Groups
Groups
Sign in
Groups
Groups
Bitcoin Development Mailing List
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of 30
Fabian
, …
Boris Nagaev
8
Aug 5
BIP draft: CISA for Taproot Key Path Spends
we use
BIP
-459 full aggregation for P2MR or P2TRH, we can recover one of the EC keys of a CISA group, solving its equation for that EC key. This saves 32 bytes per group. If a group is small
unread,
BIP draft: CISA for Taproot Key Path Spends
we use
BIP
-459 full aggregation for P2MR or P2TRH, we can recover one of the EC keys of a CISA group, solving its equation for that EC key. This saves 32 bytes per group. If a group is small
Aug 5
conduition
, …
ArmchairCryptologist
20
Jun 26
Aligning privacy incentives in P2MR
merged into
BIP360
which amends the spec to change depth-zero trees to be anyone-can-spend. Kudos to Ethan Heilman for this excellent suggestion in response to my OP. P2MR is now much
unread,
Aligning privacy incentives in P2MR
merged into
BIP360
which amends the spec to change depth-zero trees to be anyone-can-spend. Kudos to Ethan Heilman for this excellent suggestion in response to my OP. P2MR is now much
Jun 26
Pieter Wuille
, …
conduition
12
Aug 14
Giving teeth to expected EC disabling: P2XX(-T)(-ML)
p2mr-
bip
-
360
/2603 > [4]: https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m/8nr6I5NIAwAJ > [5]: https://groups.google.com/g/bitcoindev/c/p8AVEmAtWdA
unread,
Giving teeth to expected EC disabling: P2XX(-T)(-ML)
p2mr-
bip
-
360
/2603 > [4]: https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m/8nr6I5NIAwAJ > [5]: https://groups.google.com/g/bitcoindev/c/p8AVEmAtWdA
Aug 14
opus lux
, …
conduition
4
Jun 8
[BIP] P2WOTS: 64 Slot Winternitz UTXO's (witness version three)
worse than
BIP360
: - It doesn't offer any flexibility with respect to gradual migration. The complete absence of usable EC spending paths would ensure absolutely nobody will
unread,
[BIP] P2WOTS: 64 Slot Winternitz UTXO's (witness version three)
worse than
BIP360
: - It doesn't offer any flexibility with respect to gradual migration. The complete absence of usable EC spending paths would ensure absolutely nobody will
Jun 8
Amarildo
,
Alex
3
Jun 5
Q-Lock: Quantum-Resistant Spending via ECDSA + Hash-Based Secrets
-read
BIP360
(it has changed a lot) and look at SHRINCS. > > 1.
BIP360
does not introduce any new PQ algos. All it does is add a new > Taproot address that disables the (implied
unread,
Q-Lock: Quantum-Resistant Spending via ECDSA + Hash-Based Secrets
-read
BIP360
(it has changed a lot) and look at SHRINCS. > > 1.
BIP360
does not introduce any new PQ algos. All it does is add a new > Taproot address that disables the (implied
Jun 5
Matt Corallo
, …
Louise Michel
26
May 28
PQC - What is our Goal, Even?
proponents of
BIP
-
360
, which is a literal copypasta of Taproot with the key-path spend hacked out of it. be well, Louise On Thursday, May 21, 2026 at 12:17:56 PM UTC-6 conduition wrote
unread,
PQC - What is our Goal, Even?
proponents of
BIP
-
360
, which is a literal copypasta of Taproot with the key-path spend hacked out of it. be well, Louise On Thursday, May 21, 2026 at 12:17:56 PM UTC-6 conduition wrote
May 28
Olaoluwa Osuntokun
, …
conduition
18
May 22
Post-Quantum BIP-86 Recovery via zk-STARK Proof of BIP-32 Seed Knowledge
extends to
BIP
-352 (Silent Payments) > > Yup, as shown in my latest post, we can batch aggregate multiple claims into a > > single proof. If this were to be deployed at some
unread,
Post-Quantum BIP-86 Recovery via zk-STARK Proof of BIP-32 Seed Knowledge
extends to
BIP
-352 (Silent Payments) > > Yup, as shown in my latest post, we can batch aggregate multiple claims into a > > single proof. If this were to be deployed at some
May 22
Amon BAZONGO
, …
Murch
7
May 22
What if we let Quantum Hunters get Bitcoin rewards ?
we suppose
BIP
-
360
is a prerequisite to my proposal. Which means that all new addresses would be quantum-resistant. Each old-address holder is responsible to migrate to a new quantum
unread,
What if we let Quantum Hunters get Bitcoin rewards ?
we suppose
BIP
-
360
is a prerequisite to my proposal. Which means that all new addresses would be quantum-resistant. Each old-address holder is responsible to migrate to a new quantum
May 22
Erik Aronesty
, …
Ali Sherief
10
Apr 28
Deactivating ECDSA/Schnorr
PQC is
BIP360
and many invalidly assume its >> disabling of key spend path means "deactivating Schnorr". That's NOT what >> the
BIP
does: >> >
unread,
Deactivating ECDSA/Schnorr
PQC is
BIP360
and many invalidly assume its >> disabling of key spend path means "deactivating Schnorr". That's NOT what >> the
BIP
does: >> >
Apr 28
Antoine Poinsot
, …
Matt Corallo
36
Apr 19
In defense of a PQ output type
defense of
BIP
360
. I think their approach of keeping Taproot's Merkle > tree of
BIP
342 Scripts is a fine design, but my argument applies to an output > type that enables a hash
unread,
In defense of a PQ output type
defense of
BIP
360
. I think their approach of keeping Taproot's Merkle > tree of
BIP
342 Scripts is a fine design, but my argument applies to an output > type that enables a hash
Apr 19
Ethan Heilman
, …
moonsettler
46
Apr 2
Algorithm Agility for Bitcoin to maintain security in the face of quantum and classic breaks in the signature algorithms
> Using
BIP
360
, we could have a leaf script for CHECKSIG_DSA1 and a leaf script for CHECKSIG_DSA2. > > > > > > Leaf1: DSA1_PUBKEY, CHECKSIG_DSA1 > > >
unread,
Algorithm Agility for Bitcoin to maintain security in the face of quantum and classic breaks in the signature algorithms
> Using
BIP
360
, we could have a leaf script for CHECKSIG_DSA1 and a leaf script for CHECKSIG_DSA2. > > > > > > Leaf1: DSA1_PUBKEY, CHECKSIG_DSA1 > > >
Apr 2
conduition
Mar 28
Post Quantum HD Wallets with fallback SPHINCS keys
Hi List, With the progress of BIP360's P2MR address format, and Ethan's recent thread [1] about cryptographic agility, now seems a good time to
unread,
Post Quantum HD Wallets with fallback SPHINCS keys
Hi List, With the progress of BIP360's P2MR address format, and Ethan's recent thread [1] about cryptographic agility, now seems a good time to
Mar 28
Rusty Russell
, …
Anthony Towns
10
Mar 26
[0/4] A Bitcoin Scripting Proposal BIP Quartet
(eg
BIP
360
). But I'm > unsure if should fail for those, return empty, or use the second final > witness script and hope that convention survives into the future... > >
unread,
[0/4] A Bitcoin Scripting Proposal BIP Quartet
(eg
BIP
360
). But I'm > unsure if should fail for those, return empty, or use the second final > witness script and hope that convention survives into the future... > >
Mar 26
sashabeton
, …
aaron.recompile
17
Mar 24
[BIP proposal] Pay to Schnorr Key Hash (P2SKH)
Taproot or
BIP360
. And since we will need quantum upgrade at some >>> point, this upgrade is kind of (in my personal interpretation) doubling >>> down to the part
unread,
[BIP proposal] Pay to Schnorr Key Hash (P2SKH)
Taproot or
BIP360
. And since we will need quantum upgrade at some >>> point, this upgrade is kind of (in my personal interpretation) doubling >>> down to the part
Mar 24
Giulio Golinelli
, …
conduition
13
Feb 2
Falcon Post-Quantum Signature Scheme Proposal
signature opcode
BIP
following
BIP360
. > > > > > > https://blog.cloudflare.com/nist-post-quantum-surprise/#floating-points-falcons-achilles > >
unread,
Falcon Post-Quantum Signature Scheme Proposal
signature opcode
BIP
following
BIP360
. > > > > > > https://blog.cloudflare.com/nist-post-quantum-surprise/#floating-points-falcons-achilles > >
Feb 2
Hunter Beast
,
Erik Aronesty
2
12/23/25
Major BIP 360 Update
. Between
BIP360
and something like TXHASH, it's possible to make quantum safe scripts and multi-step commit-reveal vaults that don't relay solely on signatures at all.
unread,
Major BIP 360 Update
. Between
BIP360
and something like TXHASH, it's possible to make quantum safe scripts and multi-step commit-reveal vaults that don't relay solely on signatures at all.
12/23/25
Mikhail Kudinov
, …
conduition
17
Jan 18
Hash-Based Signatures for Bitcoin's Post-Quantum Future
that enables
BIP
-32-like functionality. It achieves this by getting rid of a public key compression step in the OG algorithm that results in a loss of homomorphic properties. There
unread,
Hash-Based Signatures for Bitcoin's Post-Quantum Future
that enables
BIP
-32-like functionality. It achieves this by getting rid of a public key compression step in the OG algorithm that results in a loss of homomorphic properties. There
Jan 18
conduition
, …
Nagaev Boris
4
12/1/25
SLH-DSA (SPHINCS) Performance Optimization Techniques
noticed that
BIP360
doesn't appear to specify the exact hash function to be used in SPHINCS
BIP360
specifies a new witness version and address format: P2TSH (effectively taproot
unread,
SLH-DSA (SPHINCS) Performance Optimization Techniques
noticed that
BIP360
doesn't appear to specify the exact hash function to be used in SPHINCS
BIP360
specifies a new witness version and address format: P2TSH (effectively taproot
12/1/25
James T
, …
conduition
8
9/15/25
[BIP Proposal] No burn, Quantum Migration Proposal, Quantum Secure Asset Verification & Escrow (QSAVE)
this "
BIP
" would maintain Bitcoin's value as a distributed system. It more-or-less sounds like you're suggesting to vest the power of quantum-recovery using
unread,
[BIP Proposal] No burn, Quantum Migration Proposal, Quantum Secure Asset Verification & Escrow (QSAVE)
this "
BIP
" would maintain Bitcoin's value as a distributed system. It more-or-less sounds like you're suggesting to vest the power of quantum-recovery using
9/15/25
Jameson Lopp
, …
conduition
25
9/15/25
A Post Quantum Migration Proposal
post-
BIP
-
360
+ 2 years) assumes smooth consensus and implementation. Given Bitcoin's history, this could easily stretch to 7-10 years, most likely pushing implementation
unread,
A Post Quantum Migration Proposal
post-
BIP
-
360
+ 2 years) assumes smooth consensus and implementation. Given Bitcoin's history, this could easily stretch to 7-10 years, most likely pushing implementation
9/15/25
Josh Doman
, …
Javier Mateos
5
8/19/25
Revisiting secp256r1 signatures (i.e. P256, mobile HSM support)
parallel:
BIP360
and other post-quantum debates which > will eventually lead to the addition of at least one new signature > algorithm to consensus. By the time P256 is standardized
unread,
Revisiting secp256r1 signatures (i.e. P256, mobile HSM support)
parallel:
BIP360
and other post-quantum debates which > will eventually lead to the addition of at least one new signature > algorithm to consensus. By the time P256 is standardized
8/19/25
Jameson Lopp
, …
thomas suau
54
May 18
Against Allowing Quantum Recovery of Bitcoin
I remember what i was talking about a few weeks back. I was envisioning that all the pubkeys would be merged together across all inputs, but this would
unread,
Against Allowing Quantum Recovery of Bitcoin
I remember what i was talking about a few weeks back. I was envisioning that all the pubkeys would be merged together across all inputs, but this would
May 18
Bitcoin Foundation
, …
Alex Pruden
9
8/22/25
[Draft BIP] Quantum-Resistant Transition Framework for Bitcoin
. This
BIP
deliberately excludes non-NIST submissions like SQISign, which fails to meet basic security requirements upon examination. While ML-DSA (CRYSTALS-Dilithium) shows
unread,
[Draft BIP] Quantum-Resistant Transition Framework for Bitcoin
. This
BIP
deliberately excludes non-NIST submissions like SQISign, which fails to meet basic security requirements upon examination. While ML-DSA (CRYSTALS-Dilithium) shows
8/22/25
Greg Sanders
, …
Garlo Nicon
18
7/31/25
A Taproot-native (re-)bindable transaction bundle proposal
context of
BIP360
: > https://delvingbitcoin.org/t/changes-to-
bip
-
360
-pay-to-quantum-resistant-hash-p2qrh/1811/11 > . > > Therefore, our starting position
unread,
A Taproot-native (re-)bindable transaction bundle proposal
context of
BIP360
: > https://delvingbitcoin.org/t/changes-to-
bip
-
360
-pay-to-quantum-resistant-hash-p2qrh/1811/11 > . > > Therefore, our starting position
7/31/25
Ethan Heilman
, …
Ava Chow
9
7/21/25
Human meaningful witness versioning
I misread
BIP
173 and bech32 does drop the OP_PUSH32. This answers my question. As an outcome of this conversation
BIP
360
no longer uses Witness version 3 but Witness version 2. https
unread,
Human meaningful witness versioning
I misread
BIP
173 and bech32 does drop the OP_PUSH32. This answers my question. As an outcome of this conversation
BIP
360
no longer uses Witness version 3 but Witness version 2. https
7/21/25
Ethan Heilman
7/7/25
Changes to BIP-360 - Pay to Quantum Resistant Hash (P2QRH)
changes to
BIP
-
360
(Pay to Quantum Resistant Hash) PR : - P2QRH (Pay to Quantum Resistant Hash) is now taproot (P2TR) but with the quantum vulnerable key-spend path removed. - PQ signatures
unread,
Changes to BIP-360 - Pay to Quantum Resistant Hash (P2QRH)
changes to
BIP
-
360
(Pay to Quantum Resistant Hash) PR : - P2QRH (Pay to Quantum Resistant Hash) is now taproot (P2TR) but with the quantum vulnerable key-spend path removed. - PQ signatures
7/7/25
Bas Westerbaan
, …
Q C
5
6/17/25
jpeg resistance of various post-quantum signature schemes
> of
BIP
-
360
. SLH-DSA is concering, in that 7/8 arbitrary data would make it >> about on par with the de facto witness discount. I don't want to sacrifice >> SLH-
unread,
jpeg resistance of various post-quantum signature schemes
> of
BIP
-
360
. SLH-DSA is concering, in that 7/8 arbitrary data would make it >> about on par with the de facto witness discount. I don't want to sacrifice >> SLH-
6/17/25
Ethan Heilman
, …
Pieter Wuille
8
4/14/25
Post Quantum Signatures and Scaling Bitcoin
according to
BIP
-
360
Falcon is cheaper than edDSA per signature verification. EdDSA Cycles to verify: 130000 FALCON-512 Cycles to verify: 81036 This is one of the reasons I am very
unread,
Post Quantum Signatures and Scaling Bitcoin
according to
BIP
-
360
Falcon is cheaper than edDSA per signature verification. EdDSA Cycles to verify: 130000 FALCON-512 Cycles to verify: 81036 This is one of the reasons I am very
4/14/25
Hunter Beast
, …
Jose Storopoli
20
3/13/25
P2QRH / BIP-360 Update
that this
BIP
will become a mistake in Bitcoin in 15 years or > less. > > It adds orders of magnitude to public keys sizes and/or signature sizes; > and verification computation
unread,
P2QRH / BIP-360 Update
that this
BIP
will become a mistake in Bitcoin in 15 years or > less. > > It adds orders of magnitude to public keys sizes and/or signature sizes; > and verification computation
3/13/25
Agustin Cruz
, …
ArmchairCryptologist
17
3/9/25
Proposal for Quantum-Resistant Address Migration Protocol (QRAMP) BIP
the existing
BIP
-
360
(Pay to Quantum Resistant Hash) proposal. Both of these proposals aim to protect Bitcoin from potential quantum computing threats, but they approach the problem
unread,
Proposal for Quantum-Resistant Address Migration Protocol (QRAMP) BIP
the existing
BIP
-
360
(Pay to Quantum Resistant Hash) proposal. Both of these proposals aim to protect Bitcoin from potential quantum computing threats, but they approach the problem
3/9/25