Midstate post-quantum blockchain editorial illustration, a quantum computing lab at night

Midstate: The Hidden Post-Quantum Money That Nobody Wanted to Fund

The Midstate post-quantum blockchain runs a full node on a 25 dollar single-board computer, mines on ordinary CPUs, and contains no elliptic curve anywhere in its code. Its author launched it in February 2026 with no premine, no funding round and no audience. Here is the long version, in his own words.

Project: Midstate  |  Interviewed by: Rowenta01  |  crypto-lowcap.com

#Midstate #PostQuantum #ProofOfWork #Privacy #Mining #Interview

⚠️ BEFORE WE START — NOT FINANCIAL ADVICE. This article does not constitute investment advice. These are purely personal observations from a fundamental analyst who has been covering the privacy crypto space since 2016. Micro-cap and low-cap projects carry significant risk. The positions and opinions expressed here are my own. Do your own research.
Midstate post-quantum blockchain editorial illustration, a quantum computing lab at night
Crypto-Lowcap editorial illustration — Midstate, the quantum threat

Midstate launched in February 2026 with no premine, no funding round and almost no audience, built by a single developer racing a wave of quantum computing papers that kept beating his own estimates. Before he wrote a line of Midstate’s code, he was known in Bitcoin circles as BTConometrics, the analyst who set out to falsify PlanB’s stock-to-flow model and spent years publishing quantitative Bitcoin research under that name.

I checked. Every scientific paper and every on-chain claim he cites in this interview holds up.

What follows is a long, unusually candid conversation about why a Bitcoin quant abandoned Bitcoin’s own cryptography, what the protocol still cannot do, and where he thinks it is going. Readers who followed our earlier reporting on mining centralisation and the limits of proof-of-work will recognise the same question here from a very different angle. Furthermore, anyone who read our analysis of the NØNOS post-quantum privacy OS will notice that two independent builders arrived at the same deadline from opposite ends of the stack.


1. The Midstate post-quantum blockchain at a glance

Midstate post-quantum blockchain project identity card: token MDS, supply, consensus and focus
Source: crypto-lowcap.com — Midstate, project at a glance

One figure in that card deserves a caveat rather than a footnote. The implied market capitalisation, somewhere between 14,000 and 84,000 dollars, comes from the single MDS/USDT order book on SafeTrade, where recent price ticks swung from minus 99 percent to plus 59 percent. Treat it as directional only. In contrast, the supply and emission figures are verifiable directly from the chain and from the source code.


2. Background: from Bitcoin quant to protocol builder

What was the actual moment that pushed you from analysing Bitcoin to building your own protocol?

ciphernom: I came at Bitcoin from the numbers side. For years I wrote quantitative analysis under the name BTConometrics — a bad pun on “Bitcoin econometrics” — and the thing I’m best known for is going after PlanB’s stock-to-flow model. I set out to falsify it, showed the statistics being used to support it didn’t survive contact with proper testing, and then, when I built a better-specified model and it didn’t falsify the relationship, I published that too. I was a fairly strict maximalist through most of that period.

My first instinct wasn’t to replace Bitcoin, it was to patch it. In January last year I wrote a piece about Satoshi’s coins — roughly a million bitcoin sitting in Pay-to-Public-Key outputs with their public keys already exposed on the chain, which is the one category a quantum computer could take without waiting for you to spend first. I proposed a transition window: a year for owners to move those coins somewhere quantum-resistant, and anything left over becomes unspendable.

In the same piece I wrote that we were five to ten years away. Looking back, I was writing down the consensus rather than checking it — which is precisely the error I’d spent years catching other people making.

Why Majorana 1 changed the timeline

What changed was Microsoft’s Majorana 1 announcement, in February last year. Eight qubits on a chip they said was architected to scale to a million on a single piece of silicon, and utility-scale machines in — their words — years, not decades. The physics community went after it immediately and is still going after it. The Nature paper didn’t demonstrate what the press release implied, and Microsoft has previous form on that.

Which means by my own standards I should have filed it under hype and moved on. Taking apart overclaimed results was more or less my job, and I did keep saying the claim was unproven. I also spent the rest of that year tinkering, on and off, with a chain that wouldn’t care whether it was proven or not.

It took me the better part of twelve months to notice how strange that was. My stated position and my revealed one had come apart, and when that happens the revealed one is usually the honest one.

Four orders of magnitude in fourteen years

Then in the middle of February this year a Sydney startup called Iceberg Quantum posted a preprint claiming they could factor RSA-2048 with fewer than a hundred thousand physical qubits — using a different family of error-correcting codes to cut the overhead by roughly tenfold. It went round on the 13th and I saw it that day.

What got me wasn’t the number. It was the sequence:

  • 2012: about a billion qubits
  • 2019: twenty million
  • May 2025: under one million
  • February 2026: under a hundred thousand

Four orders of magnitude in fourteen years, and every drop arriving faster than the one before it. I have spent a lot of my life staring at time series. That is not a series that flattens out because you would prefer it to.

The caveats I would demand from anyone else

I want to be fair about the caveats, because I’d demand them of anyone else. Iceberg’s number is a resource estimate from simulation, not a demonstration — nobody is factoring anything today, and the team say so themselves. Craig Gidney, whose own estimate they’d just beaten, called the gains plausible but only if you accept much harder engineering elsewhere: exotic connectivity, real-time decoding nobody has shown at scale, months of unbroken stability. The qubit count falls, but the difficulty is rearranged rather than removed. And plenty of serious people still put the real date in the mid-2030s.

That paper is what made me stop tinkering and finish the thing. I posted the repository publicly the next day — “still a few bugs to iron out, but mostly it’s working” — and launched at the end of the month.

An anchor nobody can forge

I anchored the genesis block to Bitcoin block 938708, mined on 28 February, along with the title of a piece published four days earlier: “Harvest Now, Decrypt Later: The Quantum Era’s Encryption Challenge,” from RBC’s Disruptors series. I’ll be straight that I only skimmed it. It isn’t in there because it changed my mind. It’s in there because a genesis block needs an anchor to the real world that nobody can forge afterwards — which is exactly what Satoshi used the Times headline for — and because a retail bank running that headline told me the idea had finished being a fringe concern.

Five weeks after launch, two more papers landed within days of each other. Google published a large revision downward for breaking 256-bit curves — enough that the attack runs in minutes on fast-clock hardware — and framed the whole thing around cryptocurrencies and mempools, which tells you precisely who they had in mind. Then a group called Oratomic put numbers on doing it with ten thousand reconfigurable atoms.

The largest array of that kind anyone has actually built is about six thousand one hundred, and it has never been used for computation. Same caveats as before: these are estimates, not demonstrations. But the direction hasn’t reversed once, and the curve those two papers are pointed at is secp256k1 — the one Bitcoin signs with.

Why build a new chain instead of joining an existing one

As for why I built my own instead of using something that already existed, that was the other half of it. The post-quantum chains I could find were either hardware-centralising — you need serious kit just to take part — or they leaned on a central company. Neither of those is money. Those are products with a marketing department. I didn’t want that to be the only option on the table, so I built the grassroots one.

Midstate is quantum-proof in the strict sense of the phrase, and I’ll stand behind that wording. If a cryptographically relevant quantum computer were switched on tomorrow morning, the chain would be entirely unaffected — there is no elliptic curve anywhere in it to break. That property shouldn’t only be available from somebody’s startup.

How did you approach learning the cryptography side?

ciphernom: It’s less of a jump than it sounds, because my background sits right on the seam. “Quantitative Bitcoin research” was econometrics — time series, cointegration, model specification, arguing about whether a test was even applicable to the data it was being run on. I’ve got degrees in software engineering and biostatistics. The engineering side is what let me write the node and hand-roll the SIMD assembly paths. The biostatistics is where the probability comes from — Midstate’s finality estimator and its peer-reputation scoring are both Bayesian, and that’s just applied statistics wearing a different hat.

On cryptography specifically, my rule was: read the papers, don’t invent the math. I took primitives that have been picked over for decades — Winternitz one-time signatures, Merkle signature schemes, BLAKE3 — and spent my effort on the engineering problem, which is making them fast enough and small enough to live inside a UTXO model on cheap hardware. Nobody needs a novel hash function from me. What they needed was someone willing to do the unglamorous work of making the known-good stuff practical.

Honestly, the econometrics helped more with temperament than with content. I spent years pulling apart other people’s models and finding that the impressive result was resting on a test that didn’t apply, or a regression with the same variable on both sides. Do that long enough and you become permanently suspicious of your own claims. It’s why I’ll tell you flatly that Midstate has had no audit, that BLAKE3 isn’t ASIC-proof, and that the base-layer user experience is rough — those are all things I’d have gone after if somebody else were making the claims.


3. Inside the Midstate post-quantum blockchain architecture

The Midstate post-quantum blockchain replaces the algebraic machinery most chains rely on with something deliberately dumber: a long chain of BLAKE3 hashes. As a result the design buys quantum resistance and pays for it in verification cost. The comparison below sets ciphernom’s own characterisation against the formal verifiable delay functions the academic literature describes.

Midstate sequential BLAKE3 hashing compared with formal VDF constructions, Wesolowski and Pietrzak
Source: crypto-lowcap.com — Sequential hashing versus a formal VDF

Does verifying a block require replaying the full hash sequence?

ciphernom: It does, and I’d rather be upfront about that than dress it up: there’s no shortcut proof. Checking a block costs the same as trying one nonce — a million BLAKE3 hashes, each one feeding the next.

I spent a while trying to escape that, actually. Early on I was convinced I could build a shortcut using Fiat–Shamir — produce a small proof that I’d done the million hashes, so verifiers wouldn’t have to repeat them. I was wrong, and the shape of being wrong turned out to be the useful part. Proofs like that need algebraic structure to grip: some mathematical relationship between input and output you can compress.

A hash chain is specifically built to have none. That’s what a hash is for. The absence of structure is exactly what makes it safe against a quantum computer, and it’s the same absence that makes it impossible to prove cheaply. You don’t get both, and I had to try it to believe it.

Which is precisely why the formal VDFs — Wesolowski, Pietrzak — are built on groups of unknown order instead. They buy cheap verification with algebraic structure, and then that structure has to either come from a trusted setup or rest on assumptions a quantum computer breaks. A chained hash has no trapdoor, no setup, and nothing to attack. Because each hash depends on the one before it, no amount of hardware lets you skip ahead — true for a warehouse of GPUs, true for a quantum computer.

On the word ASIC-resistant

People ask whether this makes it ASIC-resistant, and I want to be careful with that word because it gets abused badly in this space. BLAKE3 isn’t memory-hard. Could somebody tape out a chip for it? Absolutely, and if Midstate ever gets valuable enough, somebody will. Anyone telling you their hash function is ASIC-proof is either confused or selling something.

What’s true is narrower and more useful: no such chip exists today, so everyone mining Midstate is on ordinary hardware. That’s a very different starting distribution from a chain where the specialised silicon showed up years ago and the question of who gets to mine was settled before most people heard of it.

The reason it’s still practical is that blocks are independent of each other. When a node syncs, it verifies a whole chunk of them across every core at once, so sync time scales with how many cores you have rather than how long the chain is. On top of that I wrote hand-tuned SIMD paths — NEON on ARM, AVX2 on x86 — that check four or eight mining nonces per instruction, and a separate one that batches signature verification the same way. Neither of those touches the actual chain replay, and that’s on purpose: consensus code that behaves differently depending on your CPU is how you split a network.

How does the Bayesian Finality Estimator hold up against a hashrate-toggling attacker?

ciphernom: Most chains hand you a number — six confirmations, whatever — and that number is the same whether the network has been calm for a month or is being actively attacked right now. That always struck me as backwards.

Midstate’s nodes keep a running belief about how much of the network is honest, and update it from what they actually observe. Then they solve for the shallowest depth at which the risk of a reversal drops below one in a million. On a quiet chain that’s a small number. The moment a node sees a real reorg, its belief shifts toward “maybe this network isn’t as honest as I thought,” and the required depth climbs — up to a ceiling of 10,000 blocks, which is about a week.

So an attacker toggling their hashrate doesn’t fool the estimator. They just make it paranoid, which is exactly what you want it to do when someone’s toggling their hashrate.

I’ll name the honest limitation too, because it’s the interesting part: the more history a node has seen, the more evidence it takes to move it. A node that’s been running for months is harder to alarm than one that booted yesterday. Weighting recent observations more heavily is the fix and it’s on my list.

Midstate CPU mining benchmarks: Raspberry Pi 5, Xeon workstation and an older Quadro GPU
Source: crypto-lowcap.com — Midstate mining hardware benchmarks, self-reported by ciphernom

These figures come from ciphernom alone. Nobody has reproduced them independently, so read them as a single witness rather than as a benchmark. However, the ratio they describe, a ten watt board doing a third of the work of a workstation, is the claim the whole project rests on.

Was Stratum V2 or P2Pool an influence on your pool model?

ciphernom: I like the Stratum V2 ethos, but I came at this from a different angle: I wanted to solve pool operator theft specifically.

Every mining pool asks you to trust that the operator is counting your shares honestly. You send them work, they send you a number, and you have no way to check it. Midstate’s pool builds a Merkle tree of every miner’s shares and commits that tree into the block itself. Before you spend a single hash on a job, your client can ask the pool for a proof that your exact score is in that tree — and it can verify that proof mathematically, in milliseconds, without trusting anyone.

If the operator shaves your number or leaves you out, your own miner catches it and disconnects. You don’t need to audit the pool. The pool has to prove itself to you, every job, or you walk.

Why a small miner is not just buying a lottery ticket

The other half of the problem is whether a small miner is earning anything worth having in the first place. On Bitcoin, a Bitaxe is a lovely object and I’m genuinely glad people build them — but it’s on the order of a billionth of the network. It’s a lottery ticket with a nice case, and no amount of clever pool design fixes that. The network is simply too big, and it got that way because millions of purpose-built chips exist that do nothing else.

Midstate’s numbers look nothing like that, and I’d rather just hand you them. A Raspberry Pi 5 does about 70 nonces a second. My Xeon workstation does about 250. So a board costing less than dinner is doing a third of the work of a proper workstation — and it does it on under ten watts against the Xeon’s couple of hundred. That leaves the cheap ARM board more than five times more power-efficient than the expensive machine. At this particular workload small ARM cores are simply the right shape of silicon, and the workstation has no answer for it.

What that ceiling is made of

Graphics cards are faster again. An old Quadro I have sitting around manages about 3,000, and I’d assume a current card does considerably better — I haven’t tested one, so I’m not going to pretend I know where the ceiling is. But notice what that ceiling is made of: commodity hardware. You close that gap by buying more computers.

On Bitcoin you close it by buying a purpose-built chip that does nothing else, and the general-purpose machine already on your desk is something like a hundred thousand times less efficient than that chip. That’s a polite way of saying it isn’t allowed to participate at all. That’s the difference I actually care about — not that nothing beats a Pi, but that whatever beats it is something anyone can go and buy.

So somebody with a couple of boards in a closet isn’t making a gesture. They’re mining on hardware that holds its own, and their share of a pool comes down to how much hardware they bought — not which tier of equipment they were able to get access to. On Bitcoin a hobbyist miner is a symbol. On Midstate it’s a contribution you can watch accumulate.


4. Roadmap and QBolt

Midstate’s base layer asks you to send a payment in two steps, which protects you from front-running and, at the same time, makes buying a coffee absurd. QBolt is ciphernom’s answer to his own design. Our earlier interview with DragonX, another CPU-mineable privacy coin, covered a similar tension between cryptographic rigour and everyday usability.

Where is QBolt right now: code, testnet, or design stage?

ciphernom: QBolt exists because the base layer’s user experience is harsh, and I’d rather say that plainly than let people find out on their own.

Sending on Midstate takes two steps. You publish a commitment to the exact transaction first, wait for it to be mined, and only then reveal the signature and the contents. That blinds what you’re spending until it’s already sealed, which kills front-running — nobody can see your transaction in the mempool and race it. Cryptographically it’s the right call. As an experience it’s two round trips and a wait, and that is not how anyone expects to buy a coffee in 2026.

So QBolt is the answer to my own design. Open a channel once, pay through it instantly as many times as you like, settle back to the base layer when you’re done. The hard two-phase step happens twice — at the start and at the end — instead of on every single payment.

It’s live, and it’s further along than “implemented.” The covenant logic and the wire format sit in the consensus layer, and both wallets speak it — the desktop client and the browser wallet open channels with each other and settle byte-for-byte identically. That interoperability was the actual hard part and it’s done.

The browser wallet is the one I’d point at, honestly. You can open a payment channel, mint and pay invoices, route payments with hash-locked contracts, sweep them on-chain if a counterparty vanishes, and mine — all from a tab, over WebRTC, with no server in the middle. That’s a full post-quantum layer-two node running in a browser.

Will QBolt stay unidirectional, or eventually route multi-hop like Lightning?

ciphernom: The routing pieces are all in. Hash-locked contracts are a native script type, nodes can advertise themselves as hubs with their capacity and fee over the chat bus, and the timeout arithmetic and failure codes are implemented. What I won’t claim is a battle-tested routing network — advertised hubs and a busy multi-hop network are different milestones, and the second one needs liquidity that doesn’t exist yet.

There’s a real structural difference from Lightning worth stating. Because the base channels only flow one way, forwarding a payment permanently spends a hub’s capacity toward that peer — return traffic never refills it. So a routing fee on Midstate isn’t rent on an idle position, it’s compensation for inventory you just consumed. Hub economics look more like running a shop than running a toll booth. Bidirectional channels would change that, but they need a way to revoke old states, and every scheme I like for that leans on cryptography I’d have to make quantum-resistant first. That’s a real research problem, not a weekend.


5. Funding, distribution and positioning

With no premine and no dev allocation, how do you fund your own time?

ciphernom: My own time and my own conviction. No dev tax, no premine, no VC overhang — those things corrupt base-layer money, every time, without exception.

And I’d rather people check that than take my word for it. The genesis block’s reward went to two outputs whose address and salt fields aren’t random data at all — they’re plain ASCII, and read end to end they spell out “Harvest Now, Decrypt Later: The Quantum Era’s Encryption Challenge (Published Feb 24, 2026, by RBC Disruptors).” Because every Midstate address is the hash of a spending program, and no program hashes to an English sentence, those coins are mathematically unspendable. The entire founding reward is burned into a headline. You can read it straight off the chain.

That’s Satoshi’s trick with the Times headline, and it’s there for the same two reasons: it proves the chain can’t predate the date, and it says out loud what the thing is for. The chain is also anchored to Bitcoin block 938708, mined on 28 February 2026 — so anyone can pin Midstate’s birth against Bitcoin’s own clock rather than trusting mine.

It’s sustainable because the goal isn’t a company. I’m not trying to run a payroll forever. I’m trying to finish a tool and let go of it.

Where can people acquire MDS, and are more listings planned?

ciphernom: It’s on SafeTrade, and I’m not chasing any more centralized listings. The exchange I care about is the one built into the desktop wallet.

You can trade MDS for ETH on Base directly, wallet to wallet, no matching engine and no custodian. Someone posts a sell order backed by coins locked on Midstate; a buyer locks ETH in a contract on Base; one secret unlocks both sides or neither settles. Standard atomic swap logic, except the two chains don’t speak the same language.

That last part was the fun engineering problem. Midstate hashes with BLAKE3 and Ethereum has no idea what that is — there’s no built-in support for it, at any price. So I implemented BLAKE3 in Solidity, by hand, and checked it byte-for-byte against the reference implementation. That contract is what lets a Base smart contract verify a Midstate secret. Without it there’s no bridge at all.

There are resting orders on both sides now — sell orders as covenants on Midstate, buy orders as escrowed ETH on Base — so it behaves like an actual order book rather than a matchmaking service.

The part I didn’t plan: because every Midstate coin has to be a power of two, an order naturally breaks into pieces that can each be taken on their own. Partial fills fell out of the denomination rule for free. I didn’t design that in.

Midstate power-of-two coin denominations, medallions engraved 1, 2, 4, 8, 16, 32 and 64
Crypto-Lowcap editorial illustration — Midstate, power-of-two coin denominations

Where does Midstate sit next to QRL, Abelian and the other post-quantum projects?

ciphernom: Three things: proof-of-work, the hardware floor, and fungibility.

I’m not interested in a chain you need a datacenter to participate in, and I’m not interested in one governed by a foundation. Midstate runs — full node, competitive mining, all of it — on a twenty-five dollar single-board computer. I test on a 1GB Raspberry Pi 5, a machine with less memory than a phone from 2014. That constraint isn’t something I’m apologising for, it’s the entire specification. Money that requires permission to run isn’t money. If the hardware floor is a garage-sale Orange Pi, shutting the network down means finding every closet in the world.

The strangest rule in the protocol

The third one is the part nobody expects, and it’s probably the strangest rule in the protocol. Every coin on Midstate has to be a power of two — 1, 2, 4, 8, 16, no exceptions. Send someone 100 and your wallet sends 64 + 32 + 4. Three coins, and they look exactly like everyone else’s 64, 32 and 4.

Bitcoin has a chronic problem where amounts fingerprint you. A coin worth 0.03271849 BTC is an identifier — it follows you around the chain and analytics firms make a living tracing it. Midstate can’t do that, because there are only sixty-four values a coin can ever hold. Everyone’s coins come from the same tiny set, so amounts stop being a signal.

It reaches further than that. An unspent coin doesn’t publish its value at all — it’s just a 32-byte hash sitting on the chain, and the amount only surfaces when it’s spent. And it makes the CoinJoin mixer almost free to build, because getting everyone into matching denominations is the hard part of mixing, and here the protocol already did it.

Most privacy coins bolt privacy on with heavy cryptography. Midstate gets a large share of it from an accounting rule — which costs nothing to verify and can’t be switched off.

Why I deleted the working zkSTARK code

I say that as someone who tried it the other way. Early on I had zkSTARKs in the codebase as a confidential output type, and they worked. I took them out anyway. Not because they were broken — because they didn’t belong. They were heavy to verify, hard for anybody to check by reading, and an entire second cryptographic system to trust alongside the first. And by that point the denominations, the CoinJoin and the Dandelion relay were already doing most of the job between them. Deleting working code is the hardest habit to build and it’s the decision I’m most confident I got right.

The price of the denomination rule is that wallets collect a lot of small coins, so there’s a tool that sweeps thousands of them into one with a single signature. I think that’s a bargain for what it buys.


6. Security and trust

Has any external security review happened yet?

ciphernom: No paid audit. I’d rather say that plainly than let a “security” page imply otherwise.

What there is: the code is fully open, the consensus paths carry formal specifications, and the test suite is written around specific bugs I found rather than for coverage numbers. Most of the protocol changes so far have come out of my own review turning something up and me scheduling a fix.

And I’d draw a sharper line than most projects do. BLAKE3, Winternitz signatures and Merkle signature schemes are extremely well studied. My combination of them isn’t. The two-phase transaction structure, the scripting language, the covenants, the way I parameterised the signature scheme — all of that is new and none of it has been through outside eyes. On the signature parameters in particular I made an unusual choice to get signatures down to 576 bytes, and I paid for it in verification cost. That’s the trade I’d most want a cryptographer to second-guess.

Anyone who wants to look, the whole thing is there.

What does a realistic full sync look like on the target hardware?

ciphernom: I synced a 1GB Raspberry Pi 5 from genesis to height 240,000 in about four hours — verifying everything, not trusting anyone. That’s the low end of the hardware range on purpose; a normal desktop with AVX2 does it dramatically faster.

Four hours on a board that costs less than dinner is the number I actually care about, because it’s the one that determines whether ordinary people run nodes or just talk about running them.


7. Vision

You said the long-term goal is to no longer be needed. What does that look like?

ciphernom: Ossification. Bitcoin worked partly because Satoshi left — if he’d stayed he’d have become the thing to pressure, subpoena or bribe.

In practice it means the base layer stops changing. I’ll be honest that we’re not there yet: the protocol has taken several upgrades as review turned things up, and there’s one more scheduled at block 300,000. But the direction is one-way. Each of those closes a door and none of them opens a new one, and the point of the exercise is that the list runs out.

Once layer one is set and QBolt is carrying the day-to-day payments, my job is finished. The explorers, the pools, the routing hubs — those are already things other people can run, and the less I’m in the middle of them the better the project is doing.

Midstate runs on edge hardware, a single-board computer on a home shelf rather than a datacenter
Crypto-Lowcap editorial illustration — Midstate, edge hardware rather than a datacenter

If Midstate is exactly where you want it in three years, what does that world look like?

ciphernom: Cheap computers in closets, quietly settling payments for people who never had to ask anyone’s permission.

Someone in a country with capital controls holds savings that can’t be frozen. Someone paying a contractor overseas does it in seconds for a rounding error, over a routing hub run by a stranger who never learns who either of them is. The coins all look identical because the protocol only allows sixty-four denominations, so nobody can trace anyone by the shape of their money.

No treasury, no unlock schedule, no venture fund waiting to sell. And when the quantum computers that governments are building today finally arrive, the network doesn’t have to do anything about it, because it was built for that from the first block.

That’s it. Hard money, on hardware anyone can afford, that nobody owns.


8. Where to verify this yourself

Every claim the Midstate post-quantum blockchain makes can be checked without asking anyone’s permission, which is the point. Therefore the primary sources come first, and our own coverage second.

For context on how this fits the wider landscape, see our decade-long history of privacy coins and our practical field guide to the anonymous crypto stack in 2026.


9. What I would watch on the Midstate post-quantum blockchain

The Midstate post-quantum blockchain is the most cryptographically conservative thing I have looked at this year, and also one of the most fragile as a project. Both statements are true at once, therefore neither should be read on its own.

  • No audit, and a new combination of old primitives. BLAKE3 and Winternitz signatures are well studied. The two-phase transaction, the covenants and the 576-byte signature parameterisation are not. Consequently a cryptographer’s review is the single event that would move my assessment most.
  • Bus factor of one. One developer wrote the node, the wallets, the Solidity port and the pool. Ossification is the stated exit, however the protocol is still taking upgrades, with another scheduled at block 300,000.
  • Liquidity that barely exists. A single order book with price ticks swinging from minus 99 to plus 59 percent is not a market. As a result, any valuation figure here is arithmetic rather than information.
  • ASIC risk is deferred, not removed. BLAKE3 is not memory-hard, and ciphernom says so himself. If MDS ever becomes valuable, specialised silicon follows.
  • Regulatory exposure. Fixed denominations plus a built-in CoinJoin and Dandelion relay put Midstate squarely in the category European exchanges have been delisting under MiCA. Furthermore, a chain with no company behind it has nobody to negotiate on its behalf.

In short, I find the engineering unusually honest and the surrounding project unusually exposed. That combination is exactly what a lowcap looks like before anyone decides whether it matters.


crypto-lowcap.com  |  Privacy, Decentralization & Blockchain Innovation

Follow @CryptoRowenta01 on X  |  Subscribe to the newsletter

Crypto Lowcap is an independent media outlet covering privacy, decentralization and low-cap innovation since 2016. We never accept paid coverage, our analyses are our own.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *