Anza Researchers Propose Quantumglow: Post-Quantum Alpenglow Without the Speed Trade-off
Anza published Quantumglow on July 30: a post-quantum Alpenglow variant replacing BLS with a hash-based Ax scheme while claiming the same consensus latency.
Anza researchers Quentin Kniep, Kobi Sliwinski, and Roger Wattenhofer published a blog post on July 30 introducing Quantumglow: a post-quantum adaptation of Alpenglow, Solana's upcoming consensus protocol, that claims to match Alpenglow's finality latency under normal network conditions while replacing every elliptic-curve primitive with quantum-resistant alternatives.
The paper comes as Alpenglow moves toward mainnet. Anza shipped the full Alpenglow codebase in Agave 4.2, with mainnet activation targeting the Agave 4.3 release planned for October 2026. Quantumglow is forward-looking research, not a scheduled deployment, but the core claim (that Alpenglow's performance can survive a post-quantum migration) matters for the protocol's long-term credibility.
Why Dropping BLS Into a Quantum-Resistant Scheme Does Not Work
Alpenglow relies on BLS12-381 signatures for validator votes and certificate aggregation. BLS is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer, which makes it a target worth planning around. The obvious response, swapping BLS for a NIST-standardised post-quantum scheme, runs into a specific physical constraint.
Alpenglow's shred-propagation design fits each shred into a single network packet. According to the Quantumglow paper, BLS signatures are 96 bytes, while Falcon-512, one of the most compact NIST-approved post-quantum signatures, is 666 bytes; CRYSTALS-Dilithium runs larger still. A direct substitution would exceed the single-packet budget, forcing either a protocol redesign around multi-packet shreds or a fragmentation scheme that adds latency and complexity.
The aggregation problem is harder. BLS lets a node compress thousands of validator votes into a 192-byte certificate with a bitmask, per the paper. No post-quantum scheme achieves constant-size aggregation: the best current alternatives produce certificates in the tens to hundreds of kilobytes, which would balloon the data validators must receive before finalising a block.
Ax: A Hash-Based Signature Scheme Built for Alpenglow
Rather than adapt an off-the-shelf post-quantum scheme, the Quantumglow researchers designed Ax (Alpenglow XMSS), a custom hash-based signature scheme whose security depends only on the collision resistance of a cryptographic hash function, a property that quantum computers cannot attack efficiently.
The core compression technique exploits Alpenglow's validator-set structure. Validators pre-exchange and cache each other's public keys at protocol startup, so Merkle authentication paths (which account for the bulk of XMSS signature size) can be omitted from individual messages. Certain message types (skip and finalize votes) reduce further: a validator authenticates by revealing a single secret value rather than a full signature. The result is a signature footprint that fits inside Alpenglow's single-packet constraint.
Replacing Aggregation With Approval Messaging
The aggregation problem required a different approach. Quantumglow abandons certificate aggregation entirely and replaces it with a lightweight approval messaging mechanism: when a validator has observed enough votes or enough approvals from other validators to be confident a block will be finalised, it broadcasts a single signed approval to the rest of the network.
This is structurally similar to Bracha-style reliable broadcast. Each validator's approval is independently signed with Ax, so there is no aggregation step and no aggregator infrastructure. The trade-off is that the network must transmit O(n) approval messages instead of one aggregated certificate, but the Anza researchers argue this cost lands on a path that is not latency-critical in normal operation.
Under Quantumglow, certificates become local protocol events rather than network messages. A node collects incoming approvals and issues its own local certificate when its threshold is reached. No certificate is propagated across the network; the certificate is evidence of local observation, not a network-layer object. This is a structural departure from Alpenglow, where certificates travel as distinct messages.
Quantumglow introduces two local certificate types: a fast certificate that preserves Alpenglow's finality latency, and a slower certificate that handles robustness and fault tolerance in degraded conditions. The paper describes these as complementary; the interplay between them is what prevents performance degradation under normal network behaviour.
Quantumglow Claims Alpenglow's Finality Latency Under Normal Conditions
The central performance claim is that block finalisation under Quantumglow occurs at the same latency as Alpenglow when 80% of stake votes for notarisation, which is the threshold that triggers the fast path. In that scenario, no additional approval round is needed: the validator already has enough votes to issue a fast certificate locally, and the approval messaging mechanism is not on the critical path.
Extra communication rounds occur only during abnormal conditions: serious validator misbehaviour or network problems that prevent the fast threshold from being reached quickly. The paper describes these as "slower fallback execution paths" rather than the expected runtime behaviour.
Communication costs remain comparable to Alpenglow overall, and safety and liveness properties are preserved under the same security assumptions, per the paper.
Alpenglow Targets October 2026 Mainnet; Quantumglow Is Forward-Looking Research
Alpenglow has been an active area of protocol work across the Solana client ecosystem. Anza ran a bug bounty targeting four Alpenglow components in July, and the Mithril Go-based validator client produced blocks on the Alpenglow test cluster in June, a sign the ecosystem is converging on the protocol ahead of the October mainnet target.
Quantumglow is not part of the October deployment. The paper is a research contribution that Anza published alongside a broader quantum readiness post examining the four categories of cryptographic exposure in Solana's current protocol: accounts, block propagation, consensus, and user programs. The Quantumglow paper focuses specifically on consensus and is formally incorporated into the Alpenglow White Paper v1.2, published July 29, 2026. Full technical specifications, proofs, and signature size comparisons appear in Section 5 of that paper.
Anza has a credible technical path to post-quantum consensus that does not require giving up the latency gains Alpenglow introduces. Whether that path gets activated, and when, depends on how the quantum computing threat develops.
Comments
Please login to leave a comment.
Contents
- Why Dropping BLS Into a Quantum-Resistant Scheme Does Not Work
- Ax: A Hash-Based Signature Scheme Built for Alpenglow
- Replacing Aggregation With Approval Messaging
- Quantumglow Claims Alpenglow's Finality Latency Under Normal Conditions
- Alpenglow Targets October 2026 Mainnet; Quantumglow Is Forward-Looking Research
Related Content
What Is Alpenglow: Solana's Largest Protocol Upgrade Ever | Brennan Watt, Anza
Alpenglow: Solana's 100x Improvement
Alpenglow: Solana's Largest Protocol Upgrade Ever | Brennan Watt, Anza
Scale or Die at Accelerate 2025: Introducing Alpenglow - Solana's New Consensus
The State of the Network: Anza
Solana's Path To Decentralized Nasdaq | Max Resnick
Jump Crypto: The State Of Firedancer | Michael McGee
Mithril Produces Blocks on Alpenglow Test Cluster, Making Solana's Fourth Validator Client a Reality
Anza Announces Alpenglow Bug Bounty Competition Before Solana Consensus Mainnet
Breakpoint 2025: Anza Block
Agave 4.2 Ships 90% Rent Reduction, 3.3x Larger Transactions, 200ms Slots, and a 50,000 SOL Bug Bounty
Are DATs Bullish For Solana? | Carlos Gonzalez Campo
Jump Crypto: How To Improve Solana?
Solana Changelog - Mar 12 - Solana hackathon, Anza fork, Anchor IDLs, Windows support
The State Of Solana DeFi With Kyle Samani & Chris Heaney
Latest news
Pyth Network Adds 100+ Korean Equities โ Samsung, SK Hynix, NAVER, Kakao โ to Pyth Pro
Anza Researchers Propose Quantumglow: Post-Quantum Alpenglow Without the Speed Trade-off
Solana Mobile Opens Seeker Summer Round 2 With 27M SKR as Round 1 Staking Tops 50%
Bitwise Rebrands Ledger Wallet Validators From Chorus One to 'Ledger by Bitwise' on Solana, Cosmos, and Injective
Solana's First 48 Hours With 100M CU Blocks: P90 Fees Fall 30%, Congestion Collapses
Community Vote Sends Rarible Back to Solana: Development and Audits Begin
BNY Launches Digital Transfer Agency on Blockchain with Baillie Gifford's BAGEY
Kamino Opens Third Isolated RWA Market in Four Days as Obligate's oTFY Goes Live
Solana Foundation Rebuilds Its Developer Docs With CI-Tested Code, Ecosystem Bot Scanning, and an MCP Server
Solmate Infrastructure Partners With Kraken Institutional to Stake SOL Without Moving Assets Out of Custody
Solana Token Markets