# Post Quantum Money | Tomasz Stańczak - Ethereum Foundation, Jerome de Tychey - Ethereum France

- Speakers: [Jerome de Tychey](https://streameth.org/speakers/jerome-de-tychey)
- Channel: [Ethereum Denver](https://streameth.org/ethereum-denver)
- Date: 2026-03-09
- Duration: 20:21
- Topics: ETHDenver, Crypto, Web3, Blockchain, Event, Conference, ETHDenver 2025, ETHDenver 2024, Bitcoin, Ethereum
- Watch: https://streameth.org/watch/yt-hXhRgoVjXko
- YouTube: https://www.youtube.com/watch?v=hXhRgoVjXko

## Description

🚀 Get Ready for ETHDenver 2026! 🚀

We're already hard at work preparing for next year's biggest Web3 event!

Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

## Transcript

Hi there everybody. I'm back. Kelly Lavali Hunt here. Whoop. Um, just to let everybody know, there's going to be a DJ outside at 5:00 p.m. Just letting everybody know it's going to be bumping. Um, so right now I'm going to welcome two amazing guys to the stage. one um I I know him as ETC and the other one I know him from the EF. So, please welcome I need a very big round of applause for these guys. They need like to a buildup of applause and Whoops. Please welcome to the stage Tomas and Jome. I give this Y. &gt;&gt; Hello everyone. Woo. &gt;&gt; Hi everyone. &gt;&gt; Oh, we have a timer now. Oh, is it 16 minutes? 17 to uh talk about quantum money. &gt;&gt; Quantum money. &gt;&gt; All right. I have had a look at the agenda and um there's already been a lot of quantum talks. So I will take it for almost granted that everybody has rough idea about what we are going to talk about here. What do you think? &gt;&gt; I have a rough idea. Yes. &gt;&gt; Yeah. Okay. So um so I applied for a talk here saying like I'd like to talk about something that's um um almost there for Ethereum but we have a plan for it and also something that I think is going to give Ethereum an edge uh against every other blockchain. We have a plan for quantum um and we have a plan that's already running out. uh maybe you can give us a few elements of uh what's the plan for postquantum Ethereum in like one minute well two minutes like no I think the the most important thing is to uh to look at it from the perspective of there is devcon Bangkok and Justin Drake goes on stage and says and like for for a week people are saying that Justin will have a huge announcement right like that stealth announcement nobody will know what he'll announce there'll be something huge &gt;&gt; was in Russell. &gt;&gt; No, it was in Bangkok. In Bangkok. And then Justin Drake went on stage and says &gt;&gt; and everyone was expecting this massive massive momentum with Ethereum changing and showing how aggressive and Justin went on stage and says this is our fiveyear plan with like the road map and the the message later was that oh Ethereum moves so slowly. It's five years there's nothing now and like in five years everything else will be so much ahead. Now, now everyone is worried about quantum and that 5 years road map is 2 years into the the road map. So we see the quantum road map that is 5 years is lean ethereum. It's not only quantum it's a lot of other things that uh Justin and other researchers were working have been working on for now I'm worried about this one minute have been working for the last two years and it's going really uh on schedule uh or probably even ahead of schedule. Now it's accelerating with with researchers running AI and formally verifying things with AI. The example I think Alex Hicks run AI formal verification of some of the signature uh codebase. &gt;&gt; Yeah. &gt;&gt; And moreover what we're doing we we reintegrating that branch of uh foundation research into the uh protocol road map. So we want to propose at the EF uh the next five-year protocol road map and present it to all core devs and it will see uh among the other thing. I I don't know if it was published. I think was meant to publish yesterday but I think they're still waiting. Uh so when it's published it will show what we do with quantum what we do with um with the state uh what we do with further scaling and so on and so on. And yesterday you had a blog post about um this year focus of the protocol team. So this is like hardness, scaling and UX. So we continue with scaling and UX but there's hardness part as well which talks about security of the protocol. And when you think about hardness is really like security postquantum security uh and and all the aspects of saying this this is like the slower path but also faster than anyone who is not thinking about it and who hasn't worked on it for the last few years. &gt;&gt; But yet we have a an authority that started the clock. The clock is ticking for quantum. We have the National Institute for Standard Technology, the NIST in the US that said by 2030 ECDSA should start to be decommissioned. What that means is that if you have a fiduciary duty, typically you're an ETF emitters or you are a listed company that is using uh buying an asset that is relying on the CDSA. Uh you should be having some uh security risk assessments like uh oh, I'm using I I'm storing Bitcoin and Bitcoin is not quantum ready. So do I have to disclose that I have this kind of assets which means that by 2030 we should be quantum ready in the blockchain industry. We should be thinking very hard of this problem and it's there's a discrepancy between the the threat that it represent and the amount of capital and the amount of uh of public research that is actually being done in the blockchain space on this on this stage. And yeah, please. &gt;&gt; Yeah, &gt;&gt; I'm I'm thinking about that uh tweet from Nick Carter when he said, "Look, the the way developers in the markets look at this thing is totally different because developers think I have to fix it before that uh quantum point where where really everything collapses. But the developer will think about it if we ship it one day before it's fine." Uh but the markets think about it. If you don't have it ready and fully test it like three, four years before then we move our money away, we don't invest in this technology, this architecture because we just don't have certainty and when we introduce too many technology risks. &gt;&gt; So you can ask around or to uh researchers in the quantum space, research in in information in in computing in computing uh and so on. You can ask them like do you think that we already have quantum computers that is able to break ECDSA? So uh you have public publications like Google and so on saying like oh we reached this amount of cubits we reached this amount of things we this amount of things those are publication of what's going on but the reality is probably a little bit higher um and if anyone has a computer that can break the uh signature that you have on Bitcoin you wouldn't know like at some point someone will do these kind of things and the old internet that is rely relying on uh certificates that is based on um asymmetric uh signatures is at risk in this case and there was um well Nick Carter saying that he thinks the threat of quantum is important for Bitcoin. It's really simply put like you cannot differentiate uh Satoshi finally moving his coin and someone breaking Satoshi's keys and moving his coin. That would be a pretty nice uh big short, the blockchain big short moving one of uh Satoshi's coin uh after breaking the private key and uh putting an op return such as um uh sell bitcoin by docoin, something like that. Yeah, you wouldn't know. Yeah, I think that um so I'm not an expert of Bitcoin, but I think the calculations depending how you calculate was around 6 million bitcoins at risk and 1.9 million if you just look at the um the historically uh public publicly exposed coins I think uh because of the old style of uh of issuing signatures. So I think that all of the for some reason all of the Satoshi's coins are at risk or like 1.7 million there. Uh and and this is huge. This is a huge threat. And I think this is the biggest problem because it's political, right? Like so people will start deciding is it is it that you should freeze those coins or you should allow them to just float as a bounty. But if it's a bounty, then if if people that look at Bitcoin as a market, they'll say, "Oh, okay. So we have this 1.7 million bitcoins floating and then being dumped on the market. And who controls them? Most likely one of the governments or &gt;&gt; Yeah. So there's there's things we need to touch point on like uh let's not talk too much about the other chains and focus on Ethereum but nevertheless transitioning from pre-quantum to postquantum mean that we change the signature algorithm uh so transition scenarios are more or less achievable more or less realistic depending on the chain depending on and so on and when it comes to uh let's say bitcoin or sonana uh quoting Justin Drake uh if you switch to the best candidate that we have right now which is Andrew Falcon for uh quantum signature on the blockchain because the signatures are small and quite costly to generate offchain but easy to verify onchain. Uh if you put that kind of signature in the other chains, you're going to have a a 10x less performance in term of uh throughput for the blockchain. Uh so you have to rethink your architecture. You have to rethink how the blockchain works. So it's a challenge for blockchain that are historically uh very high on the throughput of number of blocks per second and it's also a challenge for blockchains that are um conservative in the way they uh handle their codebase. But that's not the case for Ethereum and I think we have an EIP coming up on the next upgrade uh to make Entra Falcon a pre-ompile. That's right. Um yeah like so it's it's I wouldn't maybe go that far to say it's not a challenge. It's just like uh that you will not be slowing down things like which whatever speed you're operating at. I think that that really you slowing down because the the signatures are are much larger and the throughput will go down. uh but the but the teams at the foundation are showing this like a linseek and the signature aggregation uh targets and they set the targets for the size of the signatures and for the throughput for the latency and all of that is being uh like progressing very nicely. So so we we see the results and if you go to leanroadmap.org I think um you can see this being tracked across all the teams and and and you can see results. This is very promising. Uh but there are many many other problems like because the same way as you have uh the old addresses in Bitcoin, you have the same situation in Ethereum. You have some addresses that didn't move ether for many many years and if you start a transition process, how you will how you'll address that problem. All those addresses uh have to be frozen. Vitalik proposes that emergency approach where where you kind of freeze the addresses but you can unfreeze them with the zk proof of holding the pre-image the the speed phrase. So that's one thing. Um the second thing is the how do you the the process itself of moving accounts to the to the new approach to the quantum signatures. So you see the first proposals of the IP is now 7702 proposed how to handle how it could handle signatures quantum signatures or like noncdsa signatures. Then there is Kohaku suggesting of oh this is how we can do aa account abstraction with uh quantum signatures. Um and then there is like entire lean road map but you have consensus layer and execution layer side of the signatures. So the consensus layer has additional question about aggregations. So how you create the those signatures but also with aggregations on the execution layer it's mostly you can do that in steps like first introduce account abstraction like more like smart contract level uh quantum signing support later you can start thinking of this being on the protocol side. So it's a it's a gradual progression on the road map over three to five years. It's very important that we finalizing like kind of finalize all the specs. But I would say it's it's too much to say. It's more like one group of people finalize the specs that they believe in. It's a it's a very strong set of researchers and they they focused on that many years and they had very very reasonable assumptions. But it's now is a stage of showing it to all the core devs. do show it to the other community and you have that governance process where they come back and say maybe maybe they never looked at it and now they suddenly start looking at it. &gt;&gt; We've seen with EF and so on and that's why you have to be so much ahead of it like even if the threat is 2030 2035 uh you really have to sing research implementations verification testing and the governance process everyone accepting the same approach. Yeah, totally. There's uh to say that the objects in the mirror are closen they look. So typically we weren't expecting I think AI to be so powerful into uh verific formal verification and so on. But like from uh so you said that there's there's two approach like we need to look at this from the execution standpoint. So the mainet EVM and uh the exe the consensus later, right? So, you said 7702. That's a new type of transaction that lets you declare a smart account to invoke your account. &gt;&gt; No, I'm Alex. So, the I've just seen yesterday I think uh Greg the Greek was wasn't it from you? &gt;&gt; No, maybe. Okay. No, Greg. Greg. Oh, Gregy and then I mean I think they proposed the updates to 7702 that would uh support different type of signatures. So I'm just just giving examples that something is coming from outside of the group of people that are working on quantum and this is the the governance now because of those announcements the governance start activating everyone else to think about quantum and what other proposals what we didn't take into account. Uh there shouldn't be anything uh ideally there like it was probably like 50 to 100 people working on it. Uh but it might be that might be. So let's come back to this attack of um I'm breaking ECDSA and I'm moving Satoshi's coin like sending a big short like sell bitcoin by docoin something like that. Uh that would be a moment of realization that uh oh well maybe someone has enough to break KCDSA now uh let's take a cautious approach and tell people that it's it's time to migrate it's time to upgrade to quantum uh postquantum ethereum. So the am I right thinking that the the the module operendi would be okay guys just declare a new smart account and your uh entrance signature uh for for this and then we can gradually migrate the the execution layer. So I think everyone is talking about this two stages of uh of quantum threats like first one is when you have significant amount of time to break the account. Uh so if you if you know the public key because uh the public key was published to to sign from the given EOA and uh whoever has the quantum computer that is uh ready to break the signatures maybe they they try to break it over two or three weeks or months or so and then they break it and you think that uh the accounts with a big amount of of E that already published their public key could be broken this way. The second thing is like in flight when you when you didn't publish your public key but you start transferring uh assets and then the quantum computer is fast enough and like the algorithms are efficient enough the error correction and so on that you can break it within seconds since the transaction was published and you can intercept it and um and do like a bit of like me uh access. So, so this should come much much later which means that we we should have this first signal if it happens that that already someone is capable of breaking uh breaking accounts. But then people are even talking about that any anybody who would be in uh in ownership of the the quantum computer that can break this &gt;&gt; should be they would try to hide this and then they wouldn't attack the accounts where it would be obvious initially. &gt;&gt; Yeah. But other things are at stake like well talking about taking right after but uh privacy on blockchain let's say monero the ring signatures are breakable on this approach. So as the EF and Ethereum took a big step towards institution on making uh easier and for users as well to uh work on the privacy side of their transactions uh postquantum transactions uh to make sure that your money stay your money transfer stays private is also a challenge that can be addressed at the same in the same way. But from the from the consensus layer point of view uh we have a challenge with BLS. BLS is just aggregation of signature which is very practical for the proof of stake of Ethereum. So there's two paths I think let me know if I get this wrong um there's two paths either finding out a way to properly aggregate entrance signature or um get over it and use uh zig proof stocks basically &gt;&gt; like the falcon or hashb signatures I think that's the approach and now they but here you're getting technical enough where I would say uh in the last weeks when I was reading everything that researchers are posting about it I I I see those changes like the hashbase the the stories the uh falcon and anyone to dig deeper into the final decisions because I talked to to Nico and Justin and because in January they were merging all the road maps so this probably is the time when it's most dynamic of what will be the final paths but they uh I think the aggregation will be based on the hashb signatures on the XMSS but I would send you to lean road map for technical details I don't want to go too deep into this and &gt;&gt; so baseline scenario we have a plan and we're executing it and apparently faster than we thought &gt;&gt; I think so I would say that when you have a fivey year road map and after two years you think we are mostly on time this is already great &gt;&gt; the last the last mile is always the the hardest one &gt;&gt; no no and now you know that generally the road maps are accelerating because you have such powerful tools to deliver. So I I'm very optimistic about this road map on Ethereum especially that like January was super strong signal when the researchers and engineers met at the F and they said like yeah we have a road map that we believe in and this is okay. uh and and we are ready to publish it and start having conversation with everyone like the lean ethereum was totally separate from everything else that we were doing and many people were very and feeling very uneasy saying like oh this ethereum is totally different they operating like it's it's different Ethereum why these researchers are not working with the rest of researchers you know those tensions when you manage the teams and and you say just go two paths and now those paths are merging and and this is very strong signal that people are feel comfortable about what &gt;&gt; chose we have 10 years of no downtime and 10 years of uh a history of 10 years of setting up the standards like it's a it's an evidence that uh Ethereum is the standards and EVM is the standard like across many different chains many different flavors of of Ethereum that have been tried out either as L2 ether as a as a layer ones and now we are about to own the narrative of the quantum transition like the new standard is getting ready for quantum and the clock is ticking again like 2030 it's three years from now so it's getting it's getting there pretty fast And uh I believe it's a really good segue into telling the institutions that hey this is going to be ready and picking Ethereum is going to make you safe for the next 10 years and for the users your isure based assets are secured as well. This was super important for me when when I thought we we've been working 5 years already on postquantum security of Ethereum but this year is when many institutions started feeling very anxious about it. So what we really are doing this year is not suddenly starting to work on quantum. We just start to communicate about it because if we communicated about it last year people wouldn't listen because I was like ah that's far away. Now they started panicking and we say oh we are prepared so let let us show you what is there on Ethereum and how we'll lead that uh transition to postquantum security and it creates this uh full understanding. People will want to read more about what Ethereum has been working on and they will see the five year road map that is in the middle and saying here we are and it was like research testing building specking building and we aren't building and all the other chains will be seen suddenly as underprepared and they and they start to have those governance stresses and that's great. &gt;&gt; Yeah, Ethereum edge against everything else and above everything else it's its brain power and the talents that it attracts and with quantum challenges we have an outstanding way to shine. Yes. And we ran out over time. So the quantum quantum clock was ticking and we over time. Thank you everyone. &gt;&gt; Thanks everyone.
