PQC output type discussion

Posted by fjahr

Aug 23, 2026/22:55 UTC

The email discusses various aspects of the development and integration of cryptographic improvements in Bitcoin, specifically focusing on the CISA (Cross-Input Signature Aggregation) and its potential bundling with P2TRv2. It highlights that BIPs 458, 459, and CISA BIP 460 have been developed with reference implementations and extensive test vectors, indicating a level of readiness for review and further consideration by the community. However, there are concerns about the potential complexity introduced by reviewing these implementations given past experiences with similar updates like Silent Payments.

The email also touches on a revision to BIP 460 aimed at simplifying wallet adoption by making opted-out inputs revert to plain BIP 341 key path spends. This change could facilitate easier integration by decoupling new signing logic from wallet software, thereby not requiring immediate adoption of new methods by wallet developers. The revised proposal is discussed in detail in a GitHub pull request comment, accessible here.

There is an ongoing debate within the community regarding the practical implications of integrating CISA with P2TRv2, particularly how it might affect the deployment timeline and overall adoption of P2TRv2. Some believe that adding CISA could delay P2TRv2's rollout and reduce its initial uptake due to the added complexity, although others argue that the benefits, especially for users focused on privacy like Payjoin and Coinjoin participants, outweigh potential delays.

Technical implementation and peer review are identified as significant factors that could influence the adoption timeline. CISA appears to be ahead in terms of development compared to the post-quantum (PQ) components of P2TRv2, which are still evolving and are based on very recently developed cryptographic schemes. A concern raised is whether the effort required to review CISA might detract from the resources available to advance the PQ part of the project.

Finally, the importance of forming community consensus is emphasized, with opinions likely split between those who see CISA as a valuable addition capable of accelerating consensus and those who view it as a distraction that could divert resources from more critical areas such as ECC (Elliptic Curve Cryptography) related enhancements. The discussion concludes by pondering the broader impacts of CRQC (Cryptographic Quantum Computing) developments on the strategic decisions related to Bitcoin's cryptographic future, suggesting that the inclusion of CISA might provide a form of insurance against potential slowdowns in CRQC progress.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback