Live data from Hacker News

Bitcoin and quantum computing

nehanarula.org

81–90 of 147 posts

Re: Bitcoin and quantum computing

#82

Earlier quoted context omitted.

Bitcoin has had significant protocol upgrades before, including the highly divisive segwit. IMO immutability is a non-issue, there's plenty of evidence that Satoshi generally agreed that consensus via the longest chain (most PoW) wins. Thus, upgrading the protocol/code to change the encryption to something quantum-resistant should be no more controversial a change than segwit. The community has already answered the "…

I looked into it and the currently leading proposal: Hourglass v2 is pretty clever. Once 'Hourglass' is enabled, the rate at which legacy (P2PK) coins can be spent is (proposed to be) capped at 1btc / block. Thus they will not be burned, but the rate at which they can be stolen/compromised will be limited such that the economic impact is at most about 1/3 the block reward. This gives holders of those old addresses th…

Doesn’t this effectively still destroy all legacy wallets? Once the throttling limit goes into effect, it will be impossible for holders of legacy wallets to transfer their bitcoin without paying ~1 bitcoin per bitcoin they want to move. Doesn’t this amount to the same thing as abolishing all legacy wallets plus increasing the mining reward with extra steps?

Re: Bitcoin and quantum computing

#83

The thing that supposedly sets Bitcoin apart from other cryptocurrencies is that it's deflationary and 'immutable', in that Satoshi is gone forever and any deviation of Bitcoin from his golden idea will result in undermining its essence. If Bitcoin can get quantum-attacked then, from a technical point of view, nothing will be lost. The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back…

No because you are not changing the ledger. You are changing the authentication mechanism for transactions. It's like adding a new supported password hash.

If you don’t also drop wallets with compromised signatures at some point after introducing secure signatures (effectively editing the ledger) they will be up for grabs.

Absent a functional ledger rewrite I expect there would be some window where miners with access to CRQCs switch their focus over to exclusively mining blocks of transactions transferring coins from insecure wallets to secure wallets under their own control. Is there actually interest in living in the world where the first person with both a CRQC and a mining farm gets to claim all of the stranded bitcoins for themselves?

Re: Bitcoin and quantum computing

#84

Naive question may be. But if quantum can break bitcoin, won't it also be able to break other encryptions that literally everyone else uses as well? So, it's not that bitcoin is particularly vulnerable right any more than banks and Gmails?

From the article:

Q: A CRQC also breaks banking, military communications, and most of the internet today! If one appears, isn’t Bitcoin the least of our problems?

A: True! Banking software, military communications, and the internet also need to be upgraded. I have high confidence they will be, successfully (I’d put my B_{HTTPS} at close to 1). Unfortunately, I have less confidence that Bitcoin will upgrade successfully since upgrading a decentralized system of honey-badger-like participants is much more challenging and people like the questioner seem to think this is a valid argument that we shouldn’t even worry about it? If you disagree and think there will be a CRQC and the rest of the internet won’t upgrade successfully, maybe you should consider shorting the stock market and buying gold. But not Bitcoin, because if we do nothing that won’t work anymore. Not investment advice.

Re: Bitcoin and quantum computing

#85
post #65

The world digital economy is worth more than 20T and we're concerned about an asset <2T!? If quantum breaks the highest form of encryption we have today, we have bigger problems at hand.

The signature scheme used by bitcoin is far from the best encryption we have today, and more resistant to being updated than most more important things. So it’s an interesting novelty.

Re: Bitcoin and quantum computing

#86
post #20

One thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a b…

I'd argue there may be an increase in value over time if the community handles the fork well.

And you’d get laughed at for that argument.

Re: Bitcoin and quantum computing

#87
post #26

Somewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this. Now, of course, the irony here would be traditional finance infrastructure winning out over de…

In the absolute disaster scenario where the ecosystem is taken by surprise by an adversary with a CRQC, regulated custodians could form a consortium to reconstitute a new quantum-resistant version of bitcoin, pooling their ownership ledgers from before the disaster to reinitialize the blockchain and consigning to oblivion all coins not held in custody.

Which would ofc be hilarious given BTC’s raison d’être.

Re: Bitcoin and quantum computing

#88

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

Does anyone happen to know if it is settled law in the United States that transferring bitcoins using a cracked key is a criminal act? It’s not immediately obvious to me that it would be covered by the CFAA.

I would be surprised if the U.S. legal system requires itself to list every possible mechanism by which someone might steal money.

Re: Bitcoin and quantum computing

#89
post #25

The mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.

two things: 1) Short markets in Bitcoin don't have unlimited depth, and the centralized ones are KYC'd so there's some risk there 2) What if it doesn't tank the price? One thing people have suggested is just burning all the vulnerable coins[1]; it reduces supply so maybe the price will... go up? The point is there's uncertainty. [1] https://x.com/lostbutlucky/status/2040878873731080681

I’m pretty sure the hope isn’t that burning some coins tanks the price. The point is that publicly demonstrating that you can crack wallet keys is what tanks the price.

Re: Bitcoin and quantum computing

#90
post #77

Earlier quoted context omitted.

This time you'll have hundreds of billions of BTC that will be hacked by someone who will probably instantly unload it. In that scenario it's hard to see the price of it not dropping >90%, so you'd have to think people would prefer a roll back. That said, I don't know how you could even do a roll back, you're not rolling back to a 'safe' state since the keys aren't safe at that point.

Very good point on the roll-back. However in terms of the hack, Bitcoin is slow - most exchanges require a few confirmations so it's 30+ minutes to land a deposit in Coinbase/Binance at minimum, and a transfer that huge would instantly set off alarms. Seems unlikely that they would be able to unload that much.

Coinbase would definitely go into buy-only mode during a major crash but that just means people would scream while they watch futures/perps go to zero.

"If you're first out the door, that's not called panicking."

Post reply on HN