PQVM-native post-quantum Layer 1

Post-Quantum TrustBefore Q-Day

Shell Chain protects signatures, key rotation, account recovery, and verification at the protocol layer while preserving familiar developer workflows before Q-Day forces migration.

What Shell Chain is

A PQVM-native Layer-1

Shell Chain is built around NIST ML-DSA-65 / SLH-DSA-SHA2-256f signatures instead of treating post-quantum security as a later migration. Native account abstraction lets users rotate keys without changing address, while Zstd, pubkey deduplication, and STARK signature aggregation shrink a worst-case 7.76 MB block to roughly 425 KB on disk after the proving window. Developers still work with Solidity and familiar RPC tooling.

30M gas / 2 s block worst-case (~7.76 MB raw) → ~425 KB final on disk after the STARK proof is shed at the end of its verification window. Live blocks are ~1.5 MB while proofs are retained. Source: BENCHMARKS.md (A1 + A2 + A3).

  • NIST-standard ML-DSA-65 + SLH-DSA-SHA2-256f signatures
    NIST FIPS 204 · NIST FIPS 205
  • PQVM with EVM-familiar semantics — existing Solidity contracts deploy unchanged
    PQVM execution layer
  • Protocol-level account abstraction — key rotation without changing address
    Protocol-level
Read the technical spec →

Post-Quantum Virtual Machine

PQVM — the execution layer that makes PQ economical.

PQVM reimplements EVM-familiar semantics in Rust, so existing Solidity contracts compile to bytecode that Shell SDK deployment flows can submit through the RPC compatibility layer. Native PQ precompiles expose ML-DSA-65 and SLH-DSA verification at the VM level — no classical-crypto precompiles ship. STARK aggregation then collapses thousands of PQ signatures into a single succinct proof, making post-quantum security economically viable at L1 throughput.

EVM-familiar semantics
Solidity bytecode works with Shell SDK deployment flows through the RPC compatibility layer — no contract rewrites required.
Solidity bytecode · Shell SDK · JSON-RPC
PQ precompiles
ML-DSA-65 (FIPS 204) and SLH-DSA (FIPS 205) verify and batch-verify are built directly into the VM — no classical-crypto precompiles.
FIPS 204 · FIPS 205
STARK aggregation
Thousands of PQ signatures collapse into a single succinct proof, making post-quantum security economically viable at block scale.
Winterfell · ~18× end-to-end
Native account abstraction
AA is a protocol primitive — not an ERC-4337 bundler dependency. Rotate keys without changing your address.
Protocol-level · no ERC-4337
Explore the architecture →

The policy countdown has already started

RSA and ECDSA have an expiration date. Chains need a migration path before users are forced into one.

This is no longer an abstract research debate. NIST standards, CNSA 2.0 guidance, and CRQC planning documents define a practical transition window for long-lived cryptographic systems.

The winning chain is not the one that announces a future hard fork. It is the one that makes post-quantum signing, rotation, and verification ordinary before the pressure arrives.

Regulatory timeline

  1. 2024-08
    NIST FIPS 203/204/205 finalized

    ML-KEM, ML-DSA and SLH-DSA become US federal post-quantum standards. source

  2. 2025
    NSA CNSA 2.0 enforcement window opens

    US National Security Systems begin mandatory PQ migration timetable. source

  3. 2030–2035
    CRQC (cryptographically-relevant quantum computer) maturity window

    NIST IR 8413 evaluation report: when classical asymmetric cryptography is expected to be at risk. source

  4. Today
    “Harvest now, decrypt later” attacks already active

    Cloud Security Alliance: long-lived encrypted data is being collected today for future quantum decryption. source

What's already in production

Release tags, benchmarks, and a public testnet replace roadmap-only claims.

Next

Public incentivized testnet (validator onboarding + independent audit) → mainnet genesis after 90 days of stable testnet.

  1. Winterfell prover: A3 STARK layer compresses Dilithium3 signatures 7.1× (batch=5). Combined A1+A2+A3 pipeline: ~18× end-to-end (7.76 MB raw → ~425 KB pruned).

  2. Protocol-level smart accounts; 32-byte native addresses (0x + 64 lowercase hex); key rotation without changing address.

  3. Hot / warm / cold tiers; ZSTD compression for cold layer.

  4. Single-flag node classification; P2P StorageCapability advertisement; auto back-fill of historical bodies.

  5. Architecture re-split, consensus slashing wired in, network amplification fix, bounded mempool channels, supply-chain CI.

  6. Batch transactions (0x7E tx type, atomic InnerCall execution), native paymaster (sponsored gas), storage profiles CLI, Prometheus metrics, /healthz + /readyz probes, witness verification RPC.

  7. Live RPC, faucet, explorer, and external validator onboarding.

  8. PlannedMainnet genesis

    After audit close-out and 90-day stable testnet.

See the release history →

Why this is not easily replicated

The only chain that satisfies three hard constraints at once.

Any competitor can match one column. Matching all three requires years of foundational rebuilding — not a fork.

 
NIST-signed PQ signatures
Ethereum tooling-compatible
Shipped (not whitepaper)
Shell Chain
ML-DSA-65 + SLH-DSA-SHA2-256f
PQVM-native
v0.27.3, testnet live
Ethereum
research stage
mainnet
PQ roadmap open
QRL / Algorand
XMSS or Falcon only
not EVM
mainnet

STARK aggregation makes PQ signatures economically viable on PQVM. Without it, PQ-native execution at this scale is too heavy to sustain.

Token economics

Where value accrues.

SHELL is consumed by every post-quantum verification, key rotation, and STARK aggregation proof — not held as governance collateral.

Tokenomics

  • Gas token

    All transaction fees denominated in SHELL with PQTx-native fee model with base fee + tip; base fee burned.

  • Validator stake

    WPoA stake-weighted proposer selection; slash conditions cover double-sign and equivocation (live since v0.17).

  • Aggregator bond

    STARK prover nodes post a SHELL bond and earn fees per accepted aggregation proof.

  • PQ verification services

    Off-chain DID resolution and key-rotation attestation are settled in SHELL.

Known risks

  • A NIST PQ algorithm is later broken

    Multi-algorithm Verifier trait; new schemes can be added without a hard fork.

  • STARK prover network centralisation

    v0.18 roadmap opens proving to bonded operators with slashing.

  • Inherited EVM vulnerabilities

    PQVM reimplements EVM-familiar execution; 69 internal audit findings already addressed.

Investors

Get on our radar.

We share testnet milestones, audit results, and token-economics updates directly with investors who register early.

No spam. One-click unsubscribe.