How Bitcoin Survives Quantum Computers (ft. Dan Boneh)
Mind map summary: Bitcoin Post-Quantum
- Quantum Threat
- Weekly Headlines
- Bitcoin will end
- Jim Cramer sells
- D-Wave claims
- Blockchain Vulnerable
- Proof-of-work systems
- Weekly Headlines
- Post-Quantum Signatures
- Lattice-based
- Rich algebra
- Community fear
- Hash-based
- No new assumptions
- SHA-256 only
- Likely Bitcoin path
- Other families
- Isogeny-based
- Multivariate
- Zero-knowledge proof
- Lattice-based
- Hash-Based Signatures
- One-time (OTS)
- 292 bytes example
- Slow verification
- Few-time (FTS)
- Security degrades
- HORSE/FORS
- Stateful few-time
- Merkle tree
- Short signatures
- State tracking risk
- Hybrid with ECDSA
- SLHDSA Standard
- 2^64 signatures
- 8KB signatures
- Unsuitable for blockchain
- Sphinx+ framework
- Smaller variant
- 2^24 limit
- 3.8KB size
- 1 billion hashes
- One-time (OTS)
- Bitcoin Implementation
- Shrinks scheme
- Long-term key
- Short-term key
- Stateful design
- Recovery mechanism
- Key management
- Account abstraction
- State counter
- Hardware wallet concerns
- User experience
- Dual-key approach
- Emergency recovery
- Shrinks scheme
- Threshold Signatures
- Challenges
- Multi-signing bloat
- Reveals threshold
- Leaks information
- Solutions
- SNARK conversion
- FHE-based
- MPC approach
- Lattice-hybrid
- Hash signature
- Lattice threshold
- User chooses
- Context-aware PRF
- Prevents mix-attacks
- Message-dependent
- Winternitz reduction
- One-time OTS
- Coverage-free
- Chain hashing
- Two-round protocol
- Challenges
- Abandoned assets
- Future problem
- Orphaned coins
- ECDSA deprecation
- Recovery ideas
- Satoshi proof
- Hidden commitment
- Future problem