AmericanFortress Unveils Cross-Chain 'Same Owner' Verification ZKP to Prevent Address Manipulation Attacks

By: www.blockmedia.co.kr|09/30/2026 09:40:25

[Block Media Reporter Lee Jeong-hwa] AmericanFortress, a developer of post-quantum cryptographic infrastructure, has unveiled a technology that verifies through Zero-Knowledge Proof (ZKP) that wallets for sending and receiving across different blockchains are under the control of the same user.

AmericanFortress recently announced that through its research on 'Seed Provenance Zero-Knowledge Proofs of Seed Provenance (ZK-POSP)', it has proposed a method to cryptographically confirm whether the sending and receiving wallets belong to the same owner before funds are disbursed in cross-chain bridge and instant exchange services, swap protocols, etc. The key point is that it can verify wallet ownership even between blockchains that use different cryptographic systems, such as Bitcoin's secp256k1 and Solana's Ed25519.

ZK-POSP is designed to prove that the receiving wallet is derived from the same secret seed as the depositing wallet before funds are disbursed on the destination chain. In this process, users do not disclose the actual seed or private key. The bridge can verify whether the wallets belong to the same user without checking the secret information of both wallets. If there is no valid proof, funds will not be disbursed on the destination chain, following the 'No Proof, No Payout' structure.

Michal Pospieszalski, CEO of AmericanFortress, stated, "Currently, bridges have no way to verify whether the destination address received is indeed the wallet of the actual depositor or if it has changed to another address during the transfer process. This technology allows for confirmation that the destination address belongs to the actual depositor without revealing other wallet information."

He further explained, "Even if two chains use different cryptographic technologies, the bridge can verify the results within one second. The key is that without proof, there is no payout."

Aiming to Prevent Address Manipulation and Poisoning Attacks, Proof Generation Takes 6.65 Seconds, Verification 475 Milliseconds

AmericanFortress explained that this technology can be utilized to prevent destination address manipulation attacks that may occur in cross-chain environments. If the destination address entered by the user during the bridge process is altered due to malware or address poisoning attacks, the existing system may disburse funds without confirming the relationship between that address and the actual depositor.

ZK-POSP prevents such issues through its 'anti-substitution' feature. Once the value corresponding to the source wallet is confirmed, even if an attacker changes the destination address to an unrelated address, they cannot create a valid proof derived from the same secret seed, thus blocking the transaction at the payout stage.

The company explained that even if malware changes the address or an attacker inserts a contaminated destination address, funds will not be disbursed unless it can be proven that the address is connected to the same secret information as the sender's wallet. AmericanFortress also disclosed the implementation performance of ZK-POSP through a paper.

According to the company, some existing methods took over 30 minutes to generate a single ZK-POSP, but this implementation generated the entire path proof, which includes three hardened derivations and two non-hardened derivations from the root, in about 6.65 seconds. Verification took approximately 475 milliseconds, and the proof size was reported to be 9.66MB.

In a 'pruned derivation' method that reduces some derivation paths based on hardened anchors, proof generation time was shortened to about 3.1 seconds, and verification time to about 253 milliseconds. The bridge connecting the two chains takes less than one second to verify both derivation proofs and their interconnections, the company explained. Proof generation is performed once on the user's device and is completed before the final confirmation of the deposit. AmericanFortress stated that the post-quantum security of ZK-POSP also inherits the security characteristics of the underlying proof system.

Expanding Use Cases for Payments and Identity Verification... 'SafeSend' to be Implemented

The application scope of ZK-POSP is not limited to cross-chain bridges. The paper also includes a 'transaction-bound proof' structure that proves the sender's identity is pre-registered for each payment transaction. This proof is protected so that only the recipient can verify it, and in the future, if an audit is needed, the recipient can prove that a specific transaction was paid to them and who sent it. In this process, there is no need to disclose the entire wallet key or other transaction histories.

AmericanFortress plans to apply this technology to its upcoming privacy payment product 'SafeSend'. The idea is to provide verification information necessary for regulatory compliance while maintaining privacy during digital asset payment processes. CEO Pospieszalski stated, "The bridge does not need to know who the user's identity is; it only needs to confirm that the deposit and withdrawal belong to the same person."

He added, "Regulatory agencies can also secure proof of payments that require actual verification without needing to request all of the user's keys. The basic principle is to prove the relationship while not disclosing the wallet itself." The company explained that this selective verification structure allows cross-chain services to confirm whether funds have moved to the correct destination wallet and, if necessary, the recipient can selectively prove that they received funds from a specific sender.

It can be utilized as a security layer that supports both privacy and compliance, as it verifies only the necessary relationships without disclosing private keys, entire wallet records, or other transaction histories.

Comments 0

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]