pqm1 0.1.0

Experimental post-quantum mnemonic payload format: BIP-39 24-word payloads with algorithm/version tags and SHAKE256 ML-DSA seed derivation. Unaudited.
Documentation

PQM-1

Status: Wallet-recovery format. Not an audited key-management system. This crate implements the deterministic mnemonic payload and seed derivation specified by PQM-1. It does not custody keys, manage passphrases, implement hardware-wallet flows, or define any chain's account/address format.

PQM-1 is a 24-word BIP-39-compatible mnemonic format for post-quantum signing keys. It reuses the BIP-39 English wordlist and checksum machinery, but the 32-byte entropy payload is interpreted as:

offset  length  field
0       1       algorithm tag: 0x01 = ML-DSA-65
1       1       version:       0x01 = PQM-1 v1
2       30      entropy:       240 bits

The payload is expanded into an ML-DSA-65 seed with SHAKE256:

seed = SHAKE256(profile_domain || payload, 32)

The default Monolythium profile domain is:

monolythium.pqm1.v1.mldsa65

Other chains can adopt the same PQM-1 payload shape while defining their own profile domain and account/address derivation.

What it is

  • A self-describing 24-word phrase format for post-quantum wallet backup.
  • A deterministic KDF from phrase payload to 32-byte ML-DSA-65 seed.
  • A small bytes-oriented API with zero Monolythium chain types.
  • A reference implementation with golden vectors.

What it is not

  • Not BIP-32 or BIP-44. PQM-1 v1 encodes one account per phrase.
  • Not compatible with MetaMask-style BIP-39 -> secp256k1 mnemonics.
  • Not a key vault or encrypted keystore.
  • Not a chain address standard. Address derivation is intentionally profile- specific and lives above this crate.

Minimal usage

use pqm1::{generate_mnemonic, Pqm1Payload, Pqm1Profile};

let mut rng = rand_core::OsRng;
let phrase = generate_mnemonic(&mut rng).unwrap();

let payload = Pqm1Payload::from_mnemonic(&phrase).unwrap();
let mono_seed = payload.derive_mldsa65_seed();

let near_profile = Pqm1Profile {
    mldsa65_domain_tag: b"near.pqm1.v1.mldsa65",
};
let near_seed = payload.derive_mldsa65_seed_with_profile(near_profile);

assert_ne!(&*mono_seed, &*near_seed);

Interop rule

If a wallet sees a 24-word BIP-39 phrase whose first payload byte is not 0x01, or whose version byte is not 0x01, it must reject explicitly. Silent fallback to BIP-32/secp256k1 derivation is an address-loss footgun.

License

Apache-2.0. See LICENSE.