Post Quantum Recovery Of Hashed Addresses With No Confiscatory Risk

Posted by shinobi

Jul 14, 2026/16:55 UTC

The ongoing debate concerning the security risks posed by quantum computing to cryptocurrency involves two main concerns. Firstly, there is a need to determine which quantum-safe signature schemes should be adopted to allow users to transition smoothly and securely. This transition is crucial for maintaining access to digital assets in a post-quantum world. Secondly, the handling of cryptocurrencies that are currently secured by ECC (Elliptic Curve Cryptography) based scripts, which are vulnerable to quantum attacks, raises significant issues. There are discussions about whether these coins should be frozen and, if so, how to enable legitimate owners to reclaim their assets without allowing potential attackers the same opportunity.

There is a recognized challenge in ensuring that no user ends up unable to produce a recovery proof, thereby losing access to their coins permanently. Proposals to address this include Adam Back's BIP 32 hierarchical proofs, recently tested in a proof-of-concept stage, which benefit any user who has generated keys via BIP 32. Another proposal suggests non-deterministic stateful proofs that must be created and timestamped before a set deadline, offering a method for users with vulnerable ECC keys to authenticate using a quantum-safe mechanism post-quantum activation.

Additionally, an idea proposed by either Tim Ruffing or Tadge Dryja introduces a commit-reveal migration scheme. In this scheme, transactions spending vulnerable ECC inputs must include an encrypted commitment confirmed within a blockchain block a predetermined number of confirmations prior to the decrypted transaction being validated. However, this method does not cover users with non-hashed address types since attackers could potentially access necessary data for a valid pre-commitment.

By combining these strategies—hierarchical proofs, stateful timestamped proofs, and commit-reveal mechanisms—a comprehensive solution could potentially be achieved for users with hashed address types. Nonetheless, it’s noted that coverage for non-hashed address types remains fundamentally unattainable due to inherent vulnerabilities that cannot be mitigated by the commit-reveal approach alone. The only scenario where users might find themselves unable to recover their coins under this layered recovery method is if they have lost access to their private keys, a situation outside the scope of current proposals.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback