Cross-chain bridges remain one of crypto’s most expensive weak points. They move value from one network to another, but they typically have no cryptographic way to confirm that the destination address is controlled by the same person who made the deposit.
A substituted payout address can look valid on-chain. Funds leave anyway.
AmericanFortress researchers have published a zero-knowledge framework meant to close that gap without forcing users to disclose recovery phrases, private keys, derivation paths, or transaction histories.
The research paper, Provenance Proofs: Linkable, Post-Quantum ZK Derivation Relations for Blockchain DeFi, Wallet and Identity Systems, is credited to Vincenzo Botta, Michal Pospieszalski, Emanuele Ragnoli, and Justus Ranvier.
It extends the team’s earlier ZKPoSP work, which showed how a single public key can be proven to come from a hidden hierarchical-deterministic seed.
The new construction asks a harder question: do two or more public values, even on different curves and chains, share that same hidden origin?
In practice, a user could present a Bitcoin address and a Solana address together with a proof that both were derived from one secret.
A bridge would check the proof before releasing assets.
An attacker who swaps in an address they do not control cannot generate a valid proof against the deposit.
The verifier learns only the claimed relationship, not the seed, not the unused addresses in the wallet, and not a reusable on-chain fingerprint unless the owner later chooses a more linkable mode.
The design offers three disclosure settings.
A joint proof demonstrates a shared origin to the party checking it and leaves little that outsiders can use later.
A deferred proof attaches randomized commitments that look unrelated until the owner decides to connect some of them.
A third option uses deterministic tags when persistent public linkability is actually desired, for example in compliance or institutional custody.
That range is the point: ownership can be attested without turning a private wallet into a public family tree.
Performance claims matter because earlier seed-provenance proofs were too slow for live settlement.
AmericanFortress reports generating a full-path proof in about 6.65 seconds and verifying it in roughly 475 milliseconds on a Plonky3-based system, with two-chain proving work around 13 seconds.
Those figures are research benchmarks, not a deployed product guarantee, but they mark a drop from earlier multi-minute proving times.
The authors also frame the scheme as hash-based and post-quantum oriented, sitting beside existing elliptic-curve signatures rather than replacing them overnight.
Pospieszalski, the company’s co-founder, CEO, and CTO, has described the security goal in economic terms.
Address-substitution attacks work today because they are cheap: the chain will pay any syntactically valid destination.
A provenance check changes the cost.
To steal the payout, an adversary would need control of the same hidden material that produced the deposit address.
In other words, they would have to bring equivalent control of the victim’s wallet secret, not merely paste a look-alike string.
That is what makes the attack economically unattractive if the check is enforced before release.
The work is still a paper plus a pending patent, not a network-wide standard. Bridges, exchanges, and custody platforms would have to verify proofs. Users would need wallets that can generate them. Even so, the research targets a real failure mode: proving related ownership across chains without exposing the recovery phrase or a ledger of past activity.