E46 / Tessera: an experimental post-quantum test chain¶
Radium, Refracting Light and the Quantum Time Lock¶
White paper, draft 1, 7 October 2026. The wording will change; the mathematics and measurements are taken from the project’s specification and test records (CHAIN-DESIGN.md, RL-V3-PAPER.md, PHASE3-RESULTS.md, QTL-V2-ANTI-LOCKOUT.md). Experimental software. No audit. No value. No promise of value.
“We are the inverse of Bitcoin, aiming to break in a brand-new algorithm, a Sponge and a Plan-Z for Bitcoin, just in case.”
Abstract¶
Bitcoin is preparing to defend a proven system against future quantum computers. E46 runs the experiment the other way round: it starts post-quantum from block 0 and puts a brand-new hash function, Refracting Light, into the one place where a new algorithm can be tested safely in public: proof-of-work. Around that core sit a Quantum Time Lock (QTL) for wallet files, Radium (Rad) collision events that measure the hash’s health in the open, a double Merkle root block header, a smooth decay-curve reward with a “neutrino” tail, and hash-only addresses that pair Refracting Light with SHAKE256. Everything in this paper is classical computing; “quantum” refers to the threats designed against and to the entanglement-inspired ideas, never to quantum hardware.
1. The Quantum Time Lock: what a delay is¶
The idea. A time lock is a box that opens only after a known amount of computer work. You can’t buy your way past it by adding more computers, because the work comes in one long line of steps, each needing the answer from the step before. Think of digging a tunnel with a single shovel: ten more diggers can’t help, because there’s only room for one person at the face.
How QTL does it. QTL protects a test file with three layers:
Argon2id (RFC 9106) turns your password into a key while deliberately using a large amount of memory (1 GiB in the reference setting). Each password guess therefore costs real memory and time, which makes guessing expensive even for someone with many machines.
A sequential puzzle: starting from a number x, square it, take the remainder modulo a large number N, and repeat T times (Rivest, Shamir and Wagner, 1996). Each squaring needs the previous result, so the steps can’t be split across cores. The person who creates the lock knows a secret shortcut (the factors of N), so sealing takes seconds while opening takes the full T steps.
AES-256-GCM encrypts the file with a key mixed from both:
K = KDF(Argon2 key ‖ puzzle result).
What we measured. The reference setting (1 GiB Argon2, 23.5 million squarings, 20 checkpoints) sealed in 2.8 s and unlocked in 314.6 s on an Apple M1, against a 312-second target. Checkpoints arrived every 15.5 to 15.9 s, steady throughout.
What the delay is not. It is a work lock, not a clock. A faster processor or better software finishes sooner. The lock guarantees an amount of sequential work, not a number of seconds on every machine. It is for test data only and must never control physical access (doors, vaults, bunkers).
The quantum twist (planned “dual delay”). Shor’s algorithm could factor N and skip the squarings. The planned design therefore adds a second lock: a long sequential chain of SHAKE256 hashes, which quantum computers can’t shortcut. A quantum attacker skips lock A (the “Shor hunt”) but still has to walk lock B (the “search back”). Because a pure hash chain gives its creator no shortcut either (Mahmoody, Moran and Vadhan, 2011), the wallet precomputes chains while idle (a “chain bank”), so sealing stays instant.
2. QTLO: QTL lockout, and how it’s prevented¶
The problem. In the first version, the lock only noticed tampering at the very end, when decryption failed. In a test, someone raised the stored work setting, and the owner sat through 393.5 seconds of work before the lock said no. A mistyped password cost the full 320 seconds too. An attacker who can edit the file could make every unlock attempt as expensive as the software allows. That’s QTLO: being locked out by your own lock.
The fix: cheapest check first. Before any heavy work, the lock runs:
Order |
Check |
Catches |
Cost |
|---|---|---|---|
1 |
Fingerprint of the whole file, kept by the owner elsewhere |
any change to the file |
under 1 ms |
2 |
Approved settings: costs must match a built-in profile |
inflated costs, even with a forged fingerprint |
under 1 ms |
3 |
RAM check against the machine’s own memory |
a lock too big for this computer |
under 1 ms |
4 |
Password check after Argon2 |
a wrong password, before the long puzzle |
about 2 s |
5 |
Puzzle checkpoints sealed in advance; progress saved |
damaged puzzle data, at the first checkpoint; crashes resume instead of restarting |
≤ 1/20 of the puzzle |
Measured: all 13 lockout cases passed. Test Two’s attack was refused in under a millisecond, where it had cost 393.5 s; a wrong password was caught in 0.05 s (toy setting). A file can never demand more work than the owner approved, and nothing the user could lose (such as a benchmark card) is required.
3. The hashing function: Refracting Light v3¶
What it is. A new hash with a 512-bit internal state made of four “lanes”, read one message bit at a time. Each bit is pushed outward by a clamp, mixed into all four lanes with multiplication, carries and rotations, and every lane also takes in its neighbour. After 8 extra finalization steps, the four lanes are rotated by 0, 29, 61 and 97 bits and XORed into a single 128-bit output, like four beams of light refracting through a prism into one.
The name, decoded. Refracting Light is named after a physics picture, an event-horizon construction (RL-EH). The picture is a metaphor; the mechanism is classical integer arithmetic:
Picture |
Mechanism |
|---|---|
Refracting light |
four lanes rotated by 0, 29, 61 and 97 bits and folded into one output (the prism) |
Entangled lanes |
every lane reads its neighbour each step; no lane is meaningful alone (classical words, not qubits) |
Black-hole core |
the hidden state: 384 of 512 bits never leave the machine |
Event horizon |
the fold, the only boundary where information gets out |
Hawking radiation |
the 128-bit output: thoroughly scrambled, so what fell in can’t be reconstructed |
White hole |
the |
Double backwards refraction |
the P and Q check shards feed every message byte back in twice more |
Neutrino cloud |
the 8 final steps; on the chain, the neutrino is also the smallest coin unit |
The message record. Before hashing, the message is split into four shards plus two check shards, P and Q, the same Reed-Solomon idea that lets RAID-6 disk arrays survive two failed drives. The code is MDS: any change to the message alters at least 3 of 6 symbols in its column, so every difference is fed into the hash at least three times.
How it tested (details in RL-V3-PAPER.md and the glossary):
Test |
Result |
|---|---|
Avalanche: one input bit flipped |
64.0 of 128 output bits change on average (ideal) |
Bias, differentials, linear patterns |
nothing beyond chance |
Fold cancellation |
no foothold; full rank |
SAT solver attack |
thousands of times slower than guessing; stalls at 8–12 steps |
Real collision search, 40–64 bits |
0.88 ± 0.08 of the ideal cost (SHA-256 control 0.92 ± 0.08) |
Grover (quantum) simulation |
matches theory; a full preimage needs ≈ 1.45 × 10¹⁹ iterations |
Independent implementations |
Python, Python-from-spec and C agree on every vector |
Where it’s used, and why only there. Proof-of-work and Rad IDs, plus half of every address. A weakness in a proof-of-work hash only makes mining easier, and difficulty adjustment absorbs that: nobody loses coins. That makes proof-of-work the right place to put a brand-new algorithm in front of the world. Planned successor: Refracting Light W (1024-bit state, 512-bit output), designed but untested.
3.1 Nothing up our sleeves 🎩¶
Cryptographers distrust magic numbers: a constant nobody can explain might hide a back door. So here’s what’s up our sleeves, which is nothing:
Multipliers 17, 257 and 65537 are the Fermat numbers 2⁴+1, 2⁸+1 and 2¹⁶+1, all prime.
Fold rotations 29, 61 and 97 are primes, spread across the 128-bit lane.
The collisions we found, shown in the open. No rabbit, just a 64-bit pair that took a laptop 2 hours 13 minutes:
a = 0040df25fe25cd3ac96eec65 → 5916199fd7b6b8d0 665cb3a0f4fed711
b = 0040df25cac7c07fd028985d → 5916199fd7b6b8d0 f805a08c4d2bd9a0
└──── 64 bits match ────┘ └── the rest doesn't ──┘
That’s exactly as hard as finding one for SHA-256 (82 collisions verified, 40 to 64 bits). If ours had come out easier, you’d be reading about it here first. (Ta-da. The sleeves are empty. Please inspect the hat.)
4. The RAD-Z function: Radium collision events¶
What a Rad is. Inside each block’s window, miners look for two short messages whose Refracting Light hashes agree on their leading bits: a partial collision, a small “decay event”.
stamp = SHAKE256("E46-rad\0" ‖ previous block ‖ window ‖ miner address ‖ nonce)
Rad = two messages a < b whose RL v3 hashes, under that stamp, share the top Z bits (Z ≥ Z_base)
The stamp ties each Rad to one window and one miner, so it can’t be precomputed or stolen.
The nonce makes each attempt a small, independent puzzle, memoryless like real radioactive decay, so a miner’s chance grows in step with their hardware, not faster.
Z-level is how many leading bits match. Each extra bit is half as likely: Z_base + 8 is 1 in 256, Z_base + 16 is 1 in 65,536. Rarity is provable by anyone with two hash computations.
Rate: each puzzle has exactly 2^20 candidates (about 2.6 seconds of work on a laptop, about one Rad in three puzzles), and Z_base starts at about 41 bits (provisional): roughly 18–19 Rads per block. It then adjusts automatically to keep 10–30 per block.
The public alarm: the expected cost of a Rad is known exactly (the birthday bound, which we measured). If Rads ever start arriving faster than that, everyone can see that the hash has weakened.
Quantum Rads (future): a parallel event in which quantum computers factor a per-window number with Shor’s algorithm, switched on only once quantum hardware outgrows classical factoring.
5. Double Merkle root structure¶
Each 120-byte block header carries two Merkle roots: fingerprints of long lists, built as binary trees of hashes.
header (120 bytes): version | prev_block | merkle_root | event_root | time | bits | nonce
│ │
transactions ───────────────────┘ └─────────── Rads + Block QTL commitments
leaf(x) = SHAKE256("E46-merkle\0" ‖ 0x00 ‖ x)
node(L, R) = SHAKE256("E46-merkle\0" ‖ 0x01 ‖ L ‖ R) odd node carried up, never duplicated
root = SHAKE256("E46-merkle\0" ‖ 0x02 ‖ leaf count ‖ tree root) the count is sealed into the root
merkle_root commits to the block’s transactions; event_root commits to its events: Rads and Block QTL commitments. Anyone can prove a single transaction or a single Rad with a short path of hashes, without downloading the block.
The 0x00/0x01 tags and the “never duplicate” rule fix two known Bitcoin Merkle flaws (CVE-2012-2459 and 64-byte-transaction ambiguity).
event_rootis all zeros until events are switched on.
5.1 Block QTL: commit, wait six blocks, reveal (opt-in)¶
The block-level version of the Quantum Time Lock. Offline, a time lock can only promise an amount of work; on a chain, block height is a clock everyone agrees on, so the delay is truly enforced.
Commit: publish only a 32-byte hash of your transaction and its signature, plus a tiny proof-of-work (about a second of laptop time) instead of a fee. Nobody can see your key or what you’re spending.
Wait: 6 blocks, about 15 minutes.
Reveal: publish the full transaction. It’s valid only if its commitment is at least 6 blocks deep.
Anyone who wanted to forge or copy your spend would only see your key at the reveal, and would then have to backdate a commitment by six blocks, which means rewriting the chain. It’s opt-in, through Block QTL addresses that start e461z…; ordinary addresses spend immediately. The idea comes from the Guy Fawkes protocol (1998) and FawkesCoin (2014).
Two hashes per header, two jobs: proof-of-work is
RL_v3(header) ≤ target; the block’s ID isSHAKE256(header).
6. Reward structure¶
Monthly decay events instead of halvings. The block reward stays constant for each 17,280-block “decay epoch” (30 days at 150-second blocks), then drops about 1.6%:
remaining = max(T − emitted, 0)
reward = max(remaining >> 20, 1 neutrino) integer arithmetic only; 1 neutrino = 10⁻⁸ E46
Value |
|
|---|---|
Total supply T |
46,000,000 E46 |
Half-life |
3.46 years (k = 20) |
First block reward |
43.87 E46 |
After 10 / 50 / 100 years |
5.97 / 0.0021 E46 / about 10 neutrinos |
Split of every reward |
80% miner · 10% N-pool (staking) · 10% Z-pool (Rads) |
100-year totals |
36.8 M / 4.6 M / 4.6 M E46 |
N-pool (staking rewards): miners who earned Z-level can lock coins against it, up to N × subsidy (N = 576, one day of blocks), and share the pool pro rata at the next collision block. Locks always release after at most 200 blocks.
Z-pool (Rad rewards): shared among Rad finders by the energy of their Rads (rarer Rads earn more), capped at Z × subsidy per finder (Z = 0.1).
Irradiated E46 (E46i): Rad rewards arrive “irradiated”, with a real half-life: every monthly decay event, the unspent amount halves (the decayed half is burnt). Spend or convert it any time to keep what’s left as ordinary E46. Your ordinary E46 never decays.
Rad tiers: matches are counted on the leading bits, in tiers of 8, 16, 24 … 64 bits, each 256× rarer. A block holding a Rad at the current tier is a collision block, which triggers the pool payouts. Life Token fusion: two tokens of one tier fuse into one of the next.
The pools never create coins; they only share their 10% slices of the curve.
The neutrino era. A neutrino can’t be split, so around year 100 the pools stop filling, around year 114 the floor of 1 neutrino per block takes over, and around year 118 the last of T is emitted. From then on every block pays one neutrino plus fees, forever: about 0.0021 E46 a year. There is no “last coin”, so miners are never left with fees alone.
7. Addresses¶
All addresses use Bech32m (BIP-350): a readable prefix, a version character, and a checksum that always catches a typo.
Kind |
Mainnet |
Testnet |
What’s inside |
|---|---|---|---|
Single-owner |
|
|
|
Single-owner, Block QTL (opt-in, §5.1) |
|
|
same as single-owner; spends need a commitment 6 blocks deep |
Shared |
|
|
|
Transaction / block / Rad ID |
|
|
SHAKE256 (tx, block); RL v3 (Rad) |
Example single-owner address: e461qd8q86chzlafsxsvwsnstt99leappd9m9u03txle073k5u70dgaqqnjq8w0
7.1 Why RL v3 ‖ SHAKE256?¶
Each half is a 128-bit hash. Side by side, a thief would need one public key that matches both halves at once:
Attack on an address |
RL v3 alone |
RL v3 ‖ SHAKE256 |
|---|---|---|
Quantum (Grover) |
≈ 2⁶⁴ |
≈ 2¹²⁸, about 1.8 × 10¹⁹ times harder |
Classical, both sound |
≈ 2¹²⁸ |
up to ≈ 2²⁵⁶ |
If RL ever turns out weak |
broken |
SHAKE256 still holds the line |
Your new hash is in every address, and a well-studied hash backs it up. Each half is the other’s fallback. SHAKE256 is from the SHA-3 family (a “sponge”, FIPS 202), a completely different design from Bitcoin’s SHA-256, and E46 uses no SHA-2 anywhere.
Anyone can shake ingredients together. A mixmaster mixes perfectly: RL-EH stirs the black hole, SHAKE256 shakes the martini, and the address needs both.
8. Why not just do what Bitcoin is doing? The inverse¶
What Bitcoin is investigating. Bitcoin’s elliptic-curve signatures would fall to a large quantum computer running Shor’s algorithm. Its community is discussing proposals to add post-quantum output types (for example BIP-360) and how, or whether, to migrate or retire coins whose public keys are already exposed. Bitcoin has to change carefully: it secures an enormous amount of value, every change must be backward-compatible, and its hash (SHA-256) is already trusted and stays.
What E46 does instead: the inverse.
Bitcoin |
E46 |
|
|---|---|---|
Proof-of-work hash |
proven (SHA-256d) |
brand-new (Refracting Light), tested in public |
Signatures |
elliptic curve today; post-quantum migration being discussed |
post-quantum from block 0 (SLH-DSA, hash-based) |
Quantum approach |
defend against Shor |
build on the other side of quantum: hash-only security; entanglement-inspired features |
Value at risk |
very high |
none (testnet) |
Goal |
stay secure |
find out: invite people to break a new algorithm |
Plan-Z, just in case. E46 doesn’t compete with Bitcoin; it runs the experiment Bitcoin can’t afford to run on itself. If Refracting Light survives years of public attack, the world has a tested alternative hash and real operating experience with hash-based post-quantum signatures. If it breaks, the break happens on a chain with nothing to lose, and everyone learns from it. A sponge (SHAKE256) for safety, and a Plan-Z (the Z-level Rads that monitor the hash) for honesty.
9. What this paper claims, and what it does not¶
Claims (each backed by a measurement or standard): RL v3 passed every local test listed; QTL v2 prevents the measured lockout cases; the reward schedule is integer-exact and never mints outside T plus the neutrino tail; addresses and IDs use only hash-based primitives.
Does not claim: that Refracting Light is secure (no external cryptanalysis yet); that QTL is a clock or suitable for physical access; any real quantum or nuclear process; any monetary value. Peer-to-peer networking is specified last and not yet designed.
Governance and housekeeping. MIT licence, like Bitcoin Core. Releases are signed on a dedicated offline machine and built reproducibly, so anyone can check them. Small fixes are decided by the maintainer; anything touching supply, rewards or the proof-of-work hash needs contributor consensus. The genesis block will carry NASA’s TESS satellite’s newest discovery on launch day (a TOI planet-candidate number): a date nobody could have known in advance. (E46 is not affiliated with NASA.) Tor and I2P are supported quietly, off by default.
Read next: RL-V3-GLOSSARY.md (plain-language definitions and citations), RL-V3-PAPER.md (the formula), CHAIN-DESIGN.md (full specification).