Quantumnet Makes Post-Quantum ZK Infrastructure an Operations Problem
Tezos’s new Quantumnet testnet combines post-quantum signatures, STARK-based consensus aggregation, and ZODA data availability. Its most practical lesson for ZK builders is that cryptographic migration depends as much on key lifecycle and operator tooling as on proof design.

Tezos has moved its post-quantum work from isolated protocol components into a running testnet. Quantumnet, announced on September 24, brings post-quantum manager keys, consensus keys, consensus aggregation, and data availability into one experimental network.
The ZK-relevant change is the replacement of mainnet-style BLS aggregation with a post-quantum STARK-based aggregation system developed by the LeanEthereum project. This preserves the need to aggregate consensus operations while moving away from pairing-based signatures. Quantumnet also replaces the current KZG-based Data Availability Layer with ZODA, a scheme based on hashes and erasure coding.
That combination changes the engineering question. A post-quantum system is not simply a familiar blockchain with a different signature algorithm. Quantumnet uses ML-DSA-44 for tz5 manager keys, while tz6 consensus keys use XMSS, a stateful hash-based signature scheme. The split exists because ML-DSA provides the authorization properties needed for user operations, while the consensus path still needs a way to aggregate signatures efficiently.
The operational consequence is significant: XMSS keys have a finite signature budget. The Quantumnet tutorial sizes the key for 131,071 signatures—roughly three days of baking—and rotation is currently manual. Octez does not yet warn operators when that budget is being depleted. This is a non-blocking but important caveat: Quantumnet is experimental, not production infrastructure, and its first iteration exposes unfinished key-management workflows by design.
Tezos’s own engineering milestone shows why aggregation remains an open problem. Its post-quantum signature-aggregation work is explicitly experimental and tracks the integration of XMSS, LeanMultisig, new protocol interfaces, gas costs, and testnet validation. In other words, the proof system cannot be evaluated separately from serialization limits, consensus operations, and operator procedures.
For ICP and other ZK builders, the useful takeaway is a testing checklist rather than a claim that Quantumnet is ready to copy. When a proof or signature primitive is stateful, expose remaining capacity as a first-class metric. Test rotation and recovery before benchmarking throughput. Measure aggregation costs at the protocol boundary, including message size, verification time, and failure behavior. Finally, keep experimental networks disposable: Quantumnet’s maintainers explicitly warn that future iterations may restart from a fresh chain and that balances and history should not be expected to persist.
Quantumnet therefore matters less as a finished post-quantum design than as a live integration experiment. It puts ZK-style aggregation, cryptographic migration, data availability, and operator safety in the same test environment—exactly where hidden assumptions become visible.
Get the wire in your inbox
Every new signal, straight from the generator. No noise, unsubscribe anytime.


