PQM-1
Status: Wallet-recovery format. Not an audited key-management system. This crate implements the deterministic mnemonic payload and seed derivation specified by PQM-1. It does not custody keys, manage passphrases, implement hardware-wallet flows, or define any chain's account/address format.
PQM-1 is a 24-word BIP-39-compatible mnemonic format for post-quantum signing keys. It reuses the BIP-39 English wordlist and checksum machinery, but the 32-byte entropy payload is interpreted as:
offset length field
0 1 algorithm tag: 0x01 = ML-DSA-65
1 1 version: 0x01 = PQM-1 v1
2 30 entropy: 240 bits
The payload is expanded into an ML-DSA-65 seed with SHAKE256:
seed = SHAKE256(profile_domain || payload, 32)
The default Monolythium profile domain is:
monolythium.pqm1.v1.mldsa65
Other chains can adopt the same PQM-1 payload shape while defining their own profile domain and account/address derivation.
What it is
- A self-describing 24-word phrase format for post-quantum wallet backup.
- A deterministic KDF from phrase payload to 32-byte ML-DSA-65 seed.
- A small bytes-oriented API with zero Monolythium chain types.
- A reference implementation with golden vectors.
What it is not
- Not BIP-32 or BIP-44. PQM-1 v1 encodes one account per phrase.
- Not compatible with MetaMask-style BIP-39 -> secp256k1 mnemonics.
- Not a key vault or encrypted keystore.
- Not a chain address standard. Address derivation is intentionally profile- specific and lives above this crate.
Minimal usage
use ;
let mut rng = OsRng;
let phrase = generate_mnemonic.unwrap;
let payload = from_mnemonic.unwrap;
let mono_seed = payload.derive_mldsa65_seed;
let near_profile = Pqm1Profile ;
let near_seed = payload.derive_mldsa65_seed_with_profile;
assert_ne!;
Interop rule
If a wallet sees a 24-word BIP-39 phrase whose first payload byte is not
0x01, or whose version byte is not 0x01, it must reject explicitly. Silent
fallback to BIP-32/secp256k1 derivation is an address-loss footgun.
License
Apache-2.0. See LICENSE.