Skip to content
Qrypt

Research

Notes from the lab.

Short explanations of the ideas behind Qrypt’s assessments. Longer articles will be published here as the research programme develops.
  1. Note 001Cryptographic exposure

    What a recoverable public key does and does not mean

    An EVM address is a hash of a public key. The key itself stays hidden until the account signs something: every transaction signature allows the public key to be recovered. From then on, the key is public for good.

    Today that has no practical consequence. It matters only for the long-term threat model, where a large fault-tolerant quantum computer could derive a private key from a public one. Accounts that have never signed keep one extra layer — the hash — though an address can be reused across chains, so absence of a signature on one network proves little.

    Analyze a wallet

  2. Note 002Methodology

    Why quantum readiness is a status, not a score

    A number implies a ranking, and a ranking implies we can say one ordinary token is more quantum-ready than another. We cannot. Nearly every token delegates authorisation to the accounts that hold it and the chain that orders its transfers.

    A status describes what was observed: conventional cryptography, a detected post-quantum or hybrid mechanism, or insufficient evidence. It leaves the uncertainty where it belongs.

    Read the definitions

  3. Note 003Post-quantum transition

    The cost of larger signatures

    An ECDSA signature is 64 bytes. ML-DSA-44 is 2,420; the smallest SLH-DSA parameter set is 7,856. For a blockchain, signature bytes are paid for by every node, forever.

    That is why migration is an engineering programme rather than a parameter change: it touches transaction formats, fee markets, aggregation and state growth. The standards are finished. The integration work is what remains.

    Compare algorithms