> They weirdly[1] frame it around cryptocurrencies and mempools and salvaged goods or something [...] > [1] The whole paper is a bit goofy: it has a zero-knowledge proof for a quantum circuit that will certainly be rederived and improved upon before the actual hardware to run it on will exist. They seem to believe this is about responsible disclosure, so I assume this is just physicists not being experts in our field…
> Given the limited transaction throughput, migrating all vulnerable coins would take years ... How? I just googled: about 55 million addresses with bitcoin in them, about 144 blocks per day, about 3000 to 5000 tx per block. In something like 100 days all the coins would be moved to other addresses. I gotta say it'd be hilarious if to speed up that migration-to-quantum-resistant-addresses process, the Bitcoin communi…
This paper claims 60-70% throughput loss with 59 times(!) larger storage space requirements.