Post-Quantum Addresses
POSITRONIC introduces addresses whose spending key is an ML-DSA-44 signature key (FIPS 204), the NIST post-quantum standard. They are strict PQ AuthScript outputs, witness version 2, and coexist with classical addresses: the same wallet can hold both, and a transaction can mix legacy, post-quantum and asset inputs.
Address families
| Family | Output script | Mainnet | Testnet and regtest | Used for |
|---|---|---|---|---|
| Legacy | P2PKH | N… | t… | Classical single-key addresses |
| Strict PQ, witness v2 | OP_2 <32-byte commitment> | pq1z… | tpq1z… | ML-DSA-44 wallet addresses |
| Strict ECDSA, witness v3 | OP_3 <32-byte commitment> | nq1r… | tnq1r… | secp256k1 witness addresses |
| Generic AuthScript, witness v1 | OP_1 <32-byte commitment> | nc1p… | tnc1p… | Contracts and covenants. Wallets never hand them out |
Generic witness v1 used to be encoded as nq1p… / tnq1p…. That encoding is now rejected, with no alias and no migration: only the address string changed, not the commitment or consensus. External integrations and old testnet address books must use nc1p… / tnc1p….
Address derivation
| Step | Detail |
|---|---|
| Seed | Standard BIP39 mnemonic and 64-byte seed |
| PQ master key | HMAC-SHA512(key = "Neurai PQ seed", seed): a 32-byte seed and a chain code. The key "Neurai PQ seed" keeps the PQ tree apart from the classical BIP32 tree ("Bitcoin seed") of the same mnemonic |
| HD path | m_pq/100'/1900'/0'/chain'/i' on mainnet, m_pq/100'/1'/0'/chain'/i' on testnet and regtest. Chain 1 is change. Every level is hardened and uses HMAC-SHA512 only, with no secp256k1 step (NIP-022) |
| Key generation | ML-DSA.KeyGen_internal(ξ) from FIPS 204, where ξ is the 32-byte seed of the child |
| Public key | Serialized as 0x05 followed by the 1312-byte ML-DSA-44 public key |
| Commitment | TaggedHash("NeuraiAuthScript", 0x02 ‖ 0x01 ‖ hash160(public key) ‖ SHA256(OP_TRUE)). The lead byte is the witness version and 0x01 the PQ auth type |
| Address | Bech32m, witness version 2, over the 32-byte commitment. Human-readable part pq on mainnet and tpq on testnet and regtest |
Because derivation is deterministic from the mnemonic, a post-quantum account has the same backup story as a classical one. PQ private keys are not WIF-compatible, so they cannot be swept into a legacy wallet. ML-DSA-44 has no public derivation, so there is no xpub in the classical sense.
Strict ECDSA keys come from their own classical branch, m/84'/1900'/0'/chain/i on mainnet and m/84'/1'/0'/chain/i on testnet and regtest, so legacy, PQ and ECDSA accounts recover independently from the same seed.
Spending
A strict PQ output is spent with exactly four witness items:
0x01 <ML-DSA-44 signature> <0x05 ‖ public key> OP_TRUE
The auth type must be 0x01 and the witness script must be exactly OP_TRUE. The node recomputes the commitment with lead byte 0x02, checks it against the output and verifies the signature. OP_TRUE is never evaluated: the template is the whole spending condition. Strict ECDSA works the same way with auth type 0x02, a compressed secp256k1 key and lead byte 0x03.
For script logic on top of a post-quantum key, use generic AuthScript v1 with auth type 0x01. See Covenants and opcodes.
| Size | Bytes |
|---|---|
| ML-DSA-44 public key | 1312, plus the 0x05 header |
| ML-DSA-44 signature | about 2420 |
| Maximum PQ script element | 3072 |
Node and wallet support
- Consensus: ML-DSA-44 verification in the strict PQ template and in generic AuthScript, with larger script elements and stack limits when the covenant flags are active (NIP-018).
- Policy: mempool and relay accept the larger witness items, and signing RPCs verify with the same flags as consensus (NIP-020, NIP-021).
- Wallet and RPC: PQ keys in the keystore, address decoders, native PQ-HD derivation and signing RPCs (NIP-019, NIP-022).
- Address type: chosen with
-addresstype=legacy|pq|ecdsawhen the wallet file is created, and stored in it.pqandecdsaneed-bip44=1. - Mixed transactions: legacy, PQ and asset inputs can be combined in one transaction. Mempool policy never replaces a transaction that involves assets (NIP-025).
- Script:
OP_CHECKSIGFROMSTACKandOP_CHECKSIGADDaccept ML-DSA-44 keys, so oracles and threshold scripts can be post-quantum as well.OP_OUTPUTAUTHDESTlets a covenant require payment to a given strict destination (NIP-041).
-addresstype | Hands out by default | Also on request |
|---|---|---|
legacy | Legacy (Base58) | Strict ECDSA |
pq | Strict PQ | Strict ECDSA |
ecdsa | Strict ECDSA | None |
Activation
The strict families and NIP-041 destination introspection activate at block 10 of the reset testnet and at block 0 on regtest. Mainnet is not scheduled. Before activation a node still hands out strict addresses, but refuses to pay to them, and policy rejects outputs to them.
Reference
The derivation and encoding details for library implementers, including test vectors, are in the node repository under NIP/ (post-quantum address technique, NIP-022 PQ-HD derivation, mixed transactions) and in doc/covenants.md. The JavaScript libraries neurai-key, neurai-jswallet and neurai-sign-transaction implement all four families.