QUBEX Sentinel (qubexsentinel)

QUBEX Sentinel

QUBEX Sentinel is a NIST-standard ML-DSA-87 verification checkpoint for institutional crypto custody. No migration, no custody of keys.

1 Followers

Recent casts

Most CBOM tools today scan servers, containers, source code. Enterprise IT. But the hardest cryptography to inventory lives in firmware, SaaS dependencies, OT systems with 15-year refresh cycles, and protocol defaults nobody documented. The invisible crypto is where the real migration risk lives and in custody specifically, the problem is structurally different. No central admin, distributed key material, validators running whatever they want. The enterprise CBOM playbook doesn't translate.

  • 0 replies
  • 0 recasts
  • 0 reactions

The EO split — key establishment by 2030, signatures by 2031 — reflects a real engineering constraint. Key exchange is session-level: negotiate, use, discard. If ML-KEM breaks, you renegotiate. Signatures are permanent: a cert signed today is trusted for years, code signed today runs in production indefinitely. You can't un-sign. In crypto custody this is especially sharp — on-chain signatures are immutable by design. A validator signing with ML-DSA can't roll back if something goes wrong. The sequencing question in custody isn't just "when" — it's "what happens to everything you've already signed."

  • 0 replies
  • 0 recasts
  • 0 reactions

Organizations don't know where their cryptography lives. It's buried in TLS configs, third-party libraries, firmware, protocol defaults nobody revisited. CBOM is supposed to fix this — but discovery alone isn't enough. Without mapping inventory to data sensitivity and regulatory exposure, you're triaging blind. Especially in crypto custody, where key material isn't behind a corporate firewall — it's on-chain, distributed, and has no central admin to push a migration. The inventory problem there is structurally different.

  • 0 replies
  • 0 recasts
  • 0 reactions

Top casts

200/200 NIST ML-DSA-87 known-answer test vectors passed. Both signing modes. Full validation scripts public. Anyone can verify. github.com/SpirosDR1/Qubex-PQC-Benchmarks

  • 1 reply
  • 0 recasts
  • 0 reactions

The Trump EO on PQC doesn't mandate migration of all systems by 2031. High-value assets and high-impact systems: PQC digital signatures by Dec 31, 2031. Everything else: different timeline. For institutional custody — the verification layer is what makes migration auditable. Not just deploying PQC. Proving it was verified correctly. 200/200 NIST ML-DSA-87 vectors passed. qubexsentinel.com/verify

  • 1 reply
  • 0 recasts
  • 0 reactions

The post-quantum conversation focuses almost entirely on signing infrastructure. The verification layer — the independently auditable proof that a signature was produced correctly — is the overlooked half. Why this matters for institutional custody: https://paragraph.com/@qubexsentinel/why-the-verification-layer-is-the-overlooked-half-of-pqc-migration?referrer=0xbD8355B1144a21769dD8bcF1F612966fC9a83d75

  • 0 replies
  • 0 recasts
  • 0 reactions

Onchain profile

Ethereum addresses