WeAD

QMC White Paper

Riemann Spectral Consensus & Post-Quantum Matrix Signatures · 31 August 2026

Paper contents

How to read this paper

This is not a rewrite of the company paper at /white-paper. It is the technical case for the latest addition to the quantum sector: using the Montgomery–Odlyzko correspondence — the statistical identity between Riemann zeta zeros and the Gaussian Unitary Ensemble (GUE) — as a spectral filter on Proof-of-Quantum, paired with a Quantum Signature Matrix layer on top of NIST ML-DSA.

Two layers of truth. QMC mainnet is live. New blocks must carry a matching Riemann GUE bind and a Cs / K(t) extract bind — that is a live lock, not a blog. Historical blocks before those heights were Dilithium-only. The bind is labelled quantum-sim; it is not a hardware QPU proof and not a proof of the Riemann hypothesis.
Node pack switch: OFF. Reference curves are public; node software and keys are not. Seed-derivation constants and Dilithium domain-separation strings are not in this paper. Deep spec unlocks when independent verifiers are chosen. Status: GET /api/quantum/spectral/verifiers.

Already live (production audit 2 September 2026): chain id 7771, ~30s blocks, Dilithium P2P handshake, consensus ceil(2n/3) Dilithium votes (four WeAD validators, quorum 3), native token QWD (8.1 billion, 6 decimals), two completed lock-and-mints to Soneium (1868) — 2 wrapped QWD, two holders, both WeAD wallets — the wrapped token's owner renounced, and one QSM digest witnessed there. Wallets are ML-DSA-44, generated in the browser. Seal start heights on 7771: GUE bind 480305, Cs/K(t) extract 480846, QSM header 484940, epoch label 485034. At or above each height the seal is mandatory; below it, absent is legacy. Field-absent alone is never legacy.

What this paper adds: the public statistical law (Montgomery–Odlyzko / GUE Wigner) that the live bind is tested against, and the research program that tightens that filter. It does not publish node source, seed-derivation constants, or Dilithium domain-separation strings.

1. Executive thesis

Decentralized networks now face a dual failure mode.

First, Shor’s algorithm makes elliptic-curve signatures a timed bomb. NIST finalized FIPS 204 (ML-DSA) in August 2024. The dangerous years are not 2035. They are the years between a cryptographically relevant quantum computer and a completed migration, when old keys are still on-chain and still spendable.

Second, Proof-of-Quantum as the industry sketches it — “run a random circuit, publish the samples” — is already under classical pressure. Tensor-network contraction has closed much of the 2019–2023 supremacy gap. A chain that accepts a bitstring as proof of a QPU will eventually accept a laptop.

QMC’s answer is to stop treating quantum advantage as a beauty contest of samples and start treating it as a spectral identity.

The Montgomery–Odlyzko law says the local spacing statistics of the non-trivial zeros of the Riemann zeta function

ζ(½ + it) = 0

match the eigenvalue spacings of the Gaussian Unitary Ensemble. The GUE nearest-neighbour law (Wigner surmise, β = 2) is

P(s) ≈ (32/π²) s² exp(−4s²/π)

Those same GUE statistics govern energy-level spacings of complex, non-integrable quantum Hamiltonians — the fingerprint of quantum chaos. QMC’s new layer asks: does the spectrum of the operator you claim to have executed sit in the GUE class that both Riemann zeros and chaotic quantum systems occupy?

Classical simulators can fake marginals. They have a much harder time faking a full spectral form factor of a chaotic unitary without paying the cost of the evolution they are trying to avoid. That cost-asymmetry is the intended security reduction. It is not finished. It is why this paper exists.

On signatures, QMC does not invent a new NIST algorithm. It wraps ML-DSA in a Quantum Signature Matrix: deterministic matrix hashing of chain state, number-theoretic domain separation, and prime-harmonic proposer shuffling when a hardware QRNG byte is actually in the pool. Unforgeability still rests on Dilithium.

2. The problem, stated without theatre

2.1 Shor does not “maybe” break wallets

Every major public chain still authenticates spend with elliptic curves. Given P = kG, recovering k is the assumption. Shor reduces that to an abelian hidden-subgroup problem, which a large low-error quantum computer solves in polynomial time.

Every wallet that has ever sent a transaction on a transparent chain has published its public key. That is a future loot box. Patching Ethereum or Bitcoin later means a hard fork and a long tail of abandoned keys. QMC never started native accounts on ECC. That part is already shipped: ML-DSA-44 in the browser, Dilithium on the handshake and the vote.

2.2 Grover is a different, smaller problem

Grover is a quadratic speedup on unstructured search. For SHA-256 that is often summarized as “256 bits become 128.” That matters for proof-of-work. Live docs already say it is not a special QMC feature. Honest paper, same sentence.

QMC refuses the hash race. Proposer selection is stake plus a random beacon. When the ANU pool has bytes, that beacon is labelled quantum. When it does not, the status API says quantum: false and uses CSPRNG. A chain that lies about entropy is worse than a chain that sometimes uses classical randomness.

2.3 The classical-simulation hole in PoQ

Random Circuit Sampling was the 2019 supremacy experiment. The following years produced tensor-network methods that ate a large fraction of that gap. A naive PoQ rule — submit RCS samples, check a fidelity statistic — has a known failure mode: a laptop simulates the shallow circuit and never buys a QPU.

That is the problem the Riemann layer is aimed at. Not “quantum is cool.” Sample tests are not a proof of hardware.

3. What is already running

A white paper that ignores the live chain will be compared to the live chain and discarded. Foundation, verified 31 August 2026:

FactProduction
NetworkQMC mainnet, chain id 7771, ~30s blocks
TokenQWD, 8.1 billion supply, 6 decimals
SignaturesDilithium / ML-DSA-44 on users, peers, and votes
Consensusceil(2n/3) Dilithium votes · 4 validators · quorum 3
P2Pws://wead.live:9900 · unsigned peers dropped
BridgeLock-and-mint toward Soneium (1868)
Explorer / wallet / docs/quantum-blockchain · /qmc-wallet · /qmc-docs
Current backend fieldPublic blocks may show quantum-sim
QRNGANU when pooled; otherwise CSPRNG and not labelled quantum
OperatorsWeAD hosts — not three independent continents

The revolutionary work is not pretending four validators are a thousand. It is putting Dilithium in the handshake and the vote while the rest of Web3 still signs with the curve Shor eats — then adding a spectral test so “quantum” cannot mean “we ran a simulator and posted the JSON.”

4. The new architecture

L0 Live chain (shipping) Dilithium accounts & votes · QWD · 30s blocks · Soneium rail L1 Proof-of-Quantum + Riemann spectral filter (this addition) Chaotic / Haar-like unitary → extract spectrum Unfolded spacings + form factor vs GUE / zeta law Fail ⇒ proposal invalid, even if Dilithium votes exist L2 Quantum Signature Matrix ML-DSA is the unforgeability primitive State hashed as a matrix · Dilithium signs one digest L3 Election + Soneium anchoring QRNG when live + prime-harmonic shuffle Epoch digest visible on Soneium

Votes without a passing spectral certificate do not finalize. That is the rule that makes L1 more than a blog post.

5. How Riemann spectral verification works

5.1 The mathematics that is already true

Montgomery pair correlation (1973) and Odlyzko’s computations. After unfolding, the two-point correlation of Riemann zeros tracks

R2(u) = 1 − (sin(πu) / πu)²

which is the GUE pair correlation. It is an empirical law of enormous weight, not a marketing metaphor. A complete proof for ζ(s) is still open.

GUE and quantum chaos (Bohigas–Giannoni–Schmit, 1984). Spectral fluctuations of a classically chaotic quantum system without time-reversal follow GUE. Integrable systems follow Poisson (level clustering). Diagnostic: chaos → GUE repulsion; fakes and integrable toys → Poisson or intermediate.

Wigner surmise is the right shape (quadratic repulsion at s → 0). Production tolerances should use the exact GUE spacing distribution plus a finite-N correction.

5.2 The scientific gap we will not paper over

Research claim, not a finished theorem. “Circuit output states match GUE, therefore tensor networks fail in polynomial time” is the program — not something you get for free by citing Montgomery.
  1. Bitstrings are not eigenvalues. An RCS histogram is a distribution on {0,1}n. GUE laws are about spectra of operators. The protocol must extract eigenphases of U, or eigenvalues of an effective Hamiltonian, not raw samples.
  2. Universality is a limit. A 12-qubit toy does not give a million spacings. The test needs a minimum spectral batch before it has power.
  3. Moment matchers exist. An adversary who only has to fit two histogram moments will. The filter is a battery: nearest-neighbour, number variance, spectral form factor K(t), plus a commitment to the circuit that was run.
  4. This is not a proof of the Riemann hypothesis. QMC uses the statistical identity as a public reference curve. Hilbert–Pólya is motivation, not a consensus gadget.

5.3 The intended protocol

Setup. Each epoch publishes a seed s (QRNG when the pool is live, otherwise CSPRNG, always labelled). From s it derives a chaotic / Haar-promoting circuit family — not Clifford, not shallow brickwork that tensor networks eat — plus a spectral extraction method.

Execution. The proposer runs the circuit, unfolds the spectrum to mean spacing 1, and commits to a compact sketch. A labelled simulator may run in early phases and must never count as hardware PoQ.

Verification (cheap, classical). Every other validator re-derives the circuit from the public seed, opens the commitment, computes spacings and the form factor, and tests against published GUE / Montgomery–Odlyzko tolerances. Poisson, unjustified GOE, or moment-matched-but-form-factor-dead traces fail and cannot enter the Dilithium vote set.

Why Riemann belongs in the name. Zeta zeros are the most famous infinite GUE-like spectrum in mathematics. The acceptance region is not “whatever our fridge did last Tuesday.” It is a century of numerical number theory. Validators trust a public statistical law, plus a circuit anyone can re-derive from the seed.

5.5 Published ε windows (2 Sep 2026)

The battery is now a public table a verifier can rerun: KS vs Wigner and vs Poisson at M=32, number variance Σ² at L=1,2,3, and the K(t) ramp of the live Cs extract. Bind size stays 32. Extract stays n=6 — that is not Haar, and the GUE verdict stays informational. Full QPE is not on the 30-second path.

Named classical family: 1D MPS / tensor-train contraction of the Cs brickwork, cost X = χ* = 64, plus the exact dense 23n baseline. At live n=6 a laptop wins. If a named algorithm under that cost produces a passing K(t) after the family is no longer a toy, rotate Cs (new model id; historical seals still verify). The live family cs-kt-v1 is not rotated.

Table: GET /api/quantum/spectral/windows. One-seed rerun: /api/quantum/spectral/windows/rerun?seed=…. Seed-derivation constants stay out of this paper.

Formulas the table is tested against (audited 2 Sep 2026). Wigner surmise β=2: P(s) = (32/π²) s² e^{−4s²/π}, CDF F(s) = erf(2s/√π) − (4s/π) e^{−4s²/π}, mean spacing 1. Poisson CDF 1 − e^{−s}. Spacings are circular on 2n=64 eigenphases, unfolded to mean 1. KS is the two-sided sup over both sides of each step (matches scipy.stats.kstest). Form factor K(t) = |Tr U^t|² / N, N=64: Haar CUE gives ⟨K(t)⟩ = min(t,N)/N (0.0156 at t=1); i.i.d. diagonal phases give ⟨K⟩ = 1. Σ²(1) is ≈0.34 (sine kernel) for exact GUE and L for Poisson; the published GUE median ≈0.39 is finite-M (32 draws) with sample-edge unfolding. The Cs family is one-qubit U3 + CZ brickwork with uniform angles — not Haar SU(2), not Clifford, exactly unitary (‖UU†−I‖ ≈ 10−14), seed-deterministic bit-for-bit under a pinned PCG64 generator.

5.6 Hardware vs sim epochs (2 Sep 2026)

Two epoch types: sim and hardware. Live blocks are sim. The measured labelled backend is quantum-sim, with a public false-reject table against Poisson and a depolarizing noise model. That model is not Wukong and not a rented QPU. hardware_poq is true only on a measured hardware epoch — none is measured. A sim epoch cannot mint hardware rewards. ANU empty ⇒ quantum: false. Rented QPU time is not WeAD-only.

Registry: GET /api/quantum/spectral/epochs. Reward gate: /api/qchain/rewards/hardware.

5.7 Operator set (2 Sep 2026)

The live operator set is four WeAD validators. A second WeAD host votes over P2P. That is not an external partner and not three continents. One seat is reserved for an operator who is not a WeAD host. It is empty. Applications are recorded; they do not become validators. Mini wallet is Startale — not a QMC consensus operator. Explorer, docs, and this paper name the same set. The node-pack switch stays OFF until independent verifiers are named. Company paper stays at /white-paper.

Registry: GET /api/qchain/operators.

5.4 What simulation resistance can honestly mean

AttackerWhat they can doWhat the filter is for
Shallow RCS spoofTensor-network / Clifford mimicBan those circuits from the family
Moment matcherFit P(s) with a classical RNGForm factor + number variance
Rented QPUSubmit a real spectrumDilithium identity + stake — GUE does not stop rented hardware
Label fraudCall a simulator a QPUPublic quantum_backend field; quantum-sim never satisfies hardware PoQ

6. QSM — what it is, and what it is not

NIST FIPS 204 (ML-DSA) is the unforgeability primitive. QMC wallets, votes, and P2P already speak Dilithium. QSM does not replace that. Restructuring Dilithium’s error vectors “using zeta bounds” would leave the FIPS parameter set. We will not do that and then claim NIST.

What QSM adds:

  • Deterministic state-matrix hashing — the epoch is a matrix of roots, validator set, spectral commitment, previous digest. Dilithium signs one digest. That digest is the natural object to anchor on Soneium.
  • Number-theoretic domain separation — seeds and dimensions so votes, bridge, and faucet cannot collide. Engineering hygiene, not a new hardness assumption.
  • Prime-harmonic proposer shuffle — when a QRNG byte is present. When the pool is empty, the same shuffle runs on CSPRNG and is not called quantum.

The lab at /quantum-chain is sign, verify, QRNG, Bell, BB84. This paper promotes QSM to the state-binding layer of consensus. Same name, sharper job.

Live (2 Sep 2026): header verify is one ML-DSA-44 over the QSM matrix digest. Votes still sign the block hash. This is not a new NIST algorithm and is not an SVP “optimization.” Domain-separation strings stay out of this paper.

7. Why this is revolutionary — if we hold the line

  1. Native post-quantum accounts in production. Most “quantum-safe” projects wrap Dilithium around an ECC chain or promise a future fork. QMC users already hold Dilithium keys. Peers that do not speak Dilithium are dropped.
  2. A public, number-theoretic definition of quantum work. Other PoQ sketches ask you to trust a lab. Riemann spectral consensus asks you to trust GUE universality — the same law that ties chaotic nuclei and zeta zeros. Mathematics as the auditor of the fridge.
  3. An honest split. Quantum-resistant is Dilithium (done). Quantum-powered is the spectral filter (this addition). The live API already refuses to stamp quantum: true on CSPRNG. The new layer refuses to stamp hardware PoQ on quantum-sim.
  4. A public EVM rail without making ECC the root. Soneium is liquidity and attestation. The security root stays on QMC.
  5. A receipt for science, not a screenshot. Quantum Alchemy, QAIP, Dilithium-signed discoveries need a chain that understands quantum objects. A spectral commitment is “this operator was chaotic, this digest is on Soneium, this signature is ML-DSA.”

8. What it means for the world

The migration window

PQC standards (2024), agency migration through 2030, classical public-key retirement toward 2035. The money at risk is every long-lived key on every transparent ledger. If even one major chain delays, the first CRQC week is a global bank run on elliptic curves. A live Dilithium L1 with a public explorer, a browser wallet, and a Soneium rail is a place already on the far side of that fork.

Trust in a world of simulated everything

The next decade will train institutions to distrust claimed quantum advantage. A chain that binds a GUE test to a Dilithium vote and a Soneium digest gives courts and labs a receipt that a chaotic spectrum was committed at block height H.

Energy and consensus ethics

Proof-of-work turned electricity into security. Proof-of-stake turned capital into security. Proof-of-Quantum, done badly, turns press releases into security. Done well, it turns scarce physical entropy and scarce chaotic spectra into security — without a hash-rate race Grover can discount.

This paper does not claim: a proof of RH; that four WeAD validators are a world computer; that every current block is Wukong hardware; that Dilithium is “harder than NIST” because of zeta functions; that an early mainnet is a place to move life savings without treating it as early.

9. Roadmap

  1. Phase I — Live bind (shipped 31 Aug 2026). New blocks require a recomputable GUE bind and a Cs / K(t) extract bind. Dilithium still signs. This paper publishes the reference curves, not the node pack.
  2. Phase II — QSM as state binding (header bind shipped 2 Sep 2026; epoch witness on Soneium 2 Sep 2026; statistical windows shipped 2 Sep 2026). New blocks matrix-hash the header. Dilithium signs that one digest (ML-DSA-44 / FIPS 204, parameter set unchanged). Votes still sign the block hash. A QSM digest is now witnessed on Soneium 1868 as an ECC transaction — liquidity and attestation, not a post-quantum token. KS / Σ² / K(t) windows are a public rerun table; n=6 is not Haar. Domain-separation strings stay out of this paper.
  3. Phase III — Hardware PoQ epochs (shipped 2 Sep 2026). A labelled sim epoch cannot mint hardware rewards. quantum-sim never counts as hardware PoQ. Wukong is not stamped on sim extract. False-reject table vs sim is public.
  4. Phase G — Production network (shipped 2 Sep 2026). Status, explorer, Mini, and this paper name the same operator set: four WeAD hosts, one empty non-WeAD seat, no continents. Real Dilithium wallets and non-faucet transfers are on-chain. The switch badge stays OFF.
  5. Phase IV — Node pack, switch-gated. Independent verification becomes runnable only after independent verifiers are chosen and the node-pack switch is ON. Until then the switch stays OFF.

Worked intuition

Poisson spacings allow level clustering: P(s) stays finite as s → 0. GUE has quadratic repulsion: P(s) ∼ s². A spoofed spectrum of “random numbers in an interval” clusters. A chaotic quantum spectrum refuses to sit on top of itself. That fingerprint is why physicists have used spacing statistics since Wigner. QMC’s bet is that the same fingerprint can be a consensus opcode.

Live status: GET /api/qchain/status · Operators: GET /api/qchain/operators · Windows: GET /api/quantum/spectral/windows · Epochs: GET /api/quantum/spectral/epochs · Verifier switch: GET /api/quantum/spectral/verifiers · Docs: /qmc-docs · Native security is QMC + Dilithium. Soneium is the EVM rail. Spectral GUE is a live bind. Reference curves are public; node software and keys are not.

10. Production board (A–G, audited 2 Sep 2026)

PhaseWhat shippedLive evidence
AGUE bind on every block; bind match is consensus, KS is informationalspectral.qsm_bind from height 480305
BCs/K(t) extract bind, model cs-kt-v1, n=6extraction.qsm_bind from 480846
CQSM 4×4 header digest, one ML-DSA-44 signature; encoder v2 since the auditqsm_header from 484940; v in each seal
DSoneium 1868 rail: two locks, two mints to two WeAD wallets, one digest witness (ECC, not PQ); token owner renounced 3 Sep/api/qchain/bridge/locks · /bridge/epoch
EPublic KS / Σ² / K(t) window table with one-seed rerun/api/quantum/spectral/windows
FSim vs hardware epochs; hardware_poq=false on every live block; epoch label required from 485034epoch_type on /api/qchain/block/latest
GNamed operator set: four WeAD validators, one empty non-WeAD seat; real wallets and non-faucet transfers/api/qchain/operators

Audit method: four independent read-only passes (spectral mathematics, consensus and chain rules, public API and pages, bridge and quantum backends) against the live server, then fixes deployed the same day. The audit changed no history: every historical block still verifies under its own seal version and start height.

11. What is not 100% (and is said out loud)

  • The bridge is one-way. QMC → Soneium mints work. Burning wrapped QWD on Soneium does not credit native QWD; such events are booked at /api/qchain/bridge/returns as pending_manual. bridge_release is relayer-only and can only refund a lock that never minted. Public POST /api/qchain/bridge/release returns 403.
  • One WeAD relayer, one signer. The wrapped-QWD token (0x017E…CD58) has no owner: renounceOwnership landed 3 Sep 2026 (tx 0x3ab7…2935, block 27631490), and mint/burn are callable only by the bridge contract (0xeE6d…4306), fixed once and unchangeable. What remains single-signer is the bridge's own owner() — the relayer EOA that calls release. Both wrapped-QWD holders are WeAD wallets. Both contracts are source-verified on Blockscout as of 3 Sep 2026 — token and bridge — as bytecode matches with a partial metadata hash: the original build metadata was not kept, so the source was reconstructed and compiled to a byte-identical body (solc 0.8.19, via-IR, OpenZeppelin 4.9.0).
  • No hardware epoch exists today. 197 earlier blocks (heights 1,758–31,500, 7–17 March 2026) are labelled wukong on the live chain — seed-derived GHZ, 1,000 shots each, 197,000 measured shots in total, each with its histogram on the block. Recounted 3 Sep 2026 from the mainnet store: 197 of 488,204 blocks. Origin Wukong is now in maintenance and rejects jobs; IonQ is a cloud simulator; every live block is quantum-sim. A cloud QPU attempt is now hard-capped so it can never hold the 30-second slot. Those March proofs do not carry a provider job ID.
  • QRNG is rate-limited. ANU returns 429; the proposer seed is a labelled CSPRNG (quantum: false) until a paid ANU quota or another QRNG is in place.
  • Four validators, all WeAD. The P2P handshake signs identity but not a fresh nonce, so a captured handshake could be replayed against the second WeAD host; the fix needs both hosts and is scheduled with the next node-pack build.
  • Small-n spectra. n=6 is a toy a laptop wins; the K(t) verdict is informational. The Cs angles are uniform, not Haar SU(2). Growing n or rotating the family is a research step, not a switch.
  • 27 accounts, 31 transactions at audit time. This is an early mainnet. Treat it as early.

Fixed in the same audit (2 Sep 2026): public bridge release closed; chain id 0 no longer accepted; in-block nonce simulation (two txs from one sender in one block now both apply; a duplicate nonce is rejected; a stale mempool tx is dropped instead of skipping the height); mint fails closed when no minter is set; stake/unstake/claim signatures are single-use; seal requirements are keyed to start heights rather than "field absent"; QSM encoder v2; JSON-RPC errors return codes on HTTP 200 and validate 40-hex addresses; PCG64 pinned for the GUE draw; Dilithium verify fails closed on a non-boolean result.