Bitcoin's quantum fix is splitting into three lanes and none of them are finished

Started by Hannah_36, Yesterday at 03:44 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Bitcoin's quantum fix is splitting into three lanes and none of them are finished   Views(Read 91 times)

Hannah_36

Decrypt ran a useful roundup today on where Bitcoin actually stands against the quantum threat, and it does a decent job of cutting through the usual doom headlines. The core problem hasn't changed. Bitcoin wallets rely on elliptic-curve cryptography, and a large enough quantum machine running Shor's algorithm could in theory work backwards from an exposed public key to the private key and sign away the coins. Nobody has that machine yet, but the estimates for when one might show up keep getting pulled closer

The article splits the response into three buckets. First is making quantum-resistant transactions work under the current rules, which is where StarkWare comes in. They mined what they call the first quantum-safe Bitcoin transaction on mainnet last month, and an open competition where AI models ended up leading the leaderboards reportedly cut the estimated cost of building one from around $320 to roughly $67 in a week. StarkWare itself admits it is a workaround, since the transactions are nonstandard and only help coins whose public key has never been revealed

The second bucket is the proper fix, changing Bitcoin itself to use post-quantum signatures through something like a soft fork. That is the durable answer, but anyone who watched past upgrades knows how slowly Bitcoin governance moves. Designing, testing and getting consensus on a signature change takes years, and the article notes the community has only recently started engaging with it seriously

The third bucket is custody. Coinbase's head of cryptography laid out how the exchange, which holds roughly $250 billion in assets, is building post-quantum custody that can adapt to whichever signature scheme Bitcoin eventually picks. There is even a hardware fallback planned in case the chosen standard doesn't play nicely with the key-splitting methods custodians use today. Running alongside all of this, researchers also published a Zcash-style design for shielded Bitcoin transfers, which leans on the same cryptographic toolkit

The most useful line in the piece is the admission that nothing shipped this week makes Bitcoin quantum-safe on its own. What we are seeing is the defence getting cheaper while the threat timeline gets measured more carefully. The gap between those two curves is effectively the runway the industry has left. Whether that runway is five years or fifteen, coins sitting in old addresses with exposed keys look like the obvious weak spot

Where do people here land on the soft fork question? I can see custodians protecting their own clients long before the base layer changes, which leaves ordinary self-custody users in an awkward spot


QueueDay

Coinbase guarding roughly $250 billion is the part that stood out to me. If the biggest custodian is already planning a hardware fallback, they clearly don't trust that the eventual standard will be friendly to multisig and key splitting. That tells you more about the timeline they are working to than any headline does

Northern Nicola

Going from $320 to $67 in a single week is impressive, but it is still a cost per transaction that most people will never pay for a routine transfer. It reminds me of the early SegWit fee debates

The real question is whether it keeps falling. If it hits a few dollars, then moving old coins into a quantum-safe setup becomes something normal holders would actually do

Tia

Soft forks are slow on purpose, and that conservatism has kept Bitcoin alive through a lot of bad ideas. I would rather wait an extra year than rush a signature change that breaks something nobody noticed in testing

GrimUpNorth53

Remember that the coins most at risk are the ones where the public key is already on chain. That includes a lot of very old outputs and any address that has been reused. Those are exactly the coins whose owners are least likely to move them

So even a perfect soft fork doesn't solve the problem of dormant coins. At some point the community has to decide whether to freeze them or let whoever gets there first take them
My model overfit so hard it memorised my birthday

Tel86

Exposed public keys are the whole ballgame here. StarkWare's approach does nothing for them

That is why I don't see the workaround as more than a stopgap for careful users

Save money on everyday spending Free cashback on thousands of retailers
View offer