Qlyphs Docs

Verified by design

Your wallet checks every listing itself, against a proof signed by two independent witnesses.

Token balances and listings live on top of Quantus, so someone has to read the chain and keep track of them. That is a job where a wrong answer is expensive: if a server told your wallet that a fake listing was real, you could be asked to pay for something that does not exist.

Qlyphs solves it by making sure your wallet never has to take anyone's word for it. It checks. This page explains how, in three ideas: the chain is read the same way every time, two witnesses sign what they read, and your wallet verifies a small proof against their signatures.

Read from the chain, block by block

The first idea is that the state of the market is not stored in some database you have to trust. It is computed from the chain, by following a strict routine.

  • Sent 3 QTCblock #184,222
  • Received 12.5 QTCblock #184,220
  1. 01 / 05

    Blocks keep arriving

    Quantus produces a new block every few seconds. Some hold a transaction, some are empty. The newest block is drawn with a dashed border on purpose: it has just appeared and could still be replaced.

  2. 02 / 05

    Only final blocks count

    Qlyphs ignores anything that is not final. As soon as a newer block is on top, the one below it turns final and becomes safe to read. This is why a balance never jumps back after you have seen it.

  3. 03 / 05

    Read in order, from a fixed start

    Every final block is read from the same starting block, one after another, never skipping and never reordering. A received payment or a sent one becomes a line of your activity, tagged with the block it came from.

  4. 04 / 05

    The same chain gives the same result

    The rules are fixed and applied identically every time, so anyone who replays the chain reaches the same state, byte for byte. Nobody has to be trusted for the answer, because anyone can recompute it.

  5. 05 / 05

    Reading is not holding

    Nothing that reads the chain holds a key. It can look at everything and move nothing. The only thing able to sign a transaction is your wallet, on your device.

Qlyphs reads only finalized blocks, in order, from a fixed starting block, and applies the same rules every time. The same chain always gives the same state, byte for byte. Nothing that reads the chain holds a key: it cannot move anything.

Two witnesses, two implementations

Because the state is computed, anyone can compute it, and two independent parties do. Two witnesses replay the chain on their own: two separate implementations, each on its own Quantus node. Each signs the state it computed with its own ML-DSA-87 key. They must agree, or nothing is signed.

Your wallet carries their public keys in its own code, and never accepts a key from a website or a server. If it did, an attacker would only need to present a key of their own.

One proof, one listing

The witnesses fold the whole state into a single hash, the root, and sign that. Your wallet does not need the whole state to check one listing, only the listing and about twenty hashes. Scroll through what it does with them:

listingroot
Witness 1 · ML-DSA-87 ✓Witness 2 · ML-DSA-87 ✓
  1. 01 / 05

    One entry arrives

    The wallet does not download the market. It receives a single entry of it: the listing it is about to buy. The market can hold a hundred thousand entries, and the wallet only ever touches this one.

  2. 02 / 05

    A neighbour joins it

    Along with the listing comes one hash per level of the tree. The wallet hashes the listing together with its neighbour, the entry next to it. The result is a new hash that stands for both of them.

  3. 03 / 05

    And again, level by level

    It repeats the step: the result is paired with the next hash it was given, and so on, climbing one level at a time. About twenty hashes are enough to cover a state of a hundred thousand entries, which is why this stays instant.

  4. 04 / 05

    It reaches a root

    At the top there is a single hash, the root. The wallet computed it itself, from the very listing it will pay for. It is a fingerprint of the whole market that changes if any single entry changes.

  5. 05 / 05

    The witnesses’ root must match

    That root has to be the one both witnesses signed with ML-DSA-87. A fake listing, or a listing with a changed price, produces a different root, and the wallet refuses. There is no way to slip a lie past this check without breaking a post-quantum signature.

What your wallet checks before paying

Putting it together, this is the full list. Every item has to pass, every time:

  • both witness signatures, against the keys built into the wallet;
  • that both signed the same root, for the same finalized block, recently;
  • that the listing is on the chain and still open, on its own Quantus node;
  • that the payment it is about to sign matches the proven listing exactly.

If anything fails, it refuses. There is no fallback to an unproven answer.

The trees use SHA-512: even a quantum computer running Grover's algorithm leaves a very wide margin.

On this page