Groups
Groups
Sign in
Groups
Groups
Bitcoin Development Mailing List
Conversations
About
Send feedback
Help
Sort By Relevance
Sort By Date
1–30 of many
Antoine Riard
Oct 2
Getting BIP54 past the finish line
it post
quantum
or other security fixes, and imo it's better as a community we don't sleep on them. Cheers, Antoine OTS hash: dbc7c36dbce85e4885b4d140bb90a1d775176b7ec60753d02a655e42418062bb
unread,
Getting BIP54 past the finish line
it post
quantum
or other security fixes, and imo it's better as a community we don't sleep on them. Cheers, Antoine OTS hash: dbc7c36dbce85e4885b4d140bb90a1d775176b7ec60753d02a655e42418062bb
Oct 2
Olaoluwa Osuntokun
, …
Liam Gilligan
8
Sep 23
A Post-Quantum Path for BIP 324
post-
quantum
peer-to-peer) > - CRQC (cryptographically relevant
quantum
computer) > - HNDL (harvest now, decrypt later): Recording classically encrypted > traffic
unread,
A Post-Quantum Path for BIP 324
post-
quantum
peer-to-peer) > - CRQC (cryptographically relevant
quantum
computer) > - HNDL (harvest now, decrypt later): Recording classically encrypted > traffic
Sep 23
James T
, …
conduition
9
Sep 21
[BIP Proposal] No burn, Quantum Migration Proposal, Quantum Secure Asset Verification & Escrow (QSAVE)
, and
quantum
computers were a distant thought, but he acknowledged that in certain circumstances we might need to rewrite the chain. However, you are right: this is vanishingly unlikely
unread,
[BIP Proposal] No burn, Quantum Migration Proposal, Quantum Secure Asset Verification & Escrow (QSAVE)
, and
quantum
computers were a distant thought, but he acknowledged that in certain circumstances we might need to rewrite the chain. However, you are right: this is vanishingly unlikely
Sep 21
James T
Sep 22
QSAVE post-quantum solution for non-migrated coins
post-
quantum
transition solution that avoids burning coins. I have tried to incorporate the feedback I received on my earlier posts. The proposed solution is laid out in five draft
unread,
QSAVE post-quantum solution for non-migrated coins
post-
quantum
transition solution that avoids burning coins. I have tried to incorporate the feedback I received on my earlier posts. The proposed solution is laid out in five draft
Sep 22
conduition
, …
Murch
7
Sep 18
SHRINCS: an efficient hash-based signature scheme for Bitcoin (first draft)
>>
quantum
)*. SHRINCS' security depends only on properties of > >>> the (truncated) SHA256 hash function which are believed to > >>> be post
unread,
SHRINCS: an efficient hash-based signature scheme for Bitcoin (first draft)
>>
quantum
)*. SHRINCS' security depends only on properties of > >>> the (truncated) SHA256 hash function which are believed to > >>> be post
Sep 18
conduition
, …
Antoine Riard
4
Sep 18
DropKick ⚽️ - A minimal commit/reveal PQ rescue protocol
coins of
quantum
procrastinators - those who take no >> action to move their coins to PQC-enabled wallets by Q-Day. >> >> https://conduition.io/bitcoin/dropkick
unread,
DropKick ⚽️ - A minimal commit/reveal PQ rescue protocol
coins of
quantum
procrastinators - those who take no >> action to move their coins to PQC-enabled wallets by Q-Day. >> >> https://conduition.io/bitcoin/dropkick
Sep 18
duncan0k
,
conduition
5
Sep 18
Standardizing public key exposure classification for existing outputs
post-
quantum
leaves exist, and NOT_EXPOSED has no member today. Draft, reference implementation and 25 vectors: https://github.com/duncan0k/pubkey-exposure-classification
unread,
Standardizing public key exposure classification for existing outputs
post-
quantum
leaves exist, and NOT_EXPOSED has no member today. Draft, reference implementation and 25 vectors: https://github.com/duncan0k/pubkey-exposure-classification
Sep 18
Liam Gilligan
Sep 17
[BIP Proposal] Transport Feature Negotiation
Hi everyone, TL;DR (using Terms and Defs below): In order to support encryption upgrades and the addition of authentication to P2P, I propose we
unread,
[BIP Proposal] Transport Feature Negotiation
Hi everyone, TL;DR (using Terms and Defs below): In order to support encryption upgrades and the addition of authentication to P2P, I propose we
Sep 17
2099999997690000
,
duncan0k
2
Sep 11
[BIP draft] Unspendable Internal Keys for Wallet Policies
post-
quantum
use. Under current rules a CRQC that solves Q can key-path spend any P2TR output regardless of how Q was built; on-chain, a tweaked NUMS key and a bare untweaked key are indistinguishable
unread,
[BIP draft] Unspendable Internal Keys for Wallet Policies
post-
quantum
use. Under current rules a CRQC that solves Q can key-path spend any P2TR output regardless of how Q was built; on-chain, a tweaked NUMS key and a bare untweaked key are indistinguishable
Sep 11
jeremy
, …
conduition
6
Sep 4
Knowledge Gathering: SPV Proof Applications In the Wild and Proposed
before a
quantum
attacker did, ie a commit/reveal protocol. Details here: https://conduition.io/bitcoin/dropkick/ and here: https://groups.google.com/g/bitcoindev/c/
unread,
Knowledge Gathering: SPV Proof Applications In the Wild and Proposed
before a
quantum
attacker did, ie a commit/reveal protocol. Details here: https://conduition.io/bitcoin/dropkick/ and here: https://groups.google.com/g/bitcoindev/c/
Sep 4
Antoine Riard
,
conduition
3
Aug 26
post-quantum: solution ideas to "tripwire"game-theory issues + a certificate-based rescue protocol
mass-
quantum
-theft event. I think you can do that with a soft-fork, if you go as deep of designing merge-mining mechanisms to minimize miners equivocation, at the time of the "
unread,
post-quantum: solution ideas to "tripwire"game-theory issues + a certificate-based rescue protocol
mass-
quantum
-theft event. I think you can do that with a soft-fork, if you go as deep of designing merge-mining mechanisms to minimize miners equivocation, at the time of the "
Aug 26
Pieter Wuille
, …
waxwing/ AdamISZ
22
Aug 19
Giving teeth to expected EC disabling: P2XX(-T)(-ML)
to build
quantum
computers, we have no reason to expect anyone will build a QC that can break 192-bit curves but not 256-bit curves. There is actually incentive not to do so, especially
unread,
Giving teeth to expected EC disabling: P2XX(-T)(-ML)
to build
quantum
computers, we have no reason to expect anyone will build a QC that can break 192-bit curves but not 256-bit curves. There is actually incentive not to do so, especially
Aug 19
Antoine Riard
,
conduition
4
Aug 11
The game-theory problems of PQ sunsetting modes
a-
quantum
-emergency/18901
Quantum
attackers would want plausible deniability, but also finality (no backsies). Otherwise the attack is pointless. regards, conduition On Monday
unread,
The game-theory problems of PQ sunsetting modes
a-
quantum
-emergency/18901
Quantum
attackers would want plausible deniability, but also finality (no backsies). Otherwise the attack is pointless. regards, conduition On Monday
Aug 11
shinobimonkey
,
conduition
6
Aug 11
Quantum Recovery Of Hashed Address Secured Coins With No Confiscatory Risk
for a
quantum
safe scheme), and a timestamp to prove that this attestation was produced before some pre-defined deadline chosen to expire before a viable
quantum
computer exists.
unread,
Quantum Recovery Of Hashed Address Secured Coins With No Confiscatory Risk
for a
quantum
safe scheme), and a timestamp to prove that this attestation was produced before some pre-defined deadline chosen to expire before a viable
quantum
computer exists.
Aug 11
Fabian
, …
Boris Nagaev
8
Aug 10
BIP draft: CISA for Taproot Key Path Spends
not actually
quantum
-safe by default, need to solve the Q-day timing problem). 2. Hide the EC pubkeys behind a hash in the SPK (eg P2MR or P2TRH), and attach the EC pubkey in the witness
unread,
BIP draft: CISA for Taproot Key Path Spends
not actually
quantum
-safe by default, need to solve the Q-day timing problem). 2. Hide the EC pubkeys behind a hash in the SPK (eg P2MR or P2TRH), and attach the EC pubkey in the witness
Aug 10
Fabian
,
waxwing/ AdamISZ
5
Aug 10
BIP draft: Full-Aggregation of BIP 340 Signatures
post-
quantum
note since I don't think readers could understand this to be
quantum
secure and it opens a pretty big can of worms to start mentioning things that a BIP is not. I think
unread,
BIP draft: Full-Aggregation of BIP 340 Signatures
post-
quantum
note since I don't think readers could understand this to be
quantum
secure and it opens a pretty big can of worms to start mentioning things that a BIP is not. I think
Aug 10
Jonas Nick
, …
waxwing/ AdamISZ
15
Aug 10
DahLIAS: Discrete Logarithm-Based Interactive Aggregate Signatures
post-
quantum
secure. > > (Is it worth mentioning the co-EUF-CMA definition here? Perhaps in a > footnote? While it's both in the weeds, and also has no direct implication
unread,
DahLIAS: Discrete Logarithm-Based Interactive Aggregate Signatures
post-
quantum
secure. > > (Is it worth mentioning the co-EUF-CMA definition here? Perhaps in a > footnote? While it's both in the weeds, and also has no direct implication
Aug 10
conduition
, …
ArmchairCryptologist
20
Aug 10
Aligning privacy incentives in P2MR
post-
quantum
transition cannot > rely primarily on self-reliance. If the migration requires most users to > understand Q-Day timing, keep EC spend paths secret, or react quickly
unread,
Aligning privacy incentives in P2MR
post-
quantum
transition cannot > rely primarily on self-reliance. If the migration requires most users to > understand Q-Day timing, keep EC spend paths secret, or react quickly
Aug 10
3D
,
conduition
2
Jun 13
Simple Setup for SPHINCS+ Bitcoin-style Address (proof-of-concept)
post-
quantum
signature schemes. I put together a small, two-program proof-of-concept to show how double-shake256 with SPHINCS+ using small paramaters can produce bitcoin sytled
unread,
Simple Setup for SPHINCS+ Bitcoin-style Address (proof-of-concept)
post-
quantum
signature schemes. I put together a small, two-program proof-of-concept to show how double-shake256 with SPHINCS+ using small paramaters can produce bitcoin sytled
Jun 13
Erik Aronesty
, …
Saint Wenhao
7
May 31
Weak Quantum Bounty Ceremony
made by
quantum
computer and can > prove it, but then it will be clear who leaked it, because the > signature has a unique nonce. This is where ZK can help. But how to do > ZK onchain
unread,
Weak Quantum Bounty Ceremony
made by
quantum
computer and can > prove it, but then it will be clear who leaked it, because the > signature has a unique nonce. This is where ZK can help. But how to do > ZK onchain
May 31
opus lux
, …
conduition
4
Jun 8
[BIP] P2WOTS: 64 Slot Winternitz UTXO's (witness version three)
post-
quantum
-utxo-winternitz-signatures/2530 > > A live signet with full P2WOTS support is live for testing and a wallet demo can be interacted with from my website. I will
unread,
[BIP] P2WOTS: 64 Slot Winternitz UTXO's (witness version three)
post-
quantum
-utxo-winternitz-signatures/2530 > > A live signet with full P2WOTS support is live for testing and a wallet demo can be interacted with from my website. I will
Jun 8
Amarildo
,
Alex
3
May 24
Q-Lock: Quantum-Resistant Spending via ECDSA + Hash-Based Secrets
approach to
quantum
resistance >> for Bitcoin that I believe is simpler than BIP-360 P2QRH. >> >> **Q-Lock:
Quantum
-Resistant Spending Protocol** >>
unread,
Q-Lock: Quantum-Resistant Spending via ECDSA + Hash-Based Secrets
approach to
quantum
resistance >> for Bitcoin that I believe is simpler than BIP-360 P2QRH. >> >> **Q-Lock:
Quantum
-Resistant Spending Protocol** >>
May 24
Matt Corallo
, …
Louise Michel
26
May 28
PQC - What is our Goal, Even?
, because
quantum
-resistant hybrid addresses > would be the specified standard for consumer wallets, and those wallets > would already have at least two script leaves. The
unread,
PQC - What is our Goal, Even?
, because
quantum
-resistant hybrid addresses > would be the specified standard for consumer wallets, and those wallets > would already have at least two script leaves. The
May 28
Nikita Karetnikov
, …
conduition
16
May 28
PQC: Lattice-based signatures
So you'd essentially be computing: e = H(R || hybrid_pk || m) P = e^{-1} * (s*G - R) ie the same as BIP340 Schnorr, but hashing a commitment to the
unread,
PQC: Lattice-based signatures
So you'd essentially be computing: e = H(R || hybrid_pk || m) P = e^{-1} * (s*G - R) ie the same as BIP340 Schnorr, but hashing a commitment to the
May 28
Jason Resch
, …
Peter Todd
7
May 28
One Time Signatures as an Advantage?
post-
quantum
-secure > hash-based signature scheme. However, to achieve the stateless feature > of being able to sign multiple messages, requires a significant size >
unread,
One Time Signatures as an Advantage?
post-
quantum
-secure > hash-based signature scheme. However, to achieve the stateless feature > of being able to sign multiple messages, requires a significant size >
May 28
3D
,
conduition
2
May 26
[BIP Proposal] Hybrid SPHINCS+ / secp256k1 Key Derivation for Quantum-Resistant Paper Wallets
bridge for
quantum
-hardened cold storage/paper wallets while post-
quantum
consensus migration is still in the future. What does this even mean? There is no way to "
quantum
unread,
[BIP Proposal] Hybrid SPHINCS+ / secp256k1 Key Derivation for Quantum-Resistant Paper Wallets
bridge for
quantum
-hardened cold storage/paper wallets while post-
quantum
consensus migration is still in the future. What does this even mean? There is no way to "
quantum
May 26
Amon BAZONGO
, …
Murch
7
May 22
What if we let Quantum Hunters get Bitcoin rewards ?
concerned about
Quantum
. That is a fact regarding the number of
quantum
-related BIP 2. Now, the ecosystem has no incentive to actively participate in
Quantum
research. But the obvious
unread,
What if we let Quantum Hunters get Bitcoin rewards ?
concerned about
Quantum
. That is a fact regarding the number of
quantum
-related BIP 2. Now, the ecosystem has no incentive to actively participate in
Quantum
research. But the obvious
May 22
Olaoluwa Osuntokun
, …
conduition
18
May 21
Post-Quantum BIP-86 Recovery via zk-STARK Proof of BIP-32 Seed Knowledge
post-
quantum
, just discussing the technical possibilities. > > > > > > Best, > > > Abubakar Sadiq > > > On Friday, April 10, 2026 at 7:47:09 PM
unread,
Post-Quantum BIP-86 Recovery via zk-STARK Proof of BIP-32 Seed Knowledge
post-
quantum
, just discussing the technical possibilities. > > > > > > Best, > > > Abubakar Sadiq > > > On Friday, April 10, 2026 at 7:47:09 PM
May 21
Jason Resch
,
Pieter Wuille
5
May 20
A "Quantum-Agile" Bitcoin address proposal
On Wed, May 20, 2026, 9:02 AM Pieter Wuille wrote: > Hi Jason, > > See my comments below. > > On Tuesday, May 19th, 2026 at 11:27 PM,
unread,
A "Quantum-Agile" Bitcoin address proposal
On Wed, May 20, 2026, 9:02 AM Pieter Wuille wrote: > Hi Jason, > > See my comments below. > > On Tuesday, May 19th, 2026 at 11:27 PM,
May 20
Jameson Lopp
, …
thomas suau
54
May 12
Against Allowing Quantum Recovery of Bitcoin
. While
quantum
computers are still in theory, so if I would have to guess, then I would put more money on a scenario, where RIPEMD-160 collision is found faster than anyone will break
unread,
Against Allowing Quantum Recovery of Bitcoin
. While
quantum
computers are still in theory, so if I would have to guess, then I would put more money on a scenario, where RIPEMD-160 collision is found faster than anyone will break
May 12