PQC output type discussion

Posted by AntoineP

Oct 1, 2026/10:19 UTC

The discussion surrounding the adoption of P2TRv2 in the context of Bitcoin's future security against quantum computing threats highlights several critical considerations. The primary concern is whether the disabling triggers within the protocol, designed to protect against quantum attacks, will be trusted and utilized effectively by users. Without this trust, the consensus necessary for widespread adoption of P2TRv2 may not be achieved. This credibility is deemed self-reinforcing; as more users rely on it, the likelihood of its successful implementation increases. However, there are potential design choices that could undermine this dynamic, such as encouraging the use of a migration output type for purposes other than accessing a post-quantum (PQ) signing algorithm, which might lead to implementations that omit essential PQ spending paths.

Moreover, the conversation touches upon the integration of P2TRv2 with other cryptographic enhancements like CISA (a theoretical cryptographic improvement) and PQC (Post-Quantum Cryptography). There is an argument that including these features could encourage more users to adopt P2TRv2, which in turn could make the ecosystem robust against quantum computing risks. However, concerns remain about the possible controversial nature of EC (Elliptic Curve cryptography) disabling mechanisms embedded in P2TRv2, which could deter migration if seen as confiscatory or overly invasive.

The technical dialogue also delves into the practical aspects of user and developer adoption. It is suggested that mainstream wallet developers could play a crucial role by defaulting to P2TRv2 addresses, which would not diminish user functionality but provide a hedge against potential quantum threats. This transition could be facilitated by deriving emergency static PQ keys from existing mnemonic phrases used by wallet holders, ensuring a seamless change without additional complications. However, some friction points are anticipated, such as user confusion over new address types and possible incompatibilities with existing services, highlighted by issues with the bech32m address format, detailed here.

Ultimately, the discourse reflects a broader debate on the necessity and timing of adopting new cryptographic standards to secure Bitcoin against emerging threats. The necessity for a migration strategy that includes EC disabling as a defense against quantum risks is emphasized, contrasting with other options like P2MR (another proposed Bitcoin protocol enhancement) that may not provide sufficient incentives for widespread adoption or may come at higher costs. The discussion underlines the importance of choosing a path that balances immediate feasibility with long-term security needs, ensuring Bitcoin remains resilient in the face of evolving technological challenges.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback