# Making Bitcoin Quantum Resistant | Isabel, Alex, Hunter, Eric

- Channel: [Ethereum Denver](https://streameth.org/ethereum-denver)
- Date: 2026-03-09
- Duration: 24:58
- Topics: ETHDenver, Crypto, Web3, Blockchain, Event, Conference, ETHDenver 2025, ETHDenver 2024, Bitcoin, Ethereum
- Watch: https://streameth.org/watch/yt-s8Qdi0Rv7AU
- YouTube: https://www.youtube.com/watch?v=s8Qdi0Rv7AU

## Description

🚀 Get Ready for ETHDenver 2026! 🚀

We're already hard at work preparing for next year's biggest Web3 event!

Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

## Transcript

Action. All right, quantum computing. Who here is Okay, show me with your hands if you think quantum computers will break SHA-256 within the next 5 years. &gt;&gt; Oh, no. Wow. Okay. &gt;&gt; elliptic curve cryptography? &gt;&gt; It was a trick question cuz &gt;&gt; [laughter] &gt;&gt; Uh and and so people know SHA-256 is a hash algorithm that's used by Bitcoin. Bitcoin has also for signatures a different curve a different thing called it's it's based on elliptic curve cryptography also known as public private key cryptography and the curve it uses a secp256k1. And the difference between a hash and a signature is very significant in the context of quantum computers because you need a separate a different algorithms to to to break either. And so hash algorithms like SHA-256 are actually believed to be very difficult for even the most ideal biggest quantum computer we can imagine. We theorize that we would need a quantum computer bigger than the moon to break 256-bit hash-based cryptography using Grover's algorithm. That's not really what we're worried about in the next 5 years. What we're worried about in the next 5 years are signatures. And that is is goes over with Shor's and that basically ends elliptic curve cryptography and RSA cryptography. And if and even if we don't get quantum computers in the next 5 years that are capable of doing that, the government really wants us to be prepared for a problem they may have caused. And so there's also the NCSA 2.0 timeline from 2027 to 2035. &gt;&gt; Okay, now who didn't raise their hand because they knew that? &gt;&gt; [laughter] &gt;&gt; Okay, so maybe maybe we take a step back here and let's let's ask some of the higher level questions &gt;&gt; [laughter] &gt;&gt; and and Hunter, [clears throat] I'm going to hold you to 1-minute answers this whole talk, all right? Okay, so we'll we'll go down the line. I'll introduce myself quickly. I'm moderating this panel. My name's Eric. I'm the founder of Epoch Ventures. We're a Bitcoin focused venture capital fund. And then to my left, we have Isabel. You want to introduce yourself? &gt;&gt; I'm Thank you for the clap. I'm Isabel Cox and Duke and I'm along with Hunter one of the co-authors of BIP 360 which is the first quantum mitigation proposal for Bitcoin Core or a Bitcoin Core protocol. Yeah. &gt;&gt; Yeah, and I will say Isabel is an incredibly talented and hardworking technical communicator and that's why I I chose her to help me co-author the BIP. She basically rewrote it and then took all the parts that were just like way too like not really relevant for what people needed to know. And it still wound up being 19 pages long and it actually didn't really do anything novel truly. All it did was it made it so that we have a way to voluntarily over time opt in to this new protection against a specific vulnerability in Bitcoin. And I that's something we didn't start off with originally. Back 2 years ago, I started working on the BIP 360 just in a very different way and so it took us a long time to arrive at this solution we came came to. Our thinking is much clearer, but there's still many end problems that also still need to be solved. So it'll be the first of many BIPs that will be come coming soon to Bitcoin to address the problem of quantum resistance. And yeah, I'm very grateful that everybody came to to talk about this very serious issue. So Hunter is a local out here in Denver and we've been friends for a little while and I remember when he first started thinking pretty heavily about quantum and and we were talking and we're thinking through different ideas and we're like, "Hey man, you you got to create more awareness for this." And then you did that first post on the Bitcoin It wasn't on Bitcoin talk, it was on the It was on the dead mailing list. Yeah, it was on the dead mailing list. And and that kind of sparked a lot and I think that's led to a lot of things since now and um and yeah, I'm excited to jump into it. But Alex, introduce yourself down at the end. &gt;&gt; Uh hey guys, I'm not Can you guys hear me? I'm not from Denver, but I live in Montana, so not too far, still in the Rockies. But uh yeah, I'm the CEO of a company called Project 11 and we focus on post-quantum cryptography at less on the protocol layer, more on the wallet layer. As I'm sure we're going to talk about, there's many aspects of applying post-quantum cryptography to a network like Bitcoin, but because Bitcoin and other digital assets rely on decentralized ledgers, there's not like a central protocol or a central entity that can migrate you, even assuming that the solution exists inside of the protocol. So, Project 11, we focus a lot on like the wallet layer and the wallet level infrastructure to support post-quantum cryptography that will be eventually included into Bitcoin thanks to work like BIP 360 and with other networks as well. So, that's a little bit about me. &gt;&gt; So, I I think a good place to start with this discussion is what does it mean for a quantum computer to really break any sort of signature algorithm? And Alex, I'll throw it to you to kind of start off with that. &gt;&gt; Uh yeah, sure. So, okay, so what what does a quantum computer do to break ECDSA? So, quantum computers as a kind of a theoretical concept have been around since the 70s and it wasn't until the 90s that someone came up with an actual use case to solve a practical problem. And that practical problem just so happens to be the hard problem that underlies the asymmetric cryptography that Hunter talked about a second ago, that underlies the security of ECDSA, which is what authorizes your Bitcoin transaction, okay? So, ownership in Bitcoin is entirely conferred by your ability to sign a digital signature. And your identity on chain is your address, and underneath your address is something called your public key, and that's kind of as the name infers, is meant to always be public, and it's okay if people know it in the classical setting. But what Shor's algorithm, which is this quantum algorithm that breaks ECDSA does, is by only having knowledge of this public key, the thing that you're supposed to be able to share with everybody, you can actually reverse engineer the private key, the thing that enables you to sign. So, that's the main problem is that by knowledge of this thing that is supposed to be public, I can actually sign for you, and what does that mean? It means I own your Bitcoin simply by knowing your public key. So, you know, the kind of deep philosophical problem here is it it breaks the concept of ownership on chain, right? Cuz ownership is guaranteed by these digital signatures. Digital signatures can now be created by anyone with a quantum computer of sufficient scale, and so that's the problem that we need to solve. &gt;&gt; So, it's kind of like we have two publicly known variables, and we're hiding a third private variable in the equation, and quantum computers that classical computers can't do is potentially have some sort of reverse calculation to find that private variable. &gt;&gt; Right. You need to basically you you need to go back to the paradigm that classical cryptography has up to this point given us, which is that hey, like this public key, the public variable can be public and not introduce a vulnerability, right? And then that can re-guarantee you this, you know, as long as you have the as long as you and only you know if you know your keys, it's still your crypto. So, not your keys, not your crypto. Your keys, only your crypto. So, that's what post-quantum cryptography, the replacement for ECDSA, and it's got a couple different forms we may talk about, but that's really the whole concept is basically giving you what you want kind of from like a you know kind of first principles level from a signature scheme, right? You shouldn't No one else other than you should be able to sign. &gt;&gt; Yeah. &gt;&gt; Isabelle, what do you think about that? &gt;&gt; Um what do I think about that? Well, I think one thing that is sort of important to point out about Bitcoin is that there's sort of layers of quantum vulnerability happening with Bitcoin that we're going to kind of address at different stages potentially. Um so right now when you think about different output types, different address types uh for Bitcoin, only two of them actually do share the public key. So if you're practicing really good wallet hygiene, you know, you're not reusing addresses when you spend Bitcoin, obviously your public key is revealed. Um then in theory, you know, if you're just sort of huddling your Bitcoin um in one of these other address types with hash public keys, um your coins are functionally protected until you spend them. Um once you're spending, that's you know, again your public key is revealed. So if you have a really fast quantum computer, potentially um those coins could get plucked right out of the mempool before those transactions are confirmed. But generally speaking, I think that's sort of like an important point for us to sort of understand is that there's different output types in Bitcoin with different levels of quantum vulnerability. &gt;&gt; The one important Oh, I'm sorry. I didn't mean to &gt;&gt; Go ahead. Go ahead. &gt;&gt; I was going to say one important thing to note though I think is that uh and I think so the two there's two types of signature of spend types that expose your public key directly, but also if you reuse the you know, even if you paid a public key hash which you know, you you only reveals the you know, if your hash protects your public key, but using spending from that P2PKH UTXO reveals the underlying if you're doing that twice, you are vulnerable. And as your if you're doing that twice, you are vulnerable. And as Isabelle said, as long as you're doing good wallet hygiene, that's fine. But I there's a case that I want to highlight cuz a lot of people forget about. Is in a lot of custodial workflows, and you know, we have like you're a VC, so you may use a qualified custodian. A lot of times they they do they generate they don't generate additional keys every time because they rely on MPC to regenerate the same key because they're trying to solve a different problem, which is like, "Hey, we want to make sure your key doesn't get exposed." And so, you know, varies by custodian, but for a bunch of reasons, there are folks that today, although they could solve this, don't actually solve this, and they still have a lot of their Bitcoin exposed. And so, in total, it's around 30% of all Bitcoin is under exposed public keys. Sorry, I just wanted to add that. &gt;&gt; Sure. I think also like a very large chunk of that also is just actively in output types that have public keys exposed, and that is pay to public key output types, which is where most of, for instance, Satoshi's coins are hanging out. Um so, if you think about, you know, the numbers of Bitcoins that are fully exposed, maybe half or a little less than half of those um are literally within these sort of very very old address types where public keys are exposed and are ultimately unlikely to move, right? I mean, we can debate this, but um I think it would be a very big deal if Satoshi came back and moved all of his coins to quantum safe addresses. &gt;&gt; And for people to I'm sorry. Uh for for people to um uh get a a good sense for the scale of the problem, uh Project 11 has actually done some really good work on something that they call the Bitcoin risk list. It's uh spelled with a Q, R I S Q, the Bitcoin risk list. It it it basically shows uh like a very up-to-date like current tally of the number of coins held in addresses that have exposed public keys. And there's 6.9 million total. 1.7 million of those are uh like Satoshi era coins. And uh the the remainder are like a mix of like address reuse and other things and um the &gt;&gt; [clears throat and cough] &gt;&gt; and so if you want to get a sense of that that's that's important to know and important context that basically a third of the supply would be vulnerable to what we call a long exposure attack where the keys have been exposed for a long time and a quantum attacker could have the opportunity to work over them basically for as long as they needed. So the earlier quantum computers that might not have as much error correcting codes or fault tolerance those will like like what we call a near intermediate scale quantum computer those could potentially be be made through either Shor's algorithm improvements to the software or with even like classical accelerators like GPU accelerators like how AMD is working with IBM now which is interesting. That those those that's that's some of the things I worry about a little bit. We'll probably see long exposure happen first. We're not exactly sure with the increasing rate of technological advancement that we're seeing with AI and everything like just building on each other we think like ordinarily we might have two years between when long exposure attack becomes possible and short exposure attacks become viable. For short exposure the only good way to mitigate against those is to activate either a signature scheme a commit reveal scheme or you're going to just have to take your transactions directly to the miner and hope they they don't keep your they don't reveal your public key before they mine the block. And so there's there's different ways to like work through the quantum transition but that said we also have to be very aware and take you have the time that we have now the precious time pre Q day to prepare and do everything we need to think about all the aspects of this problem. It is a vast multi-dimensional problem in ways that are very subtle until you really dive into it and really come to understand all that when we see the essentially the sunsetting of elliptic curve cryptography, all the parts of the stack, not just in the layers, layer one, layer two, or whatever, but also in the infrastructure that it runs on, the PGP, SSL, SSH, SSL, all of that. They these these do not like even PGP it has post-quantum cryptography, but only for encryption and not signatures. We are not prepared right now for all that this will affect. And so I invite everyone to hear working and thinking on the problem to really deeply reflect on all that is affected by the end of elliptic curve cryptography, including things like Peterson commitments, bullet proofs, ZK-SNARKs that are based on elliptic curves like BLS, all of that stuff. It is it is over and we need to understand like really feel get a a sense for and understand the consequences for when a public key can no longer safely be made public. essentially a return to symmetric cryptography. &gt;&gt; Okay, so let's let's take a step back and let's try to summarize here. We've got quantum computing has a certain rate of progression today and we're concerned that it can break a variety of different forms of cryptography. There is a limited amount of uh quantum resistant cryptography that we have today and we probably need much more. And how that cryptography is applied to various different technologies is something that's complex and particularly within Bitcoin, which because of how its consensus works, it's probably the most complex question. Because not only do we have to deal with multiple different types of uh cryptography as well as hashing algorithms, um but we also have to deal with the consensus of a group to update the protocol. Whereas, if we're talking about other types of protocols that don't require consensus, those those additions can be implemented much more easily. Or even more centralized protocols that require consensus. &gt;&gt; A A good example that would actually be banks. Like first of all, they can hire experts and print money to like pay those experts to fix their and then they'll just rewrite their own ledgers cuz they can. And so like none of the solutions that are going going to work for them will work for us. &gt;&gt; Yeah. Yeah, this is actually &gt;&gt; A consensus mechanism in a distributed network is a particularly challenging variable to deal with when it comes to making something post-quantum secure. So Okay, so let's let's get into like the nitty-gritty questions around the debate of it. So we get that there's a potential risk. We understand that there are current solutions being worked on. I think an area to clear up is one on the quantum cryptography side, what what do you guys say to potential critics of the progression in quantum cryptography? What is the fundamental problem of why people would say quantum cryptography is not coming for a long time? And then what is the case for it's actually or sorry, not quantum cryptography or idiot Yeah, yeah, quantum computing isn't coming for a long time. And what's the case for it coming very quickly? I'm not sure who wants to take uh answer. &gt;&gt; They're both immature. So like the post-quantum cryptography is the shield against the sword of quantum computers. And they're both developing nascent technologies. Uh like SLHDSA has been around since 2015. Uh which is actually pretty good in the grander scheme of things because uh uh originally when Satoshi reached for the elliptic curve he used in Bitcoin, it had only really been in existence for about 8 years. So there's that. But also the principles behind it had been known and well understood ever since uh Koblitz's paper in the Koblitz's paper in 1985, right? On elliptic curve cryptography. And so we're we're we're building on things that like we think will be hard for quantum computers. Uh we're pretty sure about hashes, but all cryptography has a half-life and we have to be keenly aware of that. &gt;&gt; So, that's that's on the signature side and then uh Alex, there's a bell on on the actual quantum side, like what's what's the problem here? What are what's concerning people, particularly in the past year, when they're saying the pace of quantum computing has picked up? &gt;&gt; You can take that one. &gt;&gt; Okay. Um yeah, I think one thing Okay, so quantum computing, where are we at? Okay, what like you know, is it coming? Is it ever going to be here? Uh okay, important date December 2024. December 2024 was when Google announced for the first time ever this this uh device called Willow, which was a quantum computer that demonstrated something called below-threshold error correction. Okay, and and that was a really key step because effectively it was a demonstration of an architecture that could theoretically scale. Up to this point until that point, quantum computing existed as a concept and people doubted actually as to whether or not it could ever scale. So, in 2024, less than 2 years ago, Google demonstrated definitively that yes, this can scale. Now, what they did with Willow was a very small machine. And ultimately, it can't like that architecture itself cannot scale to the degree you would need to in order to break Bitcoin, but it showed the path. So, I think that's that's one very important thing to know. And then since then, there've been a lot of major breakthroughs and one of the most recent ones actually just came last week, which deals with basically the estimate for the size of quantum computer that you would actually need to break Bitcoin. So, as recently as 2017, cryptographers and quantum computer scientists and quantum physicists estimated you would need a quantum computer with 20 million qubits. Right? So, qubit is like a bit, it's the fundamental unit of quantum computation. Kind of gives you a sense for how big it is. Yeah, physical qubits, right? It and then just last week, a paper came out showing that actually if you apply to these algorithms Shor's algorithm a certain way and you arrange your resources in a certain way and use a certain type of error correction, you could actually get that number down to 100,000 qubits. Okay, so but we're still nowhere near 100,000 qubits. But the problem is the bar to clear keeps dropping. While at the same time results like Google show that progress is happening and at some point those two lines are going to cross. And by the way, the last thing I'll say before I hand it over to you Isabella is just beyond a certain point whoever is building these machines does not have any incentive to share progress, right? Because we're talking about breaking cryptography here. So I either you're going to use it to steal Bitcoin or try and recover your social security keys in which case you don't want to telegraph that or you're going to use it to try and read like the, you know, Chinese Communist Party's emails. Either way, you don't want to reveal that you have this capability and so as progress starts to advance, I think we as a community have to worry is the state of the art that we see out there actually what the real state of the art &gt;&gt; We're we're running low on time. I I I think a key question here is you know, really quickly like what's the difference between a physical qubit and a logical qubit and why does it matter? &gt;&gt; Uh well, I mean it matters and and the difference is error correction, but uh I also want to make a note to to how for for people to understand that quantum computers right now are not cheap and they're probably not going to be cheap for a very long time. And what I mean by not cheap is that they cost billions of dollars to build and millions of dollars to run. They have two different cryogenic coolants that are very like you don't see them anywhere else outside of like a particle accelerators. And so these are not going to be really necessarily being used to attack Bitcoin economically for a long time. It's the major players here are spooks. They are the NSA and the PLA. &gt;&gt; Okay, we um I I that when it comes to the quantum side that's what I mean to say so we see some progress but the the reality is that we have to understand that these computers need to factor larger and larger numbers and when I was referring to the question earlier I think the critic the critic's side of this is that well they're not factoring larger numbers they've been kind of at a stalemate with that for some time and we're not sure how that will progress. &gt;&gt; not as applicable to elliptic curve cryptography it's more for like RSA RSA is on on large primes but uh factoring large primes but uh elliptic curve is more uh it's it's a it's it's it's definitely a different problem it's similar in nature because it's applicable to Shor's because uh Shor's the way it works is it uses Fourier transform in a really like serious way optimized way that's like just way way more powerful than uh we could ever accomplish with classical uh and it's it's &gt;&gt; And yeah and one thing I would say to the critics and look I mean they have a point the point is that quantum computers today can't do very much that's true that's that's indisputable. I think the question is will the path of progress be kind of like very telegraphed where it's like oh well now we can factor 100 and now we can factor 200 or are the quantum is the builder of a quantum computer just going to get the air correction down get the ratio of physical to logical qubits down low enough to the point where then they could just build something that then at that point could break a 256-bit number cuz as Hunter pointed out correctly these things are extremely expensive. You kind of there's no if you're not going to have something that is capable of doing this it's kind of pointless to build. So I think that's the other thing to consider not that the critics are wrong it's true these things don't do don't do this today but it's a question of like how much of a how much lead time will we have when they do do that. &gt;&gt; And I I I don't think we should bet the future on Bitcoin on discounting future progress. &gt;&gt; This is true this is true this is something that everybody should be looking into um Isabelle if there is one final message you want to leave the audience with &gt;&gt; I would say that um this is a problem that's not just going to be solved by introducing PQC. I mean, we've been really talking a lot about PQC, but kind of something I was sort of alluding to earlier is that there are a lot of challenges with Bitcoin and sort of quantum hardening Bitcoin that have nothing to do PQC. For instance, all of Satoshi's coins being quantum uh insecure um and likely not moving to PQC addresses, right? So, um you know, I think that's something for people to think about it is like you know, there's going to be potentially very, very serious market impacts to Bitcoin um if we don't do other potentially very invasive things. Like, there are proposals out there to completely freeze uh Satoshi's coins and all pay to public key addresses. There are, you know, all sorts of different proposals for how should we should handle it. I actually think that those are the more controversial, more complicated, and in some ways more interesting questions um because to your point, you know, getting consensus around something like that is going to be an incredibly difficult and politically challenging problem to solve. So, from my perspective, I mean, there's so many issues with introducing PQC. That's going to be a show in terms of governance and consensus. Um but, it's it's really not just about that, you know? I mean, like from my perspective, the even potentially bigger issue is what do you do about coins that don't move to PQC addresses, you know, 4 million Bitcoin hit the market in a matter of hours once this quantum computer arises and somebody actually, you know, takes advantage of it. Um that's a potentially, you know, Bitcoin project destroying event regardless of whether or not we have PQC. So, that's I I think my kind of core point I want to make. &gt;&gt; And okay, we we got to wrap it up. I'm sorry, guys. Everybody check out BIP 360, bip360.org. And uh project 11. &gt;&gt; QED clock. &gt;&gt; Yeah. All right, thank you. &gt;&gt; Thanks, guys. Appreciate it.
