Live data from Hacker News

Bitcoin and quantum computing

nehanarula.org

71–80 of 147 posts

Re: Bitcoin and quantum computing

#71
Naive question may be. But if quantum can break bitcoin, won't it also be able to break other encryptions that literally everyone else uses as well? So, it's not that bitcoin is particularly vulnerable right any more than banks and Gmails?

Re: Bitcoin and quantum computing

#72

Naive question may be. But if quantum can break bitcoin, won't it also be able to break other encryptions that literally everyone else uses as well? So, it's not that bitcoin is particularly vulnerable right any more than banks and Gmails?

Yes and no. I'm no expert, but there's two things that don't make it nearly as dangerous as it is for BTC.

The first is the fact that many things are centralized. Things like Signal already have quantum-resistant encryption, and if they don't, they're able to implement it relatively quickly because it's centralized. BTC is not centralized and needs to jump through a bunch of hoops to get anything done.

The second is that because those things are centralized or close to, you can roll back changes with ease. For instance, if you hack a bank and steal a bunch of money from an account you're far more likely to be able to freeze those funds and get other banks to help stop everything before they're gone forever. You can't do that with BTC.

Re: Bitcoin and quantum computing

#73
post #34
post #23

Earlier quoted context omitted.

In theory nothing prevents that but it would be so contentious that the backlash (e.g. 90% drawdown) may be even worse than just letting the hacks stand.

The Bitcoin “value overflow incident” on August 15, 2010 is probably the closest thing and that didn't affect the price much (though one BTC was around 8c at the time)

This time you'll have hundreds of billions of BTC that will be hacked by someone who will probably instantly unload it. In that scenario it's hard to see the price of it not dropping >90%, so you'd have to think people would prefer a roll back.

That said, I don't know how you could even do a roll back, you're not rolling back to a 'safe' state since the keys aren't safe at that point.

Re: Bitcoin and quantum computing

#74
post #25

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

two things: 1) Short markets in Bitcoin don't have unlimited depth, and the centralized ones are KYC'd so there's some risk there 2) What if it doesn't tank the price? One thing people have suggested is just burning all the vulnerable coins[1]; it reduces supply so maybe the price will... go up? The point is there's uncertainty. [1] https://x.com/lostbutlucky/status/2040878873731080681

What risk are you envisioning in #1?

Re: Bitcoin and quantum computing

#75

The thing that supposedly sets Bitcoin apart from other cryptocurrencies is that it's deflationary and 'immutable', in that Satoshi is gone forever and any deviation of Bitcoin from his golden idea will result in undermining its essence. If Bitcoin can get quantum-attacked then, from a technical point of view, nothing will be lost. The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back…

Bitcoin has had significant protocol upgrades before, including the highly divisive segwit. IMO immutability is a non-issue, there's plenty of evidence that Satoshi generally agreed that consensus via the longest chain (most PoW) wins. Thus, upgrading the protocol/code to change the encryption to something quantum-resistant should be no more controversial a change than segwit. The community has already answered the "…

> Anyone know if there's a way out that doesn't require this?

Honestly, I see this as a way for the powers that be to force explicit KYC. You want those coins? You prove they're yours, you stick your name on that wallet and all the liability that comes along with it. Otherwise the government (some government) holds onto them until you can definitively prove they're yours. I dont think this scenario is likely, but I can see it being something that is proposed or tried.

Re: Bitcoin and quantum computing

#76

The thing that supposedly sets Bitcoin apart from other cryptocurrencies is that it's deflationary and 'immutable', in that Satoshi is gone forever and any deviation of Bitcoin from his golden idea will result in undermining its essence. If Bitcoin can get quantum-attacked then, from a technical point of view, nothing will be lost. The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back…

Bitcoin has had significant protocol upgrades before, including the highly divisive segwit. IMO immutability is a non-issue, there's plenty of evidence that Satoshi generally agreed that consensus via the longest chain (most PoW) wins. Thus, upgrading the protocol/code to change the encryption to something quantum-resistant should be no more controversial a change than segwit. The community has already answered the "…

I looked into it and the currently leading proposal: Hourglass v2 is pretty clever. Once 'Hourglass' is enabled, the rate at which legacy (P2PK) coins can be spent is (proposed to be) capped at 1btc / block. Thus they will not be burned, but the rate at which they can be stolen/compromised will be limited such that the economic impact is at most about 1/3 the block reward.

This gives holders of those old addresses the maximum amount of time to move their coins to more modern addresses and still the ability to move some coins after the deadline. If legacy keys are compromised in bulk, IE access to sufficiently powerful quantum computing is rapid and widespread, then there will be high competition via the existing txn fee bidding process for that 1btc/block slot. Thus most of the value of the will be captured by the txn fee and go to the miners, effectively boosting the mining reward by ~1/3.

Re: Bitcoin and quantum computing

#77
post #34

Earlier quoted context omitted.

The Bitcoin “value overflow incident” on August 15, 2010 is probably the closest thing and that didn't affect the price much (though one BTC was around 8c at the time)

This time you'll have hundreds of billions of BTC that will be hacked by someone who will probably instantly unload it. In that scenario it's hard to see the price of it not dropping >90%, so you'd have to think people would prefer a roll back. That said, I don't know how you could even do a roll back, you're not rolling back to a 'safe' state since the keys aren't safe at that point.

Very good point on the roll-back.

However in terms of the hack, Bitcoin is slow - most exchanges require a few confirmations so it's 30+ minutes to land a deposit in Coinbase/Binance at minimum, and a transfer that huge would instantly set off alarms. Seems unlikely that they would be able to unload that much.

Re: Bitcoin and quantum computing

#78
post #59

Earlier quoted context omitted.

> fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? It won't work. The only way to authenticate who ones what coins is with signatures. If the signature algorithm is broken, you can't tell who the original owner is to move the coins to a safe signature algorithm. You need to more to safer signature algorithm before the break, after the break it is game over. > It’s worth remem…

> The only way to authenticate who owns what coins is with signatures Maybe the only fully cryptographic absolutely zero-trust way? In practice there are very few bitcoin outputs that aren't linked to an offline identity and most users could easily produce a proof of ownership. Of course, this is not ideal and everyone would prefer not to go down that route. But even if we prepare in time and Bitcoin provides a quant…

> In practice there are very few bitcoin outputs that aren't linked to an offline identity and most users could easily produce a proof of ownership.

Any who is going to in charge of reading that proof of identity and moving the coins? A trusted centralized party? The point of Bitcoin is to avoid exactly that sort of trust relationship, otherwise use the banking system.

> Satoshi's wallet alone could crash Bitcoin's value as a currency if dumped on the open market.

No one knows, but the incentives are aligned with a softfork to burn Satoshi's coins.

Re: Bitcoin and quantum computing

#79

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

Does anyone happen to know if it is settled law in the United States that transferring bitcoins using a cracked key is a criminal act? It’s not immediately obvious to me that it would be covered by the CFAA.

Re: Bitcoin and quantum computing

#80
post #26

Somewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this. Now, of course, the irony here would be traditional finance infrastructure winning out over de…

In the absolute disaster scenario where the ecosystem is taken by surprise by an adversary with a CRQC, regulated custodians could form a consortium to reconstitute a new quantum-resistant version of bitcoin, pooling their ownership ledgers from before the disaster to reinitialize the blockchain and consigning to oblivion all coins not held in custody.
Post reply on HN