to leave a comment.

AmericanFortress, a developer of post-quantum cryptographic infrastructure for blockchain, decentralized finance (DeFi), and digital identity systems, announced that it has unveiled a new technology that can verify, using Zero-Knowledge Proof (ZKP), that a sending wallet and a receiving wallet are under the control of the same user.
According to the 'Seed Provenance Zero-Knowledge Proof (Zero-Knowledge Proofs of Seed Provenance·ZK-POSP)' research published by AmericanFortress, this technology is designed to cryptographically confirm whether the sending and receiving wallets have the 'same owner' before cross-chain services such as bridges, instant exchange services, and swap protocols disburse funds.
A key aspect is that it can be verified even between blockchains using different cryptographic systems, such as Bitcoin's secp256k1 and Solana's Ed25519.
The method proposed by AmericanFortress is structured to prove that the receiving wallet was derived from the same secret seed material as the deposit wallet before funds are disbursed on the destination chain. In this process, users do not disclose their actual seed or private key. The bridge only confirms if the same ownership relationship is established without knowing the secret information of the two wallets.
In other words, it's a 'No Proof, No Payout' structure, where funds are not disbursed on the destination chain if a valid proof is not presented.
Michal Pospieszalski, CEO of AmericanFortress, explained, "Currently, bridges have no way of verifying whether the received address belongs to the actual depositor's wallet or if it was changed to a different address during transmission. This technology allows verification that the destination address belongs to the actual depositor without disclosing other information about the two wallets."
He added, "Even if two chains use different cryptographic technologies, the bridge can verify the results within 1 second, and post-quantum security can also be ensured through the security characteristics of the underlying proof system. The key is that there is no payout without proof."
This technology directly targets the problem of destination address tampering, which has been repeatedly raised in cross-chain environments recently.
In a bridge environment, if a user's entered destination address is changed to another address due to malware or address poisoning attacks, there is a possibility that the system may disburse funds without verifying the relationship between that address and the actual depositor.
AmericanFortress explained that these attacks can be blocked through the 'anti-substitution' characteristic applied to ZK-POSP. Even if an attacker replaces the destination address with an unrelated address after the value corresponding to the source wallet has been confirmed, it cannot generate a valid proof that it was derived from the same secret seed, thus blocking it at the fund disbursement stage.
The company explained that even if malware changes the address or an attacker inserts a compromised destination address, funds will not be disbursed unless that address can be proven to be linked to the same secret information as the sender's wallet.
Through this paper, AmericanFortress also unveiled benchmarks regarding ZK-POSP implementation performance.
According to the company, while some previously cited systems required more than 30 minutes to generate a single ZK-POSP, the AmericanFortress implementation generates a full path proof, undergoing three hardened derivations and two non-hardened derivations from the root, in approximately 6.65 seconds.
Verification takes approximately 475 milliseconds, and the proof size is presented as 9.66MB. In the pruned derivation method, which reduces part of the path based on a hardened anchor, proof generation time is reduced to approximately 3.1 seconds, and verification time to approximately 253 milliseconds.
In a bridge environment connecting two chains, the company explained that it takes less than 1 second to verify both derivation proofs and their interconnections. Proof generation is performed once on the user's device and is completed before the deposit is finally confirmed.
AmericanFortress stated that the post-quantum security of this method inherits the security characteristics of the underlying proof system.
The application scope of ZK-POSP is not limited to cross-chain bridges. The paper also presented a 'transaction-bound proof' structure that proves the sender is a registered identity for each payment transaction.
This proof is protected so that only the recipient can verify it, and it is designed to allow the recipient to prove that a specific transaction was paid to them and who sent it if an audit is required in the future. The company explained that there is no need to disclose the entire wallet key or other transaction details in this process.
AmericanFortress plans to apply this technology to 'SafeSend,' a privacy payment product scheduled for future release. The idea is to simultaneously support privacy and regulatory compliance requirements during digital asset payment processes.
CEO Pospieszalski stated, "Bridges do not need to know the identity of the user. They only need to confirm that the deposit and withdrawal belong to the same person. Regulatory bodies also do not need to demand all of a user's keys; they only need to secure proof for payments that actually require verification."
He added, "The principle we have established is to prove only the relationship and not disclose the wallet itself."
AmericanFortress believes that this selective verification structure can also be utilized in regulatory environments. Cross-chain bridges confirm that funds have moved to the correct destination wallet, and recipients can selectively prove that the funds were transferred from a specific sender if necessary.
The explanation is that in this process, it can be used to balance privacy and compliance, as only the necessary relationships can be verified without disclosing full wallet records, private keys, or other transaction details.
Newsletter
Get key news delivered to your email every morning
to leave a comment.