PQC output type discussion

Posted by sipa

Sep 17, 2026/16:08 UTC

The discussion revolves around the security assumptions and practical implications of using different cryptographic spending paths, specifically addressing concerns related to the orange threat model. The concern raised is about the rationale for employing the PQ (Post-Quantum) spending path under certain security models, particularly when it seems to render previous secure methods like P2WSH as still secure. There's an argument suggesting that the distinction between the red and orange security models might be redundant due to their reliance on conditions such as no address reuse or pubkey sharing, which are often debated in security contexts.

In terms of address reuse, it’s highlighted that while general control over this practice is limited, there are specific use cases where address reuse is manageable, particularly for long-term holding addresses. This aspect underscores that not all forms of address reuse lead to security vulnerabilities—only those involving addresses that have previously engaged in transactions are at risk. This differentiation informs the broader discussion on the suitability and security of newer cryptographic methods like P2TR and P2TRv2 compared to traditional ones.

Further complicating the security landscape is the introduction of P2MR output types. The shift towards these alternatives could potentially offer a safer haven against quantum threats compared to P2TRv2, reflecting a strategic retreat from reliance on ECC-based spending paths until they are fully disabled. This transition strategy, however, isn’t just about technical feasibility but also encompasses psychological factors and user confidence in the security paradigms employed.

Moreover, the conversation touches upon the integration of CISA into the security framework of these cryptographic methods, questioning the interaction between cost implications and perceived security enhancements offered by such incorporations. The skepticism here is directed towards whether adding regulatory frameworks like CISA should influence the core security assessments of cryptographic protocols rather than being considered separately. This point raises broader questions about the alignment of security costs with actual security benefits in evolving digital currency ecosystems.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback