The day quantum computers break Bitcoin — will the world end?
Which Bitcoin assets are at risk from a cryptographically relevant quantum computer, and what the timeline and migration debate around post-quantum cryptography looks like.
Entries tagged with this topic. Spans across types and sources — explore connections between people, events, and themes.
23 entries
Bitcoin Institute ↔ Satoshi Nakamoto, Adam Back
Which Bitcoin assets are at risk from a cryptographically relevant quantum computer, and what the timeline and migration debate around post-quantum cryptography looks like.
Blockstream CEO Adam Back stated Bitcoin faces no quantum computing threat for ~20–40 years, pointing to NIST post-quantum signatures like SLH-DSA that Bitcoin can adopt before threats materialize.
Adam Back's reply to a question about whether Bitcoin faces near-term risk from quantum computing, pointing at NIST-standardized SLH-DSA and a 20–40 year horizon.
Hunter Beast ↔ Ethan Heilman, Isabel Foxen Duke
Pay-to-Merkle-Root (P2MR), a quantum-resistant output type. Like Taproot without the quantum-vulnerable key path spend — commits only to the Merkle root of a script tree. SegWit v2, soft fork.
After the London High Court ordered bitcoin.org to remove the Bitcoin whitepaper, Cobra responded on Twitter with a critique declaring cryptographic rules superior to court-enforced ones.
Specifies Bech32m, a checksum variant of Bech32 that fixes an insertion-error weakness, and mandates its use for native SegWit v1+ (Taproot) addresses while v0 keeps Bech32.
Pieter Wuille ↔ Jonas Nick, Tim Ruffing
Schnorr signatures replacing ECDSA for Taproot. Provably secure, non-malleable, with efficient multi-signature aggregation — complex scripts become on-chain indistinguishable from simple payments.
Pieter Wuille ↔ Jonas Nick, Anthony Towns
Specifies tapscript — the taproot script-path validation rules: Schnorr signature checks via OP_CHECKSIG/OP_CHECKSIGADD, OP_SUCCESS upgrade opcodes, and a per-input sigops budget.
Pieter Wuille ↔ Jonas Nick, Anthony Towns
Taproot — Bitcoin's most significant protocol upgrade since SegWit. Combines Schnorr (BIP 340) with MAST so complex spending conditions look like simple payments on-chain.
Dhruv Mehta ↔ Tim Ruffing, Jonas Schnelli, Pieter Wuille
Defines the v2 P2P transport: unauthenticated opportunistic ChaCha20Poly1305 encryption over ElligatorSwift-encoded ECDH key exchange, producing a pseudorandom bytestream with v1 fallback.
Peter Todd participated in the Zcash trusted setup ceremony in October 2016 — driving across BC, shielding his laptop in a Faraday cage, and torching the hardware — then criticized the process.
Fixes ECDSA signature malleability with two consensus rules: LOW_S, requiring the lower-half S value, and NULLFAIL, requiring failing signatures be empty byte arrays.
Bitcoin Institute ↔ Pieter Wuille, Gregory Maxwell, Satoshi Nakamoto
On January 15, 2016, Bitcoin Core v0.12 replaced OpenSSL with libsecp256k1 — Wuille and Maxwell's custom elliptic-curve library — for consensus-critical ECDSA verification.
New SegWit v0 signature-hash algorithm: commits to the input's spent amount, fixes O(n^2) quadratic hashing, and changes OP_CODESEPARATOR/FindAndDelete handling.
Restricts ECDSA signatures in Bitcoin scripts to strict DER encoding, removing OpenSSL's implicit role in consensus validity and reducing transaction malleability.
Long-time Bitcoin Core contributor (gmaxwell), Blockstream co-founder, co-developer of libsecp256k1. Authored CoinJoin, co-designed Confidential Transactions. Known for deep technical write-ups.
Introduced hierarchical deterministic (HD) wallets — an entire tree of key pairs derived from a single master seed. Eliminated frequent-backup needs and enabled organized parent-child key derivation.
Bitcoin Institute ↔ Nils Schneider, Gavin Andresen, Wei Dai, Pieter Wuille, Satoshi Nakamoto
On November 20, 2011, Bitcoin v0.5 shipped with the Crypto++ SHA-256 subset removed and replaced by OpenSSL. Wei Dai's library, a direct codebase dependency since v0.1, was gone.
American cryptographer (1980-2011), Mixmaster lead developer, KU Leuven PhD candidate. Died by suicide 68 days after Satoshi's last message. Later named in a Satoshi-identity hypothesis.
Belgian software engineer (sipa), Bitcoin Core committer since 2011. Author/co-author of BIP-32, BIP-141 (SegWit), BIP-340/341 (Schnorr/Taproot). Initiator of libsecp256k1; Blockstream co-founder.
Mike Hearn points Satoshi to a forum discussion about the security of the secp256k1 curve, noting Hal Finney's concerns about its risk profile.
Bitcoin Institute ↔ Satoshi Nakamoto
How Bitcoin uses elliptic-curve keys, digital signatures, hash functions, and deterministic derivation to secure ownership without trusted third parties.
Satoshi Nakamoto ↔ James A. Donald
Satoshi argues Bitcoin represents 'a major battle in the arms race' for financial freedom, citing Gnutella and Tor as decentralized P2P networks proven resilient against government shutdown.