Justin proposed a key rotation approach with a one-day lifetime, but Gottfried noted that current estimates suggest DLOG could be broken in under 10 minutes with error-correcting qubits, making such approaches potentially ineffective.
Jan and Gottfried discussed the security implications of quantum computers for encrypted Mempools, agreeing that once quantum computers become available, the encrypted Mempool would be considered broken and not worth maintaining. They debated whether an attacker would target the Mempool directly or focus on more valuable targets first, and considered the potential for detecting quantum attacks through out-of-order blocks or key breakthroughs. The group concluded that while pre-quantum encryption might provide temporary security, the effort required doesn’t justify the benefits, especially given the limitations of current post-quantum alternatives.
The team discussed challenges with implementing post-quantum cryptography, particularly regarding signature sizes and overhead costs. Justin raised concerns about the space issues triggered by post-quantum algorithms and questioned whether classical encryption would be sufficient for their needs. Jan and Gottfried agreed that more research is needed on both classical and post-quantum approaches, with Jan suggesting they should first determine their stance on whether to use classical or post-quantum encryption before proceeding with further design work. The discussion highlighted the need to balance implementation complexity with security requirements, particularly regarding encrypted mempools and protocol integration options.
The team discussed post-quantum security considerations for encrypted mempools, with Jan expressing the view that classical solutions could work well if properly engineered, while others noted challenges in transitioning between pre-quantum and post-quantum approaches. Jannik presented concerns about validator-based whitelist approaches, highlighting potential bribery risks and suggesting external committees as a safer alternative. The group identified key research areas including post-quantum versus classical solutions, collusion resilience mechanisms, and automated detection of bad behavior in non-enshrined designs. Anders shared a new design for censorship resistance using directed acyclic graphs in the older trusted set approach from EIP-8105.
w%?hU.#3)w%?hU.#3)w%?hU.#3)YouTube recording available: https://youtu.be/R1es3FdhHVA