There’s a new BIP draft in the air, aimed at boosting Bitcoin’s security against quantum threats. Authors include some familiar names like Lopp, Papathanasiou, and others. They’re proposing a shift to a quantum-resistant crypto standard with a three-phase rollout.
So the idea is to scrap ECDSA and Schnorr signatures and adopt P2QRH outputs instead. But I'm thinking... should we just make old output types non-standard instead of outright invalidating them? I feel like that could cause chaos.
Totally agree. We can still send coins to some weird formats right now. If we go all out on disabling old types, we'd essentially kill Script, and that’s kinda drastic.
Exactly, if the size jumps up, we're looking at some serious mempool congestion. SPHINCS+ signatures are like 70k bytes, right? Imagine the bottleneck.
Yeah, the signature size is a real concern. P2QRH's signatures could balloon to over 7k bytes, that’s nuts! Higher fees and fewer transactions per second? Like going from 7 TPS to less than 1 is a disaster waiting to happen.
But if we force everyone to migrate, we’re risking burning coins, especially with a soft-fork approach. Some users won’t even know what hit them if we disable OP_CHECKSIG.
Right, it’s gonna be a mess if half the Bitcoin community is stuck on old scripts. Those still using legacy outputs would be sitting ducks… not good at all.
And what’s the deal with Satoshi’s bitcoins? Some say they’re at risk, but isn’t the threat mostly about actual spending? Like, if they never move, are they really at risk?
It’s tricky. Quantum computing could potentially get to your private key if you expose your public key regularly. Like with old P2PK addresses which reveal that straight away.
Exactly! Plus, current Segwit addresses only show hashed keys until used. Way safer than older formats. Those early coins are definitely in more danger.
I mean, Lopp is on this BIP and he’s definitely no stranger to the concerns about quantum recovery. His earlier posts hint at a strong stance against letting quantum attacks become a reality.
But there are like five other authors too, so it’s not all just him. Still, this feels like we’re between a rock and a hard place. Protect old coins or risk a severe network impact.
Some have such wild fears about Satoshi-era coins being stolen, but does anyone actually think that’s a likely scenario? Seems a bit exaggerated to me.