Segwit commitment to post-quantum witness data?

Posted by ajtowns

Aug 20, 2026/04:36 UTC

The discussion revolves around the optimal structure for handling commitments in transactions involving both taproot bip340 signatures and post-quantum (PQ) signatures. The primary concern is whether to include per-input commitments or a single transaction-wide commitment, particularly in scenarios involving consolidation transactions with multiple inputs but a single output.

In one approach, each input would carry its own annex committing to a PQ signature, along with a witness stack containing both the script and the necessary signatures (bip340 and PQ). This setup suggests that each input independently secures its own commitments and signature verifications, potentially enhancing security by isolating each input's cryptographic details.

Conversely, an alternative suggestion focuses on efficiency by proposing a single annex in the first input that commits to all PQ-style witnesses across inputs. This method could reduce redundancy and save space, albeit only a modest amount compared to the size of PQ signatures. However, this could simplify the transaction structure and might be effective if integrated with broader cryptographic simplifications such as those proposed under CISA guidelines. Here, the idea would be to consolidate signatures into fewer inputs, possibly reducing the overhead associated with managing multiple cryptographic operations.

The debate also touches on the implications of chaining cryptographic styles and sequential support requirements, which implies a protocol where support for a newer style mandates compatibility with preceding styles. Additionally, there is mention of a potential new opcode specifically for PQ signature verification ("CHECK_PQ_SIG_VERIFY"), which might streamline the process by directly utilizing signatures from a dedicated PQ-style witness stack. This approach hints at introducing a specialized "pq-altstack" for handling these operations uniquely, thereby segregating them from traditional stack operations and avoiding unauthorized interactions with the stack.

Overall, the discussion encapsulates a technical introspection into how blockchain transactions might evolve in response to quantum computing threats and the ongoing development of cryptographic standards. The choices between isolated versus consolidated cryptographic commitments reflect broader themes in blockchain technology governance: balance between efficiency, security, and forward compatibility.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback