What is post-quantum cryptography?
Why quantum computers threaten the signatures most coins use, what ML-DSA is, how Quantus handles its larger signatures, and what it means for mining.
The problem quantum computers create
Most cryptocurrencies sign transactions with elliptic-curve schemes such as ECDSA or Schnorr. Their security rests on a maths problem that ordinary computers cannot solve in any practical time, but a large enough quantum computer running Shor's algorithm could. Anyone with such a machine could work out a private key from its public key and spend the coins.
What ML-DSA is
ML-DSA is a digital signature scheme built on lattice problems, for which no efficient quantum attack is known. It was standardized through the NIST post-quantum cryptography program and grew out of the CRYSTALS-Dilithium design. Quantus signs every transaction with it: ML-DSA-65 by default, and ML-DSA-87 for users who want a higher security level.
The cost, and how Quantus handles it
Post-quantum signatures are much larger: an ML-DSA-65 signature is 3,309 bytes, where an elliptic-curve signature is about 64. Quantus uses zero-knowledge proofs and cryptographic aggregation to reduce the extra space this takes on-chain.
What about mining?
Proof of Work relies on a hash function rather than on signatures, and hash functions are far less exposed: the best known quantum speedup against them, Grover's algorithm, is only quadratic. Quantus mines on the Poseidon2 hash. For you as a miner nothing changes: you mine with your qz address like any other coin.