Segwit commitment to post-quantum witness data?

Posted by sipa

Aug 26, 2026/17:22 UTC

The email delves into the significant implications of not incorporating post-quantum (PQ) signatures in blockchain technology, specifically within the context of block extensions. This concern is reminiscent of the discussions held during the 2015-2017 period regarding the segregated witness proposal. A vital point raised is that without PQ signatures, proof of work (PoW) does not commit to all relevant validation data. The integrity and security of blocks are crucial as they are relatively costly and time-consuming to validate—taking approximately 10 minutes of global PoW effort per block. This extensive validation process acts as a deterrent against the creation of invalid blocks due to the high costs associated with them.

Moreover, if PQ signatures are omitted, it introduces potential vulnerabilities where any relay node could generate numerous invalid versions of a block at minimal cost, complicating the validation process. Each version would require independent verification since the results cannot be cached, fundamentally altering how blocks are identified and validated. Typically, nodes are compelled to accept blocks if they appear valid, which would no longer be feasible under these conditions because the block's identity would only relate to its effects rather than its validity.

Another critical aspect discussed is the auditability of transactions, particularly in scenarios involving multisignature configurations like 2-of-3 setups. The visibility of which signers were involved in authorizing a transaction is crucial, especially when theft occurs. However, certain operations such as OP_CHECKMULTISIG used in these situations have been removed in newer protocol upgrades like BIP-342 Tapscript, posing challenges for future script proposals. The email suggests two potential solutions to address these issues in the context of block-wide SNARK proofs: either integrating the proof as part of the consensus rules or adopting an "after the fact" proof, which some nodes may accept, similar to utreexo. This approach would ensure the proof confirms the existence of specific pqdata that matches the commitments in the revealed data and adheres to the validity rules when combined with the non-pqdata.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback