Live data from Hacker News

Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

research.google

31–40 of 40 posts

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#31
I have compiled some notes about these recent announcements here, as it pertains to ECC and Bitcoin.

Note: There are specific address types that are safer to use for long-term storage than others, such as Native SegWit addresses starting with `bc1q`. The newest Taproot type starting with `bc1p` is insecure because it directly encodes a "tweaked" public key into the addresses.

https://bc1984.com/quantum-feasibility

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#32
Pretty much all of quantum control right now is based on the idea that qubits are these fragile things that have to be corrected, but thats because poor assumptions for quantum control are used (SO(3) precession). And even when they are treated like open quantum systems (like everything naturally is, even at 10mK and 10^-11 Torr), stuff like linblad master equations are used which is based on born-markov assumption that the env is a memoryless bath... when one stops using these poor assumptions and treat the system as a dynamical object that has natural states of stability that dont need to be actively corrected... these crypto breaking alarms are going to seem very tame.

This also has implications for alot of PQC and QKD stuff that's based on static model assumptions...

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#33
post #5

Why do they care about cryptocurrencies but not about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as HTTPS and many other electronic signature solutions? Is this a case of cryptocurrency market manipulation? And why do they think that the US government would care about securing cryptocurrencies? Aren't they designed to circumvent the government regulation?

Citibank has a good report: https://www.citigroup.com/rcs/citigpa/storage/public/Citi_In...

Tradfi has way more at risk... and the hardware/software that cant be upgraded that the financial system uses every day...

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#35
post #18

> [...] including transitioning blockchains to post-quantum cryptography (PQC), which is resistant to quantum attacks. PQC is not defined as "being resistant to quantum attacks" nor does it necessarily have this property: PQC is just cryptography for which no quantum attack is known yet (for example even when no one has tried to design a quantum computation to break the cryptography). One can not demonstrate that a s…

I think that "having no known quantum attack" is a reasonable interpretation of "quantum resistant". If there were no possible "quantum attack" (under appropriate complexity assumptions, such as EC-DLP not being in P), then we could call it "quantum proof" instead of quantum resistant.

I understand what you mean, but I think such a concept or definition would be highly misleading: "having no known quantum attack" means every novel encryption method would be automatically "quantum resistant" for having had 0 adversarial attempts to find quantum or even classical weaknesses!

There should be some measure of competence-level-adjusted man-hours of cryptographers and mathematicians trying to swing their favorite hammers at the problem; in order to estimate this "quantum resilience".

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#36
post #18

Earlier quoted context omitted.

I think that "having no known quantum attack" is a reasonable interpretation of "quantum resistant". If there were no possible "quantum attack" (under appropriate complexity assumptions, such as EC-DLP not being in P), then we could call it "quantum proof" instead of quantum resistant.

I understand what you mean, but I think such a concept or definition would be highly misleading: "having no known quantum attack" means every novel encryption method would be automatically "quantum resistant" for having had 0 adversarial attempts to find quantum or even classical weaknesses! There should be some measure of competence-level-adjusted man-hours of cryptographers and mathematicians trying to swing their…

In minutes, on a single computer, for example, is the lowest bar.

* https://mathematical-research-institute.sydney.edu.au/quantu...

* https://magma.maths.usyd.edu.au/magma/

Props to John Cannon, George Havas, Charles Leedham-Green, et al.

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#37

Earlier quoted context omitted.

My read of this post is that there's nuance here and that by the time we see 32-bit integers being factored then the roadmap to 256 bit integers can be counted in months on ten fingers rather than being a decade out. The underlying scaling needed to go to 32 bit requires only linear progress to get to 256

>The underlying scaling needed to go to 32 bit requires only linear progress to get to 256 Nope. Firstly, for RSA you need to scale from 32 to 4096. Secondly, Shor requires N^2*log(N) quantum gates where N is number of bits in the integer, so the scaling is superquadratic. And it's very much an open question whether QEC protocols will continue to work with the same efficiency on the required scales.

[deleted]

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#38

Earlier quoted context omitted.

We are talking to different things. There is linear engineering progress for getting from 32 bits to 256 bits being factored is my claim. If we want to talk RSA the engineering journey from factoring 21 to 35 is big, because it requires creating logical qubits with error rates that we are only now seeing companies report. But the engineering journey from 32 bits that are tolerant enough to run a factoring algorithm t…

>it requires creating logical qubits with error rates that we are only now seeing companies report And yet 21 was not factored on a real hardware. >There is linear engineering progress for getting from 32 bits to 256 bits being factored is my claim. IMO it's a very bold claim until linear progress is demonstrated between 8, 16, and 32 bits. Not in theoretical papers. On a real hardware. With honest experiments using…

  And yet 21 was not factored on a real hardware.
Yes it was, they used a VIC-20. Also an abacus. Not to mention a barking dog. https://eprint.iacr.org/2025/1237

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#39

> [...] including transitioning blockchains to post-quantum cryptography (PQC), which is resistant to quantum attacks. PQC is not defined as "being resistant to quantum attacks" nor does it necessarily have this property: PQC is just cryptography for which no quantum attack is known yet (for example even when no one has tried to design a quantum computation to break the cryptography). One can not demonstrate that a s…

Can't the same be said of classical attacks?

Re: Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly

#40
post #9
post #5

Why do they care about cryptocurrencies but not about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as HTTPS and many other electronic signature solutions? Is this a case of cryptocurrency market manipulation? And why do they think that the US government would care about securing cryptocurrencies? Aren't they designed to circumvent the government regulation?

> Is this market manipulation? No > why do they think that the US government would care about securing cryptocurrencies? Our largest institutions manage tens of billions of dollars in cryptocurrency and the US government has designated currencies appropriate for the strategic crypto reserve > Why do they [not care] about the entire world's infrastructures that are based on RSA and elliptic curve algorithms, such as H…

>> Is this market manipulation?

> No

"No" is not exactly the right answer, the authors are explicit about this in the paper:

"We the authors attest that at the time of the initial arXiv and IACR ePrint publication of this article, none of us hold any short positions against any cryptocurrency assets. Some of us hold long positions in cryptocurrencies, including some that involve the use of post-quantum cryptography. The authors reserve the right to initiate any positions in these assets in the future."

Post reply on HN