PQC output type discussion

Posted by sipa

Aug 17, 2026/22:28 UTC

The recent proposal for the CISA output type in cryptographic systems has sparked a significant reconsideration of post-quantum (PQ) output types, emphasizing its potential to drive efficiency through reduced data requirements per transaction. Unlike typical PQ-security profiles, CISA leverages asymptotically minimal byte witnesses for aggregated elliptic curve (EC) spend transactions, which promises better efficiency than current models like P2TR. This enhancement could encourage adoption even among users who are not primarily concerned with PQ security due to its superior efficiency.

However, the transition to new output types like CISA faces substantial challenges. The first major challenge is the need for widespread software and infrastructure updates, which requires buy-in from developers across various platforms including open-source and proprietary wallets, as well as centralized custodians. Such changes often involve significant time and effort, particularly in convincing entities that see less immediate benefit from these updates. The second hurdle is user acceptance. Historically, forcing users towards new technologies has been both rare and unpopular, suggesting that any new adoption must be organically motivated by clear advantages or user demand.

Despite these challenges, the introduction of CISA could lead to significant reductions in transaction fees under certain conditions, specifically in scenarios involving transactions with many inputs and few outputs. However, this alone may not suffice to accelerate adoption unless there's a consistent high-fee environment, which currently seems unlikely given the historically low fee rates. Moreover, the complexity of integrating CISA might act as a deterrent rather than an incentive, especially considering the technical and economic adjustments required for its implementation.

Further complicating the landscape is the potential integration of other technologies alongside CISA, such as enhancements to EC disable forks which would incur additional costs and potentially disrupt existing systems. Discussions around new witness styles in a post-CRQC world suggest a shift towards metrics that prioritize computational over bandwidth resources, indicating a broader reevaluation of resource limits in blockchain technologies.

In conclusion, while CISA offers promising efficiencies, the broader implications for its adoption reflect a complex interplay of technological readiness, economic incentives, and stakeholder willingness to embrace change. The ongoing debate and development will determine if such innovations will pave the way for more efficient and secure blockchain operations in a future dominated by quantum computing capabilities.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback