Paper 2026/1660

Transient Quantum Resistance, with Application to Ethereum Consensus

Pranay Anchuri, Offchain Labs
Matteo Campanelli, Offchain Labs, University of Tartu
Rosario Gennaro, Offchain Labs, City University of New York, The Graduate Center, CUNY
Abstract

Candidates for post-quantum migration carry additional costs compared to their pre-quantum counterparts, especially for signatures, and they lose attractive properties of schemes such as BLS: homomorphism, and hence direct signature aggregation. We propose a methodology through which a pre-quantum primitive may still be securely used past Q-day (the advent of quantum computers) in settings where forgery of signatures or cryptographic proofs need only be prevented for a bounded lifespan (transient quantum security). The idea is to bind a fresh, ephemeral, ordinary pre-quantum key to a long-term post-quantum identity once per lifespan window, so a forgery under the fresh key is useful only for that window, and to derive the fresh key so that its exposure never leaks the long-term secret. Our main case study is the post-quantum migration of Ethereum consensus, where we give a solution that keeps relying on BLS and (i) retains signature aggregation, central at Ethereum's scale, without a SNARK prover, so the consensus-critical aggregate stays a single ~96-byte BLS signature, about three orders of magnitude smaller than the hundreds of kilobytes a SNARK-aggregated hash-based alternative needs per aggregate, as in the current proposal for post-quantum Ethereum consensus; and (ii) needs only an additional ~590-690 bytes per epoch of per-validator reveal traffic. Security holds as long as a standard pairing-based variant of the computational Diffie-Hellman problem (co-CDH') cannot be broken by a quantum computer within the 6.4-minute duration of an Ethereum epoch; we discuss the hardware and time budgets such a break would require today, and how they may shrink as quantum hardware improves. We also provide a formal model and security analysis for the construction, and, of independent interest, a new analysis of BLS where the secret key is sampled similarly to the Dodis-Yampolskiy VRF (IACR PKC 2005) and the adversary is given a related group element as leakage.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-quantum cryptographyBLSaggregatable signaturesEthereum consensus
Contact author(s)
panchuri @ offchainlabs com
binarywhalesinternaryseas @ gmail com
rosario @ ccny cuny edu
History
2026-08-15: approved
2026-08-11: received
See all versions
Short URL
https://ia.cr/2026/1660
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1660,
      author = {Pranay Anchuri and Matteo Campanelli and Rosario Gennaro},
      title = {Transient Quantum Resistance, with Application to Ethereum Consensus},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1660},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1660}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.