Skip to main content

Post-Quantum Addresses

POSITRONIC introduces addresses whose spending key is an ML-DSA-44 signature key (FIPS 204), the NIST post-quantum standard. They are strict PQ AuthScript outputs, witness version 2, and coexist with classical addresses: the same wallet can hold both, and a transaction can mix legacy, post-quantum and asset inputs.

Address families​

FamilyOutput scriptMainnetTestnet and regtestUsed for
LegacyP2PKHN…t…Classical single-key addresses
Strict PQ, witness v2OP_2 <32-byte commitment>pq1z…tpq1z…ML-DSA-44 wallet addresses
Strict ECDSA, witness v3OP_3 <32-byte commitment>nq1r…tnq1r…secp256k1 witness addresses
Generic AuthScript, witness v1OP_1 <32-byte commitment>nc1p…tnc1p…Contracts and covenants. Wallets never hand them out

Generic witness v1 used to be encoded as nq1p… / tnq1p…. That encoding is now rejected, with no alias and no migration: only the address string changed, not the commitment or consensus. External integrations and old testnet address books must use nc1p… / tnc1p….

Address derivation​

BIP39mnemonic→ 64-byte seedPQ masterHMAC-SHA512 key"Neurai PQ seed"PQ-HDhardened path,HMAC onlym_pq/100'/…ML-DSA-44KeyGen_internal(ξ)from the child seed0x05 ‖ 1312 BcommitmentTaggedHash of02 ‖ 01 ‖ hash160‖ SHA256(OP_TRUE)Bech32mwitness v2 addresspq1z… / tpq1z…
StepDetail
SeedStandard BIP39 mnemonic and 64-byte seed
PQ master keyHMAC-SHA512(key = "Neurai PQ seed", seed): a 32-byte seed and a chain code. The key "Neurai PQ seed" keeps the PQ tree apart from the classical BIP32 tree ("Bitcoin seed") of the same mnemonic
HD pathm_pq/100'/1900'/0'/chain'/i' on mainnet, m_pq/100'/1'/0'/chain'/i' on testnet and regtest. Chain 1 is change. Every level is hardened and uses HMAC-SHA512 only, with no secp256k1 step (NIP-022)
Key generationML-DSA.KeyGen_internal(ξ) from FIPS 204, where ξ is the 32-byte seed of the child
Public keySerialized as 0x05 followed by the 1312-byte ML-DSA-44 public key
CommitmentTaggedHash("NeuraiAuthScript", 0x02 ‖ 0x01 ‖ hash160(public key) ‖ SHA256(OP_TRUE)). The lead byte is the witness version and 0x01 the PQ auth type
AddressBech32m, witness version 2, over the 32-byte commitment. Human-readable part pq on mainnet and tpq on testnet and regtest

Because derivation is deterministic from the mnemonic, a post-quantum account has the same backup story as a classical one. PQ private keys are not WIF-compatible, so they cannot be swept into a legacy wallet. ML-DSA-44 has no public derivation, so there is no xpub in the classical sense.

Strict ECDSA keys come from their own classical branch, m/84'/1900'/0'/chain/i on mainnet and m/84'/1'/0'/chain/i on testnet and regtest, so legacy, PQ and ECDSA accounts recover independently from the same seed.

Spending​

A strict PQ output is spent with exactly four witness items:

0x01 <ML-DSA-44 signature> <0x05 ‖ public key> OP_TRUE

The auth type must be 0x01 and the witness script must be exactly OP_TRUE. The node recomputes the commitment with lead byte 0x02, checks it against the output and verifies the signature. OP_TRUE is never evaluated: the template is the whole spending condition. Strict ECDSA works the same way with auth type 0x02, a compressed secp256k1 key and lead byte 0x03.

For script logic on top of a post-quantum key, use generic AuthScript v1 with auth type 0x01. See Covenants and opcodes.

SizeBytes
ML-DSA-44 public key1312, plus the 0x05 header
ML-DSA-44 signatureabout 2420
Maximum PQ script element3072

Node and wallet support​

  • Consensus: ML-DSA-44 verification in the strict PQ template and in generic AuthScript, with larger script elements and stack limits when the covenant flags are active (NIP-018).
  • Policy: mempool and relay accept the larger witness items, and signing RPCs verify with the same flags as consensus (NIP-020, NIP-021).
  • Wallet and RPC: PQ keys in the keystore, address decoders, native PQ-HD derivation and signing RPCs (NIP-019, NIP-022).
  • Address type: chosen with -addresstype=legacy|pq|ecdsa when the wallet file is created, and stored in it. pq and ecdsa need -bip44=1.
  • Mixed transactions: legacy, PQ and asset inputs can be combined in one transaction. Mempool policy never replaces a transaction that involves assets (NIP-025).
  • Script: OP_CHECKSIGFROMSTACK and OP_CHECKSIGADD accept ML-DSA-44 keys, so oracles and threshold scripts can be post-quantum as well. OP_OUTPUTAUTHDEST lets a covenant require payment to a given strict destination (NIP-041).
-addresstypeHands out by defaultAlso on request
legacyLegacy (Base58)Strict ECDSA
pqStrict PQStrict ECDSA
ecdsaStrict ECDSANone

Activation​

The strict families and NIP-041 destination introspection activate at block 10 of the reset testnet and at block 0 on regtest. Mainnet is not scheduled. Before activation a node still hands out strict addresses, but refuses to pay to them, and policy rejects outputs to them.

Reference​

The derivation and encoding details for library implementers, including test vectors, are in the node repository under NIP/ (post-quantum address technique, NIP-022 PQ-HD derivation, mixed transactions) and in doc/covenants.md. The JavaScript libraries neurai-key, neurai-jswallet and neurai-sign-transaction implement all four families.