Posted by Pieter Wuille
Jun 16, 2026/20:09 UTC
The email addresses key concepts and terminology concerning expected cryptographic (EC) disabling forks related to Bitcoin output types, with a focus on the timing of these forks relative to the introduction of new output types and the anticipated quantum day (Q-day). The terms "Later," "Never," and "Now" represent different expectations for when EC paths or opcodes for specific Bitcoin output types will be disabled. "Later" implies that disabling is expected after the output type is introduced but before Q-day. This classification aims to influence usage patterns by avoiding premature coin burning due to the expectation that EC disabling will occur timely, thus not being treated as confiscation.
The discussion also explores the strategic implications of adopting certain output types like P2MR ("Merkle-Never") and P2TRv2 ("Taproot-Later"), in light of their compatibility with current technological constraints and future expectations. P2TRv2, for instance, is seen as preferable within the "Later" category because it offers lower adoption friction due to cost-effectiveness and aligns better with the taproot incentive structure, which is significant until EC disabling becomes essential. Furthermore, this output type does not necessitate immediate changes since it is designed to become relevant only when a disabling fork appears inevitable or fear around it peaks sufficiently.
The email elaborates on the necessity of having at least one "Later" output type to facilitate a meaningful migration away from susceptible cryptographic methods, particularly as quantum computing advances pose increasing risks to existing cryptographic foundations. It argues that focusing solely on types like P2MR, which do not anticipate an EC disabling fork, would likely lead to inadequate protection levels against quantum threats, describing such an approach as insufficient for ensuring broader currency survival.
In discussing broader strategic concerns, the notion of using a "Later" type as a primary Quantum Post-Quantum Cryptography (PQC) migration strategy is emphasized. This approach could serve as a focal point for consensus, although alternative strategies might involve introducing multiple output types to cater to different security needs and adoption timelines. The text critiques overly conservative or diversified approaches as potentially diluting the effectiveness of a unified migration strategy.
Lastly, potential future scenarios are sketched out depending on how quickly a comprehensive quantum-resistant system needs to be implemented. These range from smooth transitions enabled by early and widespread adoption of new technologies to more chaotic adjustments following an unexpected acceleration in quantum computing capabilities. Each scenario underscores the importance of proactive and coordinated actions within the Bitcoin community to navigate the challenges posed by quantum technologies effectively.
Thread Summary (19 replies)
Jun 3 - Jun 13, 2026
20 messages • 19 replies
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback