mt logoMyToken
ETH Gas
عربى

AmericanFortress Unveils Zero-Knowledge Proof for Cross-Chain Wallet Verification

يجمعcollect
شاركshare
blockchain main4

AmericanFortress, a Wyoming-based team working on post-quantum wallet cryptography, is publishing new research that lets a cross-chain bridge or swap service check, before it pays out, whether the wallet receiving funds on one chain is controlled by the same hidden secret as the wallet that sent them on another. The paper, laid out in the paper , extends a proof system the same authors call ZKPoSP, Zero-Knowledge Proofs of Seed Provenance, from certifying a single derived address to certifying relationships between several addresses at once, including addresses built on entirely different cryptographic curves.

The proof itself reveals nothing beyond the fact being checked. A verifier learns that two addresses share a hidden origin, not what that origin is, not the derivation path used to reach either address, and not any other address the same wallet controls. Besides bridges, the paper works through the same machinery for institutional key custody and for recovering a wallet’s trusted identity after a key is rotated. AmericanFortress says the construction is designed to hold up against quantum computers, and the technique is the subject of a pending patent application the company owns.

Checking that the payout wallet belongs to the depositor

The mechanism the paper works through in most detail is what it calls cross-scheme provenance: a user derives a Bitcoin address and a Solana address, on secp256k1 and Ed25519 respectively, from one shared hidden secret. To move funds from Bitcoin to Solana through a bridge, the user submits both addresses along with a proof that they trace back to the same secret. If an attacker, or malware sitting between the user and the bridge, swaps in a Solana address it does not control, that address cannot produce a valid proof against the Bitcoin deposit, and the paper’s stated security property is that the bridge should then withhold payout. The same check extends to a refund address using identical proof machinery, so a source, destination, and refund address can all be certified as belonging to one owner without any new cryptography.

The paper works through this against a hypothetical instant-exchange API it calls Swapper X, built to resemble how such services typically expose deposit, status, and payout endpoints. AmericanFortress is explicit that this is a worked design example rather than a real integration: no bridge or exchange has implemented the check, and Swapper X is not modeled on any specific existing provider. What the example establishes is where in a bridge’s existing flow the extra verification step would sit, right after a deposit confirms and before payout, not how any particular bridge would actually adopt it.

The timing lines up with a costly year for cross-chain infrastructure. Kelp DAO’s LayerZero-based rsETH bridge lost roughly $292 million on April 18 after a forged cross-chain message convinced the bridge a deposit had occurred when it had not, prompting Aave to freeze rsETH markets while it assessed potential bad debt. That particular failure sat upstream of anything a same-owner check between deposit and payout wallets would address, since the deposit itself was fabricated rather than genuine funds being redirected to the wrong recipient, a reminder that this proof targets one specific failure mode, address substitution against a real deposit, rather than bridge security broadly.

A second use: proving who sent a payment without exposing a wallet’s full history

The paper applies a related version of the same machinery to AmericanFortress’s own upcoming product, described in the paper as SafeSend. Payments there go to fresh, one-time stealth addresses that only the intended recipient can recognize, built from a viewing key and a spending key the recipient publishes in advance. When a sender pays, they attach a proof tying the payment to a registered identity and to that specific transaction, then encrypt their name so that only the recipient, using a value both sides can independently derive from the payment’s shared secret, can read it. A blockchain observer sees a fresh address and a proof; only the recipient learns who paid them.

The same construction lets a recipient later prove provenance to an auditor for a chosen set of payments, showing which registered sender sent each one, without disclosing the viewing key that would expose every payment they have ever received or will receive. AmericanFortress positions this as a compliance answer rather than a bridge one: proving the source of specific funds on request, without the wallet-wide exposure that handing over keys to an auditor currently requires.

What the benchmark numbers do and do not show

AmericanFortress reports that a single derivation proof over a full path, three hardened steps and two non-hardened ones, takes about 6.65 seconds to generate and 475 milliseconds to verify, on a proving system built with Plonky3, with proof sizes near 9.7 megabytes. A shorter proof starting from an already-established hardened anchor takes about 3.1 seconds. The company describes this as a large improvement over unspecified prior work it says took upward of 30 minutes per proof, though that comparison, and its source, do not appear in the paper’s own benchmark section.

Those figures describe one proof for one value, not the cross-chain check itself. The paper states directly that it has not separately benchmarked the multi-value proofs a bridge transfer actually needs. The roughly 13.3 seconds to prove and 950 milliseconds to verify given for a two-chain transfer is built by multiplying the single-proof numbers, before adding the separate proof needed to link the two together, a step the paper says it has not measured.

إخلاء المسؤولية: تعود حقوق نشر هذه المقالة إلى المؤلف الأصلي ولا تمثل MyToken(www.mytokencap.com)الآراء والمواقف ؛ يرجى الاتصال بنا إذا كانت لديك أسئلة حول المحتوى وحقوق التأليف والنشر وما إلى ذلك.
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup
القراءة ذات الصلة