FREEDOM/FACTORY FREEDOM/FACTORY

Why We Are Building a Post-Quantum Hardware Wallet

In this post, we will explain why we are building a post-quantum hardware wallet, and why we believe this matters for anyone who owns digital assets.

There are many moving parts behind a blockchain, but we will focus mainly on elliptic-curve cryptography and ECDSA, which stands for Elliptic Curve Digital Signature Algorithm. The name may sound complicated, but ECDSA is simply one of the main systems that wallets use to prove that a transaction was approved by the owner of an account.

Blockchain 101

Blockchains such as Ethereum and Bitcoin use digital signatures to confirm that a transaction is valid. In simple terms, a digital signature is how your wallet proves to the blockchain that you control a particular address and that you have approved the movement of funds from it.

To understand how this works, we first need to look at your seed phrase. Most people know that a seed phrase is the list of 12 or 24 words shown when a wallet is created, but it is less obvious how those words allow you to send and receive crypto.

For Ethereum wallets, your seed phrase is converted into a large wallet seed. This seed is extremely powerful, because it can be used to create many different accounts and addresses. A useful comparison is your Apple ID or Google account: you can use one of them to access many different services without creating and remembering a completely separate login for each one. In a similar way, one wallet seed can be used to generate many blockchain accounts, each with its own address and private key.

From the wallet seed, your wallet derives a private key. A private key is essentially a very large secret number that gives you control over an account. The wallet then uses a mathematical process called elliptic-curve multiplication to create a matching public key, which is later processed further to produce your Ethereum address.

The chain of derivation looks like this:

seed phrase → wallet seed → private key → public key → address

How does your wallet send crypto?

When you want to send crypto to another address, your wallet uses the private key to create a digital signature. It combines the transaction information - such as how much you want to send, which address should receive it, and the transaction fees - with your private key, and passes all of it through ECDSA. The result is a signature that proves the transaction was approved by the account owner.

When the transaction is sent to the blockchain, the network can check the signature and confirm which account authorised it. The blockchain does not need to see your private key, and your private key does not need to leave your wallet. This works because, with conventional computers, discovering a private key from a public key is considered practically impossible.

A simple comparison would be mixing paint:

It is easy to mix blue and yellow paint to make green. But if someone only gives you the finished green paint, it is much harder to work out the exact amount and exact shade of blue and yellow that were originally used.

This system has worked very well for many years. But it may no longer remain secure once sufficiently powerful quantum computers are built.

The Quantum Problem

Let us expand upon the paint example. The security of public keys relies on a difficult mathematical problem known as the discrete logarithm problem. A simplified version can be written like this:

g^x mod p = y

The question is: if you know the values of g, p and y, can you calculate x?

For example, imagine the following equation:

2^x mod 11 = 9

Because the numbers are small, you could naively start counting from zero and work your way up until you reach the solution - in this case, x = 6. Finding the answer is relatively easy here, especially with a calculator. But real cryptographic systems use numbers and mathematical structures that are vastly larger and more complicated.

With normal computers, calculating the result from the starting value is easy, while working backwards is extremely difficult. As the numbers become larger, the amount of work required increases so dramatically that even the most powerful conventional computers would need billions of years to find the answer.

Quantum computers are built differently from normal computers, and can run certain algorithms that conventional machines cannot run efficiently. One of these is Shor’s algorithm, which could be used to solve exactly the type of mathematical problem that protects ECDSA private keys.

A sufficiently powerful and reliable quantum computer running Shor’s algorithm could potentially calculate a private key from its public key. For a blockchain account whose public key has been revealed through a transaction, this could allow an attacker to recover the private key, create valid signatures, and take control of the account.

What Does This Mean for Blockchains?

No quantum computer capable of doing this exists today. Current quantum computers are still far too limited and unreliable to break the cryptography used by Ethereum, Bitcoin, or modern hardware wallets. However, companies, universities and governments continue to invest heavily in quantum computing, and progress is being made in areas such as hardware design and quantum error correction. Even Vitalik Buterin, the creator of Ethereum, has given 20% odds that ECDSA could be cracked by 2030.

We believe major blockchains will introduce ways to become resistant to quantum attacks, but this will likely involve migrating off the digital-signature systems used today. And even once those upgrades ship, it does not automatically mean that existing accounts will be safe. Traditional Ethereum accounts are tied to ECDSA private keys, so users may need to complete a manual upgrade or migration process.

You can think of this like a bank introducing a new, more secure type of account. The bank may make the new account available, but it cannot necessarily move everyone’s money automatically. Each customer may still need to switch to the new account and transfer their funds into it.

The safest time to complete such a migration is before a powerful quantum computer exists. Once the threat becomes real, users and institutions may be forced to move assets quickly, while attackers attempt to target the accounts that have not yet been upgraded.

Why We Are Building PQ1

This is why we decided to build PQ1.

PQ1 is designed to approve transactions using post-quantum signatures rather than ECDSA. This means it does not rely on the same elliptic-curve security assumption that a sufficiently powerful quantum computer could eventually break.

Instead of waiting for an emergency migration, users can move their assets into an account that is already protected using post-quantum cryptography. Once the assets are held there, future transactions can be approved without creating ECDSA signatures or exposing an ECDSA public key.

PQ1 is not based on the claim that quantum computers will break blockchains tomorrow. It is based on the idea that protecting trillions of dollars in digital assets should not depend on waiting until the threat becomes urgent.

The blockchain industry may eventually need to replace one of its most important security foundations. We believe it is better to begin preparing for that transition now, rather than attempting to solve it at the last possible moment.

Related reading

Built for what comes next

PQ1™ is the first hardware wallet that protects Ethereum and EVM holdings against quantum computers. Hash-based post-quantum signing (SPHINCS+, per the NIST FIPS-205 design) in an open-firmware, air-gapped device. $179.

Reserve PQ1™