QP2 Protocol MODULAR VERIFIERS

Your address
survives
every algorithm.

The threat keeps moving. AI math is searching curves now, and the lattices meant to replace them. Quantum hardware is the later pass at the same curve. QP2 does not marry the account to any of them. The address is a contract. The verifier is a module. One transaction swaps it.

⚠ Structured account
  • ECDSA key is the address
  • Lattice swap is the same kind of object
  • AI searches both. Funds sit on the key
Keys cracked · funds drained
VS
◆ Modular account
  • Address is a contract, not a key
  • Verifier swaps in one transaction
  • Hash, lattice, or whatever is next
Same address · any algorithm · funds stay
What AI math can search Oct 7, 2026
Curves Exposed

ECDSA · pairings

Structure is public the first time you send. AI can search it now. Shor searches the same object later.

Lattices The new risk

ML-DSA · Falcon · FHE

The planned replacement. Same problem: usable structure. Not where a long-term account should sit.

Hashes No trapdoor

SHA-256 · SLH-DSA · WOTS · SPHINCS

Nothing algebraic to pull on. One module you can select. Not the account itself.

Vitalik Buterin vitalik.eth Minimize exposure to quantum-vulnerable cryptography, and to AI-vulnerable cryptography.
Curves Published structure 4M+ Ethereum keys already on-chain
Lattices AI-exposed class ML-DSA · Falcon · FHE
Plugin Verifier, not the address Swap the scheme. Keep the account.
1 tx To change algorithm Address stays. Funds stay.

Three kinds of object.
Only hashes have nowhere to search.

The split is not “quantum versus classical.” It is structured versus not. AI-accelerated math is aimed at structure. Curves have it. Lattices have it. Hashes are built to have none. A quantum computer, when it exists, is a second pass at the curve.

Structured · already published

Curves

ECDSA · pairings

The account most of Ethereum sits on. The public key is on-chain after the first send, and it stays in charge of the funds. AI can search that structure without a quantum computer. Shor, later, searches the same object.

Retire the key. Do not reuse it.
Structured · the planned swap

Lattices

ML-DSA · Falcon · FHE

What “post-quantum” was about to mean. Vitalik’s October 7, 2026 point: this is the core new risk. The next two years of AI math can seriously damage concrete lattice security. If a lattice is still used, the key has to be far larger — his inference was about 10×.

Not the default. Optional, and paranoid.
No exploitable structure

Hashes

SHA-256 · Keccak · SLH-DSA · WOTS · SPHINCS

Lean Ethereum’s signature direction for the past year: no lattices, no ML-DSA, no Falcon, no lattice commitments in proofs. Grover is the known speedup, and it is not a practical break. If hashes ever worry you, add rounds before adding bytes.

A module you can select. Not the account.

I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.

The core new area of risk is ML-DSA / FHE / lattices. Hash-based beats lattice-based wherever a hash can do the job. Fresh addresses if the move is easy. Botched migrations have cost him more than hacks.

Now AI math

Search over structure. No qubits. Curves and lattices both qualify. This is the threat the account has to be built for.

Next two years Lattice sizes

Today’s ML-DSA-class parameters are the ones he expects to take the hit. Hash constructions do not share that structure.

Later · ~2030 Quantum hardware

Shor still breaks a live ECDSA key, in hours, once the machine exists. Second threat. It does not start the clock.

QP2 is not named in that post. The constraint is. The address is a contract, so a new threat model is a verifier swap, not a migration. Each transaction is signed by a fresh key that is retired in the same block. The registry can hold a hash vault, SLH-DSA, a larger lattice, or a scheme that does not exist yet. You choose the module. The address does not change.

Factoring already had
this kind of surprise.

Naive factoring is a 2n/2 search. Decades of human math turned it into the number-field sieve, 2O(n1/3), which is why RSA keys are hundreds of bytes and not 64. The question AI forces is whether curves and lattices are hiding a jump like that. Signatures and proofs already have a hash-only exit. Public-key encryption does not — that is a theorem — so anything with a trapdoor should be sized as if the jump arrives. About 10×, if you still want it long-term.

What gets searched

Factoring, naive 2^(n/2)
After the sieve 2^O(n^(1/3))
 
Curves have structure
Lattices have structure
Hashes are built not to
 
Longer ECDSA keys do not help.
A lattice at today’s size may not either.
4M+
Exposed Ethereum public keys Any address that has ever sent a transaction has its public key permanently on-chain. No deletion. No expiry. Forever harvestable.
$200B+
ETH held in exposed addresses Estimated value sitting on keys that are already public. The harvest is the published structure, whether the break is found by AI math or, later, by hardware.
0
Address-preserving paths live today Changing algorithms still means a new account, a fund migration, or a hard fork. Separating the address from the key is the missing piece.

Every current approach has
a critical flaw.

The industry spent the last decade planning a swap from ECDSA to lattices. That swap is now the risk. None of the current approaches let you follow a hash-only path on existing EVM chains without abandoning the address or moving the funds.

Solution
Why It Falls Short
EVM Native
Address Preserved
Ethereum EIP-8141Hegotá hard fork · H2 2026+
Requires a protocol-level hard fork. Estimated 2029 for core PQ infrastructure, full ecosystem migration well beyond that. Does not help users on Base, Arbitrum, Polygon, or any other EVM chain. Changing algorithm still requires creating a new address on legacy AA paths.
ETH Only
No
QRL 2.0 / ZondNew L1 blockchain
Entirely new chain. Users must migrate all assets, abandon existing Ethereum addresses, lose DeFi positions, ENS names, and years of on-chain history. Requires leaving the EVM ecosystem. Not a solution for existing Ethereum users.
New Chain
No
ML-DSA / FALCON on-chainPure PQ verifier in Solidity
ML-DSA and Falcon were the default "quantum-safe" replacements. They are also the schemes Vitalik named on Oct 7, 2026 as the core new risk from AI math, alongside FHE and other lattices. Gas (~800K in pure Solidity) is the smaller problem. Parking everyone's keys on a structured lattice is the larger one.
Yes
Yes, but…
Anchor Wallet (Pauli Group)Lamport signatures · Ethereum
Lamport is hash-based, which is the direction lean Ethereum is taking. Each signature is 10–50KB, so it only works as cold storage. No modular verifier, no way to move to SLH-DSA or a tighter hash scheme without a new account.
Yes
Storage only
Standard ERC-4337 WalletsSafe, Biconomy, Alchemy
Key rotation is possible but not designed around fresh keys. The underlying authentication is still a reused ECDSA key. Changing the signer still publishes the old public key in the rotation transaction, and leaves it relevant. No hash-based verifier path.
Yes
Reused key

On-chain verification cost per transaction — Base L2. Cost is not the ranking that matters if the cheap lattice is the AI-exposed one.

QP2 OTA Verifier
~33K gas · $0.0000003
Normal ECDSA (baseline)
~21K gas · baseline
FALCON-512 · lattice
~400K gas · $0.000004
ML-DSA-44 · lattice
~800K gas · $0.000007
Lamport (Anchor Wallet)
~1.2M+ gas · $0.00001+

One architectural inversion
changes everything.

Traditional EVM: address = f(ECDSA_pubkey) — your identity is your key. Break the curve, or the lattice you migrated to, and the identity breaks with it.

QP2: address = contract_address — permanent. The key is a swappable slot. Break the structure in the slot and the address still holds the funds.

01
Generate a one-time address

Your wallet derives addr_n from your master seed: keccak256(masterSeed || n || chainId || proxyAddr). This address has never signed anything. Its public key is hidden behind a hash until the moment it is used — the fresh-address property, without moving funds to a new account.

02
Deploy your permanent proxy

The QP2Factory deploys your proxy via CREATE2. The proxy address is deterministic — the same on Ethereum, Base, Arbitrum, Polygon, and every future EVM chain. Your address is permanent and chain-agnostic from day one.

03
Sign once, rotate forever

Each transaction is signed by the current addr_n and simultaneously registers addr_n+1 as the next authority. After signing, addr_n is retired permanently. A search of that curve key finds a key that controls nothing.

04
Upgrade algorithm anytime

The proxy stores an IQP2Verifier module. Call switchVerifier() when the threat moves — curves, lattices, hashes, or whatever is written next. Same proxy. Zero fund movement. No algorithm is the account.

05
High-value vault mode

For critical accounts, enable SHA256VaultVerifier: a two-transaction commit-reveal. Phase 1 commits sha256(txn_data + key + nonce) without revealing it. Phase 2 reveals and executes. That commitment is a hash. Recovering the signing key is not enough. The attacker still needs a preimage that was not published.

OTA Key Rotation — Per Transaction

masterSeed (stored in secure enclave)
│
├─ derive addr_0 ← current auth
├─ derive addr_1 ← next auth
└─ derive addr_2 ← future
TXN 1: execute(target, data, addr_1, sig_0)
│
├─ ecrecover(sig_0) == addr_0 ✓
├─ execute call to target
└─ store addr_1 as new auth
addr_0 pubkey now exposed (~2 sec)
Break of addr_0, however fast: too late
addr_0 already retired. Controls nothing.
TXN 2: execute(target, data, addr_2, sig_1)
└─ addr_1 now retired, addr_2 active
Proxy address: 0xABCD... NEVER CHANGES
keccak(factory, salt, initcode)
same on all EVM chains

The algorithm is a plugin.
Your address is the product.

QP2 treats cryptographic algorithms as swappable modules. The proxy stores a verifier address — one switchVerifier() call changes it. The registry is the menu: one-time keys, a hash vault, SLH-DSA, a lattice at much larger parameters, and schemes that are not written yet. Your address does not move either way.

AI-exposed · optional
ML-DSA-44
NIST FIPS 204 · Module lattice

Still a NIST standard. Also the scheme Vitalik named, with FHE and other lattices, as the core new risk from AI math. Not the recommended path. If a deployment uses it, parameters should be far more conservative than today's 128-bit sets — his inference was about 10× key size for anything you still want long-term. QP2 can register those larger sets without a new address.

Pubkey size1,312 bytes
Sig size2,420 bytes
StructureMLWE lattice
Lean EthereumNot used
AI-exposed · optional
FALCON-512
NTRU lattice · not on the lean roadmap

Smallest NIST lattice signatures (666 bytes), which is why it looked attractive. It is also explicitly off Ethereum's lean roadmap, for the same reason as ML-DSA: NTRU is structured. Kept as an optional plugin, not a default. Smaller signatures are not a reason to prefer it over SLH-DSA.

Pubkey size897 bytes
Sig size666 bytes
StructureNTRU lattice
Lean EthereumExcluded
Governed by $QP2
Future Algos
NIST Round 2 · Unknown 2030+

NIST will keep publishing schemes, including ones with new structure. QP2 token holders vote on which verifiers enter the registry. A hash module is one choice when structure looks risky. A larger lattice is another. Switching is one transaction. The account address never changes.

Governance$QP2 token vote
Audit requiredYes, mandatory
Migration1 transaction
Address changeNever
QP2VerifierRegistry.sol — on-chain verifier registry Governed by $QP2
algoId 10 → 0x1a2b... OTAVerifier // ACTIVE · FRESH KEY
algoId 11 → 0x3c4d... SHA256VaultVerifier // ACTIVE · HASH
algoId 5 → 0x9c0d... SLHDSAVerifier // NEXT · HASH-ONLY
algoId 2 → 0x7a8b... MLDSAVerifier44 // OPTIONAL · AI-EXPOSED
algoId 1 → 0x5e6f... FALCONVerifier // OPTIONAL · NOT ON LEAN ROADMAP
algoId ? → 0x???? [Next hash-based] // TOKEN VOTE WHEN READY

Why the math
actually works.

// Fresh key

Retirement, not a race with hardware

A reused ECDSA key is published once and then guards the funds for years. That is the object AI math, and later Shor, would search. QP2 signs with addr_n and retires it in the same transaction. The public key is visible for about one block. A break of that key — however fast — finds something that no longer controls the account.

// Hash layer

The second layer has no structure

The SHA-256 vault does not depend on a curve or a lattice. Using it means an attacker needs the retired signing key and the committed preimage. Grover’s algorithm takes a 256-bit hash down to about 2128 operations, which is still not a practical search. There is no reason yet to pad hash output. If that worry grows, add rounds first.

// Attack Math

Formal Attack Analysis

Structured key

Curves: ECDSA, pairings
Lattices: ML-DSA, Falcon, FHE
// AI searches structure now
// Shor searches a live curve later
Reused key cracked → funds move
Retired key cracked → controls nothing

Hash

SHA-256 · Keccak · SLH-DSA
→ no algebraic trapdoor
Grover: ~2^128 ops
→ not a practical search
Pad rounds before output size
Assumption: the hash holds

Hashes, sized as they are: Keccak-256 and SHA-256 are only known to fall to Grover’s quadratic speedup. An object designed to have no exploitable structure is the assumption this protocol stands on. Curves and lattices are the objects AI has something to pull on. The account address, derived with Keccak via CREATE2, does not need a new primitive for that.

// Cross-Chain Replay

Replay Attack Prevention

Every QP2 digest includes address(proxy), block.chainid, and nonce. A signature valid on Base cannot be replayed on Ethereum. A signature valid in transaction 47 cannot be used for transaction 48. The domain separation is enforced at the cryptographic layer — it cannot be bypassed by a relayer or bundler.

// Protocol Sovereignty

Protocol Cannot Override User

The QP2 multisig controls the VerifierRegistry — it can add new verifiers and deprecate old ones. It cannot execute transactions on behalf of users, cannot migrate user accounts, cannot access user funds, and cannot change the active verifier without a valid proof from the user's current key. The registry is an upgrade menu, not a backdoor.

The time to prepare
is before the migration.

Don't scramble your funds into a new wallet. That is the advice in Vitalik's Oct 7, 2026 post, and it is the failure mode QP2 is built to avoid. The threat keeps moving — AI math on curves and lattices now, quantum hardware later, and something else after that. The verifier is a plugin, so the next shift is one transaction, not a new account.

~$0 Gas per transaction on Base today
1 txn to upgrade algorithm, same address
Plugin Any verifier, same address
0 Existing protocols you need to abandon
TARGET EVM CHAINS
BasechainId 8453
Ethereum MainnetchainId 1
Arbitrum OnechainId 42161
PolygonchainId 137
BNB ChainchainId 56
Any EVM Chainsame proxy address