Deriving the transfer assumption using minted serial numbers

Determine whether reductions that call a forger at serial numbers minted by the reduction can derive the transfer assumption from the preparation assumption and rapid mixing for invariant quantum money schemes.

Background

For rapidly mixing invariant quantum money schemes, the paper decomposes security into the preparation assumption and the transfer assumption. The preparation assumption rules out efficient state preparation after measuring the banknote, while the transfer assumption asserts that any successful forger can be matched, up to a polynomial loss, by a forger that measures first.

The paper proves a barrier for fully black-box reductions that invoke the forger only at the serial number supplied to the reduction. It leaves unresolved whether this barrier can be overcome by reductions that generate their own serial numbers and invoke the forger at those minted serial numbers.

References

Whether reductions that also call it at serial numbers they mint can derive it is open.

— Path-Finding, Orbit State Preparation, and the Security of Invariant Quantum Money  (2609.39774 - Schmiedel et al., 30 Sep 2026) in Section 10, Conclusion, paragraph “Is the transfer assumption true?”

For schemes in which no efficient algorithm can list an orbit, it is open whether the second follows from the first, or from the first required at every serial number.

— Path-Finding, Orbit State Preparation, and the Security of Invariant Quantum Money  (2609.39774 - Schmiedel et al., 30 Sep 2026) in Section 10, Conclusion, paragraph “From the mint's serial numbers to the adversary's”