# Ian Smith - Quantum Risks of Hybrid Cryptography

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2026-07-09
- Duration: 19:41
- Watch: https://streameth.org/watch/yt-JpgYt_3viYQ
- YouTube: https://www.youtube.com/watch?v=JpgYt_3viYQ

## Description

Migrating to Post Quantum Cryptography carries layers of risks which are mitigated over time.

## Transcript

Uh this is not related to Ethereum in any way. Uh I'm letting lean Ethereum just handle that. Uh and I'm advising them, but you know, I talked to Justin Drake. I let him know my opinion. Um, I think that they should have proven cryptography instead of a brand new uh snark over Lattis. Um, that is just now being built. I'm doing the same thing for Bitcoin and other projects. Uh, I'm co-founder of Surmount Systems, which is doing BIP 360. Uh, I'm co-author of BIP 361, which is basically saying someday your private key is going to not be secure. The problem here is that when other people try to solve for quantum risk, they're typically doing some kind of hybrid cryptography because there's a data problem. And quantum just bit the bullet and said we're going to deal with the data problem instead of trying to deal with uh a new hybrid system that may not be done well. There is hybrid cryptography used right now in your Chrome browser. It's used on Cloudflare. It's used um in Signal. And the good way to do this is through one of the the hybrid standards like ML Chem or MLDDSA that has then uh also an elliptic curve attached. Uh the most common is ML Chem um what 25 uh they call it 768 but it also uses the ED25519 curve and they split the key in half. Half is encrypted half the AES key is encrypted using the elliptic curve and half of the AES key is encrypted using MLEM. you need both halves to to crack the system and classical attacks would still require uh a very very very long time against the AES. So this is generally regarded as secure. Um and that's what I would recommend doing if that's what you need to solve for. The problem is that this hybrid cryptography is very very new. There is not a good standard of the NIST has actually been taken over by the NSA. Everybody who works at the NIST has NSA on their resume and they're advising against hybrid cryptography. They're saying, "Oh, just go with the Lattis. You can trust it. It's so trustable. You should trust it with everything and don't use any other cryptography ever." And that makes a lot of people nervous. Um the lack of standardization means that everybody's doing crazy stuff and it's not being examined well before it's being implemented. There's implementation mistakes. Uh there's just cognitive dissonance regarding what should be done uh versus the way that it's actually being done. So the first one that makes very clear mistakes is Q&amp;X. Uh I have ranted at their CTO um who has only had one job in in tech and that is CTO of the same project that has not had a test net after seven years. This is his first blockchain project. um their smart contract has been audited repeatedly and had been broken into repeatedly. The biggest issue with QAnx is that their system has sepix k1 onchain and they use uh some xlink offchain. Xlink is a MLDDSA implementation which is good lattice cryptography as much as we can trust the NIST but they don't actually lock the oh I didn't I didn't put the I don't have the source code because they don't release the source code they they don't have uh the transaction they put the hash of the account inside the green light system the green light system is only for the account. So, it's just a a race between the quantum attacker and the legitimate user. Worse, they say that they are putting a 24-hour green light and so they're just leaving the car unlocked for 24 hours hoping that no one drives it off. Um, I've referred to this repeatedly on X and Twitter or X um, and Telegram saying you have two keys, one to unlock the door and one to unlock the engine. And the engine key will not be secure because it's, you know, only linked to the security of uh, a quantum attack. the the door key is Xlink and Xlink means that your your car is unlocked for 24 hours after you drive it to the store. It's unlocked the entire time and you cannot lock it. So, they need to put the actual transaction hash as the payload inside of Xlink and then and then I'd be fine with it. It would be totally fine if they did that. They refuse. I don't know what to say. It's not secure the way that they built it. Um, quantum coin is really odd. It's the original name was Doge protocol and it was the postquantum version of Doge. And what they did instead of using the Doge code is that they used Go Ethereum, a 10-year-old copy of Go Ethereum, which has had three major security incidents, all of which were handled by the Ethereum Foundation, but not publicized in a way that made the people using Go Ethereum actually perform the necessary upgrades. Uh, this is not good. Um, I went into their Discord and I talked with them. They're extremely rude. I suggested they needed to have an audit done because they can make tons of mistakes and they shut it down and, you know, muted me like that. Fine. But the problem is that they've never had any audit of their cryptography and they refuse to do one. Their source code is public. Here's their header uh for like the data storage. Um that is a link to their actual cryptography in their GitHub. And they're doing hybrid cryptography in an unodudited way. And they're doing hybrid cryptography in an unverified way. They're nesting the data backwards as far as I can tell. But without like a good checklist or a good audit trail or how do you do this properly, it's really hard to know and it's something that we should all be extremely nervous about. Um so this is some I list them as they implemented postconquy but it's unsafe. It's a It's a problem. Um, socoin claims to only have SEC Pix K1 involved in the bulletproofs, but the bulletproofs are the proof that you didn't like double spend and a couple other things. And so, it's a necessary security mechanism. So even though they're using postcon cryptography for the wallet, the proof of what the wallet's doing is insecure is it's technically a hybrid, but they didn't do it right. Um, and they're using sect ptx1 in their source code and their wallet refuses to build if you remove the sepx1 section. So this is actually a paste of their GitHub. Um the problem here is that they need to use maybe you know uh Shaw 256 in ZK Stark. They can probably do that but they can't use bulletproofs for that architecture. They need to switch to a much slower and much more expensive architecture instead of this super fast. We'll have sepk1 guarantee our postquantum chain. That's a problem that they are not, you know, properly addressing with the the way that they've implemented the cryptography and implemented the trust and consensus in their chain. I have over 90 chains that I've identified as usually lying, usually often making mistakes like this where they're relying on elliptic curves in some way. Starknet is one of those. Starknet says, "Well, yeah, we're post quantum. Super easy. They have account abstraction built into every single wallet." This is good. This allows for them to migrate off of their custom elliptic curve that they call Stark. They named four different kinds of cryptography stark on starknet by starkware. They use the stark curve which uses which you know then does transactions on stark net using zk starks. There's confusion when you name everything the same. It's like smurfs but the smurfs had different nouns and only one verb. to smurf something. In this case, there's only one noun and they use that noun for everything in their entire ecosystem. And uh one of the things that they use is Poseidon which is an Ethereum foundation um tool. This is the recent attack against uh Poseidon using uh number of theoretic transforms in the attack. The attack does not scale on silicon, but the quantum version of NT uh known as Qntt solves all of the memory issues that they have as a problem in the silicon version of the attack. Uh basically, they didn't notice much uh performance increase switching from CPU to GPU. it was like a 3x increase. Um, and the reason for that is just it's mostly memory bound. But when you do this in a quantum circuit, the cubits are very readr performant. It's the measurement at the end that's the problem, but you only measure the circuit once. So the Qntt solves all of the scalability problems of the memory issues in NT. The main distinction is that it this isn't as as cheap as shores, but it's not it's not postquantum, but it's not as uh easy to attack as it is to attack uh uh elliptic curves. So it'll come in between RSA 20048 and breaking uh hashes at 160 bits using grovers. Somewhere in between that you know like 3 to 5 year range you'll see attacks on Poseidon um become viable. The I haven't done Qntt as a quantum circuit. My quantum circuit skills are okay but not that good. uh it would take me I I think maybe like a week or two to figure out the quantum circuit for doing Qntt at the scale required. Um but it again this is going to shores is going to break elliptic curves first and then it'll break RSA and then it will break uh you'll be able to use Q&amp;T to break Poseidon. There is a second uh curve used for P uh co a field that is used for Poseidon one. Poseidon one may break faster than RSA 2048. Uh so Poseidon 2 is what they're standardizing on. Poseidon 2 will break later. This is just based off of cubit estimates. It's based off of, you know, how how large the circuit is approximately. It's basically, you know, AI/Napkin math. Um, I can do it both ways and I got the same, you know, around the same result both ways. It's not quantum safe. Uh, most hashes are. Uh, but Poseidon is not most hashes. It's al actually algebra. And that algebra now has an attack. Poseidon does not use NT. The attack does. So that's a a problem. Hideera lies just flat out. They claim to have hybrid cryptography. They claim they can become postquantum. They claim that they're postquantum. They claim all sorts of things. They lie just flat out. They're using this is a copy of their source code. This is a link to their source code. It's SEC P6K1 as you can clearly see. Um, and they're claiming to be the postquantum solution to Ethereum. I confronted them again. They lied. I showed them their claims because I, you know, kept a copy of all of their their marketing claims and their their CTO uh on stage and, you know, on YouTube and all these things. And yeah, he's claiming they're postquantum. He's lying and most people there don't know it. Dragon Chain uses psychics K1. Also, they claim to be hybrid. They're doing a hash. They're not revealing the public keys on chain, but they're lying about the hybrid status. They don't use any postconquer cryptography at all. They're just using a hash. Um, and it's one of those things that they will not admit to being a problem, but it's clearly a problem. So this is the last chain. Um, equilibrium used a uh NP complete problem that was theorized to be quantum safe. uh the problem was their implementation of the cryptography that had been considered quantum safe for the previous seven years. 7 years later, someone figured out that their implementation was insecure and was able to break it on a laptop. This is why we need standards. This is why you should not trust any cryptography for the first 10 years after it is created. This was a 7year later break and it was a surprise to everybody. And so their value immediately hit zero. Just it went from being a billions of dollars chain to literally zero. Immediately. And they admitted it. I mean, good good on them, you know. uh they trusted something that was claimed and regarded to be safe. Here's the actual quantum resistance um chains. KillVPN and quantum EVM are both based off of Cellframe. Cellframe is crypto agile. It has uh 19 plus different pieces of cryptography already to just swap in. It's a wallet transaction. You don't even need to upgrade the wallet. you just transact from one cryptography type to another and you're done. Um we use MLDDSA uh by default. Um at my urging uh NTRU Prime is included which is the basis for uh Falcon. Falcon is also using the NTRU prime lattice, but they screwed up and did photo floating point over it, which is a bad idea. The Gaussian sampler is a a bad thing. The reason that's bad is that the floating point allows you to attack the emulator and drain the private key by monitoring USB voltage draw. So your hardware based security is is just gone if if you use Falcon. Uh QRL doesn't upgrade their their system even when you send them CVEEs. I sent them like 30 CVEEs and they refused to upgrade. These are known known weaknesses, known exploits, and they're just refused to handle it. Archimo is a is a little little minor chain. um they're using hashbased cryptography um a version of XMSS that they they kind of like homegrrew uh and everything that they did non-standard I consider an absolute win. Um I reviewed their cryptography uh for hours and hours and talked with the lead developer for hours and hours about this afterwards. Um, I think it's solid. Uh, it's just using hashbased crypto. So, they have no intention of going to smart contracts. Uh, the dev says he'll go to dumb contracts one day, you know, which is basically just having different transaction types like NFTts. And that's about it.
