Quantus white paper review highlights STARK-based privacy gains and flags 27% premine risk

Quantus white paper review highlights STARK-based privacy gains and flags 27% premine risk

N
News Editor
2026-09-29 09:48:32
Quantus, a privacy-focused public blockchain built around the NIST post-quantum signature standard ML-DSA, is scheduled to launch its mainnet on Sept. 9, 2026. In a long-form review republished by BlockTempo from the blog of "Physics Apprentice" at "Gazing at the Singularity," the project is described as one of the more technically interesting public-chain designs the author has read this year. The core idea is to use a STARK-based proof system that relies only on hash functions to move bulky post-quantum signatures off-chain for aggregation, which in turn improves throughput and creates a privacy layer at the same time. The paper says this lets Quantus turn privacy transfers into a cheaper scaling path rather than an expensive add-on. The review also spends substantial time on trade-offs. Quantus uses Wormhole addresses to break the on-chain link between sender and receiver, but transfer amounts remain visible, making the privacy model closer to Tornado Cash-style link breaking than Monero-style amount concealment. On tokenomics, the author’s main concern is the chain’s 27% genesis premine, equal to 5.67 million QTC, with the full allocation unlocked over the first four years. The article argues that this creates a heavy early supply overhang for a network positioned as a store-of-value asset, even though the project also adopts a 21 million cap, a smooth issuance curve, and a burn mechanism intended to recycle part of privacy-transfer fees back into future miner rewards.

Quantus, a privacy-focused blockchain that uses the NIST post-quantum signature standard ML-DSA, is set to launch its mainnet on Sept. 9, 2026. In an article republished by BlockTempo from the blog of "Physics Apprentice" at "Gazing at the Singularity," the author argues that Quantus’ most notable design choice is its use of a hash-based STARK system to move bulky post-quantum signatures off-chain for aggregation, gaining both higher throughput and privacy in the process. The same review says the chain’s biggest weakness is its 27% genesis premine, with the full allocation unlocked over the first four years.

The author wrote that interest in Quantus began after hearing from contacts in Singapore’s crypto market earlier this year about a privacy blockchain using post-quantum cryptography. That interest grew later after a whale active in NEAR and ZEC said NEAR Intents would support a new post-quantum privacy chain after its cross-chain bridge rollout, and that chain was Quantus. The author then started reading the white paper and documentation in detail, and also tried mining with a GPU. The article says Quantus currently ranks first on WhatToMine by profitability, which the author compared to the experience of mining ETH in 2017.

The piece is framed throughout as a personal study note rather than investment advice.

Why the author thinks a new post-quantum chain is needed

The review says Shor’s algorithm, proposed in 1994, means that once sufficiently powerful commercial quantum computers arrive, the elliptic curve discrete logarithm problem behind ECDSA could be broken quickly. The author describes that as a long-term threat hanging over both modern cryptography and the cryptocurrency industry, and notes that a Google paper published this year pushed the discussion closer to an engineering-level estimate of required resources.

In the author’s view, existing blockchains will eventually have to migrate, and that creates at least two layers of difficulty:

  • A technical problem: which signature algorithm and parameter set to choose, and how a live chain can replace its cryptographic core without shutting down.
  • A governance problem: if migration is voluntary, it may take an extremely long time; if it is mandatory, the question becomes whether coins that do not move should be frozen, including Satoshi Nakamoto’s holdings.

The article adds that privacy chains face an even harder version of the same issue because quantum computing threatens not only balances but also the privacy of historical transactions. Against that backdrop, the author says Quantus has a clear positioning: instead of going through a painful migration later, it starts from day one in a post-quantum environment and aims to be a "post-quantum Bitcoin with privacy."

Using a NIST standard is the easy part; signature size is the hard part

According to the review, Quantus uses the lattice-based signature scheme ML-DSA from the NIST post-quantum standards and supports two parameter sets:

SchemeNIST security levelPublic keySignaturePositioning
ML-DSA-65Level 3~1,952 bytes~3,309 bytesWallet default
ML-DSA-87Level 5~2,592 bytes~4,627 bytesConservative option

The author says keeping both options makes sense. ML-DSA-87 is more conservative and offers a larger security margin, but it also produces larger signatures. ML-DSA-65 is expected to be the default for most users, while ML-DSA-87 may appeal more to institutions or users who want a wider safety margin.

The review stresses that adopting a NIST post-quantum standard on day one is not the most technically demanding part. The real challenge is what comes after that choice. A Bitcoin ECDSA signature plus public key is roughly a little over 100 bytes, while ML-DSA-65 reaches more than 5,000 bytes, nearly 50 times larger, according to the article. Because block space is limited, the author says a post-quantum chain’s QTPS usually falls at least one order of magnitude below conventional TPS. If BTC copied Quantus directly, the article estimates throughput could drop from 7 to 10 TPS to below 1 QTPS.

The white paper’s own throughput table for transparent transfers, under a 12-second block time and 3.75 MB block size, is cited as follows: transparent transfers using ML-DSA-87 are about 7.3 KB each, around 510 transactions per block, and about 43 QTPS; transparent transfers using ML-DSA-65 are about 5.4 KB each, around 690 transactions per block, and about 58 QTPS.

The author says 40 to 50-plus QTPS is enough for a chain positioned as a store of value, but not the end state.

STARK moves signatures off-chain and creates privacy at the same time

The review says the most elegant part of the Quantus design is its use of zero-knowledge proofs to address scaling and privacy together.

The article first draws a distinction between two broad proof families. SNARK systems often rely on assumptions such as elliptic-curve pairings, and those assumptions sit within the reach of Shor’s algorithm. STARK systems rely only on hash functions. In that setting, the relevant quantum threat is Grover’s algorithm and its square-root speedup, which can be handled by increasing security parameters. Quantus, according to the white paper, uses Plonky2, described in the article as a STARK-like system based on FRI commitments, together with the Poseidon2 hash function. The author says that means the privacy pipeline avoids assumptions that quantum computers could directly break.

Quantus calls its privacy transfer mechanism a Wormhole address. The article breaks the flow into three steps.

Entering the Wormhole

A user computes an address as H(H(salt | secret)). The review says a normal address is a single hash of a public key, while this double-hashed address has no corresponding private key. Coins sent there effectively go into a black hole that no one can spend from directly.

The receipt

Each block header commits to a Poseidon2 Merkle tree, referred to in the article as a zk-tree, that records each incoming transfer. Later, the user can prove in zero knowledge that they know the secret for a given Wormhole address and that the address did receive the funds, without revealing which deposit it was.

Exiting the Wormhole

Using that ZK receipt, the user remints the coins on-chain and sends them to any normal address or another Wormhole address. The public inputs of the proof are only the nullifier, a recent block hash, the amount, and the destination address.

The author says the result is that observers see funds sent to what looks like an ordinary address and then left untouched, while elsewhere someone appears to withdraw coins out of thin air. The source address is never debited on-chain, and nothing on-chain points back to it directly.

More important, each exit does not need to carry a roughly 5,000-byte ML-DSA signature on-chain. It only needs a STARK proof that can be aggregated. The article says Quantus uses two aggregation layers:

  • A private batch layer, where a wallet can package up to seven exits into one proof, shuffle the slots, and fill empty slots with dummy proofs. Observers cannot be sure how many real transfers are in a batch.
  • A public batch layer, where miners or professional aggregators combine up to 53 private batches into one public proof and take part of the fees.

That means 7 × 53, or 371 privacy transfers, can share one proof of about 266 KB, according to the white paper figures cited in the article. The review says this pushes privacy-transfer throughput above transparent-transfer throughput by an order of magnitude:

ModeTransactions per blockQTPS
Privacy transfers (current mainnet figure)~5,200~430
Privacy transfers (theoretical limit)~33,000~2,800

The author’s conclusion is that on Quantus, privacy is not an expensive optional feature. It is the cheaper scaling path. The review calls that the strongest idea in the white paper because it runs against the usual assumption that privacy always comes with a performance penalty.

The article also notes that the white paper includes implementation details on multisig wallets, advanced accounts with guardians and timelocks, and HD-Lattice wallet derivation, though those sections are not discussed in depth.

Privacy trade-offs: closer to Tornado Cash than Monero

The review is explicit that Quantus’ privacy model is not the same as Monero’s. Wormhole transfers hide the link between sender and receiver, but they do not hide the amount. Both the deposit and withdrawal amounts remain visible on-chain. The author says that makes the model closer to Tornado Cash-style link breaking than to XMR or the ZEC shielded pool, where amounts are also concealed.

The white paper itself, as quoted in the article, acknowledges that if an observer can match a suspiciously timed deposit and withdrawal with the same amount, the anonymity set narrows. To reduce that risk, the wallet uses 0.01 QTC increments for privacy transfers so that many transactions share the same amount, and it adds dummy proofs inside batches to dilute the anonymity set.

The author’s practical conclusions are straightforward:

  • Large transfers, unusual amounts, and quick in-and-out behavior all weaken privacy.
  • Wormhole addresses receiving mining rewards are structurally identifiable, so miners need to be careful.
  • The anonymity set depends on how many people are using the system at the same time, which means privacy is thinner during quiet periods.

Monetary policy: 21 million cap, no halving, and fee burning to refill the security budget

The article says Quantus positions QTC as a store-of-value asset closer to BTC, XMR, and ZEC than to smart-contract platforms such as ETH or SOL. It therefore uses a classic proof-of-work design, with the Poseidon2 hash function, GPU-friendly mining, a 12-second block time, and a hard cap of 21 million coins.

Its issuance curve differs from Bitcoin’s. There is no four-year halving cycle. Instead, the block reward is defined as:

block_reward = (max_supply − current_supply) / 50,000,000

That means one fifty-millionth of the remaining mineable supply is released each block, creating a smooth exponential decay curve. Using ln 2 × 50,000,000 blocks × 12 seconds, the author estimates a half-life of about 13.2 years. In other words, the remaining mineable supply halves roughly every 13 years.

On top of that, Quantus implements a burn mechanism that the article compares with the Zcash community’s NSM proposals:

  • Transparent transfers: all fees go to miners.
  • Privacy transfers: half the fee goes to miners and half is burned.

The review explains that burned coins reduce current_supply, effectively returning them to the not-yet-mined pool, where they are reissued to future miners along the same exponential curve. In the article’s example, burning 1 QTC today would lead to about 0.5 QTC being re-mined over the next 13 years, with the rest released over a longer period. The author describes this as a way to smooth fee income into the future and ease the long-term decline in proof-of-work security budgets.

Still, the article does not treat that as a full solution. It says the mechanism depends on sustained privacy-transfer activity, and the amount recycled depends on total fees paid. By contrast, Monero’s tail emission is fixed at 0.6 XMR every two minutes regardless of usage. The author frames the difference as one model where the budget exists only if people use the network, and another where the budget exists no matter what.

Fee design creates a strong split between transparent and private transfers

The review highlights a detail in Quantus’ fee structure:

  • Transparent transfers cost a fixed ~0.0062 QTC, or ~0.0081 QTC under ML-DSA-87, regardless of amount.
  • Privacy transfers cost 0.04% of the transferred amount, with a minimum fee of 0.01 QTC. That means transfers below 25 QTC all pay the 0.01 QTC minimum, and only larger transfers move to percentage-based pricing.

The author says this creates a strong incentive for large transfers to use transparent addresses. In the example given, sending 1,000 QTC would still cost 0.0062 QTC through a transparent transfer, but 0.4 QTC through a privacy transfer, a gap of more than 60 times. The likely result, according to the article, is that privacy addresses will be used mostly for many small transfers.

The author says that logic resembles the layering seen in traditional finance: small everyday payments behave more like anonymous cash, while large transfers resemble named bank wires. But the design also creates two side effects:

  • Large amounts rarely enter the privacy pipeline, so the privacy pool skews small. Since large transfers are already easier to match by amount, the users who most need privacy for large transfers may find it hardest to get on Quantus.
  • Burning and security-budget refill depend mainly on the minimum fees paid by small privacy transfers, which weakens the smoothing effect described earlier.

The author’s biggest concern: a 27% genesis premine

The article says tokenomics is where the main risk sits. Although Quantus has a 21 million maximum supply, 27% of that total, or 5.67 million QTC, was premined in the genesis block. The allocation is described as follows:

  • Founders, team, and investors: 23%, or 4.83 million QTC, locked for one year after mainnet launch and then released linearly over 36 months, enforced on-chain.
  • Company: 4%, or 840,000 QTC. Of that, 3% follows the same one-year lock plus 36-month linear unlock schedule, while 1% was unlocked at genesis. The author estimates that portion may be intended for operating needs such as listing fees or NEAR Intents liquidity.

The review points out that the white paper says there is "no developer tax" and miners receive all block rewards. The author says that statement is technically correct, but argues that the developer tax did not disappear; it was collected upfront in the genesis block.

Using the issuance formula and unlock schedule from the white paper, and assuming a 12-second average block time, no burning, and no schedule changes, the author presents the following supply snapshots:

Point in timeTotal issuedMined supplyGenesis allocationGenesis share
End of year 1~6.45 million~790,0005.67 million (mostly still locked)~88%
End of year 4~8.58 million~2.91 million5.67 million (fully unlocked)~66%
End of year 10~11.94 million~6.27 million5.67 million~47%

The author argues that for a chain marketed as a store-of-value asset and benchmarked against Bitcoin, miners would have produced less than 3 million coins by the end of year four, while the 5.67 million QTC held by the team, investors, and company would already be fully unlocked. Even by year 10, mined supply would only just catch up with the genesis allocation.

The article ties that directly to the 13.2-year half-life of the smooth issuance curve. The flatter the issuance path, the less miners receive early on, and the larger the premine’s share of circulating supply becomes in the early years. Bitcoin released half its total supply in the first four years, the author notes, while Quantus miners would not reach half of the mineable supply until around year 13. In the author’s view, smooth issuance is a good design on its own, but paired with a 27% premine it leaves early ownership heavily tilted toward insiders.

For comparison, the article notes that Bitcoin and Monero had no premine. Zcash’s Founders’ Reward amounted to 20% of block rewards over the first four years, or about 10% of total supply, and was distributed gradually through mining, yet still triggered years of debate in the community. The author says Quantus’ insider allocation is close to three times ZEC’s and was assigned at genesis.

The review also adds an important caveat: the chart shows supply sources, not current holders. Unlocked does not mean sold. The team could hold long term or use part of the allocation for ecosystem development. Even so, the author says that for an asset seeking to become a "post-quantum Bitcoin," the market will have to absorb a continuing unlock schedule from year two through year four, creating a structural overhang that holders need to take seriously.

Liquidity remains limited, and the conclusion is cautious

The article says that at the time of writing, Quantus had not yet connected to NEAR Intents and was not listed on major exchanges, leaving OTC trading or mining as the main ways to obtain the asset. Liquidity, the author says, is another issue that still needs time to be tested.

In the closing section, the author says Quantus takes ideas from BTC and ZEC and reworks them into a post-quantum store-of-value design: adopt a NIST post-quantum standard from day one to avoid a future migration, then use a hash-only STARK system to aggregate large signatures off-chain and gain both higher QTPS and link-breaking privacy. The burn-and-reissue mechanism also shows, in the author’s view, that the team has thought seriously about the long-term security budget of a proof-of-work chain, even if the mechanism only eases the problem rather than solving it.

On the technical side, the author calls it one of the most interesting public-chain white papers read this year. On tokenomics, the conclusion is much more guarded. A 27% premine combined with full unlock over the first four years is described as a major concern, especially for a network positioned as a store-of-value asset. With liquidity still limited, the author’s bottom line is clear: worth studying, worth trying through mining, but heavy positioning deserves caution.

References cited in the article

The review lists the Quantus white paper, NIST FIPS 204 for the ML-DSA standard, and Zcash ZIP 233 and ZIP 234 among its main references. It also says the 13.2-year half-life estimate comes from ln 2 × 50,000,000 blocks × 12 seconds, and that the supply chart was calculated from the white paper’s issuance formula and unlock schedule under assumptions of a 12-second average block time, 365 days per year, no burning, and no schedule changes. Under those assumptions, total issued supply at the end of years 1, 4, and 10 is about 6.4549 million, 8.5767 million, and 11.9369 million QTC, respectively.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.