Quantum Recovery Of Hashed Address Secured Coins With No Confiscatory Risk

Posted by shinobimonkey

Jul 24, 2026/00:39 UTC

The email proposes a series of mechanisms aimed at enhancing the recovery of coins for their rightful owners while discussing potential implementation hurdles and solutions. The primary strategy involves additive encumbrances that introduce new proofs of secret knowledge alongside traditional signatures by private keys, as well as commit-reveal schemes. These schemes require transactions to be committed and then wait for a number of blocks before they become consensus valid. However, the sender acknowledges that these methods alone cannot guarantee full recovery coverage for all coins, particularly if the owner retains their private key.

To address these gaps, the sender suggests an integrative approach where multiple recovery schemes are layered together. By allowing any single scheme to meet the spending threshold, it is believed that complete coverage could be achieved. This approach hinges on only one new security assumption: the necessity to keep public keys or internal script paths confidential. Moreover, it takes into account that many users may inadvertently leak master public keys to third-party servers when querying balances, which could potentially compromise security.

Another significant focus of the email is on addressing the challenges posed by existing xpub usage and ensuring compatibility with various wallet types through the Electrum protocol. The sender describes a recovery path applicable to BIP 32 based wallets, covering both legacy and newer derivation paths. For hashed-address types, the proposed derivation proof is deemed sufficient for recovery without proactive actions from the user prior to a fork implementing these changes.

Additionally, the concept of stateful timestamped proofs is revisited. These proofs combine a signature over a new quantum-safe public key with a timestamp to confirm the authenticity of a transaction before a certain deadline. This method aims to remain space-efficient within blockchain constraints and is presented as preferable to more cumbersome zero-knowledge proofs (ZKPs).

Lastly, the sender reiterates the utility of commit-reveal schemes for hashed address types, emphasizing the need for enhanced secrecy in public key management. The email concludes by seeking feedback on potential oversights or implementation details that might have been missed, reflecting an ongoing dialogue with peers to refine the proposal further.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback