Public key recovery for EC leaves in P2MR (BIP-360)

Posted by sipa

Jul 8, 2026/20:31 UTC

The discussion revolves around the intricate issues and strategies associated with cryptocurrency security and efficiency post-Quantum day (Q-day), particularly focusing on EC (Elliptic Curve) disabling and address handling. The primary concern is the significant limitations imposed on users to achieve post-CRQC (Cryptographically Relevant Quantum Computing) pre-EC-disabling security, which includes stringent measures like prohibiting address reuse, public key sharing, and any transactions. Such restrictions are not typically feasible for casual users who may not even be aware of the arrival of Q-day and could continue using vulnerable software.

The debate over whether to include batch verification in the Bitcoin core remains unresolved, as it has not been updated or merged even seven years after P2TR was deployed, highlighted by the stagnation seen in the related pull request The PR. This lack of progress questions the necessity of sacrificing security for a feature that remains unutilized, suggesting that optimizing for adoption without friction should be prioritized over secondary ecosystem benefits.

Further scrutiny is given to the actual utility of posting bare public keys within SPKs, which appears limited outside theoretical applications such as proof-of-reserve systems or potential future uses in denial-of-service protection within the Lightning network gossip system. However, even in these cases, alternative cryptographic methods like generic ZK proof systems might offer more advantages despite higher computational demands.

Moreover, the practicality and marketing strategy behind different types of outputs post-Q-day, such as P2MR versus P2TRv2, and P2TRH, are critically evaluated. The options presented to users often come with severe caveats regarding security practices that are unlikely to be adhered to by the majority, thus potentially leading to a false sense of security. While some users might opt for solutions like P2TRH or P2MR under the impression they offer better protection post-Q-day, the strict conditions required to ensure this protection mean that many will misuse these options. Consequently, even if these alternatives are marketed as superior, their real-world effectiveness in providing additional security might be limited unless all recommended practices are strictly followed, which seems improbable for the average user.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback