Note: There are specific address types that are safer to use for long-term storage than others, such as Native SegWit addresses starting with `bc1q`. The newest Taproot type starting with `bc1p` is insecure because it directly encodes a "tweaked" public key into the addresses.
Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
31–40 of 40 posts
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#32This also has implications for alot of PQC and QKD stuff that's based on static model assumptions...
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#33Why do they care about cryptocurrencies but not about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as HTTPS and many other electronic signature solutions? Is this a case of cryptocurrency market manipulation? And why do they think that the US government would care about securing cryptocurrencies? Aren't they designed to circumvent the government regulation?
Tradfi has way more at risk... and the hardware/software that cant be upgraded that the financial system uses every day...
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#34Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#35> [...] including transitioning blockchains to post-quantum cryptography (PQC), which is resistant to quantum attacks. PQC is not defined as "being resistant to quantum attacks" nor does it necessarily have this property: PQC is just cryptography for which no quantum attack is known yet (for example even when no one has tried to design a quantum computation to break the cryptography). One can not demonstrate that a s…
I think that "having no known quantum attack" is a reasonable interpretation of "quantum resistant". If there were no possible "quantum attack" (under appropriate complexity assumptions, such as EC-DLP not being in P), then we could call it "quantum proof" instead of quantum resistant.
There should be some measure of competence-level-adjusted man-hours of cryptographers and mathematicians trying to swing their favorite hammers at the problem; in order to estimate this "quantum resilience".
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#36Earlier quoted context omitted.
I think that "having no known quantum attack" is a reasonable interpretation of "quantum resistant". If there were no possible "quantum attack" (under appropriate complexity assumptions, such as EC-DLP not being in P), then we could call it "quantum proof" instead of quantum resistant.
I understand what you mean, but I think such a concept or definition would be highly misleading: "having no known quantum attack" means every novel encryption method would be automatically "quantum resistant" for having had 0 adversarial attempts to find quantum or even classical weaknesses! There should be some measure of competence-level-adjusted man-hours of cryptographers and mathematicians trying to swing their…
* https://mathematical-research-institute.sydney.edu.au/quantu...
* https://magma.maths.usyd.edu.au/magma/
Props to John Cannon, George Havas, Charles Leedham-Green, et al.
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#37Earlier quoted context omitted.
My read of this post is that there's nuance here and that by the time we see 32-bit integers being factored then the roadmap to 256 bit integers can be counted in months on ten fingers rather than being a decade out. The underlying scaling needed to go to 32 bit requires only linear progress to get to 256
>The underlying scaling needed to go to 32 bit requires only linear progress to get to 256 Nope. Firstly, for RSA you need to scale from 32 to 4096. Secondly, Shor requires N^2*log(N) quantum gates where N is number of bits in the integer, so the scaling is superquadratic. And it's very much an open question whether QEC protocols will continue to work with the same efficiency on the required scales.
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#38Earlier quoted context omitted.
We are talking to different things. There is linear engineering progress for getting from 32 bits to 256 bits being factored is my claim. If we want to talk RSA the engineering journey from factoring 21 to 35 is big, because it requires creating logical qubits with error rates that we are only now seeing companies report. But the engineering journey from 32 bits that are tolerant enough to run a factoring algorithm t…
>it requires creating logical qubits with error rates that we are only now seeing companies report And yet 21 was not factored on a real hardware. >There is linear engineering progress for getting from 32 bits to 256 bits being factored is my claim. IMO it's a very bold claim until linear progress is demonstrated between 8, 16, and 32 bits. Not in theoretical papers. On a real hardware. With honest experiments using…
And yet 21 was not factored on a real hardware.
Yes it was, they used a VIC-20. Also an abacus. Not to mention a barking dog. https://eprint.iacr.org/2025/1237Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#39> [...] including transitioning blockchains to post-quantum cryptography (PQC), which is resistant to quantum attacks. PQC is not defined as "being resistant to quantum attacks" nor does it necessarily have this property: PQC is just cryptography for which no quantum attack is known yet (for example even when no one has tried to design a quantum computation to break the cryptography). One can not demonstrate that a s…
Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly
#40Why do they care about cryptocurrencies but not about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as HTTPS and many other electronic signature solutions? Is this a case of cryptocurrency market manipulation? And why do they think that the US government would care about securing cryptocurrencies? Aren't they designed to circumvent the government regulation?
> Is this market manipulation? No > why do they think that the US government would care about securing cryptocurrencies? Our largest institutions manage tens of billions of dollars in cryptocurrency and the US government has designated currencies appropriate for the strategic crypto reserve > Why do they [not care] about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as H…
> No
"No" is not exactly the right answer, the authors are explicit about this in the paper:
"We the authors attest that at the time of the initial arXiv and IACR ePrint publication of this article, none of us hold any short positions against any cryptocurrency assets. Some of us hold long positions in cryptocurrencies, including some that involve the use of post-quantum cryptography. The authors reserve the right to initiate any positions in these assets in the future."