Papers
Topics
Authors
Recent
Search
2000 character limit reached

Publicly Verifiable Quantum Money

Updated 18 July 2026
  • Publicly Verifiable Quantum Money is a quantum cryptographic scheme where banknotes are quantum states verified using public algorithms rather than secret keys.
  • Research explores constructions like hidden subspaces, algebraic structures, and oracle-based methods to balance public verification with strong unforgeability.
  • Key challenges include achieving noise tolerance, reusable security, and practical implementations from standard cryptographic assumptions.

Searching arXiv for recent and foundational papers on publicly verifiable quantum money to ground the article. Publicly verifiable quantum money is a class of quantum cryptographic schemes in which a bank mints quantum states that function as money, while authenticity can be checked by any verifier using public information rather than a bank-held secret. The central security objective is unforgeability: even given valid banknotes and the public verification procedure, an adversary should be unable to produce more valid banknotes than it legitimately possesses. The subject spans private-key schemes descended from Wiesner’s proposal, oracle and black-box constructions for public-key money, candidate plain-model schemes based on hidden subspaces, group actions, modular forms, and lattices, and several restricted or neighboring notions—such as almost-public coins, franchised quantum money, and quantum cheques—that clarify which aspects of public verifiability are presently achievable (Aaronson et al., 2012, Aaronson, 2011, Behera et al., 2020).

1. Foundational definitions and problem formulation

Quantum money schemes are commonly organized by who can verify. In private-key quantum money, only the bank can verify; Wiesner’s original construction belongs to this model, with verification requiring secret basis information held by the bank (Guan et al., 2017, Aaronson et al., 2012). In public-key or publicly verifiable quantum money, anyone can run the verification algorithm using public information alone, without access to a bank secret and without online interaction with the bank (Aaronson et al., 2012, Ananth et al., 2023).

A public quantum money scheme may be formalized as a tuple of algorithms for key generation, minting, and verification. One formulation used for public quantum money includes private-key-gen(1^λ), public-key-gen(sk), mint(sk), and verify(|v⟩,ρ), with perfect completeness even after many successful verifications using the same public verification resource (Behera et al., 2020). In the older public-key formulation, the bank outputs a public key and a quantum banknote ρs\rho_s, and the public verifier accepts fresh valid notes with high probability while a counterfeiter cannot increase the expected number of valid notes beyond what it initially held (Aaronson, 2011, Aaronson et al., 2012).

A recurring distinction is between bills and coins. Quantum bills typically carry unique serial numbers and may therefore compromise privacy, since bills can be traced through those serials. Quantum coins instead require repeated invocations of minting to output exactly the same pure state, so that all instances are indistinguishable copies and there is no per-instance classical tag (Behera et al., 2020). This distinction matters because most public-key quantum money proposals have taken the form of bills, whereas the public-coin setting directly raises privacy and symmetry questions.

The standard security target is some form of unforgeability or copy-resistance. In one formulation, a scheme is sound if no quantum polynomial-time counterfeiter, starting with kk valid notes, can cause the verifier to accept more than kk output notes except with negligible probability (Aaronson, 2011, Aaronson et al., 2012). In another, the adversary’s expected gain is bounded in a utility-based game that counts successfully verified outputs minus originally minted notes (Behera et al., 2020). Publicly verifiable money intensifies this problem because verification itself exposes structure about the money state; the core design challenge is to reveal enough information to verify but not enough to counterfeit (Roberts et al., 2021).

2. Early constructions and the hidden-subspace paradigm

Wiesner’s original money consisted of qubits chosen from the BB84 set {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}, indexed by a classical serial number known to the bank. Security followed from no-cloning and from the fact that measuring in the wrong basis disturbs the state, but the scheme was private-key because the bank’s secret classical description was necessary for verification (Guan et al., 2017, Aaronson et al., 2012). That model established the unclonability intuition but did not solve public verifiability.

The first major public-key proposal based on a classical hardness assumption was hidden-subspace quantum money. In that approach, a banknote is a uniform superposition over a random subspace AF2nA \subseteq \mathbb{F}_2^n of dimension n/2n/2: A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle. The crucial complementary-basis identity is

H2nA=A,H_2^{\otimes n}|A\rangle = |A^\perp\rangle,

where AA^\perp is the dual subspace (Aaronson et al., 2012). Verification uses only two tests: membership in AA in the computational basis, and membership in kk0 after an kk1-qubit Hadamard transform. The resulting verifier is exactly the rank-1 projector

kk2

so honest notes are accepted with perfect completeness (Aaronson et al., 2012).

The hidden-subspace work had two layers. First, it proved that a black-box version based on classical oracles for membership in kk3 and kk4 is unconditionally secure against quantum counterfeiters making polynomially many queries (Aaronson et al., 2012). Second, it proposed an explicit public-key instantiation in which the public key encodes kk5 and kk6 as zero sets of random multivariate polynomials, so that users can evaluate membership publicly without learning a basis for the hidden subspace (Aaronson et al., 2012). The security of the explicit instantiation rests on a conjectured hardness of recovering the subspace from those polynomial descriptions.

Two broader consequences followed. First, the hidden-subspace scheme gave a concrete model of how public verification can be compatible with quantum unclonability. Second, its security proof introduced a new inner-product adversary method, a variant of Ambainis’s adversary technique suited to state-generation lower bounds rather than ordinary decision problems (Aaronson et al., 2012). This tool was later tied to the Complexity-Theoretic No-Cloning Theorem, which showed that even given copies of a state kk7 and a phase oracle recognizing it, increasing the total kk8-mass of one’s outputs still requires kk9-type query complexity (Aaronson, 2011).

3. Oracle, black-box, and impossibility landscapes

Oracle results have played an outsize role in the theory of publicly verifiable quantum money because they separate what is conceivable in principle from what is realizable from standard assumptions. A quantum-oracle construction showed that public-key quantum money exists relative to a fair oracle accessible equally to the bank, verifiers, and adversaries (Aaronson, 2011). This established that any unconditional impossibility proof would need to be non-relativizing.

At the same time, black-box separations sharply constrain which classical primitives can plausibly underwrite public-key quantum money. A central negative result shows that collision-resistant hash functions cannot be used as a black-box to construct public-key quantum money schemes where the banknote verification makes classical queries to the hash function (Ananth et al., 2023). The model is an oracle-aided scheme kk0 in a world with a random oracle kk1 and a kk2 oracle, where minting and key generation may have quantum oracle access but verification has only classical access to kk3. In that setting, no reusable secure public-key quantum money scheme exists (Ananth et al., 2023).

The underlying attack combines state synthesis relative to kk4 with compressed oracle techniques. Once the verifier’s classical oracle behavior has been sufficiently recorded in a database, the adversary can replace the random oracle by a hardcoded classical description and then use a kk5-powered synthesizer to prepare states that the verifier accepts. This yields a black-box separation not only from collision-resistant hashing, but also from one-way functions, private-key encryption, digital signatures, and collapsing hash functions insofar as those live in the same oracle world (Ananth et al., 2023).

This line of work rules out an important family of hoped-for constructions: those in which public verification interacts with a classical hash or random oracle only through classical queries. It does not rule out schemes where verification uses quantum queries, nor does it rule out non-black-box constructions such as those relying on quantum-secure indistinguishability obfuscation (Ananth et al., 2023). A plausible implication is that successful public-key quantum money must exploit genuinely quantum access patterns or stronger structural assumptions than generic collision resistance.

A related misconception is that public verification should behave like ordinary public-key verification for classical signatures. In fact, several constructions require a public verifier that is itself a nontrivial quantum circuit, and the adversary’s ability to run that circuit is part of the security burden rather than a benign feature (Aaronson, 2011, Aaronson et al., 2012).

4. Restricted and intermediate notions: almost-public, franchised, and cheque-like systems

Because fully public quantum money from standard assumptions remains elusive, several intermediate notions have been proposed that preserve part of the functionality while weakening another dimension.

The most direct such notion is almost public quantum coins. In that framework, one starts from a stateless private quantum coin scheme kk6 with rank-1 verification and lifts it to a public quantum coin scheme with private verification (Behera et al., 2020). The public coin state is

kk7

where kk8 is the private coin state and kk9 for any constant {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}0 (Behera et al., 2020). Public verification is comparison-based: a user who already possesses honest coins can test an incoming coin by performing a projector onto the symmetric subspace over the wallet plus the incoming coin,

{0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}1

Because tensor powers of identical pure states lie in the symmetric subspace, honest coins are accepted deterministically (Behera et al., 2020).

This construction is “public” in the sense that no secret key is used during public verification and no bank interaction is required, but it is only almost public because verification consumes a fresh honest coin as a comparison anchor and because the scheme is secure only against non-adaptive, all-or-nothing, rational attacks (Behera et al., 2020). The paper proves that standard non-adaptive unforgeability fails: from {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}2 valid public coins an adversary can, using a particular symmetric-state attack, produce {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}3 accepted coins with probability inverse-polynomially close to 1 (Behera et al., 2020). What survives is a weaker rational notion in which the adversary’s expected utility remains negligible: {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}4 Thus the scheme is very close to public verifiability operationally, but not to the fully reusable public-key model (Behera et al., 2020).

A second intermediate notion is franchised quantum money. Here, verification is still local and non-interactive, but each user receives a unique secret verification key rather than a globally public verification key (Roberts et al., 2021). The syntax includes Setup, Franchise, Mint, and Verify, and the crucial new notion is sabotage security, which requires that an adversary cannot cause one honest user to accept a note that another honest user later rejects (Roberts et al., 2021). The construction is based on hidden subspaces together with standard signature and CPA-secure symmetric encryption primitives, and it is provably secure assuming one-way functions (Roberts et al., 2021). This suggests that the main obstacle in public-key quantum money is precisely the exposure of the verification structure.

A third related primitive is quantum cheques. These are presented as an alternative to fully publicly verifiable quantum money: a cheque is issued for a particular recipient and can be verified using a public key, but only by a single user. The construction is based on LWE and proceeds through two new primitives: signatures with publicly-verifiable deletion and 2-message signature tokens (Barhoush et al., 2024). The description indicates that all payments and deposits are classical once the bank has issued the initial quantum cheque (Barhoush et al., 2024). This suggests a shift from bearer-style money to recipient-bound quantum payment instruments.

These restricted notions are not merely fallback models. They isolate distinct dimensions of the public-money problem: public verification without universal reusability, local verification without public verification, and public-key validation without bearer transferability.

5. Public-key constructions beyond hidden subspaces

Several later proposals move away from hidden subspaces toward richer algebraic or representation-theoretic structures.

One candidate family builds money states as joint eigenstates of commuting unitary operators. In this framework, the public key consists of commuting unitaries {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}5 acting on a Hilbert space {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}6, with a well-separated joint eigenbasis {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}7. The serial number is a classical approximation to the eigenvalue vector

{0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}8

where {0,1,+,}\{|0\rangle,|1\rangle,|+\rangle,|-\rangle\}9. Verification uses phase estimation against the AF2nA \subseteq \mathbb{F}_2^n0 to ensure that the note is the joint eigenstate associated with the signed serial number (Kane, 2018). The abstract security problem is to manufacture

AF2nA \subseteq \mathbb{F}_2^n1

for some AF2nA \subseteq \mathbb{F}_2^n2, and any successful forgery reduces either to breaking the classical signature scheme or to solving that state-manufacturing problem (Kane, 2018). In a black-box model, solving it for arbitrary commuting unitaries requires AF2nA \subseteq \mathbb{F}_2^n3 controlled-AF2nA \subseteq \mathbb{F}_2^n4 gates (Kane, 2018). The concrete proposal instantiates the commuting operators using Hecke operators on spaces of modular forms (Kane, 2018).

A different direction uses group actions. A 2025 proposal adapts Zhandry’s group-action money scheme by replacing the quantum Fourier transform with the quantum Hartley transform, yielding real-amplitude banknotes

AF2nA \subseteq \mathbb{F}_2^n5

where AF2nA \subseteq \mathbb{F}_2^n6 (Doliskani et al., 24 Mar 2025). The serial number is the classical group element AF2nA \subseteq \mathbb{F}_2^n7. The switch from QFT to QHT breaks naive verification because it confuses AF2nA \subseteq \mathbb{F}_2^n8 with AF2nA \subseteq \mathbb{F}_2^n9; the paper introduces a new verification algorithm using group-action twists to distinguish the two sectors (Doliskani et al., 24 Mar 2025). It also gives a method for computing the serial number from the money state via continuous-time quantum walks on Cayley graphs, and a recursive quantum Hartley transform with gate complexity approximately n/2n/20 (Doliskani et al., 24 Mar 2025). This illustrates how public-key verification can depend delicately on the transform defining the money basis.

A more ambitious 2024 development gives a general quantum duality for group representations and applies it to public-key quantum money and quantum lightning. The main principle states that efficiently implementing a unitary representation is equivalent to efficiently implementing a Fourier subspace extraction on its irreducible decomposition (Bostanci et al., 2024). Using non-Abelian group actions, the paper constructs public-key quantum money and quantum lightning in the plain model under new assumptions such as preaction indistinguishability for group actions and dual-mode one-way homomorphisms (Bostanci et al., 2024). In this setting, money states take the form

n/2n/21

with public verification given by a Fourier-type measurement into the isotypic component labeled by the irrep n/2n/22 (Bostanci et al., 2024). A plausible implication is that non-Abelian representation theory may provide a structurally richer route to public verification than Abelian hidden-structure paradigms.

Other works point toward lattice-based directions. One 2022 title proposes publicly verifiable quantum money based on Gaussian superpositions over random lattices and verification using a lattice discrete Fourier transform, with unforgeability under the hardness of the short vector problem (Khesin et al., 2022). A 2022 scheme based on random lattices and a 2025 note based on one-time memories, conjugate coding, and hardware assumptions also aim at public verifiability, though the latter explicitly permits only a limited number of verifications and depends on OTM security and collision-resistant hashing (Genovese et al., 24 Dec 2025). Because the detailed source text for (Khesin et al., 2022) is unavailable in the supplied material, only that high-level description can be stated.

6. Noise tolerance, experiments, and practical constraints

A longstanding difficulty for public-key quantum money is fragility under noise. The first explicit treatment of this issue in the public-key setting appears in noise-tolerant public-key quantum money from a classical oracle (Yuen, 2024). There the banknote is again a subspace state, but verification is broadened from a rank-1 projector onto n/2n/23 to a projector onto the span of all correctable Pauli-error variants

n/2n/24

for error patterns n/2n/25 of Hamming weight at most n/2n/26 (Yuen, 2024). The verification operator takes the form

n/2n/27

so valid noisy banknotes are accepted with probability 1 (Yuen, 2024). Soundness degrades by a factor depending on the number of tolerated error patterns, giving a trade-off between robustness and security (Yuen, 2024). Conceptually, this imports CSS-code error-correction structure into the AC12 public-key oracle model without leaking stabilizer generators.

By contrast, the 2017 experimental work on hidden matching quantum retrieval games is explicitly not publicly verifiable (Guan et al., 2017). It implements the practical scheme of Amiri et al. using 4-mode coherent states

n/2n/28

assembled into a note with a classical serial number and a bank-held register tracking usage (Guan et al., 2017). Verification requires classical communication with the bank, which checks parity outcomes against its secret database. The experiment measured a total of n/2n/29 states in one verification round and bounded the forging probability by A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.0, with calibrated parameters A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.1 and A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.2 (Guan et al., 2017). These figures demonstrate practical preparation and verification of quantum banknotes, but in a bank-verified model rather than a publicly verifiable one.

This distinction matters because experimental feasibility should not be conflated with public verifiability. A scheme may be physically implementable and still fail the defining public-key criterion if verification depends on secret classical data or an online bank.

A separate 2025 proposal, “A Note on Publicly Verifiable Quantum Money with Low Quantum Computational Resources”, explicitly targets minimal quantum capability (Genovese et al., 24 Dec 2025). It uses one-time memories built from conjugate coding plus hardware, together with a classical collision-resistant hash function and digital signatures. A note consists of a family of OTMs storing preimages A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.3, their signed hashes A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.4, and a bookkeeping set of unopened indices (Genovese et al., 24 Dec 2025). Public verification uses cut-and-choose on A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.5 random OTMs, and security reduces to simulation-secure OTMs and collision resistance. The price is that the banknote supports only a limited number of verifications, approximately A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.6, since each verification consumes A:=1AxAx.|A\rangle := \frac{1}{\sqrt{|A|}} \sum_{x \in A} |x\rangle.7 OTMs (Genovese et al., 24 Dec 2025). This design is technologically modest but conceptually closer to a one-time public token than to infinitely reusable public-key money.

7. Open problems, controversies, and conceptual fault lines

Several fault lines organize the current research landscape.

The first is the gap between public verification and full public-key money. Almost-public quantum coins show that one can verify locally without a secret key if one already holds fresh valid coins, but standard unforgeability fails and only rational security is proved (Behera et al., 2020). Franchised quantum money shows that local non-interactive verification from one-way functions is possible once verification keys are individualized rather than public (Roberts et al., 2021). Quantum cheques show that recipient-specific public-key validation under LWE is more attainable than universal bearer-style public money (Barhoush et al., 2024). These are not fully public-key money in the standard sense, but they identify which ingredient remains difficult in each case.

The second is the divide between oracle evidence and plain-model realizations. Hidden subspaces and noise-tolerant public-key money are secure relative to classical or quantum oracles (Aaronson et al., 2012, Yuen, 2024, Aaronson, 2011). Those results are strong evidence of possibility, but they do not by themselves instantiate a usable scheme from standard assumptions. Candidate plain-model schemes based on modular forms, group actions, or real transforms offer sophisticated constructions, yet their security analyses remain partially heuristic or depend on newer assumptions (Kane, 2018, Doliskani et al., 24 Mar 2025, Bostanci et al., 2024).

The third is the role of classical assumptions. The black-box separation from collision-resistant hashing shows that a large class of “classical public-key style” approaches is fundamentally inadequate when verification makes only classical hash queries (Ananth et al., 2023). This suggests that public-key quantum money may require assumptions or access models that are intrinsically quantum, such as quantum queries, quantum public keys, or representation-theoretic structures not compressible into classical black-box verification.

The fourth is noise and reuse. Public verification is not enough if real banknotes decohere too rapidly. The oracle noise-tolerant construction proves that robustness is formally achievable (Yuen, 2024), while low-resource OTM-based designs show one path to practical public verification with limited quantum hardware, but only at the cost of bounded reuse (Genovese et al., 24 Dec 2025). The experimental hidden-matching work underscores that current physical demonstrations remain bank-verified rather than publicly verifiable (Guan et al., 2017).

Several open problems are stated explicitly across the literature. Among them are whether one can achieve stronger security notions for almost-public coins, including flexible or adaptive rational unforgeability (Behera et al., 2020); whether non-adaptive unforgeability of private coins implies adaptive unforgeability in stronger senses (Behera et al., 2020); whether fully public quantum money with quantum public keys exists (Behera et al., 2020); whether the Hartley-based or modular-forms schemes admit security proofs beyond heuristic or black-box analysis (Doliskani et al., 24 Mar 2025, Kane, 2018); whether non-Abelian preaction indistinguishability can be based on more standard cryptographic assumptions (Bostanci et al., 2024); and whether noise-tolerant public-key money can be instantiated from standard assumptions rather than classical oracles (Yuen, 2024).

A final misconception is that “publicly verifiable quantum money” is already a settled primitive comparable to public-key signatures. The available evidence points in the opposite direction: the concept is well-defined and structurally rich, but fully satisfactory constructions from standard assumptions remain scarce, and much of the field’s progress has come from clarifying which natural-looking approaches cannot work (Ananth et al., 2023), which restricted notions are achievable (Behera et al., 2020, Roberts et al., 2021, Barhoush et al., 2024), and which algebraic or representation-theoretic directions may eventually support robust public verification (Bostanci et al., 2024, Doliskani et al., 24 Mar 2025, Kane, 2018).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Publicly Verifiable Quantum Money.