{
  "episodeId": "SLP719",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "matt_corallo": {
      "name": "Matt Corallo",
      "role": "guest",
      "tag": "MATT"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:00",
      "start": 0.42,
      "text": "Improving the technology over time is still gonna take years and years and, and decade or, or two."
    },
    {
      "speaker": "matt_corallo",
      "time": "00:07",
      "start": 6.88,
      "text": "Hi everyone, welcome back to Stephan Livera podcast. Today, rejoining me on the show is Matt Corallo. Matt is, full time open source Bitcoin and Lightning over at Spiral, and for people who don't know, a long time Bitcoin developer, and, obviously has a lot of, you know, in, insight and input around, various things happening in the ecosystem. Today, I wanted to chat with Matt, kind of mainly about the quantum stuff Whatever else is relevant. So, you know, first off, welcome back to the show, Matt, and let's get your thoughts, do you-- what's your updated view on whether we see a so-called, cryptographically relevant quantum computer anytime soon?"
    },
    {
      "speaker": "stephan",
      "time": "00:44",
      "start": 43.51,
      "text": "Yeah, yeah, thanks for having me. yeah, I mean, I'm no, I'm no expert on quantum. Obviously, there's a lot of just engineering challenges they have, cooling, scaling these things up, you know, they need to be running at absolute zero. There's, building a, a large, a large enough refrigerator to, to fit a lot of qubits is kind of hard. We don't really have technologies for a lot of these things. They have a long ways to go. I think what- Some people are worried about, rightfully or wrongfully, that's actually driving some of the narrative is more fear that there's gonna be some kind of sudden breakthrough. So if you imagine a- you know, there's some lab that's using an LLM and the LLM gets some super creative idea, which, you know, I don't think it's, it's not gonna happen with today's LLMs, but, you know, maybe in, in a few years. And they come up with some massive breakthrough in refrigeration technology that we haven't figured out in the last two hundred years, or some massive material science breakthrough on, you know, room temperature superconductors or something, then that that might unlock quantum faster. And I think that's what some people are worried about. You know, with current LLMs, it's probably not a huge risk, but I, I think that's the bigger fear versus just the slow progress of improving the technology over time is still gonna take years and years and, and decade or, or two or whatever."
    },
    {
      "speaker": "matt_corallo",
      "time": "02:19",
      "start": 138.61,
      "text": "I see. And do you have any thoughts on the, I guess people talking about the different timelines, like as you were kind of touching on, maybe the fear is this sudden breakthrough, but a- outside of that? Do you have any thought on where-- what, what are some of the experts saying on this? Like, at least the experts I'm seeing are saying it's more-- they see it's more like, you know, like a, like a twenty-year thing?"
    },
    {
      "speaker": "stephan",
      "time": "02:43",
      "start": 163.17,
      "text": "Yeah, I think that lines up with what I've seen. Obviously, I'm no quantum material science physicist expert, but yeah, I, I think the, the experts that I've seen who aren't really just trying to pump a bag are talking about ten, fifteen, twenty, twenty-five years kind of timeline. That's not to say that we shouldn't worry about doing things to prepare for that in 10, 15, 20, 25 years, but it's still a long ways off."
    },
    {
      "speaker": "matt_corallo",
      "time": "03:14",
      "start": 193.94,
      "text": "Yeah. Now the other big, point of contention, let's say, is, and I know you've had some back and forth with Nick Carter on this, is this, this point of, are the Bitcoin developers taking quantum seriously? So what do you, what do you think about that?"
    },
    {
      "speaker": "stephan",
      "time": "03:30",
      "start": 209.62,
      "text": "Yeah, I mean, I think there's, it's definitely the case that historically, say, ten years ago, Bitcoin developers largely wrote off quantum. I think that lines up with, where the mainstream cryptographic community was at the time as well. I think, there are a lot of members of the Bitcoin community who aren't necessarily influential developers or aren't necessarily contributing actively to Bitcoin, have- Either concluded that quantum will never happen, which I, I don't think is very common among kind of influential Bitcoin developers, or Spend a lot of time, spend a lot of time talking about how far away it is because there's this, you know, conversations like, \"Oh, Bitcoin's terrible, we need to sell our Bitcoin because the quantum is gonna destroy it.\" And so people respond with, \"Guys, the like real experts are saying ten, fifteen, twenty, twenty-five years away, like you don't need to worry, whatever.\" And that, that then gets read as, \"Oh, these people think that we shouldn't do anything.\" We don't need to worry about this, or that they, that they think we don't need to worry about this, that we shouldn't do anything, and I don't think that's necessarily the right conclusion to draw from their words. It's just that they're also not talking about, well, here's what we're doing. And I think there is, it is true that people aren't talking necessarily about what work is being done, but there is work going on, right? So if you actually go look at- You know, I think that a comment that I made is, you know, if you wanna look at what, quote unquote, influential Bitcoin developers think or what, you know, is It, it, what the thinking is, go look at top organizations that fund Bitcoin developers, organizations like Prank, Chaincode, Blockstream Research, there's a few others, but, and then look at the organization as a whole, as a whole, and look at what different people within that organization is, are doing. And so if you look at Chaincode, well, Chaincode's, crypto folks, came out with, research paper talking about Bitcoin and quantum and The timelines for different things and different approaches and how it could be solved, et cetera. so clearly they're thinking about it and taking it seriously, at least approaching the problem as like, \"What shouldn't-- what are the constraints? What, what should we do? What can we do?\", et cetera. You look at Blockstream research, well, two of the cryptographers there have been working on Bitcoin post-quantum, cryptographic research, both, Tim Roughing and Jonas Nick, Bring a little less so, but Bring focuses more on day-to-day, maintenance of Bitcoin Core. So I don't think you can reasonably conclude that because the organizations that, you know, hire some of the top Bitcoin developers are working on this, clearly Bitcoin developers aren't working on this. I don't think that's a reasonable"
    },
    {
      "speaker": "matt_corallo",
      "time": "06:29",
      "start": 388.94,
      "text": "conclusion. Right, and, I know there was also the Presidio Bitcoin Quantum Summit, and that was, I think it was May of last year, around there. So, there was a lot of, you know, well-known Bitcoin, you know, developer, researcher types who were there, along with some quantum people. So, certainly, I think maybe the concern from the, let's say, the people who think quantum is coming really soon Maybe they see it like, \"Oh, that's not fast enough.\" Or, \"Oh, there's this concern of, oh, the Bitcoin community doesn't have a plan in place.\" but I think it's also maybe a bit tricky to have a plan in place because we're trying to-- and I think this is a point Peter Wuller made on, the, Bitcoin Optech podcast, which was, \"How do you bind a future community to this plan?\" Like, we could put a plan and say, \"This is what we think right now, as of February"
    },
    {
      "speaker": "stephan",
      "time": "07:26",
      "start": 445.92,
      "text": "Yeah, I think that's true. And, and I, it, it does get very complicated to talk about what should happen in a quantum, in a, you know, in, in some scenario where a quantum computer becomes a, a realistic threat to Bitcoin, because there's so much nuance to exactly what the scenario is, you know, Did we have years of slow technological progress and then we started to get to that point, which I think is by far the most likely scenario to be, to be clear, but then also How many wallets have migrated to some kind of post quantum scheme? How long ago did they migrate? Was it in the last two years? Was it ten years before? You know, was it Right before, have they not migrated at all? Which types of wallets, what groups of Bitcoiners are there? I, it, it's so much depends on the exact scenario that happens that I don't think, not only can we not bind the community to some decision we make, the future community to some decision we make now, but it's kinda hard to predict exactly what they'll do because there are a lot of things that are gonna go into that decision that We can guess at, and I think we have some reasonable guesses, but it's not clear."
    },
    {
      "speaker": "matt_corallo",
      "time": "08:48",
      "start": 528.26,
      "text": "Yeah. So in the-- Now talking in the realm of what could we Bitcoiners do in terms of, okay, having a soft fork or multiple soft forks that- Do something about this. obviously the, a big one people are talking about is the Bit360 by Hunter, Beast, and, I think Ethan Harmon and, I think one other person, I forgot the name right now. and then The, I guess the general approach is like this idea of, okay, what if you had, a special output type that was quantum resistant and, you know, pick some flavor of post-quantum cryptography, and that might be that idea. Now, I know you've also put out an idea yourself. I don't know if there's a name for it, so, in my episode with Jonas Nick, we were kinda calling it the Matt Corallo plan, let's say, but do you have a name for the Matt Corallo quantum plan or what is it?"
    },
    {
      "speaker": "stephan",
      "time": "09:38",
      "start": 577.91,
      "text": "No, I, so I, I think it's, there's, hi, so to set the stage maybe a little bit, historically in Bitcoin, it's been the case that wallets adopt new technology at a glacial pace. In fact, in most cases, wallets simply don't adopt new technology, and the only way new technologies get adopted are when wallets kind of cease being popular, go out of business, stop being maintained, and new wallets get built instead. so talking about doing A new output type that is quantum resistant has massive ecosystem cost, right? As we've seen, adopting new output types, is new address formats, new output types is, is really, really glacially slow. Now, batch thirty-two M, the Taproot output type encoding, as well as batch thirty-two before it, are designed to be a little forward compatible, so you should be able to send to a new type of output even if you don't understand it today, but who knows whether all wallets actually do that? More importantly, I think any output type where spending it has a material cost, which all of the quan-- post-quantum schemes are much slower, generally much larger than existing signatures, than existing secp signatures, and so that's gonna be higher fees, right? If you're gonna-- if you want to use a wallet that transacts these things, you're gonna have higher fees, and really materially higher fees, not just, you know, ten percent higher or something, we're talking double Triple, quadruple the fees, and all of a sudden that's kind of material. And so these, I don't really buy that these wallets are going to-- that these schemes are gonna be adopted in any time horizon that makes it relevant, right? The only reason to add post-quantum signatures to Bitcoin today would be for very, very long-term wallets to adopt it, right? So we're talking cold storage wallets. People who might, just start to use Bitcoin and not think about it and then forget about it and come back to it five, ten, twenty years later."
    },
    {
      "speaker": "stephan",
      "time": "11:48",
      "start": 708.26,
      "text": "and any scheme that wallets aren't going to jump to adopt because it has four x, five x higher fees Just doesn't accomplish that goal. It doesn't really move the needle materially. Now that's something we're gonna need eventually, so it's like it's good that people are working on this, you know, when, you know, in, in ten, fifteen years, when a cryptographically relevant quantum computer is kind of more imminent, then, okay, yeah, we're gonna need a scheme like this. We're gonna need to start migrating everyone over to this, 'cause it doesn't even make sense to have sec p signatures for anything anymore, 'cause they're just not helpful, they're not secure So I'm happy people are working on it, but I don't think it's relevant today. Oh, what can we do today that moves the needle on getting wallets ready so that there's no questions, by the, so that the, basically so that the future Bitcoin community, when a cryptographically relevant quantum computer is an imminent threat? has more options, right? Our goal is to get wallets migrated so that that community has more options on what they can do to address the problem. And the only thing that I think makes sense today that really wallets might adopt is something that has no additional cost. And so Tim Roughing actually, did, a more formal paper analyzing Taproot output and says that concluded, look, if we have a Taproot output with a post quantum signature in one of the- Script leaves and the script path spends, the-- and there's a software to disable the key path spends, then that's quantum secure. So the quantum computer can't somehow unwrap the taproot into a different script path or something like that. It's, it's-- this was actually a design goal of taproot, this was a deliberate decision, but Tim Roughing wrote a more formal paper analyzing this concl- concluding that it was done correctly. So we could do that, right? We could say, \"Okay, we're gonna add a very expensive hash-based signature scheme in a taproot leaf,\" and as a result- the future community could decide to disable that key path spend, and now these wallets are fine. They're, they're upgraded, they're done, right? So they've, they've been hiding this thing in the taproot leaf this whole time. They never revealed it, they never used it. It had zero additional cost because they just used the key path spends today. And then at some point in the future, the Bitcoin community can say, \"Okay, now it's a risk, we're gonna disable that key path spend. Now you have to use this other thing, which is more expensive, you know, larger, whatever, but it's still fine. You, you still have your money. It's, it's no, no big deal.\""
    },
    {
      "speaker": "matt_corallo",
      "time": "14:33",
      "start": 872.96,
      "text": "Yeah. So let's just take a second, just make sure we haven't lost anyone. So when we go to spend in Bitcoin today, right, in, in the Taproot context, if you're using a P2 You know, it's like a smart, like public key and signature, and then you also have this opportu- this opportunity of using a script path. And then the way they're, they're sort of designing their, their protocols and things is that you wanna use that, in most cases you wanna use the key path, but you can put in a lot of other conditions and things into some kind of script path, spending path way. And what you're talking about is this idea of, hey, what if we just use the existing taproot but with special, like, quantum resistant script path? Spending pathways that aren't shown, until you actually need it, until you actually go to spend that pathway. Have I got you? Have I got that right?"
    },
    {
      "speaker": "stephan",
      "time": "15:30",
      "start": 930.36,
      "text": "Exactly, yeah. So it just, it's totally transparent. Wallets, do it, don't even think about it. You know, it's just a slightly different format for how they create the address. The address looks the same, functions the same, and then at some point, if they need it, then they can switch to using it, and until then, it's totally transparent, zero additional cost."
    },
    {
      "speaker": "matt_corallo",
      "time": "15:52",
      "start": 952.07,
      "text": "Okay. And so then, while wallets would obviously need to do an uplift on like- Building out that special script pathway that has like a quantum resistant cryptography built into it somehow, like Sphinx Plus or Shrink or whatever, whatever these different ones are. But the actual taproot output part of it doesn't have to change, and in terms of exchange support and like exchanges sending and receiving and things like that, that part is easy, and it's maybe a bit of a gradual transition because then people can just like keep using the same setup that they already have. without having to kind of go into an entirely new paradigm where if we're going to like fully quantum outputs, and maybe we eventually are gonna go there, I mean, who knows? but we're gonna need like special hardware wallets for that and special software for that, and like, it's, it's gonna be a different user flow, isn't it?"
    },
    {
      "speaker": "stephan",
      "time": "16:45",
      "start": 1005.2,
      "text": "Yeah, yeah, so it, it does keep things simpler. Now, it's, it's still not free, so you might, you know, a hardware wallet needs to be aware of how this new address type is derived, right? Because the hardware wallet has to be able to identify which address, you know, is that change output mine? Is this input address mine? So, there is still a non-trivial lift in across the Bitcoin community, but it's much simpler, especially for just a simple wallet, right? If you're just a normal wallet that's not doing hardware Hardware wallet support, not doing anything like that, you're just a wallet, is really easy, right? and so that at least enables some of the simpler cases to really start moving Okay,"
    },
    {
      "speaker": "matt_corallo",
      "time": "17:26",
      "start": 1046.21,
      "text": "so, I'm just trying to think this through. So, and then I guess the other thing is because these quantum-resistant or the quant- the post-quantum crypt-cryptography is generally much bigger You know, in terms of the size going on chain and things like this. But as I understand, you wouldn't have to show that until you're spending that particular,"
    },
    {
      "speaker": "matt_corallo",
      "time": "17:51",
      "start": 1070.63,
      "text": "pathway, right? You're spending that particular-- Like if you're just doing, you know, standard Taproot, you know, PubKey spend, you aren't having to pay that extra price right now. It's only in the future. Right. So it wouldn't even"
    },
    {
      "speaker": "stephan",
      "time": "18:02",
      "start": 1082.22,
      "text": "appear on chain. No one even knows that you're doing this. And I think that's one open question with this approach. Is, is it better that people know that you're doing this? so there's this whole debate around when or if, quantum computer becomes an imminent threat to Bitcoin, Should Bitcoin disable insecure spend paths, right? So, seize or, or burn money that doesn't have some quantum secure pathway to spending. and if you-- if people have no idea whether that's, whether wallets have upgraded by looking at the chain, they can't see whether wallets are, are post-quantum secure or anything, that limits the knowledge the Bitcoin community has at that point point to make that decision. and so there is a question of like, well, do you actually wanna tag it on chain? Do you wanna have like a different taproot version or something just so that, or, or require that the, you know, an extra bit in the public key be, be even or odd or something just so that people could statistically determine whether this upgrade path has, has completed? And so there's, there's some question there. I think that's, that's an open question that, that needs to be resolved. But in, in terms of this approach, I think it's Relatively straightforward in terms of like, yeah, we can just do this. It's not a lot of complexity. It's, we'll get some wallets off zero, we'll give people a path, and, you know, cleans things up so that if, if a problem becomes urgent, we have this as an option, and so it seems relatively straightforward that we should kinda just do this. But Timeline and, and, and focus."
    },
    {
      "speaker": "matt_corallo",
      "time": "19:55",
      "start": 1195.34,
      "text": "I see. So just help us compare the number of soft forks required, right? So in the, let's say in the bit three sixty style of like, you, you might, you'd need a soft fork to, to give you that new type of output, and maybe it depends on if they also include Like the specific type of post quantum cryptography, and then maybe there might even be another one to, like, if they, if they, if they're gonna do like hourglass or a burn, et cetera, in the, let's say, in your proposed idea of Using a taproot script path that is quantum resistant. I presume you don't need, we don't actually need a soft fork to even, to do the first part of that. It's just that you might, you wouldn't have a soft fork to, like, burn the key path. So, or to, sorry, to, let's say, disable the key path spend on Taproot."
    },
    {
      "speaker": "stephan",
      "time": "20:44",
      "start": 1243.79,
      "text": "Yeah. I mean, in theory, wallets could start doing this now. They could say, \"Okay, I'm gonna pick, I'm gonna go implement Shrieks, I'm gonna start embedding it as a leaf in the Taproot, script tree, I'm never gonna reveal it, so no one can ever use it, and it, it would be totally fine. This wouldn't break your wallet. Probably it makes sense to do a soft fork to actually provide consensus meaning to that, to, to go ahead and kind of enshrine that definition so we're not, so that wallets don't have this weird risk of like, \"Well, if this other part of your script tree leaks, then someone could steal your money.\" So probably good to just do that, but, but you're right, technically we don't need it. The, what we do need then is some soft fork in the future to disable the key path spends. And I think that is where you get into this question of Does the future Bitcoin community want to, burn insecure coins? Because if they do, we don't need a different script version, we don't need a different Taproot version, you just disable the key path spend and you're done. whereas if the Bitcoin community in the future says strongly, \"No, we don't wanna burn insecure coins,\" then there needs to be a way to more explicitly opt in, right? There would need to be a different Taproot version so that you can say, \"Hey, yes, I'm upgraded, please disable key path spend.\" When it's a concern. I think, i-i-in my view, the Bitcoin community is kind of almost without question going to burn inscrip coins. I'm curious why you say that, because it's kind of like- That's a very"
    },
    {
      "speaker": "matt_corallo",
      "time": "22:22",
      "start": 1342.32,
      "text": "different- But I mean, I, let's, let's talk about that, because if I kind of, you know, finger in the ear, just kind of read the, read the vibe. Now, look, maybe it's a loud minority, but, the sense I get is that actually most Bitcoin people- Pro seem to side more on the idea of like, oh, it's maybe in their mind, it's sort of, they don't wanna do like the ETH DAO thing where it's like, quote unquote, rolling back the chain, or they, they had some fancy word for it where they kinda did a, you know, a specific thing to that, to the ETH DAO, you know, hack. Yeah. and so there's a perception that- You know, if you're burning these quantum vulnerable coins, then that somehow is cutting against the property rights notion that we, that we treasure inside of Bitcoin. So that seems to be the main opposition. I, I, I'm sort of-- my gut feel is towards that direction also. So I'm curious where, where you're at on that. Why do you think most Bitcoiners are actually gonna be pro-burning?"
    },
    {
      "speaker": "stephan",
      "time": "23:19",
      "start": 1398.66,
      "text": "Yeah, look, the reality is, the winning-- like, there, there will be a fork, right? So, so in the face of some quantum, high quantum risk in the medium term, someone's gonna write the code to define a soft fork, right? So there, there will be two coins, right? And it's, at that point, as is always the case, it's up to the market. So the market is gonna look at those two coins, evaluate which they care more about, which they wanna hold, and which one they wanna sell. And I, I think as we have seen pretty robustly, the market has a very, very strong incentive to converge quickly to say, \"Oh no, there's only value if there's one Bitcoin,\" and so once the market starts moving, everyone's gonna, gonna jump on that, and there, there will be one Bitcoin. So the question is, which one is the market gonna value more? And it's true, you know, it, it's complicated 'cause it, 'cause it, it's, it gets into how many different scenarios there are, all of the different pieces that might go into a scenario, and all of the different facts of how much Bitcoin has been upgraded, how much Bitcoin is, is vulnerable, how much time actually is there? Do we discover this in advance or slowly? Or really rapidly, is there some rapid breakthrough? You know, all of these are going to obviously influence that decision, but I think first and foremost Law of s-supply and demand is, is pretty king. I think, in all likelihood, wallet, you know, we've seen wallets move slowly, adapt very, very slowly, and as a result, I think there, no matter when and how a quantum computer becomes a, a threat to Bitcoin, quote unquote the number of coins available for that quantum computer to steal will be huge, even if we roll out a soft fork today and progress is really slow and gradual and public, both of which I think are likely. And, and it takes 20 years before we get a quantum computer, which also seems very possible, very plausible. Even in that case, I think wallets aren't gonna start moving for 17 years, right? And so you're gonna see a lot of quantum vulnerable coins. The other consideration is that quantum isn't a risk for, depending on how the Bitcoin community approaches it, quantum isn't a risk for any wallet that uses a secret phrase. So if the Bitcoin community says, if, if the market around Bitcoin, not just the community, but the market around Bitcoin says, \"Look, there's, s- you know, ten, five, seven million Bitcoin that are gonna be stolen by this quantum computer, that are going to enter the market,\" and I don't just mean, you know, that's some portion of Bitcoin's total supply, I mean, those are coins that are going to be actively sold on the market, not coins that are lost, you know, coins that were lost that are now- On the sell side of the market, coins that were held by long-term holders who aren't willing to sell that are now on the sell side of the market, you know, that, that's a massive increase, even if it's only one million Bitcoin, it's not a five percent increase in supply, it's a ten, twenty, thirty, forty percent increase in supply active on the market. and so I think that's gonna be a huge pressure for the market to pick one side, and that's gonna be the, the burning and secure coin side. maybe I'm wrong. I think it kinda matters. It kinda"
    },
    {
      "speaker": "matt_corallo",
      "time": "27:01",
      "start": 1621.26,
      "text": "matters if the-- I mean, it'd be, like, so again, as you said, there's so many moving parts here, we can't exactly isolate everything, but it could also be that, I mean, imagine if it's twenty years in the future and Bitcoin is like, Just gonna huddle it, right? Maybe they would actually just wanna hold it and not sell it all. So, I don't know. Maybe,"
    },
    {
      "speaker": "stephan",
      "time": "27:19",
      "start": 1639.23,
      "text": "but the, the market has to evaluate that. And obviously, if a quantum computer has been built slowly over the last twenty, over twenty years, they have investors who want their many billions of dollars of investment back, and this is the only way they can get their investment back. there's not a lot of other interesting value for a quantum computer, so I think there's gonna be a lot of pressure to, to sell some of it. and to sell probably quite a bit of it at market as fast as they can. The market has to evaluate that risk in any case. Yeah."
    },
    {
      "speaker": "matt_corallo",
      "time": "27:54",
      "start": 1673.56,
      "text": "And I guess people on the- But I think the important part is- Yeah, go on."
    },
    {
      "speaker": "stephan",
      "time": "27:57",
      "start": 1677.05,
      "text": "The other important, important factor is if they decide this, so if the market says, \"No, we're gonna allow the quantum computer to steal all the coins and sell them.\" Then there's not a lot you can do, like you just have to have already upgraded to a quantum secure output type, which I don't think is even gonna be available for many, many years."
    },
    {
      "speaker": "stephan",
      "time": "28:21",
      "start": 1700.92,
      "text": "So I think that's gonna cause more chaos versus if the market says, \"Okay, no, we're gonna burn insecure coins that doesn't apply to wallets that have a seed phrase. So you can disable insecure spend paths and say, \"Okay, actually, what isn't insecure is the zero knowledge proof that you knew the seed phrase that derived this private key.\" So wallets go from a seed phrase, write this twelve or twenty-four words, then they use a hash scheme to go to a private key, which then they use to sign transactions, and the public key, using the, and the blockchain sees the public key which it used to verify the signature. The quantum computer can go from the public key, which is on the blockchain, to the private key, but it can't go from the private key to the seed phrase because it's a hash function and not standard EC math. So if we disable insecure spend paths, we can say, okay, actually, if you have a seed phrase, you can do a zero-knowledge proof that you know the seed phrase, and then that will count as a signature. So the actual number of coins that are burned, especially if we're talking ten, twenty years in the future Is basically only lost coins at that point, right? It's basically coins that haven't moved for ten or twenty years or are using the current Bitcoin Core wallet. That's about the only wallet out there at this point that doesn't use seed phrase derivation. And so hopefully, you know, we can do this kind of, a soft fork to enable op-shrinks and Taproot leaves, and then we can use, put that in the Bitcoin Core wallet, and then There's not really any wallets left. So at that point, it's true that all wallets today, you know, if we, we do this software, can we enable it for, for this long tail of kind of specialty wallets, Bitcoin Core, some of these large custodians, whatever, don't use seed phrases, and those wallets adopt this scheme, then it's basically the case that all wallets today already are quantum secure in a world where the future Bitcoin community disables insecure spend paths. Interesting. And especially if that's a long way off, that's a lot"
    },
    {
      "speaker": "matt_corallo",
      "time": "30:30",
      "start": 1829.64,
      "text": "more, lot more compelling. so I think that is, that's a good point actually. I hadn't considered that idea that, if we use that scheme when the, they've got the seed phrase, the, the ZK proof thing that then allows them to recover, it could be more plausible then to actually do the burn in that scenario because if, like, let's say right now the number The number of vulnerable coins is, I think people have thrown around numbers like five or six million BTC that are potentially vulnerable. But in, let's say we did this scheme and you had the ZK kind of, whatever, quantum recovery, wh-whatever that scheme is called, I'm not sure The actual number of coins that are, you know, vulnerable would, would drop dramatically, and then we're pretty much talking about like the Satoshi coins and like a few other bits and pieces."
    },
    {
      "speaker": "stephan",
      "time": "31:24",
      "start": 1883.98,
      "text": "Yeah, and, and really like specialty wallets, like large custodians maybe have more unique setups that might not use a seed phrase, but also Coinbase can, can adapt. Like, Coinbase will move quickly, but the large custodians"
    },
    {
      "speaker": "matt_corallo",
      "time": "31:35",
      "start": 1894.99,
      "text": "can pay professionals to do like fancy things, so they're, like, we don't have to really worry as much about them. Yeah. Yeah. So that's not as much of a concern, I guess. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. chain, like, would that be like a, a big process? Like, imagine that happens, is it gonna be like, you know, a few years' worth of transactions to get everyone over to the new scheme?"
    },
    {
      "speaker": "stephan",
      "time": "32:03",
      "start": 1922.72,
      "text": "Yeah, in the I mean, you know, obviously, in a case where we're talking about soft forking out insecure spend paths and we're, we're making these kinds of decisions, probably there's going to be a discussion around whether the block size should increase as a, as a consequence of the increased size of signatures. and so I, I'm not really worried about that, like I imagine the block size will be adjusted appropriately"
    },
    {
      "speaker": "matt_corallo",
      "time": "32:27",
      "start": 1947.3,
      "text": "for"
    },
    {
      "speaker": "stephan",
      "time": "32:28",
      "start": 1948.02,
      "text": "the, and what would that look like? Would that be like some"
    },
    {
      "speaker": "matt_corallo",
      "time": "32:30",
      "start": 1950.28,
      "text": "kind of quantum witness discount or like, what, what would that be?"
    },
    {
      "speaker": "stephan",
      "time": "32:34",
      "start": 1953.54,
      "text": "Potentially Potentially, yeah, especially if we're talking about some of these zk schemes. You know, obviously the availability of high quality zk schemes will improve over the next ten years, fifteen years, you know, maybe they'll be super, super cheap. you know, hash-based ones probably still won't be, be tiny, but, but they'll be reasonably cost ef- efficient. and so yeah, I mean, the-- maybe there'll be a quantum witness and you'll say, okay, well, to spend coins, you have to, Have both the traditional insecure, Secp signature in normal Bitcoin, and then also there's some, you know, SegWit two that also requires a CK proof or something, and, and we can figure out what that, what that looks"
    },
    {
      "speaker": "matt_corallo",
      "time": "33:15",
      "start": 1994.98,
      "text": "like at that time. Okay, yeah, interesting. and so when it comes to the specific, I guess, I don't know if you have any, any thought on the specific- Quantum, post quantum crypto, like whether it's hash based or lattice based or some of these other, forms, do you-- have you looked into those or do you have any thought on that?"
    },
    {
      "speaker": "stephan",
      "time": "33:40",
      "start": 2019.69,
      "text": "Yeah, I mean Doing something right now, it seems clear that it should be hash based, like when we're talking about adding something as a taproot leaf so that wallets can start to have this as an option. it seems that hash based is the only good answer there, lattice Has matured a lot over the last number of years, but is still relatively novel cryptographic assumptions, and when we're really talking about things for wallets to do where we anticipate them not-- hopefully not needing to use this at all. We can make really conservative cryptographic assumptions, like just taking on, just using hashes, SHA-256 hashes, and not worrying too much about the extra cost of doing that versus a lattice scheme. so we should-- it seems fairly straightforward to me that for that kind of use case, hash-based just makes a lot more sense right now."
    },
    {
      "speaker": "stephan",
      "time": "34:42",
      "start": 2082.46,
      "text": "whether, you know, it's- it's- In the future, when quantum becomes more urgent, kind of more on the short term horizon, then we, we, the, the Bitcoin community that exists at the time will presumably reevaluate what the quantum crita-- post quantum cryptography, landscape looks like and then make a decision at that point, to add something more efficient for people as an option. but hash based isn't terrible, I mean, you know, ten x more cost or something, So it's, it's expensive, but not impractically expensive."
    },
    {
      "speaker": "matt_corallo",
      "time": "35:19",
      "start": 2118.76,
      "text": "Okay. And now, another question, I just thought of this as well, and I was just wondering, if-- Okay, so let's say we do the, I don't know the name, the Matt Corallo scheme, right? The, you know, the, the Tapscript, quantum, thing. Let's, let's say you pick a specific thing, like whether it shrinks, is there a risk that, let's say, like a bunch of people just kinda do this now? And there's no soft fork for this, let's say, and they, they encode, they, they use wallets that encode it into that. But is there a risk that the future community could rug them and say, \"Ah, no, no, we don't want to use Shrink, we want to do Ladder Space or some other thing\"? Like, is there a risk that you could- You know, think you're doing the right thing by doing this scheme, but actually the future community doesn't want to go that way or is it not gonna matter because you would have already, you know?"
    },
    {
      "speaker": "stephan",
      "time": "36:11",
      "start": 2170.64,
      "text": "I mean, sure, potentially, right? You can never predict what the future community might do, but of course, if there is a material number of coins that have opted into post quantum security via some scheme that is standard and, and well understood, I can't imagine the Bitcoin community will say, \"No, we're gonna try to argue that.\" Would be very antithetical to the value proposition of Bitcoin. But, but I do think just enshrining the scheme and making clear this is exactly the scheme, and everyone should use exactly this, and Here's how it works, by going ahead and doing a self-ork in the, the short to medium term, makes sense, not because I'm worried about people getting rugged, just by, just be-just that it- Kind of makes clearer that this is exactly what we're right, that this is the"
    },
    {
      "speaker": "matt_corallo",
      "time": "36:57",
      "start": 2216.93,
      "text": "pathway that at least- This is the thing, you know, the community- At least for"
    },
    {
      "speaker": "stephan",
      "time": "37:00",
      "start": 2219.69,
      "text": "now."
    },
    {
      "speaker": "matt_corallo",
      "time": "37:01",
      "start": 2221.41,
      "text": "Okay. Yeah. And so- I think there's one- Yeah."
    },
    {
      "speaker": "stephan",
      "time": "37:05",
      "start": 2224.92,
      "text": "I was gonna say, I think there's one last part of the picture that I see in terms of getting, that I, that I imagine the Bitcoin community will want in a wor- in a post-quantum world, you know? So in the short term, I think we should add a tap leaf, and then the Bitcoin community in the future will simply disable the key path, and, and many wallets will be upgraded. I imagine the Bitcoin community will disable insecure spend paths, but allow those Those who have seed phrases to continue to access their funds, which is gonna basically reduce the number of, coins at risk of being burned to a very, very low number. But then lastly, I imagine, and I think the Bitcoin community will, will probably also enable a quantum commitment scheme, right? So if you are this Satoshi miner, all these coins that people assume are Satoshi's, this early miner, and- The Bitcoin community doesn't want to burn your coins, but also doesn't want to kind of flush you out, right? Like, we don't wanna necessarily force this early miner to reveal whether they have the private keys or not by making them spend the coins. We could also say, okay, look, here's Q-Day, so here's the day at which Bitcoin is going to disable insecure spend paths, the day at which we're Worried that after this a quantum computer might exist, if at any point prior to this you put anywhere on the blockchain, operator, you know, witness, whatever, A hash commitment to your private key and your hash-based public key. So I just literally hash, \"Here's the private key that I have, here's a hash-based public key, I hash that, I put it on the blockchain.\" If at any point prior to QDA you do that, then at any point after QDA, even though your spend paths are disabled and you can't just spend these outputs with a normal signature, you're allowed to spend it because you committed to a new public key. So you can go on the chain and you can say, \"Actually, I'm gonna go spend that output. Here's proof that I committed to at the time, years ago, I knew the private key before quantum computers existed, so I'm...\" I'm the legit owner, and also I committed to the new public key, which is post-quantum, and now I'm gonna sign with that new post-quantum public key. This would avoid the risk of kind of flushing out these early users or forcing them to go on-chain and spend things, and that way, you know, it doesn't Kind of, it, it, it enables these people to still have their coins without wrecking their privacy."
    },
    {
      "speaker": "matt_corallo",
      "time": "39:54",
      "start": 2393.82,
      "text": "Interesting. In the case of, you know, well, Potoshi out there, I hope you're listening, but joking. But more seriously, if Potoshi, this hypothetical miner, because those coins aren't just like in one fat output, right? It's like many, many, many, many outputs of like fifty BTC or whatever. Is Potoski and whoever else is in a similar boat, are they gonna have to do that hash commitment per UTXO that they control, or is there a way to like batch it into an op return or how are they gonna do that?"
    },
    {
      "speaker": "stephan",
      "time": "40:22",
      "start": 2421.67,
      "text": "yeah, you could enable a hash tree, right? So you could allow them to do all of these commitments in a Merkle tree and then hash all the way up to the root of the Merkle tree and just commit to the root of the Merkle tree, and then they could, they could then spend by revealing the Merkle tree path. So you, you could allow them to do it in one big commitment. Of course, that would force them to kind of, when they do go to spend their coins, they would be forced to reveal that, like, they had all these coins"
    },
    {
      "speaker": "matt_corallo",
      "time": "40:51",
      "start": 2450.73,
      "text": "And on the post-Q day thing, but at least they still got their coins, they didn't lose them. Right. So that's the key point. Right. So you, you could do it in one thirty-two byte commitment if you wanted. Okay. So yeah, so that doesn't kind of become impractical for Satoshi or some other early miners to kind of have to like put in like two hundred thousand, whatever, commitments or whatever, it can be kind of batched into one, let's say. Interesting. Okay. And so, I guess, now, you spoke earlier saying that theoretically to do this plan, this, Tapleaf plan, the quantum Tapleaf plan, let's say. You don't need a soft fork today, but you said it would be a, it might be a good thing if the community were to agree on that, just for the sake of formalizing and committing to it. Let's say publicly and all of us together saying this is kind of, at least, this is our current plan or at least one current plan for quantum mitigation."
    },
    {
      "speaker": "stephan",
      "time": "41:47",
      "start": 2506.67,
      "text": "Yeah, I think that makes sense, and I think, you know, there's still more work to be done. I think probably it makes sense to do it based on Shrink's, this, this new work by Jonas Nick, I think this year, I think it actually was in January. Yeah, listeners, you can check out my"
    },
    {
      "speaker": "matt_corallo",
      "time": "42:01",
      "start": 2520.57,
      "text": "recent episode with Jonas, we, we covered that a little bit there."
    },
    {
      "speaker": "stephan",
      "time": "42:03",
      "start": 2523.44,
      "text": "Right, right. Shrink's is great. I think it's, it's, you know, cool to, to have this option to be stateful or stateless and get smaller signatures or"
    },
    {
      "speaker": "stephan",
      "time": "42:15",
      "start": 2535.4,
      "text": "But Shrink's also has, has more to go. It needs to be, concretized, right? Shrink's is kind of a high level, here's what we can do, and here's a few different options, and, and here's the kind of sizes for those options, but we have to concretize it and say like, \"No, here is Shrink's Bitcoin, the way it's gonna be done.\" I think Jonas is, is working somewhat on that. And then from there, I mean, it's straightforward, you just add it to, to a Tapleaf, you take one of the OPSs, you make it OPS Shrink Verify or, or just OPS Shrink, and you're done. but yeah, I mean, I think we should do that. I think there's, there's some work left to be done to get there, there's progress going into it, Jonas is, is making progress, I think Tim might start helping, soon is what I'm told,"
    },
    {
      "speaker": "matt_corallo",
      "time": "43:02",
      "start": 2582.31,
      "text": "so. Okay, yeah. so in terms of things that would break today, do you have any thoughts on that, like, whether it's things that rely on elliptical, elliptic curve cryptography today? you know, even I think, off the top of my head, things like silent payments and even some of these, adaptor signature style, you know, things that rely on adaptor signatures, you know, even as we talked about before, hardware wallets are gonna have to change Change software, our software that we use is gonna have to change. Like, it's a wholesale, it's a big lift. It's not just kind of, 'cause I think there's like a perception of like, \"Oh, hey, why haven't the devs just done this already?\" And it's like, no, there's like all these- Bits and pieces that have to get fixed all around the ecosystem. So do you have any thought there or any comments there just on like what needs to be fixed or changed?"
    },
    {
      "speaker": "stephan",
      "time": "43:55",
      "start": 2635.41,
      "text": "Yeah, I mean, you're right, it is, a lot of pieces. You know, I think- Again, if we assume that a future Bitcoin community disables insecure spend paths, which, again, I'm, I'm pretty confident in for, for many reasons, just 'cause the, the market's gonna be the one to decide, and the market cares about supply and demand, but if we assume that, then it's really just about these kind of more unique wallets that don't use seed phrases that need to adapt, so that's Bitcoin Core, that's some of these large custodians That's, you know, software designed for some of these large custodians. There's, there's maybe some other wallets that I'm not really thinking of, but most wallets use seed phrases, so it's not, not really as much an immediate concern for them, And so it's really just getting those wallets to move. You know, Bitcoin Core has some hardware wallet support, but, you know, we have to adapt Bitcoin Core. You know, Bitcoin Core is often used just as a, as a straightforward wallet without hardware wallet, use. So, you know, in those cases, it would be relatively simple. but yeah, I mean, there's, there's quite a bit of work. Descriptors have to be updated to, to include this derivation scheme, to include the, these public keys. But yeah, I think it's, it's not as crazy an amount of work because we don't necessarily need every type of wallet to update immediately. Of course, we'd like them to update because, in all likelihood, this'll be cheaper. So if you, if you own a wallet and you have both this Shrink's embedded pub key and also your key is derived from a seed phrase, so you could do the zk proof approach, the zk proof approach is probably gonna be slower, it's gonna be larger on chain, it's gonna be, More costly, higher fees, so, you know, you still want to migrate so that if QDA happens, you aren't, you know, fifty xing your fees. I'm, I'm throwing out a number, I don't really know what the, the number would be. You're not fifty xing your fees, you're only ten xing your fees. That would be good. So we, we do want wallets to upgrade over time, but they've got time, they've got a lot of time to do it. It's more about getting that process started, getting off zero, starting moving, Because it just takes a lot of time, as you mentioned."
    },
    {
      "speaker": "matt_corallo",
      "time": "46:18",
      "start": 2778.09,
      "text": "Interesting. And so there's also this notion of, you know, this famous, like memes of like Linus saying, \"Don't break user space,\" right? And I think, today, the way many people use Bitcoin is they might have shared their xPub around with different services, and that is a problem, right? If you have shared your xPub Like the, the quantum computer will get you, hypothetically, right? Like so that's like another thing where, or this concept where people have like watching wallets, right? So they might have the col-the private key in the hardware wallet, but they might have a watching wallet on their computer or on their phone. Like that concept has to shift. I mean, they might be like equivalent in a quantum world, but like some of these aspects have to shift, and I guess that's just gonna be also part of, part of this dis-managing a transition into a post-"
    },
    {
      "speaker": "stephan",
      "time": "47:08",
      "start": 2828.07,
      "text": "Yeah, I mean, the, you know, as new address types have been added, descriptors have changed, right? So when Taproot wallets started to become a thing, you know, you still had to adapt the ecosystem of watch-only wallets, like you mentioned, hardware wallets, whatever, to support these new forms of descriptors that support Taproot. And the same is, is true here, right? We're gonna have to have a new form of descriptor to support, this specific Taproot leaf. so that wallets can verify it and, and identify the output is theirs and, and properly derive the keys. Yeah, I mean, it, it, it takes time, it's a very slow burn. It's just a question of, of getting that process moving. Yeah. And, and, you know, no matter what we'd, if quantum happens tomorrow, right? Like tomorrow, there's some huge breakthrough in, Refrigerant technology, and all of a sudden, you know, someone comes up with the best refrigeration design in two hundred years, and now, you know, you can build a, a large quantum computer fairly easily, and, and more qubits is, is doable. these things are gonna have to happen, right? you can't- On Quantum Day, whether Bitcoin burns, old coins, disables insecure spend paths or not, the If you can't transact with SegWit, right? Either you transact with some post quantum scheme, or you try to transact with SegWit and you lose your money. So like either way, these technologies In, you know, most likely in ten, fifteen, twenty, twenty-five years, we'll have to adapt anyway, so it's good to just start getting that ball moving, give them an option that's hash-based so that the ecosystem can, can start to adopt that, start to support that over five, ten years. So that, okay, maybe in twenty years we add, lattice based crypto, but at least, okay, if you haven't updated your wallet, if wallet software is slow to adapt, which again, it tends to be, then you can just use the hash based stuff, and maybe you pay a little higher fee, but that's okay, the stuff still works."
    },
    {
      "speaker": "matt_corallo",
      "time": "49:23",
      "start": 2962.74,
      "text": "Got it. Okay. So yeah, so there's different, things that, let's say, the community and Bitcoiners have to think about and understand, okay, what path, what direction is it gonna be? Is it Output from the get-go, out of the gate, or is it gonna be this, I, I don't know, we don't have a name for it, quantum tap leaf, you know, the Matt Corallo plan, let's say the, the, the Matt Corallo plan. So we'll have to decide that. And then there'll be other things too of like, okay, are we doing the block size increase or not, like to compensate or just like leave it as is and maybe that's gonna help the people who think there's a security budget issue or whatever Any, any final thing you wanna mention?"
    },
    {
      "speaker": "stephan",
      "time": "50:07",
      "start": 3006.59,
      "text": "Yeah, I think for the most part, you know, these decisions don't need to be made today and can't be made today because it's up to the future Bitcoin community to decide these things, and, and we can't decide that in advance for them. The only thing we can do now is, is provide an, an option that we think is likely to be adopted, that we think wallets can, can start using today. that prepares them for the future in the best way possible, and, and I don't really see anything that's better than putting it in the Taproot, maybe indicating that at the consensus level so that Wallets can adapt it, can adopt it, start using it, but aren't paying a high fee today and aren't just screwing their users into a really high fee today."
    },
    {
      "speaker": "matt_corallo",
      "time": "50:54",
      "start": 3053.91,
      "text": "Yeah, what do we do about quantum? Let's, let's leave that for the listeners, so, listeners check out, Matt Corallo's work, we'll put all the links in the show notes. Matt, thank you for joining me today and, helping discuss, your ideas. Yeah, of course."
    }
  ]
}
