{
  "episodeId": "SLP670",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "clara_shikhelman": {
      "name": "Clara Shikhelman",
      "role": "guest",
      "tag": "CLARA"
    },
    "anthony_milton": {
      "name": "Anthony Milton",
      "role": "guest",
      "tag": "ANTHONY"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:11",
      "start": 11.09,
      "text": "Hi everyone, and welcome back to Stephan Livera podcast, brought to you by Bold. Today I have two guests joining me to discuss this whole Bitcoin and quantum thing, and so joining us are some esteemed researchers and developers. So, Clara Shikhelman from, so Clara is the head of research at Chaincode and also Anthony Milton. Anthony Milton, researcher and open-source Bitcoin developer. So first off, welcome to the show. Hey. Thanks for"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "00:36",
      "start": 35.77,
      "text": "having us."
    },
    {
      "speaker": "stephan",
      "time": "00:37",
      "start": 37.47,
      "text": "Yeah, so look, I, we're gonna do our best. Obviously, this, this can be quite a technical subject. I know you've, you've recently, you've put out this big report, fifty-five page report. so I've tried to read and understand it, but, w-w-we're gonna do our best to make it accessible for people. I think the first question a lot of people will have is Is this stuff even a real risk or is it just kind of overhyped announcements from the likes of Google and Microsoft and whoever? What do you guys think?"
    },
    {
      "speaker": "anthony_milton",
      "time": "01:05",
      "start": 65.05,
      "text": "I think it's difficult to tell until we'll have, if we'll have these quantum computers But I think a lot of serious researchers that were very skeptical changed their minds recently, saying, \"Okay, maybe we should take this seriously. We should have a plan. There's no need to run around panicking, but we should definitely give it some deep thought and be ready because...\" It went from it's not happening to, well, maybe. And if it's, you know, well, maybe, we should be prepared."
    },
    {
      "speaker": "stephan",
      "time": "01:38",
      "start": 98.41,
      "text": "Yeah. And now I don't understand this as well as you guys do, but the, the, some of the skepticism maybe in, in years gone past was more like, okay, you've got this machine, but it doesn't-- one, it doesn't do anything useful, or two, it doesn't have the error correction that would be required to actually be able to, let's say, crack our Bitcoin private keys. Is that like a fair summary of"
    },
    {
      "speaker": "stephan",
      "time": "02:01",
      "start": 121.02,
      "text": "Changing it seems."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "02:02",
      "start": 122.3,
      "text": "Absolutely. So until, until maybe Google's announcement last year, late last year, error correction was a massive issue, but Google had kind of a, a breakthrough with, achieving something called below threshold, which means that as they add more physical qubits to the system, they see the error rates drop. So now they can throw more resources at the problem and the error rates should reduce and things, the systems should be more stable. So this is something that was, I guess, talked about for thirty years or so And it's been demonstrated late last year, and so people are starting to pay attention, like, \"Oh, okay, m-maybe there's a path forward.\" it's maybe not so much science fiction anymore, maybe it's, it's, it's m-maybe it's just down to the engineering. If we get the engineering right, things can really start to kick off."
    },
    {
      "speaker": "stephan",
      "time": "02:47",
      "start": 166.94,
      "text": "Excellent. And maybe, you guys could tell us a little bit about, you know, why you wrote this report, why now?"
    },
    {
      "speaker": "anthony_milton",
      "time": "02:54",
      "start": 173.61,
      "text": "We wrote this report because we felt there was a lot of talk about quantum computing, a lot of, on the one side, you had people absolutely panicking and, I believe, overreacting, and on, on the other end, there are people that are just, \"We're not interested, we shouldn't be talking about this.\" And there are some deep decisions to be made, so we thought it's important to start the discussion on a very good ground, having all of the information available so the research and the in-community discussions can be held. And we can move forward in a timely manner."
    },
    {
      "speaker": "stephan",
      "time": "03:38",
      "start": 217.94,
      "text": "Great. And so let's, so again, doing our best to make this accessible for, let's say, the everyday hodler, the everyday Bitcoiner who's not sort of technically in the detail, maybe if you guys could walk us through what are some of the relevant Bitcoin basics here in terms of things like, okay, the ECD, SA and Schnorr and this, discrete logarithm problem and, you know, a little bit of those basics? so that we can understand a bit about what exactly is the problem here or the potential problem."
    },
    {
      "speaker": "anthony_milton",
      "time": "04:11",
      "start": 250.54,
      "text": "So I think the basics of all of cryptography is that you're assuming there is a difficult problem, something is difficult to do. So when we're talking about, public and private keys, such as in ECDSA and all of the signature schemes, pretty much, including the ones used in Bitcoin, the cryptographic assumption is that given Given a public key, as you show on chain, it is difficult to impossible to have the private key. So if I can show that I have the private key, this means that I know something, I have the secret, I own these funds. And then with quantum computing, this assumption can break. Suddenly going from a public key to a private key goes from invisible, impossible, takes time longer than the universe, so on, to something that can indeed happen, given a strong enough, of course, quantum computer. And this means that suddenly your funds might not be safe anymore, because for, if you're a public key is visible on chain, for example, or is out there before, and, you know, a public key by its name, it's meant to be public. You shouldn't be hiding it. So if somebody has your public key, suddenly they can get the private key and use the funds. And then we need to change to something else."
    },
    {
      "speaker": "stephan",
      "time": "05:43",
      "start": 343.26,
      "text": "Yeah. And so because this is kind of a very key thing, let me just try and explain it again, just in like simple terms. I mean, I think you did a great job, but I'm just gonna try and explain it as I understand it. So in Bitcoin, one of the things that we do is we, you know, whether, whether we're using like a cold card or a phone wallet, what we're doing is we are- Signing a message that essentially proves that we control the private key, and what we're sort of using to do that is, I guess, this ass- this assumption that it's kind of easy to go one way, but hard to go the other way. I.e., if you have the private key, it's very easy to, you know, create, to understand what, what would the public key be for that. But if you're going back the other way, the public key, it's not so easy to do that. That's kind of the key thing. And so, in simple terms, when I send a Bitcoin transaction. Really, what's going on, kind of under the hood, in simplified terms, is I am, let's say, signing a message that lets me spend these coins out of an address, you know, to which I control the private keys for that Into, and I'm locking them to, let's say, your public, you know, to your address, to which you control the private keys for that. And so this is the thing that whether we're talking in the ECDSA paradigm or the Schnorr paradigm it's, you know, this is the thing that could, that could potentially change in the quantum computer, you know, if one became sufficiently powerful enough, and then, as I understand from your report and just in general, the, it's using these quantum computers that are using Shor's algorithm, fair summary or do you have-- Would you wanna elaborate on that?"
    },
    {
      "speaker": "anthony_milton",
      "time": "07:21",
      "start": 440.73,
      "text": "So Shor's algorithm is more relevant in the context of mining?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "07:27",
      "start": 446.82,
      "text": "No, it's Grover's. You've got to, you've got to restart. Right,"
    },
    {
      "speaker": "stephan",
      "time": "07:30",
      "start": 450.04,
      "text": "right. So Shores, Shores, Gro- Yeah, 'cause, and I guess that's the other point we should touch on, right? There's an im- There's an impact at the, let's say, the private key aspects, and then there's an impact on the mining side of it, and I believe one of them is Shores and the other is Grover's."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "07:43",
      "start": 462.79,
      "text": "Yeah. So Shores is for the, the private key, public key break, and Basically solves the discrete logarithm problem, which basically is what EDFA is and what Schnorr is. So it allows you to derive the private key from the public key. And I guess, you know, probably gonna talk about this a lot, but when you have exposed public keys, that's bad news for quantum, quantum computers, quantum attackers, because That going back, going back, as you said, which takes, you know, an infeasibly long time, it could be reduced to, optimistically, let's say, hours or days. So if there's a public key that's exposed, the private key could be, could be, snatched and then the attacker can actually sign for that, that, those funds, Your ki-your money's gone, your funds are gone."
    },
    {
      "speaker": "stephan",
      "time": "08:34",
      "start": 514.08,
      "text": "Yeah. Okay. And now, could you also explain for us what's the impact on the mining side?"
    },
    {
      "speaker": "anthony_milton",
      "time": "08:39",
      "start": 519.22,
      "text": "So on, on the mining level, this is something that we're significantly less worried about. Currently, just because it's, it's a more difficult problem, like the, the time for quantum mining to be relevant is very, very long Like the, just because ASICs are so efficient that competing with them would be very difficult, but given that with Grover's algorithm, you can make, you can do things significantly quicker, and also you can't do things in parallel. So this means we can see centralization, because suddenly it's not like you have two miners, they're working, and in expectation they'll get whatever they put in. Now, if we're going to quantum mining, if they'll be working together, their results would be better. And then everybody is motivated just to create this one huge miner which absolutely shatters mining decentralization"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "09:52",
      "start": 591.74,
      "text": "Yeah. So in, in the current classical sense with ASICs, if you add another ASIC to the system, well, you double the number of ASICs or the hash power you've got, you're basically halving the, the, the, the chance to get the block, or doubling rather, to chance to get the block. Whereas if you, in the quantum space, if you, you don't want it, you don't wanna have double the systems, you wanna have the fastest system possible, you wanna get the best single system possible rather than throwing multiple independent resources at"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "10:21",
      "start": 621.14,
      "text": "dynamics of how mining operates, and then it could lead to this centralize-centralization problem mining, but as Clara said, like this is much further into the future than, the risks that sh- Sh-sh-um, sure brings. So, we, we worry about the private key break much sooner than the mining side of it. Much earlier than the mining side of it. Yep, absolutely. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "10:43",
      "start": 643.19,
      "text": "Yeah. Okay. Yeah. As, and I think that's, that seems to be what most people kind of are, are how most people are understanding this. And so- Let's now deal in the private keys and public keys world. I guess obvious questions people will have, how many coins are at risk? What would this mean for us as Bitcoiners?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "11:02",
      "start": 661.87,
      "text": "Yeah, it's pretty, pretty, substantial at the moment, So we've just finished a deep dive on the data and we're gonna pub-- be publishing it soon, but it looks like about thirty-three percent of the current supply, is at risk due to exposed public keys. And there's three main vectors or categories for the exposure. So we've got address reuse, so that's when you have, a bunch of You've spent from an address that still has some UTXOs attached to it, still has funds attached to it, so you, you spent on chain, you've exposed a public key, so the, A attacker could derive the private key for that. we've got the inherently vulnerable scripts, so these are the, the very early legacy script types like pay to public key and pay to multisig. Pay to multisig, no one uses it anymore. Don't, don't be fooled, multisig gets normally done with the other hash types, hash script types, but those two types are the legacy types, and we also have pay to taproot that also has, a public key exposed in, By default, so these are the three inherently vulnerable types. And then we've also got things like, spends on forks of Bitcoin. So remember Bitcoin Cash, the, you know, the whole wars back then, twenty seventeen. So a lot of Bitcoiners dumped their Bitcoin Cash, but still held their Bitcoin. So they transacted on Bitcoin Cash and they exposed the public keys, but they still held the basically the same UTXOs on Bitcoin. So now they've actually exposed their public keys on, on Cash. Cash or other forks, BSV, whatever, they're still sitting there on, on Bitcoin. that, that obviously after the fork, that exploded, that number went crazy. it was like three million Bitcoin were kind of quantum vulnerable at that point, and that's reduced now to something like a hundred and fifty thousand. so yeah, it's, it's pretty substantial. but address reuse is like, probably on the order of seventy percent of those, those funds. So about four and a half million Bitcoin is vulnerable due to address reuse at the moment."
    },
    {
      "speaker": "stephan",
      "time": "13:07",
      "start": 787.33,
      "text": "Okay, gotcha. So let's just summarizing that overall-- So you said the overall number of quantum vulnerable coins, you know, right. So as we speak today, what is it, like nineteen point eight? I've got to pull up that number again. As we speak today, I think it's like nineteen point, nineteen point nine million, yeah, nineteen point nine million coins have been mined into existence, and then of that nineteen point nine, you're saying thirty-three percent are vulnerable to quantum. So we're talking Something like six million, let's say. Six point five, yeah. Okay. And then of that six point five, you're saying four point five million are the ones vulnerable because of address reuse and the others are because of the script type, like Satoshi or the Potoshi coins and this kind of thing, right? Gotcha. Yep, that's right. Alright. Yep. And then just quick explanation for listeners who aren't familiar, right? You might just be used to using your standard Bitcoin wallet, actually in the background there's scripting going on and there may be different script types that your wallet is using really knowing or caring as much, right? And kind of sometimes the address can give you a clue about that, but it's not always, right? So the address is starting with a one, the address is starting with a three, address is starting with BC1, and the new Taproot addresses, but As you said, there are different script types that relate to, let's say, earlier use of Bitcoin, and those are the ones that are more vulnerable because the, the public key is already exposed. And then almost no one's using them"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "14:28",
      "start": 867.5,
      "text": "nowadays, like we've looked at the tran- like the transaction, volume of these, and it's like minuscule. So no one's using Pay to Pub Key, no one's using Pay to MultiSig, oh, sorry, some people using Pay to MultiSig now because they can start smuggling data in, but anyway, put that aside. Right,"
    },
    {
      "speaker": "stephan",
      "time": "14:43",
      "start": 883.25,
      "text": "that's more of a spammer thing, but yeah, go on. Yeah,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "14:45",
      "start": 885.35,
      "text": "yep. most people are using like the, the hash script types, so these are the types That address. Gotcha. So people are using"
    },
    {
      "speaker": "anthony_milton",
      "time": "15:00",
      "start": 899.5,
      "text": "Pay to Taproot, I think this is important. Yeah, Pay to Taproot, yeah, Pay to Taproot is gaining popularity. And, yeah, a-and on the most basic level, if you're using Taproot, then your public key is visible on chain."
    },
    {
      "speaker": "stephan",
      "time": "15:16",
      "start": 915.85,
      "text": "Gotcha. And so with Taproot, there's this concept of the key path and the script path, I guess we'll come to that later. but just to, I guess explain- In, as you said, the, the script types that are not as vulnerable, as you said, there are, cases where the public key isn't directly put on chain, it's a hash of the public key, and that's why you were saying in the case where address reuse, that's where there's a risk, because now the public key has been exposed to the world and it's literally on the chain for anyone to see, and so these script types relate to, I think I'm just listing out here, pay to pub key hash, pay to script hash, pay Script hash. So those are the, let's say, less vulnerable script types. Now, another thing, just kind of in our ecosystem and as users, we may have played around with xPub's, right? The, the famous xPub's or, might be included in what's called an output descriptor. And so this is how many people might be using, let's say, as an example, Sparrow Wallet or Nunchuck or, you know, these Electrum-based things that call out to an Electrum server, and that also includes, You know, your, your master public key. So what are some of the implications there? I'll give you, I'll give you an example. So let's say you are using an HD hierarchical deterministic master xPub just on a typical single signature hardware wallet setup. Can the quantum attacker pawn all your coins if he gets your xPub?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "16:46",
      "start": 1006.22,
      "text": "Sure, the answer's no, because, most of the derivations are hardened, and so hardened-- to create a hardened path in a HD wallet, you need to actually use, the private key, to, to create the unhardened, paths in a wallet, you can do that with the public key. So I think most, most wallets or most services, you'd, you'd have only risk of anything that's non-hardened, which would be minuscule. It'll basically only refer to the account that you're, like, you're sharing. So, I think most people probably only expose like account level"
    },
    {
      "speaker": "stephan",
      "time": "17:23",
      "start": 1042.78,
      "text": "xpubs rather than the master ones. I see. Okay, gotcha. So it's-- but then if you are still exposing an account level xpub, couldn't the quantum attacker still get, you know, the coins associated for that? Account level xPub, which would in practice hold your keys, right? Account level, yeah. Your coins, let's say. Yeah, that's true. Yeah. So I guess- But it couldn't, couldn't,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "17:43",
      "start": 1063.16,
      "text": "couldn't go outside that, and,"
    },
    {
      "speaker": "stephan",
      "time": "17:45",
      "start": 1065.18,
      "text": "right."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "17:46",
      "start": 1065.9,
      "text": "If you're mixing, you can't go up the chain either. So it depends on how compartmentalized your wallet is. Like the point of this h-hybrid wallets was to compartmentalize damage, I suppose."
    },
    {
      "speaker": "stephan",
      "time": "17:56",
      "start": 1075.67,
      "text": "Yeah."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "17:56",
      "start": 1075.83,
      "text": "And so, If your wallet uses that like standard, what is it? Bit forty-four, I think."
    },
    {
      "speaker": "stephan",
      "time": "18:04",
      "start": 1083.85,
      "text": "Yep."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "18:04",
      "start": 1084.37,
      "text": "like if you, if you go a few levels down, you, you typically see like You'd see the, apostrophes"
    },
    {
      "speaker": "stephan",
      "time": "18:33",
      "start": 1113.05,
      "text": "in the, like the, the Because BIP thirty nine and this kind of some of these things weren't adopted by core, and I think maybe there was like slightly different, concepts of whether you should harden or not harden, and I think there were a lot of the typical commercially used Bitcoin software and hardware, they kind of use the unhardened thing for practicality and ease of use reasons, but theoretically that's less secure against, you know, this, this risk, right?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "19:08",
      "start": 1148.01,
      "text": "Probably on a service by service basis, right? probably check what you've, check what you've shared and, try and determine your risk level. Like I don't think At this stage, people shouldn't worry too much about it, but it's certainly something to be aware of. Like, what is your exposure? And if, if you're with a service, not naming names, but if you're with a service and they've used some what would be considered un-unhonest,"
    },
    {
      "speaker": "stephan",
      "time": "19:33",
      "start": 1172.93,
      "text": "yeah,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "19:33",
      "start": 1173.31,
      "text": "hassle them, let them know, like, hey, fix your, fix your service. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "19:38",
      "start": 1178.0,
      "text": "The lead sponsor of this show is Bold, the best place to buy, sell, and save Bitcoin. For listeners in the US, Bold lets you secure your financial future with complete peace of mind by integrating a low fee Bitcoin only brokerage with next gen multisig vaults. With Bold, you can smash buy Bitcoin or set a DCA plan for only 0.99% fees and seamlessly deposit the Bitcoin direct to your Bold Vault. The Bold Vault is a two or three collaborative multisig where you hold two keys and Bold holds one as a redundant backup. Backup protecting against loss or theft. You can use Trezor, Ledger or cold card hardware wallets to spin up a Bold Vault in just a few minutes, and the Bold Vault is the only collaborative custody vault available with zero monthly fees. They're also offering zero fees on your first ten thousand dollars of Bitcoin buys and twenty five dollars of free Bitcoin when you buy a hundred dollars of Bitcoin or more. Try Bold today and upgrade your stacking experience over at getbold dot io. And now back to the show. But you know what, it might be in practice. Not trying to, you know, point the finger, but I think in practice, there may be a lot of, let's say, Electrum users. Now, to be fair to Electrum, it's an OG wallet from twenty eleven. The whole point of what they're trying to do is get people to be non-custodial, right, self-custodial, and not leave things on the exchange. They wanted to be very quick and easy to set up, but as part of that, that Electrum wallet user might just be connecting to random public Electrum service and in doing so, expose his"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "21:06",
      "start": 1265.9,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "21:07",
      "start": 1266.76,
      "text": "So anyway, that's, I guess these are things people need to think about, yeah, yeah."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "21:11",
      "start": 1270.77,
      "text": "Like we, we need to just make it, we're trying to, we're trying to disseminate this information and let people know, like, okay, look, this is a risk, you should look into this, We may be hazy on some of the details, but follow it up."
    },
    {
      "speaker": "stephan",
      "time": "21:23",
      "start": 1282.7,
      "text": "Yeah, right, okay. And so now let's talk a little bit about what are some of the main mitigations possible and, what are some of the approaches, that you and other researchers are looking at?"
    },
    {
      "speaker": "anthony_milton",
      "time": "21:37",
      "start": 1297.42,
      "text": "I think like the immediate call to action, this is going back to what Anthony said earlier, stop address reusing. This is a terrible habit. It's bad for privacy, it's bad now, and if the quantum risk is the motivation that you need to stop address reuse, this is the number one actionable item because this, first of all, it's a bad practice on privacy level. Second of all, in all of these cases of address reuse, at least in most Of them, people have access to the private key, they can move the funds. It's not coins from, I don't know, a decade ago that maybe are lost So I think there are some immediate actions to be done now. Also, be aware everything that you talked about Electrum and so on, xPub's, be more aware of what's going on and follow best practices For the long term, there is right now we're in the research phase. So there's a bunch of very serious, researchers, very good cryptographers, Bitcoin developers, and so on that are examining the state of quantum cryptography in, you know, in the wider academic space. There's lots of interest. It's a very popular research topic. Of publications. So in this point of time, there's work to be done there following the research that is happening, and maybe we'll get back to this later, but there are, schemes that are quantum secure right now But because it's very new cryptography, first of all, there's like a, an efficiency problem, but also when you're working with cryptography The main reason you assume that it's not broken is that it's been around for a bit and nobody has broken it yet. So there is value into taking the time, reading the publication, giving it some time to mature, let a lot of smart people look at it and try to break it, and then choose What kind of cryptographic schemes are the right ones for Bitcoin and then move forward?"
    },
    {
      "speaker": "stephan",
      "time": "24:04",
      "start": 1443.79,
      "text": "Yeah, and this is worth understanding, like even, I recall even in the Bitcoin world, things like, MuSig one was insecure versus certain kinds of attacks, and then they came out with MuSig D and MuSig two, which was, you know, which is secure against those things. So even in the Bitcoin world, this, this kind of thing can happen, and so, let's talk a little bit about some of the mitigations. I know you spell some of these out, Time to explain that Taproot thing with, you know, the-- so in Taproot we have the key path spend and then the script path spend. So could you just explain a bit about that and the relevance here in the quantum context?"
    },
    {
      "speaker": "anthony_milton",
      "time": "24:37",
      "start": 1477.12,
      "text": "Sure. So, as we said earlier, we were in general talking about- public, public keys that are exposed. And then when we're talking about Taproot, Taproot you can spend in two ways. There's the key path where it's just As any other address, you sign using your private key, you spend, you move on. The script path, there you, you can put scripts. It's come, it comes from the name, and then you can put other conditions there for the spend to go. So I think if we'll go deeper into what do we do in the day if a quantum computer appears, it might be that we want to disable The key path and only allow the script path, while in the script path we have something that is quantum secure, and I think it's, it might be Might, it might make more sense if we talk about the general ways forward. The"
    },
    {
      "speaker": "stephan",
      "time": "25:48",
      "start": 1547.64,
      "text": "schemes, yeah."
    },
    {
      "speaker": "anthony_milton",
      "time": "25:49",
      "start": 1548.74,
      "text": "Yeah. So there are, a bunch of schemes or discussions happening, and they differ on a few levels. But maybe one deep question is, let's say we chose a quantum secure signature scheme, what do we do with addresses that didn't move? Like we have it, it's merged, it's available for ten years, and then we have a quantum computer. What happens to the old coins? What happens to Coins that didn't move to this s-secure script and so on. So with Taproot, you can just like hide in the script path something that is quantum secure and keep using it as usual But maybe it's a good opportunity to dive into what do we want to do with people that didn't do that, with Satoshi's coins and so on."
    },
    {
      "speaker": "stephan",
      "time": "26:50",
      "start": 1610.26,
      "text": "Yeah, right, because I can imagine this will be a big debate also. I've seen, already some different arguments made on either side. I think Lo- James and LoP has put out an argument on more on the, burning the coin side of it. There's, there are others who are in more in the, you know, do nothing and let the chips fall where they may. So maybe, maybe you wanna talk a little bit to that, and then we can sort of go into more specific, like, what are some of the mitigations?"
    },
    {
      "speaker": "anthony_milton",
      "time": "27:14",
      "start": 1634.5,
      "text": "So, yeah,"
    },
    {
      "speaker": "anthony_milton",
      "time": "27:20",
      "start": 1640.22,
      "text": "addresses that could be stolen from, and maybe it's good for people to be informed where the chips might fall, if we let them."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "27:32",
      "start": 1651.73,
      "text": "Okay, well, yeah, we call it the burn versus deal dilemma, I suppose. It's, it's, I guess it's probably gonna be the most difficult thing to resolve from all of this. I think there's gonna be the technical proposals, and there'll be a lot of back and forth, and we'll arrive at something eventually. I, I don't know about this burn and steal, it seems like it's gonna be a divisive issue. You have, I guess concerns about property rights and confiscation and the like, and, people falling into different camps. and, you know, one, one side thinks that, well, it, it incentivizes people to, the, the first to develop a- Quantum computer that can, scoop up these funds. There's a bounty there, great, so they, they can collect that bounty and put those coins back into circulation. However, that could be disastrous for the, you know, the, the market that we have now in Bitcoin. There's so much financ-financialization, there's so, so much,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "28:32",
      "start": 1712.13,
      "text": "Risk-averse entities, I suppose, and that would just be a massive problem for them. you know, Lo-Lo-Fi thinks it quite well in the sense that this could be like a, seen as a protocol bug. So, this is something that we just need to sort of like, \"Where? Alright, these, these funds are gone. Let, let's just count them as gone, and move on.\" And how, how we do that, I guess, yeah, that's, how, how we determine what funds are gone, that's, So a challenging question, would we say that like pay to pub key, pay to multisig or certain whole whole script types wholesale, just we have to carve out? Or do we have to give people like a deadline to say, \"Hey, if you haven't migrated by a particular point, your funds are gonna be locked and, and done? \" But the, at the moment the, the r- the risk is for, I guess for the, that six and a half million Bitcoin, like the risk overwhelmingly lies with, custodians and exchanges who, who do things like address reuse. So some of these people are the ones that are saying, \"Hey, law of the jungle, let's go.\" yet they're probably some of the most exposed at the moment. So it seems strange that they've, I mean, it is easy to remove the risk of, address reuse. You literally just need to transact to a script type where there's no public key exposed, and you're done. you know, there's operational reasons perhaps for some of these exchanges and these custodians to, to be reusing. but like, yeah, it makes you wonder what's, what the motivation is. So I've, I've touched on a few, few different areas there, but we can dive into any of the details in a little bit."
    },
    {
      "speaker": "stephan",
      "time": "30:18",
      "start": 1818.49,
      "text": "Yeah, sure. I guess maybe I'm, I'm just thinking out loud, it could be that those exchanges are just confident that, all right Once we've decided the new quantum scheme, we'll just rotate all our stuff over into the new quantum scheme, and for now, we just wanna keep doing address reuse from their perspective because it's easier or it's less technical, you know, things, technical hassle to deal with, because, you know, if I give a customer an address to deposit into, I have to keep watching that address, and it's, now if I start doing like tons of addresses, it's, you know, becomes, you know, very, computationally or operationally difficult. Maybe that's"
    },
    {
      "speaker": "anthony_milton",
      "time": "30:57",
      "start": 1857.36,
      "text": "Firstly, there are modern solutions that make the management of these things easy. It's cheaper on chain, so there's really no there's no financial reason not to do that, besides, well, laziness, I guess, or lack of resources. I mean, I, I agree, of"
    },
    {
      "speaker": "stephan",
      "time": "31:19",
      "start": 1878.57,
      "text": "course, but I just remember, I remember when SegWit came out, there was like, people were campaigning at exchanges, and famously, Blockchain Dot Info were so late, I think they were like four or five years late, people were like, \"When SegWit? When SegWit?\" And, you know, it's like a new address type, and we wanna use it, and it But, they were still kind of slow on it. So I don't know, may-- but maybe it's different now, twenty twenty-five, and let's say another five years down the line, it's more advanced and people are gonna use the newest, latest stuff. I don't know. Go on."
    },
    {
      "speaker": "anthony_milton",
      "time": "31:53",
      "start": 1913.28,
      "text": "Oh, sorry, I just wanted a bit, to add a bit to the burn versus steal. So something that Changed my mind a bit. So, so there's, there's like the rule of the jungle, people, there, the whole burn, then there's suggestions like the hourglass where in each block will allow a single transaction that is from, old addresses. That we can suspect that where it's spent as like a natural rate"
    },
    {
      "speaker": "stephan",
      "time": "32:21",
      "start": 1941.4,
      "text": "limiting factor."
    },
    {
      "speaker": "anthony_milton",
      "time": "32:22",
      "start": 1942.46,
      "text": "Yeah, rate limiting. And I, in the beginning, I thought it's a good idea, but then recently I changed my mind just at looking at the numbers So if we introduce back into the system every ten minutes a hundred Bitcoin, that's sort of-- well, that sounds a bit like inflation, right? suddenly there are a hundred-- Because people would have this"
    },
    {
      "speaker": "stephan",
      "time": "32:50",
      "start": 1969.76,
      "text": "feeling of they're cycling in back old Satoshi coins or whatever."
    },
    {
      "speaker": "anthony_milton",
      "time": "32:54",
      "start": 1973.62,
      "text": "Yeah, and, and I'm assuming that whoever is doing it isn't doing it to hold it. They'll, they'll just- Bring them back into the system, sell them immediately. It's, they're not the rightful owners, they don't have the private key, they just- Yeah. But I mean, I guess it,"
    },
    {
      "speaker": "stephan",
      "time": "33:11",
      "start": 1991.41,
      "text": "it also kind of depends on your view and when this happens, right? Imagine this happens in- Fifteen or twenty years, and the world is sort of very close to hyperbitcoinization, then at that point, what are they gonna sell the coins for? Right? Are they gonna just hold, hold them because we're, you know, we're living in the Bitcoin standard? So I guess the risk is, are they gonna dump 'em all in one big thing and crash the market or whatever? I don't know. I mean, who knows? There's, there's too many moving parts to really predict, right?"
    },
    {
      "speaker": "anthony_milton",
      "time": "33:36",
      "start": 2016.33,
      "text": "Yeah. No, it's very difficult, but I'm assuming that if"
    },
    {
      "speaker": "anthony_milton",
      "time": "33:46",
      "start": 2025.55,
      "text": "Going to sell your Bitcoin right, because by then the price is crushed. Yeah, yeah. If you don't know,"
    },
    {
      "speaker": "stephan",
      "time": "33:51",
      "start": 2030.76,
      "text": "yeah. And whoever crashes, gets, they get to become the new emperor of the world and have like, I don't know, three million coins or whatever. I mean, who knows? one other thing, actually, I, I just remembered we wanna, I did wanna ask this question, just you can explain for listeners. Long range attacks versus short range attacks. Can you explain that in the quantum context? What are they?"
    },
    {
      "speaker": "anthony_milton",
      "time": "34:11",
      "start": 2051.19,
      "text": "Of course. So we were talking about"
    },
    {
      "speaker": "anthony_milton",
      "time": "34:16",
      "start": 2055.59,
      "text": "is exposed, you are open to a short range attack. This means that if somebody has, strong enough quantum computer, they can look at your public key Get the private key and sign in your name and steal your funds. And this is something they can do, let's say, within hours or days, given a strong enough computer. And this is a long range att- sorry, a short range attack. The long range."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "34:48",
      "start": 2087.73,
      "text": "Lot, lot, it's a bit inverted. Long range is when the, like for example, the public key is on chain and you, you can see it for long, long periods of time. It's that long exposure, right? So"
    },
    {
      "speaker": "stephan",
      "time": "34:58",
      "start": 2098.22,
      "text": "yeah,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "34:58",
      "start": 2098.44,
      "text": "yeah, long range is long exposure, public keys on chain, for example. Short range is like, okay, it needs to be exploited, either between like when a transaction's broadcast and then confirmed, or even shortly after it's been confirmed if like the attacker has access to the key. High amount of mining power, yeah, short re-egs or something, right?"
    },
    {
      "speaker": "stephan",
      "time": "35:20",
      "start": 2119.74,
      "text": "So,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "35:21",
      "start": 2120.7,
      "text": "short ranges, yeah, like the narrow window, and long ranges like all those reuse addresses, all those like pay to taproot, pay to pub key, pay to multisig stuff. Gotcha. Okay, so summarizing then,"
    },
    {
      "speaker": "stephan",
      "time": "35:32",
      "start": 2131.74,
      "text": "the long range attacks are the ones that are, you know, these coins are already vulnerable, right? As in the public key has already been exposed, it's in a vulnerable script type, or there's address reuse, and the quantum attacker, hypothetically, can just And he could be grinding it out for the next six months or one year if he's hypothetically got the quantum machine that can do it now and broadcast those, those transactions to, let's say, steal the coins into his own quantum-resistant, you know, whatever setup, but- The short range attack is more like, imagine you have not doxxed your public key and you just go to broadcast your transaction, just like you would a normal transaction, and at that moment, before, you know, that transaction gets confirmed into a block, the quantum attacker at that time, he sees your public key, he goes, \"Ah, hey, that's Anthony's public key for his coins,\" and my computer, my quantum computer is so powerful that I can quickly compute and back out his private key and then send a new- transaction with a higher fee to myself, and do that in the space of ten minutes or a few hours if that's the timing that, you know, your transaction was broadcast. In this example Yeah, that's right."
    },
    {
      "speaker": "anthony_milton",
      "time": "36:45",
      "start": 2205.12,
      "text": "Yeah, I think that names that are less confusing are immediately vulnerable and upon spend."
    },
    {
      "speaker": "stephan",
      "time": "36:53",
      "start": 2212.6,
      "text": "Gotcha. Yeah, yeah."
    },
    {
      "speaker": "anthony_milton",
      "time": "36:53",
      "start": 2213.42,
      "text": "Immediately vulnerable are the ones that we already see the public keys and we can immediately attack given a quantum computer, and then upon spend is something that becomes vulnerable, right?"
    },
    {
      "speaker": "stephan",
      "time": "37:05",
      "start": 2224.59,
      "text": "This episode is brought to you by CoinKite, the makers of my favorite Bitcoin hardware wallet, the Coldcard Q. Now, some people think self-custody is too hard, but it's really about taking responsibility for your Bitcoin wealth and understanding that self-custody gives you a true feeling of liberty. The Coldcard Q has a full keyboard and big screen, it's got two secure elements and a true air gap, allowing you to go fully air-gapped using QR codes from seed generation to transaction signing. You can power the device using three triple-A batteries, so you don't even have to plug"
    },
    {
      "speaker": "stephan",
      "time": "37:34",
      "start": 2254.35,
      "text": "For PC or Nunchok on mobile, and you can dial it into the right level of security and complexity that you choose. If you want a simple setup, just use twelve words and single signature. If you want passphrases, easy. If you want to add multisig or co-signing features, you've got those too. So go to coinkite dot com, use code livera to get ten percent off on your coldcard or other devices and level up your self-custody today. This episode is brought to you by Galloy, builders of banking software for the Bitcoin age. After years of risk and uncertainty, Bitcoin and banking are colliding. The regulatory environment is rapidly shifting in favor of Bitcoin and digital assets. Fintechs and crypto-native companies can become chartered banks, and traditional banks and credit unions will launch Bitcoin products. But the legacy core banking software that many financial institutions run on wasn't built for Bitcoin. The Galloy banking infrastructure stack delivers all the key elements of a modern core banking platform. With cloud native infrastructure, event based architecture, and robust APIs coming together to meet the security, scalability, and reliability needs of banks of the future. Whether you are launching a modern financial institution from the ground up, or you are adding Bitcoin backed lending or payments to your product offering, talk to the team at Galloy, visit galloy dot io, or reach out to the team at b i z at g a l o y dot io. When you spend it. Because as, as we said, in order to spend your coins, you are broadcasting to the, to the block Blockchain or into the mempool and it, which goes into the blockchain, your public key and the signature and the, you know, the whatever satisfying signatures you need to sign and conditions to move those coins or spend those coins. and I guess crucially, that it's probably fair to point out here that there's a difference in the, let's say, the power of the quantum machine that would be required for those, right? Because if you're putting a requirement that this quantum attacker needs to do it in the next ten minutes or few hours versus this quantum attacker has six months Wants to sort of try to back out a private key, maybe he would go for like these addresses or keys that control a large amount of coins and do that on a six-month basis versus like this sort of immediate sort of ten minutes to a few hours timeframe, right?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "39:42",
      "start": 2382.44,
      "text": "Yep."
    },
    {
      "speaker": "anthony_milton",
      "time": "39:43",
      "start": 2383.36,
      "text": "You can also think about a quantum attacker that is either a miner or, or associated with a miner, and then they can try and, like, they see a really juicy transaction appearing on chain, revealing its public key, and then they can be like, \"Coinbase just moved their cold storage, let me,"
    },
    {
      "speaker": "stephan",
      "time": "40:01",
      "start": 2401.29,
      "text": "let me go to work,\" or \"Binance just moved their cold storage, let me put my quantum machine on the task.\" This kind of thing."
    },
    {
      "speaker": "anthony_milton",
      "time": "40:07",
      "start": 2406.95,
      "text": "Yeah, and, and let's, and let's reorganize the chain Let, let me be the owner of this. Let's go back and--"
    },
    {
      "speaker": "stephan",
      "time": "40:14",
      "start": 2413.76,
      "text": "Yeah, and of course, there would be all the normal questions about like, you know, are they kind of the social trust if we start seeing like these massive reorgs or these, you know, if we were to start seeing like huge trans-- Every time a big transaction happens, like some, you know, there's like a huge reorg attempt on that particular transaction or that particular block, then people would start to question, you know, the credibility of the overall system. And so that's kind of another whole, And argument people will have too. I guess if the quantum attacker is maybe really sneaky about it, he might do smaller amounts and like only do small bits to try to stay under the radar and not get detected. but I, I don't know, maybe it's like a weird game theory thing, and I don't know, we don't gonna go into, you know, hours of discussion about that. honestly, if I would have a"
    },
    {
      "speaker": "anthony_milton",
      "time": "41:02",
      "start": 2461.55,
      "text": "quantum computer Like capable of these kinds of things, I would probably not go for Bitcoin first. I would go to things that keep breaking, like, you know, bridges There's all sorts of, yeah. So I would just go like, \"Oh no, this broke.\" Another"
    },
    {
      "speaker": "stephan",
      "time": "41:20",
      "start": 2480.45,
      "text": "bridge hack, 'cause that happens all the time anyway, right?"
    },
    {
      "speaker": "anthony_milton",
      "time": "41:23",
      "start": 2483.45,
      "text": "Yeah. So maybe there'd be like a"
    },
    {
      "speaker": "stephan",
      "time": "41:25",
      "start": 2484.75,
      "text": "plausible deniability there that was it a quantum thing or just like a smart contract failure somewhere, I don't know. okay. although maybe people could sort of back it out based on, you know, what happened. But anyway, let's go to the mitigations part. As I understand in your paper as well, you spell some of these out. It looks like, the CDR scheme, this commit, delay reveal scheme and Q-RAMP are some of the main ones. Can you explain some of those? Or maybe we'll take it one at a time. So what's the CDR scheme?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "41:57",
      "start": 2516.78,
      "text": "Alright, so there's a few different variants of it, but I guess the one way to describe kind of all this, the variants, is that you hide your, your current public key, your like, elliptic curve public key, behind some commitment. so you, you do like, you do, do something, you hash it, you put it on chain, like in a not return or something, and then there's like a soft fork that happens, and that soft fork introduces rules that says, okay, you can only now use, you can only transact with, By revealing a commitment and showing that you had created this commitment in the first place. so like it's basically a way to prove that you, you, you knew the pr-private key at the commit time, so you do something well ahead of time, and then later down the track you say, \"Haha, I, I did this, long ago, so that...\" Ensures that I was the rightful owner back then. there's, yeah, there's a lot of different variants of it, but that's kinda like the simplest way I've thought about describing it, hopefully. Yeah, yeah, no, I think, I think it"
    },
    {
      "speaker": "stephan",
      "time": "43:00",
      "start": 2579.96,
      "text": "makes sense. And then, what's the Q-Ramp? What's a quantum resistant address migration protocol?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "43:08",
      "start": 2588.44,
      "text": "Yeah, that's, probably one of the more severe, proposals in the sense that, it's basically saying after this date, these, transaction types are no longer, permissible, like valid or whatever,"
    },
    {
      "speaker": "stephan",
      "time": "43:21",
      "start": 2601.11,
      "text": "yeah?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "43:21",
      "start": 2601.45,
      "text": "So, yep. So it's basically like severe locking of the rules. So, for example, any elliptic curve protected, or, UTXOs, you can no longer spend them. So, it assumes that there's been- like a tra-transition to some sort of post quantum signature scheme, and then after that flag day, if you haven't migrated, too bad, you can't, you can't transact. So in some ways, this is like a realization of that whole burn the coins."
    },
    {
      "speaker": "stephan",
      "time": "43:51",
      "start": 2630.94,
      "text": "Oh, gotcha. So maybe it's kind of like for technical reasons. It would, it might be cleaner hypothetically to do the burn style, because then we know for sure all the coins that exist going forward were quantum protected by their rightful owner and aren't Being stolen, yeah, in the, you know, the rule of the law of the jungle kind of context. Yeah."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "44:11",
      "start": 2651.23,
      "text": "So QRL doesn't really say like h-how to,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "44:16",
      "start": 2656.35,
      "text": "achieve that like po-post, post quantum signature scheme, it just says like, assume that we've got one in place, we're just gonna say, like, after this day, no, no more, you can't use. It's kind of like a flag"
    },
    {
      "speaker": "stephan",
      "time": "44:25",
      "start": 2665.34,
      "text": "day, from now on, only quantum safe signatures are allowed or transaction types are allowed, so super"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "44:31",
      "start": 2670.94,
      "text": "unambiguous, like, it's very clear as"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "44:37",
      "start": 2676.67,
      "text": "That's the controversy of the burn vest still approach, like it's constant. Interesting. Yeah, but now that you mentioned that, it kinda"
    },
    {
      "speaker": "stephan",
      "time": "44:42",
      "start": 2681.5,
      "text": "does kinda make a bit more sense on the burning side because it would have the benefit of i-increasing or improving the credibility of Bitcoin as a system, because it would be like the community and the developers and everyone can credibly say, \"No, only the people who rightfully held the coins are the ones spending these coins. It's not kind of like a rampant theft kind of thing.\" yep. One other concept that might be interesting to talk about related to this mitigation is If it's known in advance, and there are ways that, as an example, let's say your wallet type, your software wallet type, can be created in a way where we have the normal spend type, but there's also this quantum resistant type, and then the idea is everyone just starts migrating to these wallets that are, let's say, quantum aware or quantum resistant, and then hopefully if that's done in advance, so let's say five, ten years in advance of the kind of the Q day or the big, you know, the day that the quantum computer is can hack our bitcoins, then, then it's kind of a more gradual transition and it's sort of a bit more graceful because now all these people would already be quantum safe, providing that, like at that point, okay, the quantum day has happened and now we have to do this soft fork to disable the old- Script types or the old transaction types and say now, from now on, only quantum, secure transaction types are allowed."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "46:09",
      "start": 2769.24,
      "text": "That's probably the ideal situation, like that's kind of what I think we would all hope for. So, Everything, tech-technically everything's in place. People start to do their, as they're transacting in their everyday business, they start to adopt these, transaction types, these new signature schemes. And so naturally, by virtue of just, you know, having to transact, people, people move into these protected schemes. I mean, it supposes that you've got a scheme in place in the first place, so that's kind of like a big technical blocker or consensus blocker, I suppose, and then you still have questions about What about the stuff that hasn't tran-transferred by the time Q-day comes? What are we gonna do with that? That's so-- I think that we want that to happen, but there's still un-un-un-solved Questions that we need to sort of like dig into as a community, yeah. like, but what you've, what you've outlined is, I think, what we probably all hope for, the way it would, the way the transition happens anyway."
    },
    {
      "speaker": "stephan",
      "time": "47:10",
      "start": 2829.65,
      "text": "Gotcha, because that's at least the least disruptive, hopefully, right? We want this to be as, you know, the lowest disruption possible, And now probably also good to talk about selecting new quantum-resistant hash algorithms. As I understand, the trade-offs here are gonna be things like it might be larger-sized transactions, it may be more compute required, so there may be debates there on, okay, are you reducing the transaction capability now of Bitcoin? And, you know, are there gonna be arguments there about like, should you have like- A new quantum type, but also raise the block size to compensate, or just nah, deal with it and just, you know, deal-- like have less transaction capability, per block, let's say?"
    },
    {
      "speaker": "anthony_milton",
      "time": "47:54",
      "start": 2873.65,
      "text": "I think it's very early to talk about this because this is such a growing field. But at some point, as we get closer and as the research feels more mature, we will have to choose some kind of a signature type Signature scheme and it might be larger, might be less efficient, and then there are, you know, there are witness discounts, there are all sorts of structures, but right now the quantum secure signature schemes don't offer the full functionality that we see from classical ones. So this is one reason to wait. But then if indeed the transactions would be Larger than we can definitely consider a witness disc like a quantum discount the way we had witness discount. This is, we've, we've done it once, yeah, and I don't think it's going to be a big deal."
    },
    {
      "speaker": "stephan",
      "time": "48:55",
      "start": 2934.97,
      "text": "Yeah, and I guess hypothetically by then, the blocks, maybe our internet capacity and our computing and our hard drive costs are lower in five, ten years' time or fifteen years' time, whatever. Sorry, go on, Anthony."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "49:05",
      "start": 2945.29,
      "text": "Yeah, the history of the, like, developments of these post quantum schemes is that, like, like starting in the '70s, there was, like Lamport schemes, and they were, like, huge. You had huge signatures, huge, pub key sizes, so, they're like pretty much you can't really use them because there's other reasons as well, but they were just both signature and public key were massive. And then as you progress, you get like variants of that, like the Merkle, the Merkle, schemes, So the public keys are like equivalent to what we've got, which like Schnorr and EdDSA, but the signatures were like still massive. And then you had-- And there's a whole like called hash-based, post-quantum, cryptography schemes. Then you've got some newer ones like the lattice schemes and the isogeny schemes. Again, there's improvements in the sizes, so they're not so large in terms of public keys and signatures, but like For, for example, I think the Isogeny ones, they are like, the time to verify or time to sign is like off the charts. It's like a hundred, yeah, looking at your"
    },
    {
      "speaker": "stephan",
      "time": "50:11",
      "start": 3010.77,
      "text": "chart, it's a hundred and thirty-five thousand times. for visual listeners, we'll put that, table on the screen, but, yeah, do, do you have any views on, you know, are there, is there any kind of a consensus or view about which of these, potential- You know, schemes will be good, yeah. Like efficiency,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "50:33",
      "start": 3032.64,
      "text": "like you, we're gonna get better schemes as we go. Like, NIST is the, I guess, the government agency that is being- responsible for managing, I guess, or trying to establish the, the standards for post-quantum cryptography, doing, doing it over the last decade or so, and they've got this, this long-running like standardization process, and they've gone through multiple rounds of, like, looking at, proposals and seeing if they like survive the test and going through the next round and just like the, like a global community is evaluating, testing, kicking the tires, making sure these things are tight. And, you know, a few years ago, one of the Like highly favored schemes was broken in a weekend, by some cryptographers, like on, on a just like a desktop computer in a few hours, and that was like one of the, the favored, favored schemes, right? So there's inherent, challenges with, I guess, developing this tech, and the, the longer something's been around, like the more confidence we've got in it. So people do have a lot of confidence in the hash-based approaches, because they've been around for so long, so many eyes. So much opportunity to, to break them, and they're seen as secure, but they do have the downsides of like the large signature sizes and the like, which, has led to some people, like Ethan, proposing like use of Starks to sort of have this like- Compression of, of the data in trans-transaction data, so instead of having like a, a few hundred potential, like quantum transactions, you could have Almost, you could have like a effective tr-uh, transaction or throughput of Bitcoin which is like an order of magnitude larger than we've got, larger than we've got now, right? So people talk about Bitcoin's like seven transactions a second at the moment, something like that, with some of these like newer cryptographic approaches com-combining it, well, I mean, the motivation is maybe post-crypt- post, quantum crypto, you can pro- maybe get like a in-increase in throughput to like seventy, eighty transactions a second Just by compressing the, the transaction data using these, these new techniques. Obviously, like a lot of this stuff is still new, it could be broken. like the, the Ethereum, you know, I hate to say it, but like Ethereum's doing some great research in this area. so watch this space, a lot of people are working in it, it's just gonna get better and better over time. But, you know, in the Bitcoin community, we need, we need to start the conversation now. We need to start now, that's what we're doing. Let's, let's get working on this, get, let's get cracking so that when the time come around Everything will go smoothly."
    },
    {
      "speaker": "stephan",
      "time": "53:13",
      "start": 3193.0,
      "text": "Yeah. Now, I have seen, also speaking of Bitcoin implications kind of to our industry, our ecosystem, I have seen some discussion from developers talking about Hang on, in the quantum world, post-quantum day or whatever, there may be certain Bitcoin techniques that aren't no longer secure. So examples I've seen, people have said submarine swaps, the thing that makes them atomic from like off-chain to on-chain swaps, that may go, like, we may lose that if we, or I've heard another one around, silent payments, that may not, that may go, or some of these other crypto tricks that we're using now, they may also become insecure or not usable. do you have any, I don't know, have you done any exploration on those kinds of things?"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "54:00",
      "start": 3240.41,
      "text": "Not at this point,"
    },
    {
      "speaker": "stephan",
      "time": "54:03",
      "start": 3242.75,
      "text": "yeah, it was- Yeah. Okay. Something I've, I've sort of seen some discussion about it. I'm not 100% sure, to be clear."
    },
    {
      "speaker": "anthony_milton",
      "time": "54:08",
      "start": 3247.87,
      "text": "Yeah, but, but I, I will say that I'll be surprised if you can't do something similar to silent payments or submarine swaps using new, given, quantum scheme that it can't be translated from one to the other. So take it with a grain of salt, but I'm pretty sure- Yeah. Sure. This, yeah, but maybe different, just like the usability"
    },
    {
      "speaker": "stephan",
      "time": "54:32",
      "start": 3272.05,
      "text": "aspect of it, right? Like as an example, if silent payment still works, but in the quantum resistant version, it's like way less easy to scan and therefore, you know, not as practical for the user, that kind of thing. So that might be, maybe that's where they were getting at. I'm not 100% sure. I, I've just, you know, when I'm watching different discussion, I sort of see some chatter here and there and, yeah, but things to think about as well,"
    },
    {
      "speaker": "stephan",
      "time": "54:59",
      "start": 3298.64,
      "text": "P-TLCS instead of H-TLCS in Lightning, maybe that changes, I don't know."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "55:03",
      "start": 3303.19,
      "text": "that's, that's based on like Taproot and stuff. Look, there's gonna be heaps of change necessary because- The fundamentally the crypto is gonna operate in different ways, like we got some, we've shown or we got some like wicked capabilities with like aggregate key aggregation and the like, which, remains to be seen that we're gonna get that with the, the post-quantum schemes. So Yeah, like it's, it's, it's gonna take time before we maybe get to parity with what we've got, potentially. Like, I don't think there's-- We're kind of being blessed in some ways with, like,"
    },
    {
      "speaker": "stephan",
      "time": "55:38",
      "start": 3337.66,
      "text": "the capabilities we have, the capabilities we have. Yeah. Yeah, that's right. I'm curious, I don't know if you know, but does this also impact schemes like Shamir's secret sharing? Like, I know, for example, the Trezor guys like that for their backups, right? They, they like that. Would that, Screw that, I don't know."
    },
    {
      "speaker": "stephan",
      "time": "55:58",
      "start": 3358.13,
      "text": "Okay. Okay, yeah, fair enough. Okay, so, alright, now, I've also seen in your report you talk about a dual-track approach as a strategy for action. So can you guys explain a bit of this, just to, so we can understand the dual-track approach?"
    },
    {
      "speaker": "anthony_milton",
      "time": "56:17",
      "start": 3377.01,
      "text": "Sure. So, so when we're thinking about the timeline, there are two timelines that we're keeping in mind. One is the very, taking things step by step Assuming that we still have a decade, and this is the assumption that a lot of large organizations are following, so we're doing our research, we're waiting for the cryptography to mature, we're doing very rigorous testing, we're moving things very slowly, and then we take about seven years to go from where we are now to quantum secure Bitcoin. And then the other timeline is we need to act now. So if tomorrow morning, for some reason, we believe that the quantum computer is around the corner, we need to choose a signature. There are a few options there for signature schemes. None of them are amazing, but we can work with them. So we do things in an accelerated phase. We, we choose something, we move forward, we start migrating UTXOs and so on, and then the whole process is something like two years. Where things become secure or unstealable much, much earlier. So these are the two timelines that we're keeping in mind when we're thinking about moving Bitcoin to a quantum secure space, and we can move from one to the other. We can start by, you know, carefully researching, going through the literature, and then when, if and when something in the world changes, we can switch from the-- This is going to take seven years First two were going to be done in two years."
    },
    {
      "speaker": "stephan",
      "time": "58:03",
      "start": 3482.72,
      "text": "Yeah, gotcha. And I guess, kind of to the disruptive point we were talking about before, if it is a very soon thing, then it's gonna be like a running for the lifeboat situation where, you know, people will be like, quickly trying to transition from the old schemes into the new schemes, and, you know, it's gonna be chaos in the memples and, you know, this kind of thing, whereas if it's like a long range- Transition like this wallet idea that automatically has both, that's gonna be a less disruptive approach, I guess."
    },
    {
      "speaker": "anthony_milton",
      "time": "58:29",
      "start": 3509.4,
      "text": "Yeah. And again, if you're super worried, I'm sorry, move your UTXOs to a hashed address. And then you can hang out for years and quantum-yeah, because now you're only vulnerable to"
    },
    {
      "speaker": "stephan",
      "time": "58:42",
      "start": 3521.83,
      "text": "short-range attacks, not long-range attacks."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "58:45",
      "start": 3524.59,
      "text": "Yeah, and short-range attacks will, You need a much more capable quantum computer to be able to exploit those, so it's gonna take a long time to crack keys initially with the first, quantum computers that are capable. And then, you know, ten years later or something, whatever, then short range attacks become viable. but like just back to the, the, the timeline, like the seven years we think is comparable to, like, the time it took to do SegWit and, and more recently Taproot. So, like, if you like, consider when they started, all the proposals that were put forward, and then when the bits were, like, created and then activated, like, they're around seven years. So, there's like parallels, we've got parallels with- Similar magnitude changes, I mean, probably post-quantum stuff's gonna be bigger, but, these are like numbers that we've kind of got some backing for."
    },
    {
      "speaker": "stephan",
      "time": "59:38",
      "start": 3577.9,
      "text": "Yeah, interesting. Yeah, and, I mean, the thing is, you know, there'll be OG hodlers who don't move their coins around that often, you know? And so, and it'll be kind of a commu- kind of first, assuming the community and the developers kind of decide this is the path forward, then there's kind of the communication and kind of getting the software built for it, and I mean, it's gonna, you know, all of these things will take time and, you know, efforts to kind of get everybody upgraded, and so, yeah, and, and there may even be disagreements in the community about like what's the right path forward, or there may be some who think, \"No, I don't believe there is a quantum computer stealing coins or whatever.\" I mean, who knows? so, yeah, okay. So I guess just summarizing a few of the kind of-- We've, we've covered a lot of stuff this episode, so So short version of it is, people used to be more skeptical of this quantum computing stuff, but now more recently, it, it seems that people are seeing this as a more realistic risk on a, let's say, a ten-year basis, something like that. the latest numbers, as you've quoted to me, it's something like a third of the coins that are in existence today are vulnerable, that is because of either the script type being an old vulnerable script type or the address, sorry. The, the public key has been disclosed in a public way and therefore it's, vulnerable. And some of the mitigations are still being discussed, different quantum signature schemes, and the idea would be hopefully that we can have a, a graceful transition into a new system where maybe people are kind of transacting with a wallet that maybe speaks both, but eventually there might be a cutoff period where we cut off the old- way and only have the new way, but many of these things are, let's say, subject still to debate. So I guess that's kind of-- I'm kind of trying to loosely summarize the key points there. any closing thoughts, from you? And of course, we will put the links in the show notes, but where can people find you as well?"
    },
    {
      "speaker": "anthony_milton",
      "time": "01:01:46",
      "start": 3706.91,
      "text": "So thanks for having us. Yeah, I, I think this is a very important discussion to start right now. I know there are researchers working on this. If you're interested in the sub- Subject, feel free to reach out. you can find our reports, you can find us on Twitter, GitHub, the usual places. the report is also floating there or here in the, I guess we'll put the link."
    },
    {
      "speaker": "stephan",
      "time": "01:02:13",
      "start": 3733.15,
      "text": "Yeah, of course, yeah."
    },
    {
      "speaker": "anthony_milton",
      "time": "01:02:14",
      "start": 3734.7,
      "text": "Yeah. Yeah,"
    },
    {
      "speaker": "clara_shikhelman",
      "time": "01:02:15",
      "start": 3735.16,
      "text": "Anthony, Anthony, Anthony"
    },
    {
      "speaker": "anthony_milton",
      "time": "01:02:15",
      "start": 3735.82,
      "text": "Milton."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "01:02:17",
      "start": 3737.78,
      "text": "yeah, we've got our domain p2 dash bitcoin dot org, which is just like, got the report up there and we'll have some- More content looking into the, the, the data, like what is exposed, the his-history of exposure, who's exposed, so that'll be published in the next few weeks. But yeah, you can find me on Nosta or Twitter, or x, or Deadman or Deadmanos."
    },
    {
      "speaker": "stephan",
      "time": "01:02:45",
      "start": 3765.34,
      "text": "Fantastic."
    },
    {
      "speaker": "clara_shikhelman",
      "time": "01:02:46",
      "start": 3766.44,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "01:02:47",
      "start": 3767.28,
      "text": "Okay, well, Clara and Anthony, thank you for joining me and, doing your best to keep this accessible for, our everyday hodlers. it's definitely a very technical subject, and I appreciate the research you guys are doing to try to pull these pieces together and make it, I guess, understandable for us. So, thank you for that."
    },
    {
      "speaker": "anthony_milton",
      "time": "01:03:05",
      "start": 3785.6,
      "text": "You too, man. It's been a pleasure."
    },
    {
      "speaker": "stephan",
      "time": "01:03:07",
      "start": 3787.26,
      "text": "No worries, thanks."
    }
  ]
}
