LatticeScan

Overview

Everything LatticeScan does, on one page

The threat is simple to state: a large enough quantum computer recovers a private key from a public one, and on Bitcoin and Ethereum a public key is revealed the first time an address is spent from. The money question is then not “is quantum coming” but “how much of what I hold is already behind a revealed key, and who can prove they owned it first.” Each tool below answers one part of that. Everything produces signed documents that a second party can verify without trusting us, and everything follows one open standard.

The standard: Proof of Quantum Solvency v1

How do you measure quantum exposure so that two parties get the same number?

An open specification (CC BY 4.0) that defines exposure classes, the solvency arithmetic, risk tiers, policy attestations, the signed document format, Bitcoin anchoring, and the ownership-commitment format. It ships with a reference verifier, one file with no dependencies, that checks signature, anchor and arithmetic of any document we issue.

For. Auditors, regulators, anyone who wants to check our work or become an assessor under the same rules.

Verify. Download the verifier from the spec page and run it on any document you are handed.

Quantum Solvency Index

How much of an exchange’s or a country’s reserve is already exposed?

Every reserve that has published its address set, scored against public chain data: the share not behind an already-revealed public key. Today 3 reserves, 801,268 BTC scored, 23.0% market quantum solvency; best El Salvador Strategic Bitcoin Reserve at 100.0%. Each snapshot is signed with our ML-DSA-65 key and its hash is stamped into Bitcoin.

For. Users choosing where to hold, analysts, journalists, the exchanges themselves.

Verify. Every row links to its signed snapshot and the OpenTimestamps proof.

Exposure

Is this address, or this set of addresses, exposed right now?

Paste Bitcoin or Ethereum addresses and get the classification per address (pay-to-public-key, Taproot, reused, spent-from, hash-protected; on Ethereum, any account that has sent), the exposed balance, the practical-risk tier, and a signed report. A PDF version is one click away.

For. Individual holders, treasurers, anyone doing due diligence on a counterparty.

Verify. The report carries a signature; the verifier recomputes the arithmetic.

Reserve attestations

Does this reserve follow its stated key-hygiene policy, and did it last week too?

A holder states a policy (for example, no more than a set amount behind any one key, or hash-protected addresses only). We check the published address set against it on a schedule and issue a signed pass/fail report each time, with every finding listed. El Salvador’s national reserve is the first public attestation.

For. Exchanges, custodians, sovereign and corporate treasuries, and the people who audit them.

Verify. Each attestation is a signed document; the verifier checks that the verdict follows from the findings.

Post-quantum ownership registry

When a classical key is finally broken, who was the owner first?

A holder signs a statement with the key that controls an address today, naming a post-quantum (ML-DSA-65) public key of their own. We verify the signature by recovering the public key and deriving the address, record the commitment, and stamp it into Bitcoin. Nothing moves. 0 commitments on record.

For. Any holder; wallets that want to file commitments automatically; custodians and courts settling later disputes.

Verify. Every record is public, with the signature and the timestamp proof, and re-verified from its own bytes on every lookup.

Canary

Will I know the moment my address becomes exposed?

Watch an address; get one email when its public key is first revealed on-chain. Free, one-click unsubscribe, nothing stored beyond the email and the address.

For. Long-term holders, treasurers, anyone with cold storage they rarely touch.

Verify. The confirmation email states the address’s current classification, so you can check it against Exposure.

Score the room

What does a whole audience’s exposure look like, live?

A shared screen for a conference or a team: everyone submits an address, the running total and the exposed share update on the big screen. No addresses are shown, only totals.

For. Event organisers, security teams running a workshop.

Verify. Same classification engine as Exposure.

Evidence pack

How do I file this in the language my regulator uses?

The same measurements mapped to control language from DORA, FINMA, MAS and the FCA, and to NIST’s migration guidance, as a signed PDF and JSON.

For. Compliance teams at regulated custodians and exchanges.

Verify. Signed like every other document.

Data feed, badges and widget

How does another site show these numbers without asking us?

One versioned JSON document with every scored reserve, the market number, pending reserves and registry totals; a CSV; SVG badges per reserve, for the market and per registered address; and a script-free widget for an iframe. Programmatic access is by API key, issued to partners.

For. Data platforms, dashboards, researchers, exchanges that want the badge on their Proof of Reserves page.

Verify. The feed is signed; the verifier recomputes its market number from its rows.

Open letter

What are we asking exchanges to do?

Publish the address set, stop reusing keys, keep large balances hash-protected, and commit post-quantum keys for treasury addresses. Signed and anchored like everything else, so the date of the ask is on record.

For. Exchanges, and the users who want to forward it to theirs.

Verify. Signed document.

Internet-facing scanner

Does this company’s public infrastructure already use post-quantum key exchange?

Where LatticeScan started: scan a domain’s TLS endpoints for hybrid post-quantum key exchange, grade it, and produce a cryptographic bill of materials. The chain-side tools above answer the money question; this one answers the network question.

For. Security teams, procurement, anyone checking a vendor.

Verify. The report lists every endpoint and cipher observed.

How it fits together

The standard defines the measurement. The index, Exposure, attestations and the evidence pack apply it to reserves and addresses. The registry records who owned what before the break. Canary tells a holder the moment their own status changes. The feed and badges carry the numbers to other sites. The scanner covers the network side of the same migration. Everything is signed with one published key and anchored in Bitcoin, and the verifier checks all of it.