The only true randomness is quantum

Every number comes from a quantum measurement, with uncloneable states, unguessable results, and unfakable proof of quantumness.

QVRF transcriptVerified
output0xc4f1…7e2b
samples
6,000
seed_manifest
0x8f3a…d41c
merkle_root
0x2b7e…9a05
audited
2,000 of 6,000
xeb_score
0.12
extractor
toeplitz
Supported quantum hardwareAmazon Web ServicesIonQ
Why it matters

Steal the seed, steal the secret

Software randomness starts from a seed, and the same seed always gives the same sequence. A quantum circuit changes if you try to intercept it, and an extracted output cannot be predicted even by the quantum observer.

Use cases

Where an unprovable outcome is a liability

Regulators, holders and auditors all ask how the number was produced.

Gaming and lotteries

How do we know the draw was not run twice?

Circuits are generated on demand and committed within seconds, leaving no room for recomputation.

Mints and allocation

Who chose the seed, and when?

The network, the buyers and the extractor each provide a challenge, so quantum circuits are made on the spot.

Key generation

Where did this entropy come from?

An immutable timeline with auditable circuit samples lets anyone prove a genuine QPU crunched the numbers.

Distribution

Who decided which accounts received which entropy?

Precommitted inventory and ordering, with individual challenges, ensure each buyer gets what they paid for.

The method

How a number gets certified

Samples are committed before the audit set is chosen, so a result cannot be picked to suit whoever ran it.

The construction was published in Nature in 2025 and demonstrated by a JPMorganChase-led team with Quantinuum, Argonne, Oak Ridge and UT Austin on a 56-qubit trapped-ion processor. QVRF implements it as a service.

UNCOMMITTEDMERKLE_ROOT COMMITTED
output0xc4f1…7e2b

Quantum hardware runs the circuits and returns raw samples. The outcome arrives from a physical process, so nobody could predict it in advance, ourselves included.

Every raw sample is hashed into a Merkle tree and the root is published. From this moment the set is fixed and nothing can be swapped out.

Only now is a subset chosen at random, re-simulated exactly on classical hardware, and scored by cross-entropy benchmarking.

A Toeplitz extractor condenses the audited samples into near-uniform bits. Your challenge draws one committed sample, and it can be drawn only once.

01Measure
02Commit
03Audit
04Extract
Project demo

Quantum Echoes, the first quantum forged token

An open edition by Quip Network, and the first QFT: a token forged from quantum randomness. Its artwork comes from QVRF output, with the seed committed before any of the images exist.

See it at echoes.quip.network

Alternatives

What you can independently check

Three approaches differ in what a buyer can check for themselves after delivery.

Hardware QRNGVRF oracleQVRF
Entropy from quantum measurementYesNoYes
Per-output proof you can re-runNoPartialEC-basedYes
Proof survives a quantum adversaryNono proof existsNoYeshash-based
Published threat modelPartialrarely publishedYesYes
YesPartialNo
What is shipped

What is live, and what is next

Quantum execution and circuit generationDeterministic circuits generated from the seed manifest and run on quantum hardware.Live
Merkle commitment and audit pipelineSamples committed before selection, subset re-simulated classically and scored.Live
On-chain verification contractsVerifying a transcript from a contract rather than from our API.In development
Trustee distributionToday Quip operates both the oracle and the trustee. Splitting those roles is next.In development
Before you start

Common questions

A pseudorandom number is decided the moment its seed is, and a classical noise source is unpredictable only because its state is hard to track. In a quantum measurement there is no value waiting to be found in advance.

Certification adds a timing threshold that rules out classical simulation, and a cross-entropy audit over a subset chosen only after the results were committed. A statistical test alone can do neither.

You can check it without trusting us. Every output ships with its full transcript, and re-running those checks is the certification.

The challenge chain uses hashes and public randomness beacons, so no elliptic-curve key exists anywhere in the pipeline. A proof that Shor's algorithm eventually forges has no place in a product sold as quantum-proof.

A standard VRF derives its output from a private key, so its unpredictability rests on that key staying secret and on elliptic curves staying hard. QVRF derives its output from a physical measurement, and hands you the evidence to check it.

Quantum execution, commitment and the audit pipeline run today. On-chain verification and trustee distribution are still in development, so Quip currently operates both the oracle and the trustee.

The network's second subnet. Quantum hardware on the network produces randomness as proof-of-useful-work, and QVRF packages that output with its evidence attached.

Get access to true randomness