← Latest papers
⚛️ quantum physics

More is Less:Optimal Security for Haar Quantum Money and More

This paper establishes that quantum money schemes based on Haar-random states and reflection oracles achieve optimal security by ensuring that a user's ability to counterfeit does not improve asymptotically unless they possess a number of banknotes sufficient for state tomography, a result proven via a new compressed-oracle framework for analyzing progress measures in quantum cloning tasks.

Original authors: Zihan Hao, Xingjian Li, Qipeng Liu, Wei Zhan

Published 2026-10-01
📖 5 min read🧠 Deep dive

Original authors: Zihan Hao, Xingjian Li, Qipeng Liu, Wei Zhan

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the realm of cryptography, the goal is often to create systems that are impossible to break, even by an adversary with unlimited computing power. One of the most fascinating frontiers in this field is quantum money, a concept first proposed decades ago that relies on the fundamental laws of physics rather than complex math to prevent counterfeiting. Unlike a dollar bill, which is a physical object that can be scanned and copied, a quantum banknote is a specific arrangement of subatomic particles known as qubits. The unique property of these particles is that they cannot be perfectly copied without destroying the original, a rule known as the no-cloning theorem. This means that if a thief tries to scan a quantum banknote to make a duplicate, the act of scanning inevitably alters the note, rendering it useless. For a system to be secure, it must ensure that no one, regardless of how many genuine banknotes they already possess, can create a single additional valid note.

For years, a lingering worry has shadowed these theoretical systems: does having more money make you better at stealing? In classical systems, wealth often buys better tools, but in quantum money, the concern was more subtle. If a counterfeiter already held a large collection of genuine banknotes, could those notes themselves provide a shortcut to creating more? Previous research suggested that as the number of notes a user held increased, the difficulty of forging a new one might decrease, effectively rewarding the wealthy with an easier path to crime. This would create a dangerous feedback loop where possessing more currency grants the power to generate even more, undermining the very stability of the system.

A new study by researchers at UC San Diego, Tsinghua University, and Purdue University addresses this question directly, proving that for a specific and promising type of quantum money, the answer is a definitive no. The team demonstrated that as long as a counterfeiter holds a number of banknotes that is small compared to the total number of possible quantum states, their ability to forge a new note does not improve at all. Whether they hold one note or a million, the effort required to create one additional valid note remains exactly the same. This finding establishes a crucial principle for future digital currencies: greater wealth should not confer greater counterfeiting power.

The researchers focused on a construction where banknotes are created from random quantum states, verified by a special type of measurement. To test the security, they imagined an adversary who starts with a certain number of these notes and tries to produce one more. They calculated the number of attempts, or queries, the adversary would need to make to succeed. Their analysis revealed a strict mathematical limit: the number of attempts required to forge a new note depends only on the size of the quantum system, not on how many notes the attacker already has. Even if the attacker uses the notes they possess to learn more about the system, they gain no advantage. The only way to make the job easier is to possess a number of notes so vast that it approaches the total number of possible configurations, a threshold far beyond what any practical user could ever hold.

This conclusion was reached by developing a new mathematical framework to track the progress of a quantum algorithm. The researchers treated the process of copying a quantum state like a journey through a landscape of possibilities. They defined a measure of progress that showed how close an algorithm was to successfully creating a copy. By analyzing how this progress changed with each attempt, they proved that the algorithm cannot speed up simply by starting with more copies. The path to a successful forgery remains just as long and difficult, regardless of the starting point. This result is not just a theoretical observation; it is a tight, proven bound that matches the performance of the best possible attack, meaning no better method exists.

The implications of this work extend beyond just money. The same principles apply to quantum copy protection, a method for preventing software piracy. In this scenario, a software developer wants to distribute a program that can be used but not copied. If a pirate manages to get multiple copies of the program, they might hope to combine them to create a new, unauthorized version. The researchers showed that for programs based on these random quantum states, having multiple copies does not help the pirate. To break the protection, the pirate must either solve a difficult learning problem to understand the software's function or attempt the same impossible task of cloning the quantum state. The presence of extra copies does not lower the barrier for either task.

The study also explored the efficiency of creating these copies. While having more notes does not make counterfeiting easier, the researchers found that if one is trying to generate many new copies at once, it is more efficient to produce them in a batch rather than one by one. However, this efficiency gain is about the method of production, not the advantage of possession. The core security guarantee remains intact: the system does not become weaker as the number of honest users or the amount of currency in circulation grows.

By proving that the security of these quantum systems does not deteriorate with the number of copies available, the researchers have removed a significant theoretical obstacle to the viability of quantum money. They have shown that the "rich get richer" dynamic, where wealth begets the power to steal, does not apply to this specific quantum construction. The laws of physics, as harnessed in this design, ensure that the difficulty of counterfeiting remains constant, providing a stable foundation for a future where digital currency is protected by the unbreakable rules of the quantum world.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →