After talking with Tamaghna about splitting the work on trustless logs and transactions indexing — and realizing I wouldn't have much to do until the implementation reaches a certain point — I returned to something I was covering back in week 1 that also got new light recently: the Post-Quantum stealth address protocol, now also my project proposal[1].
The problem to cover, briefly, is not really the spending part but securing the key-exchange protocol with an efficient and future-proof solution. The paper I'm referencing[2] relies on Learning With Errors and its Module-LWE variant — it results in larger keys, but noise separation is considered pq-hard, so it's a good candidate.
Because I already had a reference implementation, I decided to start by trying to reproduce a PoC of the ML-KEM[3] key exchange and spending using Kohaku's pq-account[4]. The coding agent quickly flagged that pq-account is Dilithium level 2 while we assumed level 3 by default — quickly figuring out that the spending part should be a stretch goal.
There's a general trick with zk-proofs and 4337[5]: generate a zk proof of a valid signature recovery, proving possession of the private key. With the traditional key exchange described in 5564[6], the next step after finding the note that belongs to you is deriving the private key that controls that stealth address.
The initial gas-sponsoring issue from the 5564 ERC can be solved quite nicely with account abstraction today and deserves a description, but it sounded like a slightly different problem. I basically came to the realization that it's better to divide the problem into:
- a pq-safe Diffie-Hellman-like key exchange and its alternatives (indexing faster than O(n) is deliberately not covered), plus measuring gas costs;
- pq-safe spending (less of a priority), as it would be covered on the protocol level according to pq.ethereum.org[7].
With the help of a coding agent I quickly ran an anvil Sepolia fork to run the whole flow, not really sure it was going to work "first prompt". Then, after :railgun:, got the PoC validated[8] on a live net with a deployed precompile.
Announcement #0 came in at 67,580 gas[9]. The ephemeralPubKey is noticeably bigger compared with existing announcements — 1088 bytes of ML-KEM ciphertext against a 33-byte compressed secp256k1 point in a classic 5564 one:
announce(uint256 schemeId, address stealthAddress,
bytes ephemeralPubKey, bytes metadata)
ML-KEM (schemeId 0x5567) secp256k1 (schemeId 0x1)
[4]: ...0440 // 1088 bytes [4]: ...0021 // 33 bytes
[5]: beef31c81ab8fd3c361dd6ab... [5]: 021e7a0e1b19d1dfbc578c...
+ 33 more words of ciphertext
Then on CT I saw something about Lean 4 and it clicked that I might also get formal verification for the algebraic part of the key exchange. I sent it to Claude, it did it, and now I need to spend a ton of time figuring out whether it's right. VCVio[10] was a huge help.
As next steps, I'm going to take a deeper dive into the existing conversations on speeding up the O(n) indexing and try to see if there's something we can improve. And I'd probably better get basic infrastructure running for 4337-sponsored spending with a custom verifier that checks an address-derivation proof instead of the full signature — before frame transactions[11] would land.
The problem there is the proving backend: if we go with Groth16/Plonk we for real get a significant improvement, but neither is itself pq-secure. Other options like STARKs are — however, much more expensive.
Sources
- [1]github.com/eth-protocol-fellows/cohort-seven/pull/269/changesMy EPF project proposal — Post-Quantum Stealth Address Protocol (cohort-seven #269).
- [2]arxiv.org/html/2501.13733v1Paper: Post-Quantum Stealth Address Protocols (arXiv) — the reference construction built on Module-LWE.
- [3]csrc.nist.gov/pubs/fips/203/finalFIPS 203 — the ML-KEM (Kyber) standard used for the key-exchange PoC.
- [4]github.com/ethereum/kohakuKohaku — the EF's privacy-first wallet tooling, including the @kohaku-eth/pq-account 4337 account with PQ signature verifiers.
- [5]eips.ethereum.org/EIPS/eip-4337ERC-4337: account abstraction via the alt mempool.
- [6]eips.ethereum.org/EIPS/eip-5564ERC-5564: stealth addresses — the announcement/key-exchange flow being made pq-safe.
- [7]pq.ethereum.orgpq.ethereum.org — Ethereum's post-quantum roadmap, which covers signatures/spending at the protocol level.
- [8]sepolia.etherscan.io/address/0xb9443280e49d728301384fdbd07eea8628d1b135The PoC announcer contract validated on Sepolia.
- [9]sepolia.etherscan.io/tx/0x26303f71ec916801787110e95f79b28b41a540fac535f68e4d6d47518203fc1cAnnouncement #0 on Sepolia — the ML-KEM announcement transaction, 67,580 gas.
- [10]github.com/dtumad/VCVioVCVio — a Lean 4 framework for formal verification of cryptographic protocols.
- [11]eips.ethereum.org/EIPS/eip-8141EIP-8141: Frame Transactions.