后量子信任先于 Q-Day
Shell Chain 在协议层保护签名、密钥轮换、账户恢复和验证,同时保留开发者熟悉的工作流,先于 Q-Day 完成迁移。
- Shell testnet
- Public
- Release
- v0.27.4
- Tests
- 2,163+
- RPC surface
- 70+ methods
- Signature scheme
- ML-DSA-65 / SLH-DSA
- Block reduction
- ~18×
Shell Chain 是什么
一条 PQVM 原生公链
Shell Chain 围绕 NIST ML-DSA-65 / SLH-DSA-SHA2-256f 签名构建,而不是把后量子安全留给未来迁移。协议级账户抽象让用户换钥不换地址;Zstd、公钥去重和 STARK 签名聚合把最坏情况 7.76 MB 区块,在验证窗口后压到磁盘约 425 KB。开发者仍然使用 Solidity 和熟悉的 RPC 工具。
假设:30M gas / 2 秒区块最坏情况(原始 ~7.76 MB),STARK proof 在验证窗口结束后丢弃,最终落盘 ~425 KB;proof 保留期间区块约 1.5 MB。数据来源:BENCHMARKS.md(A1 + A2 + A3)。
- NIST 标准 ML-DSA-65 + SLH-DSA-SHA2-256f 签名NIST FIPS 204 · NIST FIPS 205
- 具备 EVM 熟悉语义的 PQVM —— 现有 Solidity 合约可直接部署PQVM 执行层
- 协议级账户抽象 — 换私钥不换地址协议级
后量子虚拟机
PQVM — 让后量子安全具备经济可行性的执行层
PQVM 用 Rust 重新实现了 EVM 熟悉语义——现有 Solidity 合约、Shell SDK 脚本和合约 artifact通过标准 RPC 兼容层直接接入,无需改写合约。原生 PQ 预编译在虚拟机层面暴露 ML-DSA-65 与 SLH-DSA 验签接口,不携带任何经典密码预编译。STARK 聚合将数千份 PQ 签名压缩为单个简洁证明,使抗量子安全在 L1 吞吐量下具备经济可行性。
政策倒计时已经启动
RSA 与 ECDSA 已经被写上退役时间表。公链需要在用户被迫迁移之前完成迁移路径。
这已经不是抽象研究讨论。NIST 标准、CNSA 2.0 指引和 CRQC 规划文件,为长期密码系统给出了实际迁移窗口。
胜出的不会是宣布未来硬分叉的链,而是能在压力到来前,让后量子签名、换钥和验签变成日常能力的链。
监管时间线
- 2024-08NIST FIPS 203/204/205 finalized
ML-KEM, ML-DSA and SLH-DSA become US federal post-quantum standards. source
- 2025NSA CNSA 2.0 enforcement window opens
US National Security Systems begin mandatory PQ migration timetable. source
- 2030–2035CRQC (cryptographically-relevant quantum computer) maturity window
NIST IR 8413 evaluation report: when classical asymmetric cryptography is expected to be at risk. source
- Today“Harvest now, decrypt later” attacks already active
Cloud Security Alliance: long-lived encrypted data is being collected today for future quantum decryption. source
已经跑起来的东西
用公开 release、基准测试和测试网证据,替代只有路线图的承诺。
激励测试网(外部验证人上线 + 独立审计)→ 在测试网稳定运行 90 天后主网创世。
Winterfell prover: A3 STARK layer compresses Dilithium3 signatures 7.1× (batch=5). Combined A1+A2+A3 pipeline: ~18× end-to-end (7.76 MB raw → ~425 KB pruned).
- ShippedNative Account Abstraction
Protocol-level smart accounts; 32-byte native addresses (0x + 64 lowercase hex); key rotation without changing address.
- Shipped3-way block-storage pruning
Hot / warm / cold tiers; ZSTD compression for cold layer.
Single-flag node classification; P2P StorageCapability advertisement; auto back-fill of historical bodies.
Architecture re-split, consensus slashing wired in, network amplification fix, bounded mempool channels, supply-chain CI.
Batch transactions (0x7E tx type, atomic InnerCall execution), native paymaster (sponsored gas), storage profiles CLI, Prometheus metrics, /healthz + /readyz probes, witness verification RPC.
- ShippedPublic testnet live
Live RPC, faucet, explorer, and external validator onboarding.
- PlannedMainnet genesis
After audit close-out and 90-day stable testnet.
为什么难以被复制
唯一同时满足三个硬约束的公链。
单拿任何一列,都有对手能追平。要同时拿下三列,需要多年基础重建——而不是 fork 一下就行。
STARK 聚合是让后量子签名在 PQVM 上经济可行的关键。没有它,这一规模的 PQ 原生执行在性能上无法持续。
代币经济
价值在哪里累积。
每一笔后量子验证、每次密钥轮换、每个 STARK 聚合证明都会消耗 SHELL——而非作为治理抵押品持有。
代币经济
- Gas token
All transaction fees denominated in SHELL with PQTx-native fee model with base fee + tip; base fee burned.
- Validator stake
WPoA stake-weighted proposer selection; slash conditions cover double-sign and equivocation (live since v0.17).
- Aggregator bond
STARK prover nodes post a SHELL bond and earn fees per accepted aggregation proof.
- PQ verification services
Off-chain DID resolution and key-rotation attestation are settled in SHELL.
已知风险
- A NIST PQ algorithm is later broken
Multi-algorithm Verifier trait; new schemes can be added without a hard fork.
- STARK prover network centralisation
v0.18 roadmap opens proving to bonded operators with slashing.
- Inherited EVM vulnerabilities
PQVM reimplements EVM-familiar execution; 69 internal audit findings already addressed.
Investors
进入我们的雷达。
我们会直接向提前登记的投资人发送测试网里程碑、审计结果和代币经济更新。
不会有垃圾邮件,一键退订。