• 7 mins read
  • Published

Project Eleven Buys Riva Labs for Post-Quantum Security

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Project Eleven Buys Riva Labs for Post-Quantum Security Science.Report © science.report
Project Eleven Buys Riva Labs for Post-Quantum Security © science.report

Project Eleven has acquired Riva Labs to combine post-quantum signatures, MPC, account abstraction and hardware signing across blockchain infrastructure before quantum computers can threaten today's public-key systems.

Project Eleven announced the acquisition of Riva Labs on 29 September 2026 in a move aimed at rebuilding blockchain security beyond the signature layer. The deal brings together engineering and intellectual property covering hash-based post-quantum signatures, wallet infrastructure, multi-party computation (MPC), account abstraction and hardware signing for Ethereum and other public-chain ecosystems. Riva's team and technology are expected to join Project Eleven's research and product efforts.

  • The threat layer

    Most public ledgers still rely heavily on public-key systems such as the Elliptic Curve Digital Signature Algorithm and Schnorr signatures. Those schemes are not threatened by today's quantum computers, but a sufficiently capable fault-tolerant machine running Shor's algorithm could derive private keys from public information exposed by such systems. The risk is especially serious for blockchain accounts because transaction histories and public keys can remain visible for years, creating a long planning horizon for cryptographic migration.

    That risk is architectural rather than cosmetic. Replacing one signing routine does not automatically secure the wallets, key-management systems, smart contracts and consensus rules that depend on it. Project Eleven and Riva Labs are presenting the acquisition as a way to address those connected migration points together instead of treating post-quantum security as an isolated patch.

    Hash-based signatures are one branch of post-quantum cryptography. Their security relies on hash-function properties rather than the factoring or discrete-logarithm assumptions behind many current public-key systems. The trade-offs can include larger signatures, state-management requirements for some constructions and operational demands around key generation and verification. These design constraints make wallet integration and transaction economics as important as the underlying mathematical security argument.

  • Beyond signatures

    The combined pipeline is intended to connect cryptographic key management with smart-contract wallet infrastructure and protocol-level rules. Its scope includes Ethereum as well as other major Layer-1 public blockchains, although the announcement does not provide deployment data showing that the merged technology is already operating across those networks.

    MPC is relevant because it allows cryptographic operations to be distributed across participants rather than concentrated in one private-key location. Account abstraction matters at the wallet layer because it can change how accounts authorize, recover and sponsor transactions. Hardware signing adds another control point, but none of these components by itself constitutes a complete migration of a live blockchain. The practical goal is interoperability among cryptographic primitives, wallet policy, device security and network validation.

    National Institute of Standards and Technology standardization efforts have helped frame this migration around algorithms such as lattice-based mechanisms and the hash-based SLH-DSA. NIST's post-quantum cryptography program also illustrates why deployment is treated as a systems-engineering process: organizations must inventory exposed keys, test implementations, plan interoperability and replace vulnerable mechanisms before a cryptographically relevant quantum computer exists.

    The transaction announcement and independent coverage do not disclose a purchase price or other transaction terms, so no public valuation can be assigned to the deal. The available material also gives no deployment date, qubit requirement or measured performance figure. The acquisition should therefore be read as a capability and staffing decision rather than as a demonstrated network-wide result.

  • AI as a research tool

    Riva Labs is also described as bringing an AI-driven research methodology into the merged group. The stated uses include accelerating cryptographic research, cryptanalysis and code validation, with the goal of producing migration frameworks that can adapt as standardized lattice- and hash-based algorithms develop.

    That ambition needs a careful boundary. Automated tools may speed literature review, testing or code analysis, but they do not replace formal security arguments, implementation audits or adversarial evaluation. The announcement does not identify a new algorithm, disclose a cryptanalytic result or provide independent evidence that AI has validated a production cryptographic system. As work published in journals such as Nature repeatedly demonstrates across computer science and physics, a compelling technical claim still requires reproducible methods, explicit assumptions and independent scrutiny.

  • The hardware constraint

    The engineering target is practical post-quantum signing with low overhead on consumer-grade hardware. Independent summaries indicate that Riva's technology had already demonstrated post-quantum signatures on ordinary consumer hardware, a relevant milestone because deployment on familiar devices is a key hurdle for blockchain migration. The supplied material does not, however, report sample sizes, benchmark conditions, latency distributions, energy measurements or confidence intervals for those demonstrations.

    Larger keys, longer signatures and heavier computations can affect storage, bandwidth, latency and energy use across decentralized networks. Backward compatibility is therefore not a slogan but a systems problem involving old wallets, transaction formats, contract logic and network participants. Research communities at MIT and CERN have long shown, in different domains, how engineering constraints can determine whether an elegant theoretical design becomes a usable instrument; post-quantum blockchain systems face the same distinction between mathematical feasibility and operational scale.

    Hardware signing introduces a further trade-off. Dedicated implementations can isolate sensitive operations and reduce exposure to software attacks, yet they must also be manufactured, provisioned, updated and audited without creating a new point of failure. The material supplied for this acquisition does not report hardware measurements, implementation tests, side-channel results or compatibility trials.

    The broader migration challenge has already moved from algorithm choice toward hardware trust and cryptographic inventory, as an earlier security analysis illustrated. Project Eleven's acquisition adds another layer to that same problem by combining wallet architecture, distributed signing and protocol integration under one engineering effort.

    Post-quantum cryptography is designed to run on conventional computers and should not be confused with quantum cryptography. Its purpose is to replace public-key mechanisms that may fail against future fault-tolerant quantum computers while preserving ordinary digital communication and computation. The acquisition is therefore significant as a full-stack migration bet, not as evidence that a quantum attack has already occurred or that a blockchain has already been secured against it.

    Project Eleven CEO and co-founder Alex Pruden said the acquisition is intended to strengthen the company's technical team and accelerate the movement of digital assets toward post-quantum security. Riva Labs co-founder Matteo Vena said the companies share a view of the tools the industry needs and that joining Project Eleven should help scale upgrades across public blockchains. These statements describe strategic intent; they do not constitute independent validation of performance or security.

    Project Eleven's purchase of Riva Labs is a credible response to the fragmented nature of blockchain migration because it joins primitives, wallets, hardware and protocol design in one program. But the evidence establishes an acquisition and a technical agenda, not a completed deployment, independent security validation or scalable post-quantum network. Until those results are measured in working systems, the strongest conclusion is that the industry is beginning to treat quantum readiness as infrastructure engineering rather than a last-minute signature swap.

  • Related articles