For thirty years cryptography spread across the world because code is free to copy. Silicon is not. The last wall between strong cryptography and every home is no longer mathematics, it is manufacturing. This week someone leaned a ladder against that wall : https://t.co/KamvjwsNWC
Software is living its great acceleration. What took a team a year now takes a few people a month. Hardware has not had that moment. It moves slowly for honest reasons: tooling, supply chains, certification, and the cost of being wrong when you cannot patch a soldered chip.
But there is a clock on the locks now. Every signature guarding every wallet on earth rests on mathematics that a quantum machine will one day undo. The locks we use today will, in time, open by themselves. Slow is no longer free.
So it is a good sign to see a small team publish a whole post-quantum wallet in the open. Freedom Factory's PQ1: board schematics, firmware, and a ~$150 parts list, released while the thing is still unfinished rather than after it ships.
Open hardware has a hard edge and it is worth naming plainly. The schematics are open. The chips soldered onto them are not. The processor and both secure elements are proprietary parts from ST, Infineon and NXP, and there is no open equivalent to reach for, because none exists yet. That is the ceiling, and breaking it would change far more than wallets. The mathematics is public. The code is public. Then the chain of trust ends in a factory you are not allowed to see, and you take the last step on faith. Open that last step and the whole path becomes checkable by anyone: mathematics, code, board, silicon, verified end to end. A security supply chain with no article of faith left in it. For the first time, a person could hold something a nation state cannot quietly subvert.
The people who can break that ceiling exist. They are the avengers of hardware attack. They have started talking to each other. They are natural allies of ethereum and they chose to work with us. If they succeed, the balance of power shifts.
The right answer to a part you cannot audit is not to trust it less, it is to need it less. With PQ1, your recovery phrase is split across two secure chips from two different companies, and neither one ever holds all of it.
They also published while it is unfinished. The repo says so plainly: still being built, the audit still running. Publishing a design while people can still argue with it is harder than publishing a finished one, and braver.
Bias up front: it uses cryptography from our EF work. Find more at. I am not an investor and no money changed hands. I am happy to see the first hardware building on top of the SPHINCS minus work.
https://t.co/HZQP4WgWQ1
https://t.co/5P25DURAXa
Open research, then open plans, and one day open silicon. Cryptography will reach every home. It will arrive as objects, not only as code.
The ceiling keeps moving. Good to see people building right up against it. Godspeed PQ1 🫡
https://t.co/KamvjwsNWC