HOW IT WORKS
Post-quantum signatures, explained simply
Every Quantus transfer is authorised by a digital signature. Qkeep makes those signatures with ML-DSA, a scheme designed to stay secure even against large quantum computers.
Why signatures matter
Most blockchains sign transactions with elliptic-curve schemes such as ECDSA or Ed25519. A large enough quantum computer could forge those signatures from a public key. Quantus accepts only post-quantum ML-DSA signatures for transfers, so a forged elliptic-curve signature cannot move your funds.
ML-DSA in Qkeep
- ML-DSA is standardised by NIST as FIPS 204.
- Quantus uses two ML-DSA parameter sets: ML-DSA-65, which Qkeep uses for new accounts, and ML-DSA-87, a higher security level that earlier Quantus wallets used. Qkeep supports both.
- Keys are derived from your seed and signing happens inside the wallet on your device. The relay only receives signed transactions.
What it does not cover
Post-quantum signatures protect the authorisation of your transfers. They do not make everything around them post-quantum:
- Website connections use standard TLS, as on the rest of the web.
- Transfers are public on the blockchain. Private sends hide which deposits you spend, but the recipient and the amount are still visible.
- Your seed backup and your device remain the most important things to protect.
Questions
Is my wallet quantum-proof?
No wallet can promise that. Qkeep signs with a post-quantum scheme that Quantus requires, which removes the main quantum risk to your transfers. Other parts of the internet still use classical cryptography.
Do I need to do anything to use ML-DSA?
No. Every Qkeep account signs with ML-DSA automatically.