Post-Quantum Risk in Deployed Zero-Knowledge Architectures: A Layered Analysis
Abstract
Zero-knowledge proof systems are now deployed widely in production cryptographic protocols, yet many rely on assumptions (discrete logarithms, pairings, or structured reference strings) that a fault-tolerant quantum computer would break via Shor's algorithm. This systematization of knowledge (SoK) presents a four-layer decomposition (L1-L4) that separates where quantum risk enters a proof system: arithmetization, polynomial commitment, protocol logic, and non-interactive compilation. Using a two-axis taxonomy that crosses cryptographic impact (structural break, modularly replaceable break, or quantitative degradation) with deployment migration feasibility, we classify the major proof-system families, derive a modularity test for evaluating upgrade paths, and introduce "collect now, forge later" (CNFL) as the proof-system analogue of harvest-now-decrypt-later. Published resource estimates place the cost of breaking 256-bit elliptic-curve discrete logs at 1,200-1,450 logical qubits, with the pairing-friendly curves underlying KZG (BN254, BLS12-381) of the same order of magnitude but somewhat larger; under these estimates, such L2 constructions would face structural breaks once fault-tolerant hardware reaches that regime. Hash-based transparent systems, by contrast, degrade quantitatively under Grover-type speedups and QROM reduction losses rather than collapse. Case studies of Zcash, zkSync Era, and StarkNet show that practical post-quantum outcomes depend on deployment governance and upgrade architecture as much as on cryptographic primitives. The scope covers IOP/PCS-based and algebraic proof families; MPC-in-the-Head constructions are excluded. This is a self-published technical report. It has not been peer reviewed.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.