PQ Transaction Signatures #013
Transcript
- Gottfried Herold
Regarding the 5 x 6 = 30 potential signature variantions. Is there a way to modularize this into 5 + 6 variations (still a lot, of course)?
- T. Wambsgans
XMSS!
- Stefano De Angelis
Arc consensus should be fine — not large validator set no?
- Mahdi Sedaghat
Can you share more details on your batching technique? Is this batching done during the authentication phase? If so, how does it impact transaction latency? Any concrete numbers you can share?
- LatticeLover
how do we verify ecdsa signatures without ecrecover precompile?
- Antonio Sanso
I think she is explaining it now
- Tiago Merlini
We are using 8373 that we created for pq anchored key binding if that helps we got it running
- Gottfried Herold
I think having a dedicated contract for the pk storage is actually a good idea, since one could make this into VOPS state.
- Stefano De Angelis
Reacted to "I think having a dedicated contract for the pk storage is actually a good idea, since one could make this into VOPS state." with 👍
- Mira Belenkiy
Mira.Belenkiy@circle.com
- Tiago Merlini
Great happy to share what we have on the primitive
- Tiago Merlini
Reacted to "Mira.Belenkiy@circle.com" with ❤️
- Gottfried Herold
Probably want to use the version number to identify the sig scheme...
- LatticeLover
next thursday = tomorrow?
- LatticeLover
Will support lattices at ACD then :-D
Call summary
Targets
- •ARC (Circle L1) mainnet launch — mid-September 2026 - 00:06:12
- •PQTS recap presentation at ACDE — next Thursday (approx. August 28, 2026) - 00:27:33
Decisions
- •Community sentiment across 13 PQTS calls has moved away from lattice-based schemes and precompiles toward hash-based (stateless) transaction signatures; no formal protocol decision yet — governance remains with ACDE - 00:27:59
Highlights
- Organizational:
- ·Antonio to present 13-call PQTS recap at next Thursday's ACDE; will note community leaning toward hash-based over lattice/precompile approach - 00:27:33
- Ec Recover Hotfix Proposal:
- ·Proposal: repurpose EC Recover's V byte as a version number; use R/S (64 bytes) as pointers to PQ pubkey/signature in a registry contract - 00:10:52
- ·Maintains existing ABI; deployed contracts accepting ECDSA could transition to PQ without code changes - 00:12:44
- ·Frame transactions could carry the PQ signature inline, replacing need to pre-register signatures in a table - 00:21:01
- Circle Pq Transition Concerns:
- ·Circle's primary concern: ecosystem fragmentation across 30 blockchains leading to incompatible PQ signature schemes - 00:05:47
- ·Hot wallets sign 30K–70K tx/day; stateful schemes (e.g. XMSS) require key rotation and are operationally unacceptable - 00:08:23
- ·SLH-DSA preferred (stateless); 200K gas cost is concern but can be mitigated via ERC-3009 batching - 00:09:52
- ·Circle deployed SLH-DSA (SHA-2) precompile on ARC testnet; deferring parameter choices pending Ethereum alignment - 00:15:01
Action Items
- •Mira Belenkiy (Circle Research) - Mira to draft EIP formalizing EC Recover hotfix / PQ registry approach, incorporating frame transactions - 00:23:21
- •Antonio Sanso - Present PQTS 13-call summary at ACDE; flag shift away from lattice/precompile toward hash-based signatures - 00:27:33
Key decisions
Community sentiment across 13 PQTS calls has moved away from lattice-based schemes and precompiles toward hash-based (stateless) transaction signatures; no formal protocol decision yet — governance remains with ACDE
The community is shifting preference toward hash-based (stateless) signatures like SLH-DSA over lattice-based approaches or precompiles.

