PQTS2026-09-02_014

PQ Transaction Signatures #014

2026-09-02 2 decisions 408 transcript lines

Transcript

Call summary

Targets
  • PQ1 hardware wallet consumer release — Q4 2026 - 00:31:44
  • PQ1 near-final hardware devices ready — ~September 15, 2026 - 00:37:11
  • Optimized MLDSA-44 EVM contract published — September 2–3, 2026 - 00:41:31
Decisions
  • No cryptographic precompiles (MLDSA, Falcon, etc.) to be shipped; EVM optimization results validate this direction - 00:10:49
  • Native account abstraction (frame transactions replacing EOA) is SFI for Hegota - 00:09:44
Highlights
  • Mldsa Evm Optimization:
    • ·Fireblocks (Oren): MLDSA-44 EVM verification reduced from ~8M gas to 1.2M gas (6× improvement); FIPS-compliant, open source, research quality - 00:39:18
    • ·Key registration (one-time expanded key stored on-chain, ~20KB) costs ~4M gas; full cold verification ~9M gas unoptimized - 00:39:56
    • ·Main savings: eliminating quadratic memory expansion (~2M gas saved), 256-bit batched lane operations, Yul/assembly rewrites; ~10% further reduction possible - 00:43:14
    • ·At current gas prices, 1.2M gas verification costs ~$0.22; contract to be published same day or next - 00:46:10
    • ·Result supports community position against MLDSA precompile for Hegota; pure EVM sufficient at this gas cost - 00:47:22
  • Pq1 Hardware Wallet Demo:
    • ·Freedom Factory PQ1 wallet: STM32U585 (Cortex-M33) + NXPSE050 secure element; XOR key split via TrustZone; SLH-DSA Minus C10 - 00:21:49
    • ·On-chip signing: ~1.1s; cold boot (with key derivation): ~3s; SHA-256 hardware accelerator on STM32 aids performance - 00:24:43
    • ·First EVT hardware received; all code open source (WIP); STM32U585 eval board ~$100 total to run today - 00:25:36
    • ·Targeting Q4 2026 consumer device availability; uses account abstraction (modified base smart account), not native ECDSA replacement - 00:31:44
    • ·Verification contract in Trail of Bits audit; exploring Lean/eCrypt formal verification via Rust-to-Lean toolchain - 00:32:24
  • Slh Dsa Parameter Overview:
    • ·SLH-DSA chosen as PQ replacement for ECDSA; no cryptographic precompiles will be shipped; aligns with hash-based consensus/DA layer direction - 00:09:23
    • ·Moving away from Poseidon toward Blake/SHA via new 'Flock' system on Banner Fields; specific hash function TBD - 00:12:11
    • ·NIST April 2026 SLH-DSA variant cuts signature from ~8KB to ~4KB but requires 1.45B hashes to sign — impractical for hardware wallets - 00:14:34
    • ·SLH-DSA Minus C12 targets 2^14 signature budget (covers 99.99% of mainnet addresses); signing cost 37K hashes vs. 1.45B; still 47.5s on Ledger Nano S - 00:16:14
    • ·Riva Labs achieved 1.5s signing on Ledger Nano S Plus (2^24 budget) via offline precomputation of public values + grinding; paper forthcoming - 00:18:03
Action Items
  • Oren (Fireblocks) - Publish optimized MLDSA-44 EVM verification contract to announced repository - 00:41:31
  • Nicola Ceornea (Freedom Factory) - Share Lean/eCrypt formal verification progress for SLH-DSA firmware with community - 00:34:33

Key decisions

  • No cryptographic precompiles (MLDSA, Falcon, etc.) to be shipped; EVM optimization results validate this direction

    EVM optimization results validate that pure EVM implementations are sufficient, making precompiles unnecessary.
  • Native account abstraction (frame transactions replacing EOA) is SFI for Hegota

    IncludedFrame transactions replacing EOA are selected for inclusion in the Hegota upgrade.

AI Disclaimer: Some content or metadata on EIPsInsight may be AI-inferred or automatically compiled. If you find any discrepancy, please contact us at dev@avarch.org.