Anza Researchers Propose Quantumglow: Post-Quantum Alpenglow Without the Speed Trade-off
Anza published Quantumglow on July 30: a post-quantum Alpenglow variant replacing BLS with a hash-based Ax scheme while claiming the same consensus latency.
Anza researchers Quentin Kniep, Kobi Sliwinski, and Roger Wattenhofer published a blog post on July 30 introducing Quantumglow: a post-quantum adaptation of Alpenglow, Solana's upcoming consensus protocol, that claims to match Alpenglow's finality latency under normal network conditions while replacing every elliptic-curve primitive with quantum-resistant alternatives.
The paper comes as Alpenglow moves toward mainnet. Anza shipped the full Alpenglow codebase in Agave 4.2, with mainnet activation targeting the Agave 4.3 release planned for October 2026. Quantumglow is forward-looking research, not a scheduled deployment, but the core claim (that Alpenglow's performance can survive a post-quantum migration) matters for the protocol's long-term credibility.
Why Dropping BLS Into a Quantum-Resistant Scheme Does Not Work
Alpenglow relies on BLS12-381 signatures for validator votes and certificate aggregation. BLS is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer, which makes it a target worth planning around. The obvious response, swapping BLS for a NIST-standardised post-quantum scheme, runs into a specific physical constraint.
Alpenglow's shred-propagation design fits each shred into a single network packet. According to the Quantumglow paper, BLS signatures are 96 bytes, while Falcon-512, one of the most compact NIST-approved post-quantum signatures, is 666 bytes; CRYSTALS-Dilithium runs larger still. A direct substitution would exceed the single-packet budget, forcing either a protocol redesign around multi-packet shreds or a fragmentation scheme that adds latency and complexity.
The aggregation problem is harder. BLS lets a node compress thousands of validator votes into a 192-byte certificate with a bitmask, per the paper. No post-quantum scheme achieves constant-size aggregation: the best current alternatives produce certificates in the tens to hundreds of kilobytes, which would balloon the data validators must receive before finalising a block.
Ax: A Hash-Based Signature Scheme Built for Alpenglow
Rather than adapt an off-the-shelf post-quantum scheme, the Quantumglow researchers designed Ax (Alpenglow XMSS), a custom hash-based signature scheme whose security depends only on the collision resistance of a cryptographic hash function, a property that quantum computers cannot attack efficiently.
The core compression technique exploits Alpenglow's validator-set structure. Validators pre-exchange and cache each other's public keys at protocol startup, so Merkle authentication paths (which account for the bulk of XMSS signature size) can be omitted from individual messages. Certain message types (skip and finalize votes) reduce further: a validator authenticates by revealing a single secret value rather than a full signature. The result is a signature footprint that fits inside Alpenglow's single-packet constraint.
Replacing Aggregation With Approval Messaging
The aggregation problem required a different approach. Quantumglow abandons certificate aggregation entirely and replaces it with a lightweight approval messaging mechanism: when a validator has observed enough votes or enough approvals from other validators to be confident a block will be finalised, it broadcasts a single signed approval to the rest of the network.
This is structurally similar to Bracha-style reliable broadcast. Each validator's approval is independently signed with Ax, so there is no aggregation step and no aggregator infrastructure. The trade-off is that the network must transmit O(n) approval messages instead of one aggregated certificate, but the Anza researchers argue this cost lands on a path that is not latency-critical in normal operation.
Under Quantumglow, certificates become local protocol events rather than network messages. A node collects incoming approvals and issues its own local certificate when its threshold is reached. No certificate is propagated across the network; the certificate is evidence of local observation, not a network-layer object. This is a structural departure from Alpenglow, where certificates travel as distinct messages.
Quantumglow introduces two local certificate types: a fast certificate that preserves Alpenglow's finality latency, and a slower certificate that handles robustness and fault tolerance in degraded conditions. The paper describes these as complementary; the interplay between them is what prevents performance degradation under normal network behaviour.
Quantumglow Claims Alpenglow's Finality Latency Under Normal Conditions
The central performance claim is that block finalisation under Quantumglow occurs at the same latency as Alpenglow when 80% of stake votes for notarisation, which is the threshold that triggers the fast path. In that scenario, no additional approval round is needed: the validator already has enough votes to issue a fast certificate locally, and the approval messaging mechanism is not on the critical path.
Extra communication rounds occur only during abnormal conditions: serious validator misbehaviour or network problems that prevent the fast threshold from being reached quickly. The paper describes these as "slower fallback execution paths" rather than the expected runtime behaviour.
Communication costs remain comparable to Alpenglow overall, and safety and liveness properties are preserved under the same security assumptions, per the paper.
Alpenglow Targets October 2026 Mainnet; Quantumglow Is Forward-Looking Research
Alpenglow has been an active area of protocol work across the Solana client ecosystem. Anza ran a bug bounty targeting four Alpenglow components in July, and the Mithril Go-based validator client produced blocks on the Alpenglow test cluster in June, a sign the ecosystem is converging on the protocol ahead of the October mainnet target.
Quantumglow is not part of the October deployment. The paper is a research contribution that Anza published alongside a broader quantum readiness post examining the four categories of cryptographic exposure in Solana's current protocol: accounts, block propagation, consensus, and user programs. The Quantumglow paper focuses specifically on consensus and is formally incorporated into the Alpenglow White Paper v1.2, published July 29, 2026. Full technical specifications, proofs, and signature size comparisons appear in Section 5 of that paper.
Anza has a credible technical path to post-quantum consensus that does not require giving up the latency gains Alpenglow introduces. Whether that path gets activated, and when, depends on how the quantum computing threat develops.
Comments
Please login to leave a comment.
Contents
- Why Dropping BLS Into a Quantum-Resistant Scheme Does Not Work
- Ax: A Hash-Based Signature Scheme Built for Alpenglow
- Replacing Aggregation With Approval Messaging
- Quantumglow Claims Alpenglow's Finality Latency Under Normal Conditions
- Alpenglow Targets October 2026 Mainnet; Quantumglow Is Forward-Looking Research
Related Content
What Is Alpenglow: Solana's Largest Protocol Upgrade Ever | Brennan Watt, Anza
Alpenglow: Solana's 100x Improvement
Alpenglow: Solana's Largest Protocol Upgrade Ever | Brennan Watt, Anza
Scale or Die at Accelerate 2025: Introducing Alpenglow - Solana's New Consensus
What Solana's Alpenglow Upgrade Changes: Validator Costs, Finality, and 96% Fast-Path Finalization from the Test Cluster
The State of the Network: Anza
Solana's Path To Decentralized Nasdaq | Max Resnick
Jump Crypto: The State Of Firedancer | Michael McGee
Breakpoint 2025: Anza Block
Mithril Produces Blocks on Alpenglow Test Cluster, Making Solana's Fourth Validator Client a Reality
Anza Announces Alpenglow Bug Bounty Competition Before Solana Consensus Mainnet
Anza Publishes Agave 4.3 Release Schedule: Alpenglow Consensus Targets September 28 Mainnet Activation
Agave 4.2 Ships 90% Rent Reduction, 3.3x Larger Transactions, 200ms Slots, and a 50,000 SOL Bug Bounty
Are DATs Bullish For Solana? | Carlos Gonzalez Campo
Jump Crypto: How To Improve Solana?
Latest news
Solana Tokenized Equity Supply Reaches $465M as Raydium Crosses $4B in Cumulative
South Korea's Shinhan Asset Management Signs Four-Party MOU with Solana Foundation, Orca, and Etherfuse for KRW Tokenized Fund
Arbital Opens to the Public on Solana After $1.35B in Private Volume
Ramp Adds x402 AI Agent Wallets on Solana, Giving 70,000+ Businesses Autonomous Payment Capabilities
Solana Cuts Slot Time to 350ms at Epoch 1020, First Reduction Since Network Launch
Kamino's Share of Onchain RWA Lending Has Climbed from 2% to 18% Since October
Solflare Launches Merchant Cashback, Earning USDC at Nike, Best Buy, and 4,000+
Jupiter Portfolio v2 Adds Active DeFi Position Management to Solana's Most-Used Dashboard
Raydium LaunchLab Mandates CPMM-Only Graduation and Locks Creator LP at Token Migration
Backpack Securities Captured 87% of Tokenized SpaceX Trading Volume in Q2, Leading on Six of Nine Shared Stocks
Solana Token Markets