Coin Brief ENDE

Researchers outline a post-quantum upgrade path for Ethereum stealth addresses

Two posts published on the Ethereum Research forum on 28 September continue a series on making Ethereum's Stealth Address Protocol resistant to quantum computers. The author, posting as namnc, thanks several collaborators and has published an accompanying code repository for the scheme the posts recommend as a first step.

Stealth addresses let a receiver publish one meta-address while senders derive a fresh one-time address for each payment, so payments to the same person cannot be linked. On Ethereum this relies on two on-chain components: a registry where receivers publish their keys (ERC-6538) and an announcer where senders post the data a receiver needs to find a payment (ERC-5564). Receivers typically use separate viewing and spending keys, so scanning can be delegated without giving away the ability to spend.

The posts spell out the quantum threat plainly. Because the registry and announcements stay on chain permanently, a quantum attacker could recover the sender's ephemeral secret, the receiver's viewing key and the spending key from the published public values, and so see and spend every stealth payment to those addresses. The proposed upgrades target the two cryptographic building blocks: replacing elliptic-curve Diffie-Hellman with ML-KEM to protect payment discovery and unlinkability, covered in the "PQ anonymity" post, and replacing ECDSA-based spending to protect the funds themselves, covered in the "PQ spending" post. They define new scheme identifiers and discuss what changes for the existing registries and scanning services. The posts also note a limitation that already applies today: sender anonymity is not guaranteed, because the sender's account funds the payment and makes the announcement.

Researchers outline a post-quantum upgrade path for Ethereum stealth addresses
Researchers outline a post-quantum upgrade path for Ethereum stealth addresses — Coin Brief

What it means

Stealth addresses have a specific quantum problem that ordinary accounts do not: the data a receiver needs is published deliberately and permanently. That makes them a "harvest now, decrypt later" target - anything announced today can be analysed once a capable quantum computer exists, even if signatures are upgraded later.

Separating privacy (discovery) from custody (spending) is a sensible way to stage the work, since the two carry different costs. These are research posts, not EIPs; adoption would need wallet support and changes to the ERC-5564 and ERC-6538 standards.