PQC output type discussion

Jul 27 - Jul 30, 2026

  • The extensive discussion on enhancing Bitcoin's resilience against quantum threats has led to various strategic proposals centered around post-quantum cryptography (PQC) and mechanisms to disable Elliptic Curve Cryptography (ECC).

A notable approach includes the introduction of a P2TRv2 output type to offer an emergency PQC solution that incorporates Tripwire and Miner Lockdown features alongside a hash-based PQC signature opcode. This method focuses on ease of adoption, aiming to maintain fee structures similar to current standards while minimizing transition complexities for developers and users. There is also consideration for a longer-term strategy through a P2MR-based output type, which facilitates a full migration to PQC after cryptographically relevant quantum computers become operational. However, this option may face delayed adoption due to its intricate requirements and significant changes to infrastructure.

In response to the quantum threat, several innovative Bitcoin transaction output types have been proposed. The P2MR or "Pay to Merkle Root" stores a Merkle root representing a tree of leaf scripts, keeping EC points off-chain until needed, as detailed in BIP 360, which enhances security by not exposing these points prematurely. Another proposal, the P2QR or "Pay to Quantum Resistant," disables ECC opcodes from inception, ensuring quantum resistance at the cost of losing ECC efficiency prior to potential quantum breakthroughs. Additionally, the P2TRv2 extends the existing BIP 341 framework by integrating PQC opcodes with anticipated consensus changes to deactivate ECC within the output itself. A variant called P2TRH involves a scriptPubKey containing a hash of the tweaked point Q and employs public key recovery for key path spending, aligning closely with P2TRv2’s weight profile but without leaving an EC point on-chain. These modifications aim to bolster Bitcoin's defenses against quantum computing risks while balancing security, efficiency, and backward compatibility.

Recent developments have included the implementation of BIP-360 P2MR in Bitcoin Core on the regtest network, offering fresh perspectives on transaction efficiency across different types of Bitcoin transactions. This implementation focused on analyzing spends by comparing identical transactions varying only in their input configurations. Results indicated notable efficiencies in transactions using P2MR structures over those using P2TR scripts, particularly in blockchain space utilization. Such findings could influence future enhancements in Bitcoin’s transaction efficiency and cost-effectiveness, as further details and data are explored in this comprehensive documentation.

Lastly, the discourse surrounding the anticipation of Q-day, where quantum computers effectively break current cryptographic defenses, reflects a diverse range of opinions on how and when ECC should be considered vulnerable. A humorous yet insightful comment by Scott Aaronson suggests that milestones in quantum computing might not progress linearly, reinforcing the argument for preemptively working towards PQC readiness rather than waiting for clear indicators of quantum advancements. This proactive approach underscores the broader community effort to ensure Bitcoin remains secure and trustworthy as quantum technologies evolve.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback