Qanary
Menu

Your treasury,safe past
Q-Day.

Qanary treasury accounts answer to a post-quantum key: ML-DSA or Falcon signatures, verified by Arbitrum Stylus programs now live on ApeChain. A capped classical key handles daily spending, and a tripwire shuts classical keys down as weaker curves are broken.

Proof, unworn
Plate XII. The canary, Serinus canaria, on Sir Humphry Davy’s safety lamp.

No rung broken. The hot key spends within its full cap. Anything above the cap needs the post-quantum key.

Default responses. Each account chooses its own.

Plate XIII

The public keys are already on-chain.

An Ethereum account reveals its public key in its first signed transaction.1 A quantum computer that can break secp256k1 could work back from that key to the private key, and spend what the account holds.

More than 65% of ether sits in accounts whose public keys are exposed.2

About 6.9 million bitcoin is held at exposed addresses.3

The dates are set.

  1. 2026
    • June 2026United States. Executive Order 14412 sets post-quantum signatures by 2031.4
    • July 2026Singapore, CSA. The Quantum-Safe Handbook names ML-DSA and sets the dates below.5
    • July 2026Singapore, MAS. Calls for “quantum resilience before the end of this decade.”6
    • October 2026 Today.
  2. 2027
    • 31 March 2027Singapore, CSA. Migration plans due.5
  3. 2028
    • 1 January 2028Singapore, CSA. New systems quantum-safe from this date.5
  4. 2029
  5. 2030
  6. 2031
    • 2031United States. Post-quantum signatures, under EO 14412.4
  7. 2032
  8. 2033
  9. 2034
  10. 2035
    • After 2035NIST IR 8547, draft. ECDSA disallowed.7

Plate XIV

Two keys and a tripwire.

A Qanary treasury splits authority by risk. The keys a quantum computer could break get a small, leaking allowance and a fuse. The key that holds everything else is post-quantum from the start.

Fig. 1
Fig. 2
Fig. 3
Plate XIV. The cold key, the hot key’s leaking cap, and the tripwire.

Explanation of the plate

Fig. 1. The cold key. The account’s root key is post-quantum: ML-DSA-44 or ML-DSA-65 (FIPS 204), or Falcon-512. It can be derived in your browser from a recovery phrase, or live in an AWS KMS HSM. Only the cold key moves funds above the cap, changes modules, rotates keys or signs ERC-1271 messages.

Fig. 2. The hot key, under a leaking cap. A classical key, an ECDSA wallet or a passkey, spends through an executor with an allowlist: transfers of tracked assets, no approvals, no module changes. Its cap is a leaky bucket per asset that refills continuously, so nothing can be spent twice at a window boundary. The hot key never validates user operations and cannot sign ERC-1271 messages.

Fig. 3. The tripwire. An ownerless, one-way registry offers bounties on five curves whose private keys nobody knows: each public key is a public tag hashed to a curve point. secp160r1, P-192 and P-224 form the ladder, because a quantum computer breaks short curves before 256-bit ones. secp256k1 and P-256 stand for the key families in use.

When a rung is claimed, every account responds on its own. By default the hot cap halves at the first rung, drops to a tenth at the second, and the hot tier freezes at the third. A broken secp256k1 or P-256 disables that key family for good. Each account can choose a different response.

A claim is an ECDSA signature by the target key over the chain, the registry, the target and the claimant. It is bound to the claimant, so it cannot be front-run, and the bounty is paid to the claimant.

What the tripwire cannot do. A thief with a quantum computer may steal quietly instead of claiming. Cold funds rely on the post-quantum key, not on the tripwire.

Leaving an exposed wallet takes one batch: create the post-quantum account, revoke approvals, move the assets. EIP-7702 can carry the batch, but under 7702 the old key stays live, so the funds have to move.

Plate XV

The verifiers, live on ApeChain.

Post-quantum signatures are large, and checking them is heavy work. Written in Solidity, every published verifier runs past what an ERC-4337 account may spend on validation. As Arbitrum Stylus programs, all three fit inside it, and all three are live on ApeChain, an Arbitrum Orbit chain that settles to Arbitrum One.

Stylus, cached execution gasStylus, live per call on ApeChainBest published Solidity verifierERC-4337 validation budget, 500,000 gas
Falcon-512666 B signature, 897 B key
Falcon-512, Stylus, cached execution: 36,000 gas36k
Falcon-512, live on ApeChain, per call with calldata: 97,541 gas97,541
Falcon-512, Solidity: 641,000 gas (ZKNox, experimental)641k
Solidity: ZKNox, experimental
~18×less execution gas
ML-DSA-442,420 B signature, 1,312 B key
ML-DSA-44, Stylus, cached execution: 110,000 gas110k
ML-DSA-44, live on ApeChain, per call with calldata: 207,646 gas207,646
ML-DSA-44, Solidity: 1,190,000 gas (ZKNox, experimental)1.19M
Solidity: ZKNox, experimental; the tick marks 1,230,000 (Fireblocks, Sep 2026)
~11×less execution gas
ML-DSA-653,309 B signature, 1,952 B key
ML-DSA-65, Stylus, cached execution: 166,000 gas166k
ML-DSA-65, live on ApeChain, per call with calldata: 289,315 gas289,315
ML-DSA-65, Solidity: 1,550,000 gas (ZKNox, experimental)1.55M
Solidity: ZKNox, experimental
~9×less execution gas
Solid bars and ratios: execution gas for a cached program, measured on an Arbitrum Nitro node (ArbOS 61); Solidity figures as published by their authors.9 Against main-branch Solidity, ML-DSA-65 on Stylus uses 40 to 108 times less gas. Outlined bars: gas per verification call live on ApeChain, calldata included and uncached, since ApeChain has no cache manager.
Show the figures as a table
SchemeStylus, cached executionStylus, live per call on ApeChainSoliditySourceSignature, bytesPublic key, bytes
Falcon-51236,00097,541641,000ZKNox, experimental666897
ML-DSA-44110,000207,6461,190,000ZKNox, experimental2,4201,312
1,230,000Fireblocks, Sep 2026
ML-DSA-65166,000289,3151,550,000ZKNox, experimental3,3091,952
Register of deployments
ContractApeChainApeChain CurtisArbitrum One
ML-DSA-44 verifierStylus, 15.6 KB, 207,646 gas per call0x38Fc…23e1deploymentactivation0x38Fc…23e1deploymentactivationactivations paused
ML-DSA-65 verifierStylus, 15.5 KB, 289,315 gas per call0x1875…C197deploymentactivationdeployingactivations paused
Falcon-512 verifierStylus, 16.8 KB, 97,541 gas per call0x0517…cbA3deploymentactivationdeployingactivations paused
Tripwire ladder verifierStylus, 16.2 KB, 0.83 to 1.15M gas per check0x7DEA…DC4Fdeploymentactivationdeployingactivations paused
Key storeSolidity0x12cF…54f6deploymentdeploying0x12cF…54f6deployment
Quantum validatorSolidity0x0057…036adeploymentdeploying0x0057…036adeployment
Hot-tier executorSolidity0xE5A6…31f3deploymentdeploying0xE5A6…31f3deployment
Safe owner factorySolidity0x4Ce0…ABA3deploymentdeploying0x4Ce0…ABA3deployment
Account factorySolidity0xdbEE…2609deploymentdeploying0xdbEE…2609deployment
Tripwire registrySolidity0x4848…8A95deploymentdeploying0x4848…8A95deployment
Drill registry factorySolidity0xA523…8032deploymentdeploying0xA523…8032deployment
Ladder stand-in (fails closed)Solidity, where Stylus activations are pausednot used on this networknot used on this network0xBf33…b9D6deployment
Keccak-f[1600] helperSolidity, where Stylus activations are pausednot used on this networknot used on this network0x68b5…FF8Ddeployment
ML-DSA-44 verifier core (Solidity)Solidity, where Stylus activations are pausednot used on this networknot used on this network0xf2d5…588Edeployment
ML-DSA-44 expanded-key storeSolidity, where Stylus activations are pausednot used on this networknot used on this network0x49fd…f8f5deployment
ML-DSA-44 verifier (Solidity)Solidity, where Stylus activations are pausednot used on this networknot used on this network0xc9C7…2EfEdeployment

The live run, transaction by transaction

ApeChain

  1. Root key stored in the key store0x3e14…86e8
  2. Treasury funded for its first operation0x38a4…eb0a
  3. Treasury deployed by its first post-quantum operation0x8191…5801
  4. Transfer signed with the post-quantum key0xc60a…4f2e
  5. Hot tier installed0xb732…0a9c
  6. Hot-key transfer inside the cap0x16b8…68f3
  7. Hot-key transfer over the capRefused, as intended. Over the hot-key cap. This transfer needs 0.002000000000000001, and 0.001 is available right now. CapExceeded0x95f5…5db4
  8. Operation with a tampered signatureRefused, as intended. EntryPoint refused the operation: the post-quantum signature did not verify (AA24). FailedOp0x28bf…51db
  9. Drill registry created0x448b…222a
  10. Hot tier pointed at the drill registry0xf0d4…7bfe
  11. Drill: ladder rung L1 claimed0x5eb5…8b83
  12. Drill: secp256k1 claimed0x417d…13bd
  13. Hot-key transfer after the tripRefused, as intended. secp256k1 keys are disabled for good, because the tripwire proved the curve broken. ClassicalFamilyBroken0x4540…d3ad
  14. Recovery-phrase key stored0x5c78…209d
  15. Recovery-phrase treasury funded0xe305…db3d
  16. Recovery-phrase treasury deployed0xa9e7…903b
  17. Falcon-512 key stored0xa819…1685
  18. Falcon-512 treasury funded0xb0b8…da52
  19. Falcon-512 treasury deployed0xbfc7…1fba

Arbitrum One

  1. Root key stored in the key store0xc523…f5b8
  2. Root key prepared for the Solidity verifier0x0fb1…20bd
  3. Treasury funded for its first operation0x1e4c…4ece
  4. Treasury deployed by its first post-quantum operation0x0b98…6d0c
  5. Transfer signed with the post-quantum key0xa1f7…d821
  6. Hot tier installed0xb6c8…fc60
  7. Hot-key transfer inside the cap0x8e90…0a82
  8. Hot-key transfer over the capRefused, as intended. Over the hot-key cap. This transfer needs 0.000002000000000001, and 0.000001000555555555 is available right now. CapExceeded0xe2b4…d1dd
  9. Operation with a tampered signatureRefused, as intended. EntryPoint refused the operation: the post-quantum signature did not verify (AA24). FailedOp0x601c…a41b
  10. Drill registry created0xbc2f…01fd
  11. Hot tier pointed at the drill registry0x082f…9cd6
  12. Drill: ladder claim where no ladder verifier runsRefused, as intended. No ladder verifier runs on this network, so ladder claims fail closed; secp256k1 and P-256 claims still work. LadderUnavailable0x7d45…f7c4
  13. Drill: secp256k1 claimed0x08f2…5ceb
  14. Hot-key transfer after the tripRefused, as intended. secp256k1 keys are disabled for good, because the tripwire proved the curve broken. ClassicalFamilyBroken0xab82…0bd6

Plate XVI

Works with what you already run.

The verifiers are ERC-7913 contracts that any account can call. Qanary plugs into the smart-account stacks treasuries already use, and keeps keys where institutions already keep them.

  • Arbitrum StylusWASM verifiersRuns the three verifiers, each under 18 KB compressed.
  • ApeChainArbitrum Orbit chainHosts the live Stylus verifiers and settles to Arbitrum One.
  • ZeroDev Kernelv3.3Qanary installs as an ERC-7579 validator and executor.
  • Safe1.3 and 1.4.1Post-quantum ERC-1271 owners, such as a 9-of-12 council of post-quantum keys.
  • OpenZeppelinAccounts, ERC-7913Uses the verifiers directly as ERC-7913 signers.
  • AWS KMSML-DSA-44Keeps the cold key in an HSM and signs with ML_DSA_SHAKE_256.
  • Paxos USDGStablecoinBounties and caps can be denominated in USDG.