QMC White Paper
Riemann Spectral Consensus & Post-Quantum Matrix Signatures · 31 August 2026
How to read this paper
This is not a rewrite of the company paper at /white-paper. It is the technical case for the latest addition to the quantum sector: using the Montgomery–Odlyzko correspondence — the statistical identity between Riemann zeta zeros and the Gaussian Unitary Ensemble (GUE) — as a spectral filter on Proof-of-Quantum, paired with a Quantum Signature Matrix layer on top of NIST ML-DSA.
Already live (checked 31 Aug 2026): chain id 7771, ~30s blocks, Dilithium P2P handshake, consensus 2of3_dilithium_votes, native token QWD (8.1 billion, 6 decimals), lock-and-mint toward Soneium (1868). Wallets are ML-DSA-44, generated in the browser.
What this paper adds: extract a spectrum from a validator’s quantum execution, test it against GUE / Montgomery–Odlyzko statistics, and reject traces that look like classical contraction. If that filter can be made tight, QMC becomes the first L1 whose proof of quantum work is a number-theoretic spectral test.
1. Executive thesis
Decentralized networks now face a dual failure mode.
First, Shor’s algorithm makes elliptic-curve signatures a timed bomb. NIST finalized FIPS 204 (ML-DSA) in August 2024. The dangerous years are not 2035. They are the years between a cryptographically relevant quantum computer and a completed migration, when old keys are still on-chain and still spendable.
Second, Proof-of-Quantum as the industry sketches it — “run a random circuit, publish the samples” — is already under classical pressure. Tensor-network contraction has closed much of the 2019–2023 supremacy gap. A chain that accepts a bitstring as proof of a QPU will eventually accept a laptop.
QMC’s answer is to stop treating quantum advantage as a beauty contest of samples and start treating it as a spectral identity.
The Montgomery–Odlyzko law says the local spacing statistics of the non-trivial zeros of the Riemann zeta function
ζ(½ + it) = 0match the eigenvalue spacings of the Gaussian Unitary Ensemble. The GUE nearest-neighbour law (Wigner surmise, β = 2) is
P(s) ≈ (32/π²) s² exp(−4s²/π)Those same GUE statistics govern energy-level spacings of complex, non-integrable quantum Hamiltonians — the fingerprint of quantum chaos. QMC’s new layer asks: does the spectrum of the operator you claim to have executed sit in the GUE class that both Riemann zeros and chaotic quantum systems occupy?
Classical simulators can fake marginals. They have a much harder time faking a full spectral form factor of a chaotic unitary without paying the cost of the evolution they are trying to avoid. That cost-asymmetry is the intended security reduction. It is not finished. It is why this paper exists.
On signatures, QMC does not invent a new NIST algorithm. It wraps ML-DSA in a Quantum Signature Matrix: deterministic matrix hashing of chain state, number-theoretic domain separation, and prime-harmonic proposer shuffling when a hardware QRNG byte is actually in the pool. Unforgeability still rests on Dilithium.
2. The problem, stated without theatre
2.1 Shor does not “maybe” break wallets
Every major public chain still authenticates spend with elliptic curves. Given P = kG, recovering k is the assumption. Shor reduces that to an abelian hidden-subgroup problem, which a large low-error quantum computer solves in polynomial time.
Every wallet that has ever sent a transaction on a transparent chain has published its public key. That is a future loot box. Patching Ethereum or Bitcoin later means a hard fork and a long tail of abandoned keys. QMC never started native accounts on ECC. That part is already shipped: ML-DSA-44 in the browser, Dilithium on the handshake and the vote.
2.2 Grover is a different, smaller problem
Grover is a quadratic speedup on unstructured search. For SHA-256 that is often summarized as “256 bits become 128.” That matters for proof-of-work. Live docs already say it is not a special QMC feature. Honest paper, same sentence.
QMC refuses the hash race. Proposer selection is stake plus a random beacon. When the ANU pool has bytes, that beacon is labelled quantum. When it does not, the status API says quantum: false and uses CSPRNG. A chain that lies about entropy is worse than a chain that sometimes uses classical randomness.
2.3 The classical-simulation hole in PoQ
Random Circuit Sampling was the 2019 supremacy experiment. The following years produced tensor-network methods that ate a large fraction of that gap. A naive PoQ rule — submit RCS samples, check a fidelity statistic — has a known failure mode: a laptop simulates the shallow circuit and never buys a QPU.
That is the problem the Riemann layer is aimed at. Not “quantum is cool.” Sample tests are not a proof of hardware.
3. What is already running
A white paper that ignores the live chain will be compared to the live chain and discarded. Foundation, verified 31 August 2026:
| Fact | Production |
|---|---|
| Network | QMC mainnet, chain id 7771, ~30s blocks |
| Token | QWD, 8.1 billion supply, 6 decimals |
| Signatures | Dilithium / ML-DSA-44 on users, peers, and votes |
| Consensus | ceil(2n/3) Dilithium votes · 4 validators · quorum 3 |
| P2P | ws://wead.live:9900 · unsigned peers dropped |
| Bridge | Lock-and-mint toward Soneium (1868) |
| Explorer / wallet / docs | /quantum-blockchain · /qmc-wallet · /qmc-docs |
| Current backend field | Public blocks may show quantum-sim |
| QRNG | ANU when pooled; otherwise CSPRNG and not labelled quantum |
| Operators | WeAD hosts — not three independent continents |
The revolutionary work is not pretending four validators are a thousand. It is putting Dilithium in the handshake and the vote while the rest of Web3 still signs with the curve Shor eats — then adding a spectral test so “quantum” cannot mean “we ran a simulator and posted the JSON.”
4. The new architecture
Votes without a passing spectral certificate do not finalize. That is the rule that makes L1 more than a blog post.
5. How Riemann spectral verification works
5.1 The mathematics that is already true
Montgomery pair correlation (1973) and Odlyzko’s computations. After unfolding, the two-point correlation of Riemann zeros tracks
R2(u) = 1 − (sin(πu) / πu)²which is the GUE pair correlation. It is an empirical law of enormous weight, not a marketing metaphor. A complete proof for ζ(s) is still open.
GUE and quantum chaos (Bohigas–Giannoni–Schmit, 1984). Spectral fluctuations of a classically chaotic quantum system without time-reversal follow GUE. Integrable systems follow Poisson (level clustering). Diagnostic: chaos → GUE repulsion; fakes and integrable toys → Poisson or intermediate.
Wigner surmise is the right shape (quadratic repulsion at s → 0). Production tolerances should use the exact GUE spacing distribution plus a finite-N correction.
5.2 The scientific gap we will not paper over
- Bitstrings are not eigenvalues. An RCS histogram is a distribution on {0,1}n. GUE laws are about spectra of operators. The protocol must extract eigenphases of U, or eigenvalues of an effective Hamiltonian, not raw samples.
- Universality is a limit. A 12-qubit toy does not give a million spacings. The test needs a minimum spectral batch before it has power.
- Moment matchers exist. An adversary who only has to fit two histogram moments will. The filter is a battery: nearest-neighbour, number variance, spectral form factor K(t), plus a commitment to the circuit that was run.
- This is not a proof of the Riemann hypothesis. QMC uses the statistical identity as a public reference curve. Hilbert–Pólya is motivation, not a consensus gadget.
5.3 The intended protocol
Setup. Each epoch publishes a seed s (QRNG when the pool is live, otherwise CSPRNG, always labelled). From s it derives a chaotic / Haar-promoting circuit family — not Clifford, not shallow brickwork that tensor networks eat — plus a spectral extraction method.
Execution. The proposer runs the circuit, unfolds the spectrum to mean spacing 1, and commits to a compact sketch. A labelled simulator may run in early phases and must never count as hardware PoQ.
Verification (cheap, classical). Every other validator re-derives the circuit from the public seed, opens the commitment, computes spacings and the form factor, and tests against published GUE / Montgomery–Odlyzko tolerances. Poisson, unjustified GOE, or moment-matched-but-form-factor-dead traces fail and cannot enter the Dilithium vote set.
Why Riemann belongs in the name. Zeta zeros are the most famous infinite GUE-like spectrum in mathematics. The acceptance region is not “whatever our fridge did last Tuesday.” It is a century of numerical number theory. Validators trust a public statistical law, plus a circuit anyone can re-derive from the seed.
5.4 What simulation resistance can honestly mean
| Attacker | What they can do | What the filter is for |
|---|---|---|
| Shallow RCS spoof | Tensor-network / Clifford mimic | Ban those circuits from the family |
| Moment matcher | Fit P(s) with a classical RNG | Form factor + number variance |
| Rented QPU | Submit a real spectrum | Dilithium identity + stake — GUE does not stop rented hardware |
| Label fraud | Call a simulator a QPU | Public quantum_backend field; quantum-sim never satisfies hardware PoQ |
6. QSM — what it is, and what it is not
NIST FIPS 204 (ML-DSA) is the unforgeability primitive. QMC wallets, votes, and P2P already speak Dilithium. QSM does not replace that. Restructuring Dilithium’s error vectors “using zeta bounds” would leave the FIPS parameter set. We will not do that and then claim NIST.
What QSM adds:
- Deterministic state-matrix hashing — the epoch is a matrix of roots, validator set, spectral commitment, previous digest. Dilithium signs one digest. That digest is the natural object to anchor on Soneium.
- Number-theoretic domain separation — seeds and dimensions so votes, bridge, and faucet cannot collide. Engineering hygiene, not a new hardness assumption.
- Prime-harmonic proposer shuffle — when a QRNG byte is present. When the pool is empty, the same shuffle runs on CSPRNG and is not called quantum.
The lab at /quantum-chain is sign, verify, QRNG, Bell, BB84. This paper promotes QSM to the state-binding layer of consensus. Same name, sharper job.
7. Why this is revolutionary — if we hold the line
- Native post-quantum accounts in production. Most “quantum-safe” projects wrap Dilithium around an ECC chain or promise a future fork. QMC users already hold Dilithium keys. Peers that do not speak Dilithium are dropped.
- A public, number-theoretic definition of quantum work. Other PoQ sketches ask you to trust a lab. Riemann spectral consensus asks you to trust GUE universality — the same law that ties chaotic nuclei and zeta zeros. Mathematics as the auditor of the fridge.
- An honest split. Quantum-resistant is Dilithium (done). Quantum-powered is the spectral filter (this addition). The live API already refuses to stamp
quantum: trueon CSPRNG. The new layer refuses to stamp hardware PoQ onquantum-sim. - A public EVM rail without making ECC the root. Soneium is liquidity and attestation. The security root stays on QMC.
- A receipt for science, not a screenshot. Quantum Alchemy, QAIP, Dilithium-signed discoveries need a chain that understands quantum objects. A spectral commitment is “this operator was chaotic, this digest is on Soneium, this signature is ML-DSA.”
8. What it means for the world
The migration window
PQC standards (2024), agency migration through 2030, classical public-key retirement toward 2035. The money at risk is every long-lived key on every transparent ledger. If even one major chain delays, the first CRQC week is a global bank run on elliptic curves. A live Dilithium L1 with a public explorer, a browser wallet, and a Soneium rail is a place already on the far side of that fork.
Trust in a world of simulated everything
The next decade will train institutions to distrust claimed quantum advantage. A chain that binds a GUE test to a Dilithium vote and a Soneium digest gives courts and labs a receipt that a chaotic spectrum was committed at block height H.
Energy and consensus ethics
Proof-of-work turned electricity into security. Proof-of-stake turned capital into security. Proof-of-Quantum, done badly, turns press releases into security. Done well, it turns scarce physical entropy and scarce chaotic spectra into security — without a hash-rate race Grover can discount.
9. Roadmap
- Phase I — Formalization and testbed. Publish spectral-gap tolerances. Fix extraction so “output states” means a spectrum. Benchmark GUE matching on hardware and on the labelled simulator. No mainnet rule change until a false-reject / false-accept table exists.
- Phase II — QSM as state binding. Matrix-hash the header. Dilithium still signs one digest. Anchor epoch digests on Soneium. Do not retune Dilithium noise.
- Phase III — Mainnet PoQ rule. A proposal without a passing spectral certificate cannot gather Dilithium votes, except in an explicit
simepoch type that cannot mint hardware rewards. - Phase IV — Public node pack. Spectral verification must become independently runnable, or “mathematically verifiable” is false.
Worked intuition
Poisson spacings allow level clustering: P(s) stays finite as s → 0. GUE has quadratic repulsion: P(s) ∼ s². A spoofed spectrum of “random numbers in an interval” clusters. A chaotic quantum spectrum refuses to sit on top of itself. That fingerprint is why physicists have used spacing statistics since Wigner. QMC’s bet is that the same fingerprint can be a consensus opcode.
Live status: GET /api/qchain/status · Docs: /qmc-docs · Native security is QMC + Dilithium. Soneium is the EVM rail. Spectral GUE is the addition.