Post Quantum Compute by Stefano&Fabrizio (NeverLocal) || Ethereum Privacy Stack, Devconnect 2025
Ethereum Cypherpunk Congress·Mon, Feb 9, 2026, 12:00 AM
... Ethereum Privacy Stack is a global privacy summit during Devconnect 2025 bringing together Ethereum builders, protocol maintainers, and advocates. Featuring Vitalik Buterin, Roger Dingledine, Andy Guzman, Polymutex, Ameen Soleimani, and 30+ speakers on 2 stages, celebrating privacy acceleration. Ethereum Privacy Stack: http://eps25.web3privacy.info Organized by Web3Privacy Now & Privacy Stewards of Ethereum Web3Privacy now collective: http://web3privacy.info Privacy Stewards of Ethereum: https://pse.dev/
Transcript
Just check that this works. Nope. Well, it doesn't go back. Fantastic. Hey, this is good enough.
All right. Uh good morning everybody and welcome to this uh privacy summit. Act not react is kind of our approach to quantum defense and the opportunities of quantum in crypto today. We are never local. We are a small company focused on the intersection between quantum and crypto.
We are focused on both the defense side and the applications or attack side of quantum. We want to make sure that Ethereum and crypto more generally is prepared for what's coming, that we can defend against a quantum threat, but also that we can make the most out of what quantum technology can offer for crypto, the new opportunities. So, this is going to be a two-part lightning talk. So, really lightning lightning. The first part is going to be me talking about how we plan to defend Ethereum and what we need to do to make sure that the chain keeps operating.
And the second part is going to be Fabitzio who is going to talk about applications of quantum to get new cryptography. Here is really the key message. Um quantum is coming. It's not uh up for debate. It is a fact.
Quantum is a new technology of course but there are clear road maps from large manufacturers. There is a lot of investment on these road maps and you just need to check the publications peer-reviewed publications that all of these companies put out. They are on track and the road maps say that around the mid 2030s their capabilities will be such that elliptic curve cryptography is going to be broken. Now that's the expectation, but there is a nonzero possibility that elliptic cur cryptography could be threatened by the late 2020s, so 2028, 2029. It's not the most likely scenario, but it is possible with a fairly good probability.
And so we need to start preparing for this. We need to start preparing now. This is ongoing work at the uh in the Ethereum ecosystem. Uh most of the work though is focused on changing the core cryptography layer. So introducing postquantum signatures in a way that maintains sufficient performance.
Uh that requires significant time and significant coordination for a change. Definitely a fork and consensus from uh all the validators. This is okay if Qday happens after, but what if it comes slightly earlier? What if it catches us unprepared? What if we're caught by surprise?
We need to have some mechanism that allows for an emergency fallback, a graceful emergency fall back. A way where the chain can keep operating if quantum technology advances quicker than we expect today. Uh, this is something that has gone wrong. Can we fix this? Hello.
All right. Well, I will just continue talking. Um, yes, thank you. The luckily we already have a postquantum uh piece of postquantum cryptography a quantum resistance step in the derivation of our private keys. Uh this is the BIP32 uh hierarchical key derivation mechanism.
Part of the derivation is a quantum resistant hash. And so technically we already have information that can be used to demonstrate ownership of an address in a quantum resistant way. And this can be done today. It can be done with current zero knowledge uh technology. Zigg Starks are themselves quantum resistant.
And so we can um safeguard at least part of the authentication process in Ethereum and in other chains by just lifting the signatures from the current quantum weak ones to the quantum resistant ones with a proof of derivation from a seed phrase. And here is where Ethereum is uniquely uniquely positioned to resist a quantum threat resist an unexpected Qday. We have account obstruction. Ethereum is the most sophisticated of the smart chains. We have a lot of delegation already implemented and supported and we can deploy Stark powered smart accounts even today um using delegation and permits to allow the chain to recover and keep operating in a quantum emergency.
So it's a matter of getting things done. It's a matter of acting now and we can safeguard users even users who don't migrate in time from an unexpected quantum emergency. So this is the defense side. Great, we've done it. Uh imagine it's 2030.
Uh quantum computers didn't come or maybe they did come but we fixed it. Ethereum is safe. Quantum is here. Quantum technology is readily available. What can we do now?
What are the positive uses of quantum technology in crypto? Fabitio to you.
Thank you. Hello everyone. So I'm Fab. Okay. So yes, the year is 2030.
We saved Ethereum. We are all happy. What can we do? Well, I like to make this analogy that uh quantum really is like a big scary dog. It can tear you to pieces but it can also be a very nice puppy very valuable and you know brings a lot of of good things in our lives.
So how do we harness the puppy side of quantum? What can we do assuming that we have quantum to improve the overall situation? So the main point about quantum is that quantum does not behave like data. It behaves like a resource. What it means is the following.
If I tell you something like I'm doing now you know with this talk you can take this information and tell it to everyone you know you can copy this information arbitrarily. If you are you know mvered uh in a logical system this means that you have weakening. So you can use the same information again and again and again. On the other hand, if I give you an apple, you cannot really copy an apple. You can give it to someone else.
Maybe you can split it, but you cannot make a copy of it. And cubits and other quantum resources behave exactly like apples, not like data. So this thing allows us to basically do a lot of incredible cryptographic stuff that is provably impossible to achieve classically. Uh one of you know these applications are uh is for instance uh device independent security which basically means cryptographic protocols that stay secure even if the hardware they run on is compromised. uh shout out to Stefano and Nicola that are heavily working uh on this on this particular field which uses a lot of complicated math called contextuality.
Another very important application is that quantum can make protocols one shot. You probably heard about oneshot signatures. This is a topic that we started investigating uh a couple years ago together also with Justin Drake. And the idea is that we're talking about signatures that can be used only once. You can delegate someone to sign whatever message they want, but they can do it only once.
And this is probably impossible to do classically because once you give your signing key to someone, they can use it as much as they want. Uh similarly we can make multi-party computation one shot and shout out to Lev a colleague of us that is working very heavily exactly on this kind of of thing. Uh another very interesting solution is that we can basically realize one-time memories and one-time programs which as the name says are memories and programs that can be used only once. Um and you do not need tees to do this stuff with quantum. If you assume the NISK regime, we're not going deep into that.
You can basically do it uh out of the box and again this means in particular that we can do quantum money which is the holy grail of crypto. Basically quantum money is so simple which is sometimes difficult to grasp. You have to imagine something that behaves exactly like cash. There is no consensus protocol. It's peer-to-peer.
Uh it's private is inherently decentralized. It works exactly like cache. Um and again this is possible because you know the since quantum behaves like a resource. The idea is that if we have a way to knit value into quantum resources then we can only exchange them without cloning them without being able to copy them. So this quantum money is basically completely unclonable by default.
And again the funny thing is that all these things are guaranteed by physics. They are not guaranteed by computational assumptions. If you believe that our current description of the physical world is more or less correct, then that's it. Okay, super cool. But how far away?
Well, this is the interesting thing. Uh unironically, quantum cryptography is the lowest hanging fruit in quantum. We do not need any uh you know exponential speed up argument. We don't need a lot of cubits like we do for sure and you know all these other quantum algorithms. So this is unironically the first thing that we can get and it can be done with near-term quantum tech basically and in indeed we are already working on it.
This is a picture from our lab where you know we have all these weird single photon emitter uh and single photo detector equipment exactly to experiment with these things. So the only the take-h home message for this talk is that I would like to give you a more hopeful version of what quantum is. I really don't like doomerism and I think that quantum can do a lot for us. So embrace a most hope op hope hopeful version of what quantum is. That's it.
Uh we are around all day and afterwards. So if you want to know more about quantum money, quantum postquantum cryptography etc. hit us up. Thank you.
Automatic transcript — names and jargon may be misspelled.