Objective

The company thesis

Potomac is building the AI systems and quantum software needed for practical elliptic-curve key recovery. Our long-term mission includes recovering inaccessible Bitcoin and returning assets through an accountable process. This page explains the technical goal, the economic importance of the problem, and the company we are building to address it.


Practical quantum cryptanalysis

Practical quantum cryptanalysis

The technical goal is a quantum computation that recovers an elliptic-curve private key from its public key at a size used by deployed systems, executed reliably enough to matter. Published resource estimates for that computation have fallen as arithmetic circuits, compilation, and error-correction schemes have improved, and hardware demonstrations have moved fault tolerance from theory toward engineering. Neither trend shows that deployed cryptography is broken today.

Three kinds of work must come together. Circuit improvements reduce the logical resources a computation needs. AI research infrastructure widens the set of candidate improvements that can be proposed, tested, and recorded. Hardware integration determines whether a logical circuit can actually execute on a specific machine, with its architecture, error characteristics, and interfaces. A better circuit alone is not a computation, and a machine alone is not an attack.

  1. Cryptanalytic workloadElliptic-curve key recovery and its arithmetic kernels
  2. Quantum algorithmsReduce logical resources for reversible arithmetic
  3. Circuit compilationCompile and optimize for fault-tolerant execution
  4. Mapping & schedulingPlace operations and schedule limited resources
  5. Control & runtime integrationWork within interfaces exposed by providers
  6. Quantum hardwareExternalDeveloped and operated by specialist providers
Measured results inform algorithm design and compilation.The execution stack runs from a defined cryptanalytic workload through quantum algorithms, circuit compilation, mapping and scheduling, and control and runtime integration to quantum hardware developed by external specialist providers. Measured results feed back into algorithm design and compilation.

The research program


Digital assets and cryptographic exposure

Digital assets and cryptographic exposure

Digital assets are the largest class of value secured directly by elliptic-curve signatures. Bitcoin and Ethereum together represent most of a market whose total tracked capitalization was about $2.73 trillion on the morning of 20 September 2026. Those figures describe economic context, not the value exposed to a quantum attack, and Potomac’s mission concerns elliptic-curve cryptanalysis in general rather than any single network.

Market contextObserved 20 September 2026
Total tracked crypto market capitalization
$2.73 trillion06:24 UTC
Bitcoin market capitalization
$1.62 trillion06:27 UTC
Ethereum market capitalization
$315 billion06:27 UTC

Values read from separate provider endpoints on the morning of 20 September 2026, rounded, in US dollars. They are economic context. They do not measure quantum-exposed assets, lost keys, recoverable value, or company revenue, and Bitcoin and Ethereum are components of the total rather than additions to it.

Source: CoinGecko API, global and simple-price endpoints

A research observation on dormant assets

A March 2026 research paper from Google estimates about 2.3 million BTC in the 100,000 highest-value Bitcoin addresses whose public keys are exposed or reused and which have not initiated a spend in five years.

This is a specific research cohort under the paper’s selection rule and snapshot date. It is not a count of all lost Bitcoin, not an inventory available for recovery, and dormancy is not proof of loss or of absent ownership.

Source: Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, arXiv, March 2026

Exposure is not uniform. It depends on which signature scheme an account or output uses, whether its public key is visible on the chain, and the rules the network adopts. The comparison below summarizes the cryptographic dependencies of the two largest networks.

Bitcoin

Transactions are authorized by ECDSA signatures and, since Taproot, by Schnorr signatures (BIP 340), both over the secp256k1 curve. Whether an output is exposed to a key-recovery attack depends on its script type and on whether its public key has been revealed or reused on the chain.

Sources:BIP 340

Ethereum

Externally owned accounts are controlled by ECDSA keys on secp256k1. Contract accounts have no private key of their own and are governed by code, though the keys that administer them can be exposed. Validator signing and withdrawal are separate authorities using different cryptography, so a validator-signature risk is not a claim about all staked ETH.

Sources:Ethereum accounts, Validator keys


Lost keys and migration

Lost keys and migration

The standard defence against a future quantum attack is migration: owners move assets to signature schemes designed to resist it. Owners who no longer possess the credentials needed to authorize transactions may be unable to complete an ordinary migration. What happens to those assets also depends on the rules adopted by the network. Potomac’s recovery-and-return program is intended to address this problem through technical research and a governance framework developed before operations begin.

Networks are debating how to respond. Draft Bitcoin proposals such as BIP 360 and BIP 361 and Ethereum research on emergency recovery describe possible migration and rescue mechanisms. They are proposals, not adopted network policy, and a company cannot promise that historically spendable assets will remain spendable by the same means. Lost keys are a problem that protocol changes and recovery governance both affect; neither makes inactive assets ownerless.

The recovery-and-return objective

Our long-term objective is to recover access to inaccessible assets with quantum cryptanalysis and return them through a claims and governance process that considers evidence independent of the recovered key. Governance comes before operations: authority, claims rules, custody, fees, and independent review are being developed now, and no recovery service exists today.

Recovery and return framework

Building the software company

Building the software company

Quantum hardware companies develop devices and their native capabilities. Potomac develops what runs on them for this problem: cryptanalytic algorithms, AI research systems, and the software that integrates an application across compilation, fault tolerance, and execution. We intend to be a customer and application partner for those companies, buying compute access and running joint experiments rather than building machines.

The defensible capability is execution: turning a mathematical improvement into a workload that runs reliably on a real system, and being able to show, with reproducible evidence, what it cost and how well it worked. That capability compounds across hardware generations and providers.

Possible sources of value

No company total addressable market has been established, and these are business hypotheses rather than a forecast. Potomac has no signed customers, pricing model, recovery yield, or fee rate to report.

Software and research infrastructure
Cryptanalytic software, compilation tooling, and AI research systems used with hardware providers and specialist partners.
Advanced evaluation services
Measured assessments of what specific workloads cost and how reliably they execute on specific platforms.
Authorized recovery
Future recovery-and-return operations and any associated fees, subject to the governance framework and network rules.

Research outputs

The next evidence the company needs to produce:

Hardware experiments
Scoped runs of arithmetic kernels on external systems, reported with reliability, resources, and runtime.
Maximum Reliable Kernel reports
Comparable, sourced statements of the largest operand size executed reliably per operation and platform.
Research infrastructure results
Further accepted improvements produced through the model-assisted workflow, with their failures recorded.
Governance
A published recovery-and-return framework with defined authority, claims rules, and independent review.

Investors

Ivan Miskovic handles investor conversations directly.