Post Quantum transaction signature (PQTS) Breakout #14

Agenda

  • Nicola Ceornea - PQ1

Meeting Time: Wednesday, September 02, 2026 at 13:00 UTC (60 minutes)

GitHub Issue

Meeting Summary:

This meeting was the 14th Post Quantum Transaction Signature meeting focused on hash-based stateless signatures and related developments. Antonio led the discussion and presented updates on the Lattice Sphinx implementation, explaining the move from Poseidon to Blake and SHA hash functions due to performance improvements. Nicola from Freedom Factory demonstrated their PQ1 hardware wallet prototype using Sphinx Minus C12 variant, achieving 1.5-second signature times on silicon and targeting Q4 for device availability. Oren from Fireblocks presented significant optimizations for MLDSA on EVM, reducing verification costs from 8 million to 1.2 million gas through various technical optimizations including memory management and assembly-level improvements. The presenters discussed formal verification approaches using tools like Lean and EasyCrypt, with plans to explore AI-generated proofs. The conversation ended with discussions about hardware security testing and potential demonstrations at upcoming conferences like DEF CON.

Click to expand detailed summary

The meeting began with introductions, where Oren from Fireblocks mentioned he would present an optimized MLDSA EVM contract that is six times more efficient than the current state-of-the-art. Antonio clarified presentation logistics and confirmed there was space for Oren to present after his own brief presentation and Nicola’s presentation from PQ1. Justin Drake shared his contact information with Oren privately to coordinate further communication.

The meeting began with introductions and welcome messages for participants joining a Post Quantum Transaction Signature discussion. Justin Drake exchanged Telegram contact information with participants, including Gianluca from the Riva team and Ben from Australia. The meeting was scheduled to discuss hash-based stateless signatures, but the agenda was adjusted to include presentations from Nicola on PQ1 hardware wallet and Oren on MLDSA optimization.

Antonio presented updates on the transition to post-quantum cryptography, focusing on the implementation of Lynx Sphinx as a hash-based signature scheme to replace ECDSA. He explained the decision to move away from EOA accounts and not include cryptography-related precompiles, aligning with a homogeneous hash-based cryptography stack. The discussion included details on Sphinx variants, with a focus on optimizing signing costs and reducing verification time, and highlighted recent improvements by RiverLabs in signing speed on Ledger devices. The team acknowledged ongoing work on formally verifying signatures and account abstractions for the upcoming Egotra release.

Nicola presented Freedom Factory’s PQ1 hardware wallet project, which uses Sphinx Minus post-quantum cryptography instead of ECDSA. The device uses an STM32U585 chip with TrustZone technology and two secure elements (Optiga MTrust and NXP SE 050) to achieve signature times of 1.1 seconds on silicon and 3 seconds on cold start. The team is working on open-sourcing their code and developing a first-stage bootloader that would allow users to verify the authenticity of the firmware before locking it into production mode.

Nicola presented progress on a secure device project, reporting that signature operations take approximately 1.5 seconds on silicon and about 3 seconds on cold boot, with a signature budget of 65,000 per slot. The team is targeting Q4 for device availability and is currently auditing their verification contract with Trail of Bits while exploring formal verification approaches using tools like Lean and EasyCrypt. The group discussed plans to demonstrate the device at DEF CON in Mumbai, with potential participation in a post-quantum cryptography showcase.

The meeting focused on technical discussions about cryptographic implementations and optimizations. Nicola demonstrated progress on hardware devices, expecting complete devices with the final hardware revision by September 15th, including plans for fault injection testing. Oren presented significant optimization work on MLDSA for EVM, reducing gas costs from 8 million to 1.2 million for verification and 4 million for key registration, though noting this research code hasn’t been fully audited yet. The team discussed whether key generation is needed at every signing step, with T confirming that caching Merkle intermediate nodes is possible and efficient.

Next Steps:

  • Oren: Publish the optimized MLDSA EVM contract code at the specified address today or tomorrow.
  • Oren: Look into and report the token budget spent on Fable for the auto-research optimization.
  • Nicola: Continue the formal verification efforts for the PQ1 hardware wallet using Lean and EasyCrypt, and keep the community updated on progress.
  • Nicola: Bring demo devices of the PQ1 hardware wallet to DEF CON Mumbai for showcasing and potential fault injection testing.
  • Antonio: Share the numbers for key generation (KidGen) time for Sphinx with Simon in a future communication.

Recording Access:

YouTube recording available: https://youtu.be/qXdFNUNqt4Y