Your treasury,safe past
Q-Day.
Qanary treasury accounts answer to a post-quantum key: ML-DSA or Falcon signatures, verified by Arbitrum Stylus programs now live on ApeChain. A capped classical key handles daily spending, and a tripwire shuts classical keys down as weaker curves are broken.
No rung broken. The hot key spends within its full cap. Anything above the cap needs the post-quantum key.
Default responses. Each account chooses its own.
Plate XIII
The public keys are already on-chain.
An Ethereum account reveals its public key in its first signed transaction.1 A quantum computer that can break secp256k1 could work back from that key to the private key, and spend what the account holds.
More than 65% of ether sits in accounts whose public keys are exposed.2
About 6.9 million bitcoin is held at exposed addresses.3
Plate XIV
Two keys and a tripwire.
A Qanary treasury splits authority by risk. The keys a quantum computer could break get a small, leaking allowance and a fuse. The key that holds everything else is post-quantum from the start.
Explanation of the plate
Fig. 1. The cold key. The account’s root key is post-quantum: ML-DSA-44 or ML-DSA-65 (FIPS 204), or Falcon-512. It can be derived in your browser from a recovery phrase, or live in an AWS KMS HSM. Only the cold key moves funds above the cap, changes modules, rotates keys or signs ERC-1271 messages.
Fig. 2. The hot key, under a leaking cap. A classical key, an ECDSA wallet or a passkey, spends through an executor with an allowlist: transfers of tracked assets, no approvals, no module changes. Its cap is a leaky bucket per asset that refills continuously, so nothing can be spent twice at a window boundary. The hot key never validates user operations and cannot sign ERC-1271 messages.
Fig. 3. The tripwire. An ownerless, one-way registry offers bounties on five curves whose private keys nobody knows: each public key is a public tag hashed to a curve point. secp160r1, P-192 and P-224 form the ladder, because a quantum computer breaks short curves before 256-bit ones. secp256k1 and P-256 stand for the key families in use.
When a rung is claimed, every account responds on its own. By default the hot cap halves at the first rung, drops to a tenth at the second, and the hot tier freezes at the third. A broken secp256k1 or P-256 disables that key family for good. Each account can choose a different response.
A claim is an ECDSA signature by the target key over the chain, the registry, the target and the claimant. It is bound to the claimant, so it cannot be front-run, and the bounty is paid to the claimant.
What the tripwire cannot do. A thief with a quantum computer may steal quietly instead of claiming. Cold funds rely on the post-quantum key, not on the tripwire.
Leaving an exposed wallet takes one batch: create the post-quantum account, revoke approvals, move the assets. EIP-7702 can carry the batch, but under 7702 the old key stays live, so the funds have to move.
Plate XV
The verifiers, live on ApeChain.
Post-quantum signatures are large, and checking them is heavy work. Written in Solidity, every published verifier runs past what an ERC-4337 account may spend on validation. As Arbitrum Stylus programs, all three fit inside it, and all three are live on ApeChain, an Arbitrum Orbit chain that settles to Arbitrum One.
Show the figures as a table
| Scheme | Stylus, cached execution | Stylus, live per call on ApeChain | Solidity | Source | Signature, bytes | Public key, bytes |
|---|---|---|---|---|---|---|
| Falcon-512 | 36,000 | 97,541 | 641,000 | ZKNox, experimental | 666 | 897 |
| ML-DSA-44 | 110,000 | 207,646 | 1,190,000 | ZKNox, experimental | 2,420 | 1,312 |
| 1,230,000 | Fireblocks, Sep 2026 | |||||
| ML-DSA-65 | 166,000 | 289,315 | 1,550,000 | ZKNox, experimental | 3,309 | 1,952 |
| Contract | ApeChain | ApeChain Curtis | Arbitrum One |
|---|---|---|---|
| ML-DSA-44 verifierStylus, 15.6 KB, 207,646 gas per call | 0x38Fc…23e1deploymentactivation | 0x38Fc…23e1deploymentactivation | activations paused |
| ML-DSA-65 verifierStylus, 15.5 KB, 289,315 gas per call | 0x1875…C197deploymentactivation | deploying | activations paused |
| Falcon-512 verifierStylus, 16.8 KB, 97,541 gas per call | 0x0517…cbA3deploymentactivation | deploying | activations paused |
| Tripwire ladder verifierStylus, 16.2 KB, 0.83 to 1.15M gas per check | 0x7DEA…DC4Fdeploymentactivation | deploying | activations paused |
| Key storeSolidity | 0x12cF…54f6deployment | deploying | 0x12cF…54f6deployment |
| Quantum validatorSolidity | 0x0057…036adeployment | deploying | 0x0057…036adeployment |
| Hot-tier executorSolidity | 0xE5A6…31f3deployment | deploying | 0xE5A6…31f3deployment |
| Safe owner factorySolidity | 0x4Ce0…ABA3deployment | deploying | 0x4Ce0…ABA3deployment |
| Account factorySolidity | 0xdbEE…2609deployment | deploying | 0xdbEE…2609deployment |
| Tripwire registrySolidity | 0x4848…8A95deployment | deploying | 0x4848…8A95deployment |
| Drill registry factorySolidity | 0xA523…8032deployment | deploying | 0xA523…8032deployment |
| Ladder stand-in (fails closed)Solidity, where Stylus activations are paused | not used on this network | not used on this network | 0xBf33…b9D6deployment |
| Keccak-f[1600] helperSolidity, where Stylus activations are paused | not used on this network | not used on this network | 0x68b5…FF8Ddeployment |
| ML-DSA-44 verifier core (Solidity)Solidity, where Stylus activations are paused | not used on this network | not used on this network | 0xf2d5…588Edeployment |
| ML-DSA-44 expanded-key storeSolidity, where Stylus activations are paused | not used on this network | not used on this network | 0x49fd…f8f5deployment |
| ML-DSA-44 verifier (Solidity)Solidity, where Stylus activations are paused | not used on this network | not used on this network | 0xc9C7…2EfEdeployment |
The live run, transaction by transaction
ApeChain
- Treasury with an AWS KMS root key0x32D0…A958dashboard
- Treasury from a recovery phrase0x399C…2B6cdashboard
- Falcon-512 treasury0xcF36…0AC4dashboard
- Root key stored in the key store0x3e14…86e8
- Treasury funded for its first operation0x38a4…eb0a
- Treasury deployed by its first post-quantum operation0x8191…5801
- Transfer signed with the post-quantum key0xc60a…4f2e
- Hot tier installed0xb732…0a9c
- Hot-key transfer inside the cap0x16b8…68f3
- Hot-key transfer over the capRefused, as intended. Over the hot-key cap. This transfer needs 0.002000000000000001, and 0.001 is available right now. CapExceeded0x95f5…5db4
- Operation with a tampered signatureRefused, as intended. EntryPoint refused the operation: the post-quantum signature did not verify (AA24). FailedOp0x28bf…51db
- Drill registry created0x448b…222a
- Hot tier pointed at the drill registry0xf0d4…7bfe
- Drill: ladder rung L1 claimed0x5eb5…8b83
- Drill: secp256k1 claimed0x417d…13bd
- Hot-key transfer after the tripRefused, as intended. secp256k1 keys are disabled for good, because the tripwire proved the curve broken. ClassicalFamilyBroken0x4540…d3ad
- Recovery-phrase key stored0x5c78…209d
- Recovery-phrase treasury funded0xe305…db3d
- Recovery-phrase treasury deployed0xa9e7…903b
- Falcon-512 key stored0xa819…1685
- Falcon-512 treasury funded0xb0b8…da52
- Falcon-512 treasury deployed0xbfc7…1fba
Arbitrum One
- Treasury with an AWS KMS root key0xA3d2…EbEedashboard
- Root key stored in the key store0xc523…f5b8
- Root key prepared for the Solidity verifier0x0fb1…20bd
- Treasury funded for its first operation0x1e4c…4ece
- Treasury deployed by its first post-quantum operation0x0b98…6d0c
- Transfer signed with the post-quantum key0xa1f7…d821
- Hot tier installed0xb6c8…fc60
- Hot-key transfer inside the cap0x8e90…0a82
- Hot-key transfer over the capRefused, as intended. Over the hot-key cap. This transfer needs 0.000002000000000001, and 0.000001000555555555 is available right now. CapExceeded0xe2b4…d1dd
- Operation with a tampered signatureRefused, as intended. EntryPoint refused the operation: the post-quantum signature did not verify (AA24). FailedOp0x601c…a41b
- Drill registry created0xbc2f…01fd
- Hot tier pointed at the drill registry0x082f…9cd6
- Drill: ladder claim where no ladder verifier runsRefused, as intended. No ladder verifier runs on this network, so ladder claims fail closed; secp256k1 and P-256 claims still work. LadderUnavailable0x7d45…f7c4
- Drill: secp256k1 claimed0x08f2…5ceb
- Hot-key transfer after the tripRefused, as intended. secp256k1 keys are disabled for good, because the tripwire proved the curve broken. ClassicalFamilyBroken0xab82…0bd6
Plate XVI
Works with what you already run.
The verifiers are ERC-7913 contracts that any account can call. Qanary plugs into the smart-account stacks treasuries already use, and keeps keys where institutions already keep them.
- Arbitrum StylusWASM verifiersRuns the three verifiers, each under 18 KB compressed.
- ApeChainArbitrum Orbit chainHosts the live Stylus verifiers and settles to Arbitrum One.
- ZeroDev Kernelv3.3Qanary installs as an ERC-7579 validator and executor.
- Safe1.3 and 1.4.1Post-quantum ERC-1271 owners, such as a 9-of-12 council of post-quantum keys.
- OpenZeppelinAccounts, ERC-7913Uses the verifiers directly as ERC-7913 signers.
- AWS KMSML-DSA-44Keeps the cold key in an HSM and signs with ML_DSA_SHAKE_256.
- Paxos USDGStablecoinBounties and caps can be denominated in USDG.