首个 PQVM 原生的后量子 L1。

在 Q-Day 之前完成量子安全升级,无需迁移。

NIST ML-DSA-65 签名、原生账户抽象、STARK 签名聚合 —— 全部运行在具备 EVM 熟悉语义的 PQVM 之上。

时机

时间窗口已经不再是假设。

后量子密码学已不再是研究课题,而是有明确时间表的联邦强制迁移。

时间事件为什么重要
2024-08NIST FIPS 203/204/205 finalized[1]ML-KEM, ML-DSA and SLH-DSA become US federal post-quantum standards.
2025NSA CNSA 2.0 enforcement window opens[2]US National Security Systems begin mandatory PQ migration timetable.
2030–2035CRQC (cryptographically-relevant quantum computer) maturity window[3]NIST IR 8413 evaluation report: when classical asymmetric cryptography is expected to be at risk.
Today“Harvest now, decrypt later” attacks already active[4]Cloud Security Alliance: long-lived encrypted data is being collected today for future quantum decryption.
目前由 ECDSA / Schnorr 保护的链上资产
超2万亿美元
Bitcoin + Ethereum + major EVM L2 TVL, all bound to pre-quantum signatures.对一条不可变的链而言,迁移窗口为零。
  1. [1][2024-08] NIST FIPS 203/204/205 finalized
  2. [2][2025] NSA CNSA 2.0 enforcement window opens
  3. [3][2030–2035] CRQC (cryptographically-relevant quantum computer) maturity window
  4. [4][Today] “Harvest now, decrypt later” attacks already active

可被验证的技术

三个协议级设计 —— 已交付、已 benchmark、开源。

下面每一个声明都对应公开仓库里的代码。

#01

原生后量子签名

以 ML-DSA-65(FIPS 204)为主签名;以 SLH-DSA-SHA2-256f(FIPS 205)为保守备选。

shell-crypto, shell-pqvm/precompiles
#02

原生账户抽象(不是 ERC-4337)

三条协议级验证路径:首次使用 / 默认账户 / 自定义 validator。地址是 32 字节原生格式(0x + 64 位小写十六进制),与以太坊 20 字节地址完全不同。密钥轮换从不更换地址 —— 无 bundler、无 paymaster。

shell-core::transaction · ACCOUNT_ABSTRACTION_GUIDE.md
#03

STARK 签名聚合

Winterfell STARK 证明将一个区块中所有 ML-DSA-65 签名聚合为单个 proof。证明管线完全异步——在基准测试和浸泡测试中从未阻塞共识。结合 Zstd 压缩和公钥去重,三层管线将 30M gas / 2 秒最坏情况的 7.76 MB 区块在验证窗口后压缩到落盘约 425 KB——端到端约 18× 的降幅。STARK 单层峰值压缩率为 7.1×(批量=5,持续 4–7×)。

tools/stark-bench · BENCHMARKS.md
~18×
端到端压缩比
7.76 MB → ~425 KB · A1 Zstd + A2 dedup + A3 STARK
source: BENCHMARKS.md
157 proofs/sec
持续吞吐
6 小时 soak,0 失败
source: BENCHMARKS.md
18.7 ms
p99 证明延迟
平均 6.4 ms / proof
source: BENCHMARKS.md

已交付

代码,而不是路线图。

每一个已交付的里程碑都链接到公开的 release tag;本页每一个数字都链接到对应的 benchmark / commit / NIST 文档。

2163+
通过的测试数
source: ShellDAO/shell-chain
108
已修复的审计发现
source: release notes
v0.27.4
当前 release
shell-chain v0.27.4
source: GitHub release
  1. Winterfell prover: A3 STARK layer compresses Dilithium3 signatures 7.1× (batch=5). Combined A1+A2+A3 pipeline: ~18× end-to-end (7.76 MB raw → ~425 KB pruned).

  2. Protocol-level smart accounts; 32-byte native addresses (0x + 64 lowercase hex); key rotation without changing address.

  3. Hot / warm / cold tiers; ZSTD compression for cold layer.

  4. Single-flag node classification; P2P StorageCapability advertisement; auto back-fill of historical bodies.

  5. Architecture re-split, consensus slashing wired in, network amplification fix, bounded mempool channels, supply-chain CI.

  6. Batch transactions (0x7E tx type, atomic InnerCall execution), native paymaster (sponsored gas), storage profiles CLI, Prometheus metrics, /healthz + /readyz probes, witness verification RPC.

  7. Live RPC, faucet, explorer, and external validator onboarding.

  8. PlannedMainnet genesis

    After audit close-out and 90-day stable testnet.

Token 经济

价值在哪里沉淀。

SHELL 不是“治理玩具”。每一次 PQ 验证、每一次密钥轮换、每一个 STARK proof,都直接消耗代币。

#01

Gas token

All transaction fees denominated in SHELL with PQTx-native fee model with base fee + tip; base fee burned.

#02

Validator stake

WPoA stake-weighted proposer selection; slash conditions cover double-sign and equivocation (live since v0.17).

#03

Aggregator bond

STARK prover nodes post a SHELL bond and earn fees per accepted aggregation proof.

#04

PQ verification services

Off-chain DID resolution and key-rotation attestation are settled in SHELL.

完整的代币分配、解锁方案与国库政策见投资人 Memo(需 NDA)。

风险披露

我们没有假装的事。

下列五项是投资人在尽调中最常提出的风险,每一项都附上具体的、已交付或已排期的缓解措施。

R01

A NIST PQ algorithm is later broken

↳ MitigationMulti-algorithm Verifier trait; new schemes can be added without a hard fork.
R02

STARK prover network centralisation

↳ Mitigationv0.18 roadmap opens proving to bonded operators with slashing.
R03

Inherited EVM vulnerabilities

↳ MitigationPQVM reimplements EVM-familiar execution; 69 internal audit findings already addressed.
R04

Thin early ecosystem

↳ MitigationSolidity bytecode runs on PQVM, while deployment and writes use shell-sdk for PQ-native signing and 32-byte address handling.
R05

Regulatory uncertainty

↳ MitigationProtocol holds no user assets; DID layer decoupled from KYC; MIT-licensed open source.
阅读完整风险登记册 →

Investors

进入我们的雷达。

我们会直接向提前登记的投资人发送测试网里程碑、审计结果和代币经济更新。

不会有垃圾邮件,一键退订。