Hey all. Kicking off a convo about keeping Bitcoin safe from future threats. So, there’s this idea floating around about holding back the public key until you actually spend. Quantum resistance isn’t just some sci-fi anymore, it’s real. BIP360 / P2QR is one proposal where we don’t show the public key upfront. Seems like a smart move to lower risks.
Protecting Bitcoin from Future Quantum Risks
2 replies 347 views
Totally agree about that. XMSS feels like a disaster waiting to happen. Stateful signatures seem cool in theory but can go wrong fast when regular folks use them. I mean, half the time people mess up their backups or wallets and then ask, "Where are my coins?" 😂 Like you said, adding complexity with internal signing states isn’t user-friendly at all. Dilithium being stateless sounds promising though, but framing it as just an engineering challenge? Nah, Bitcoin has way more layers.
I get the vibe that the privacy folks aren’t jumping into NIST’s recommendations without a solid check for backdoors. Like, Satoshi picked secp256k1 over NIST’s P-256 for a reason, right? Just one dude’s choice, but I bet a lot of developers feel the same way. A little skepticism never hurts, imo.