Live data from Hacker News

Bitcoin and quantum computing

nehanarula.org

21–30 of 147 posts

Re: Bitcoin and quantum computing

#21

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

Interesting, considering the extra liability / (stability) volatility that bitcoin options provide when making ROI and hashrate calculations, this can be a triple threat.

Like publicly destroying ivory /poppy stockpiles while simultaneously holding puts/futures on correlating pharmaceutical financial instruments.

Re: Bitcoin and quantum computing

#22
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

A hard fork implies a difference in consensus rules, and what do you propose that difference be?

Existing wallets need to actively commit to some PQ signature mechanism, prior to Q-day.

Re: Bitcoin and quantum computing

#23
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

In theory nothing prevents that but it would be so contentious that the backlash (e.g. 90% drawdown) may be even worse than just letting the hacks stand.

Re: Bitcoin and quantum computing

#24
post #16
post #10

> Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin? I've had this thought for awhile actually: how would reproducing some random number be legally "stealing" under any legal system in the world? Putting aside that cryptocurrencies have always been about "code decides" etc, that they're outside of the legal system entirely, but I'm struggling to see where there's any actual property interest her…

I can't imagine that getting laws passed is going to help. The government can't just order a bank to restore funds, the way they can with regular currency. They could try forcing the culprit to return them, but it seems unlikely for the culprit to be in your jurisdiction. I suppose we could pass laws to prevent them from ever spending the money in a country that they can control. Even then, they'd have to find ways a…

You might be surprised how many crypto hackers have been arrested and convicted. Usually they want to spend the money in civilization.

Re: Bitcoin and quantum computing

#25

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

two things:

1) Short markets in Bitcoin don't have unlimited depth, and the centralized ones are KYC'd so there's some risk there 2) What if it doesn't tank the price? One thing people have suggested is just burning all the vulnerable coins[1]; it reduces supply so maybe the price will... go up? The point is there's uncertainty.

[1] https://x.com/lostbutlucky/status/2040878873731080681

Re: Bitcoin and quantum computing

#26
Somewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this.

Now, of course, the irony here would be traditional finance infrastructure winning out over decentralized, which could definitely deal a psychological blow to BTC's perceived value... but it's something I've been thinking about lately as this existential threat rises on the horizon.

Re: Bitcoin and quantum computing

#27
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

[dead]

Re: Bitcoin and quantum computing

#28
post #26

Somewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this. Now, of course, the irony here would be traditional finance infrastructure winning out over de…

Microstrategy is already pushing/funding quantum resilience for Bitcoin, so yes!

Re: Bitcoin and quantum computing

#29
post #22
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

A hard fork implies a difference in consensus rules, and what do you propose that difference be? Existing wallets need to actively commit to some PQ signature mechanism, prior to Q-day.

Even if Q-day means there is a way to deterministically retrieve any private key from a public key (is that what it means? or is the blast radius of q-day contained? This is a bit above my level of cryptography), I’m sure we could come up with something to minimize the damage. In the worst case, it might involve a claim process with an authority or consensus mechanism to prove who the rightful owner of the funds is and revert the unauthorized transactions on the new chain.

Yes, this is not ideal! But if the wallet conversion requires active participation, preemptive measures are also not ideal.

Re: Bitcoin and quantum computing

#30
post #11

As was alluded to in the comments, my colleagues at Blockstream Research are doing some work on this with mechanisms called SHRINCS and SHRIMPS. Of course, inventing and demonstrating a quantum-resistant signature mechanism isn't the same thing as deploying it in consensus or upgrading everyone's UTXOs to it, and it's fair to say that there are many steps in between!

This work is important, and I'm looking forward to forming an opinion on it. Maybe a future post! For those who are interested, this is what I'm aware of:

- Tim Ruffing proved that Taproot's commitment scheme was quantum-resilient: https://eprint.iacr.org/2025/1307

- Jonas Nick and Mikhail Kudinov have proposed SHRINCS: https://delvingbitcoin.org/t/shrincs-324-byte-stateful-post-... and SHRIMPS: https://x.com/n1ckler/status/2038695067754328095.

Post reply on HN