What a measured qubit can do that Math.random() never will

When I started telling people that the Quantum Genesis seeds came from "quantum randomness," the first question was always the same: "So... like Math.random() but with extra steps?"

Fair question. On the surface the outputs look identical — a stream of numbers with no obvious pattern. But the moment you dig into where the numbers come from, the difference stops being academic. Math.random() produces a value by computation. A measured qubit produces one by physics. This post is the long-form version of the answer I kept giving.

I'll explain both sides, the hybrid approach we ended up using, the code, and — because "trust me, it's quantum" is not a methodology — the statistical tests we ran on 100 of these seeds.

Quantum Genesis NFT #25 — IBM Quantum ibm_fez

What your code calls "random"

Every call to Math.random() in JavaScript, or random.random() in Python, runs a deterministic algorithm. The most common implementation is the Mersenne Twister (MT19937), which produces 2^19937 − 1 values before repeating.

That number is huge, and for games, simulations, and most applications it's perfectly fine. But it has one property that separates it from true randomness:

> Given the same internal state, a PRNG will always produce the same sequence. The output is predetermined the instant you set the seed. There is no uncertainty — only the illusion of it.

It's also forensic-friendly: an attacker who observes enough output can reconstruct the internal state and predict every future value. For the Mersenne Twister, that takes only 624 consecutive 32-bit outputs.

What a measured qubit actually gives you

Quantum randomness comes from the measurement of a quantum state. Simplest possible example:

  1. Start with a qubit in |0⟩.
  2. Apply a Hadamard gate. The qubit is now in superposition: (|0⟩ + |1⟩) / √2.
  3. Measure it.

The outcome — 0 or 1 — is governed by the Born rule: 50% probability each, and no hidden variable, no internal state, no algorithm decides which one you get. This isn't a gap in our knowledge. Quantum mechanics says the outcome is fundamentally undetermined until measurement.

That's what physicists mean by "true randomness." The outcome doesn't exist before measurement. It's not hidden and it's not computed. It emerges from the measurement interaction itself.

The key difference: same seed, same output

PRNG (pseudorandom)Quantum RNG (true random)
Seed 42 → output 0.6394...Circuit run #1 → 0.8271...
Seed 42 → 0.6394... (always)Circuit run #2 → 0.1548... (different)
Deterministic algorithmPhysical measurement process
Reproducible by designNon-reproducible by the laws of physics
State reconstructable from outputNo internal state to reconstruct

Run the same quantum circuit twice on the same hardware and you get different measurement distributions. That's not noise or error; it's the fundamental nature of quantum mechanics doing its job.

The approach we settled on: a quantum seed feeding a deterministic stream

For the collection we used a hybrid that gets the best of both worlds:

  1. Quantum source: a 12-qubit H+CNOT maximum-entropy circuit runs on real hardware (Origin Quantum WK_C180 or IBM Quantum ibm_fez/ibm_torino).
  2. Measurement: 8,000 shots (Origin) or 4,096 shots (IBM) produce a probability distribution.
  3. Hashing: the distribution is hashed via SHA-256 into a 256-bit seed.
  4. Deterministic expansion: the seed initializes a custom RNG class that produces a reproducible stream of values.

That's the paradox at the center of the project:

> The art is fully deterministic from its seed. But the seed itself is quantum random. You can reproduce any piece if you have its seed. But nobody — including the quantum computer — could have predicted that seed before the circuit ran.

Why do it this way? Verifiability. Anyone can take the seed from our metadata and regenerate the exact same art. The quantum randomness provides the unpredictable origin; the deterministic RNG provides the reproducible pipeline.

QuantumRNG: the class behind it

Here's the core of our deterministic RNG, seeded from quantum measurements:

import hashlib
import struct

class QuantumRNG:
    """Deterministic RNG seeded from quantum measurement data.
    Uses SHA-512 expansion + xorshift128+ for fast generation."""

    def __init__(self, hex_seed: str):
        # Expand the 256-bit quantum seed to 512 bits via SHA-512
        expanded = hashlib.sha512(bytes.fromhex(hex_seed)).digest()
        # Initialize two 64-bit state variables
        self.s0 = struct.unpack('<Q', expanded[0:8])[0]
        self.s1 = struct.unpack('<Q', expanded[8:16])[0]
        if self.s0 == 0:
            self.s0 = 0xDEADBEEFCAFEBABE
        if self.s1 == 0:
            self.s1 = 0x0123456789ABCDEF

    def _next(self) -> int:
        """xorshift128+ algorithm — one step."""
        s1 = self.s0
        s0 = self.s1
        self.s0 = s0
        s1 ^= (s1 << 23) & 0xFFFFFFFFFFFFFFFF
        s1 ^= (s1 >> 17)
        s1 ^= s0
        s1 ^= (s0 >> 26)
        self.s1 = s1
        return (self.s0 + self.s1) & 0xFFFFFFFFFFFFFFFF

    def random(self) -> float:
        """Return a float in [0, 1)."""
        return (self._next() >> 11) / (1 << 53)

    def randint(self, a: int, b: int) -> int:
        """Return a random integer in [a, b]."""
        return a + int(self.random() * (b - a + 1))

    def choice(self, seq):
        """Pick a random element from a sequence."""
        return seq[self.randint(0, len(seq) - 1)]

Three design decisions worth naming:

  • SHA-512 expansion spreads the quantum seed's full entropy across the initial state.
  • xorshift128+ is fast, has a period of 2^128 − 1, and passes standard statistical tests.
  • The class exposes the same API as Python's random module, so it's a drop-in replacement.

The circuit we run on hardware

The seed-generation circuit is designed for maximum entropy:

# Simplified version of the quantum circuit
# 12 qubits: Hadamard on all + CNOT entanglement chain

from qiskit import QuantumCircuit

qc = QuantumCircuit(12, 12)

# Put all qubits in superposition
for i in range(12):
    qc.h(i)

# Create entanglement chain (CNOT cascade)
for i in range(11):
    qc.cx(i, i + 1)

# Measure all qubits
qc.measure(range(12), range(12))

# Run on real hardware with 4096 shots
# Each shot produces a 12-bit string
# The distribution of 4096 shots becomes the seed source

The Hadamards put every qubit in an equal superposition. The CNOTs entangle them into correlations with no classical analog. Together they produce a measurement distribution with maximum Shannon entropy.

Did we actually verify it?

Claiming "quantum randomness" without evidence is just a vibe. Here's how we checked the seeds.

Shannon entropy. For a 12-qubit circuit there are 4,096 possible outcomes (2^12), so the maximum Shannon entropy is 12 bits. Our measurements consistently scored above 11.8 bits — within 98% of the theoretical maximum.

import math

def shannon_entropy(distribution: dict) -> float:
    """Calculate Shannon entropy of measurement distribution."""
    total = sum(distribution.values())
    entropy = 0.0
    for count in distribution.values():
        if count > 0:
            p = count / total
            entropy -= p * math.log2(p)
    return entropy

# Example from NFT #25 (IBM Quantum ibm_fez):
# entropy = 11.87 bits (max possible: 12.0)
# This indicates near-perfect uniformity across outcomes

Chi-squared uniformity test. Under the null hypothesis (uniform distribution), each of the 4,096 outcomes should appear once per 4,096 shots. Across our 100 quantum seeds, chi-squared p-values stayed above 0.05 — statistically indistinguishable from uniform random, which is exactly what quantum mechanics predicts for a max-entropy circuit.

Bit-level analysis. Individual bits showed no bias: each bit position split roughly 50/50, no detectable correlation between bit positions after the CNOT chain, and no patterns across consecutive seeds.

Quantum Genesis NFT #50 — midpoint of the collection

What this gives the collection's provenance

Most generative NFT projects derive traits from block.timestamp, block.difficulty, or an off-chain PRNG. All of those are deterministic. A miner can manipulate block variables; a developer can cherry-pick seeds that produce flattering outputs.

Quantum-sourced seeds change the terms:

  • Provable uniqueness: each seed comes from a physical event that can't be replicated or predicted.
  • No developer cherry-picking: the measurement produces what it produces; nobody previews seeds and picks favorites.
  • Verifiable pipeline: given the quantum seed from IPFS metadata, anyone can regenerate the art and check it matches.
  • Two-processor provenance: NFTs #1–18 carry Origin Quantum heritage; #19–100 carry IBM Quantum heritage. Each piece records its processor and backend.

The randomness isn't merely better — it's a different category. PRNG outputs are computed. Quantum outputs are measured. That distinction matters when the art is supposed to be genuinely unrepeatable.

For the full implementation — smart contract, IPFS pipeline, minting, and all the Python — I wrote a deeper dive: I Used a Real Quantum Computer to Generate Art, and the Randomness Is Nothing Like What Algorithms Can Do. The contract (ERC-721 + EIP-2981, symbol QGEN, MAX_SUPPLY=100) is verified on Polygon at 0x488fCfaEA5fDf1cF6BAED5e8A34D7858033E1a27. Metadata is on IPFS and every seed is recorded.

One honest caveat to close with: if someone ever tells you their randomness is "unhackable," check what the seed source actually is. For us, the proof was in the statistics — run the tests on your own seed pipeline before you trust it.

Comments

Popular posts from this blog

Getting Your Collection Visible on OpenSea, Step by Step

Polygon versus Ethereum for an NFT contract, from the gas bills up

Quantum Error Correction, or Why Your Qubits Forget What They Were Doing