Hacking Bitcoin wallets with quantum computers could happen
cnbc.com
cnbc.com
If QC are ever built - and that is a big if, not a foregone conclusion - then these networks will react long before the quantum computers are powerful enough to attack.
Can you elaborate on this? AFAIK taproot only makes it so you don't have to divulge the non-executed branches of code, but everything still uses hashes/ecdsa signatures so the threat model stays the same.
https://bigthink.com/technology-innovation/google-quantum-co...
The chose an inherently quantum problem that's difficult for classic computers (including supercomputers) to simulate but matches what the quantum hardware does natively; now we're approaching the stage where quantum hardware can do something more than simulations of quantum hardware. However, that's far from effective 'general purpose' quantum processors that would be capable of executing the quantum algorithms that have interesting implications on cryptography and other fields.
For example, factoring primes - we can brute force e.g. 256bit prime numbers on classical hardware and can't really brute force 1024 bit numbers. That can be done with a quantum computer with 2*n fully entangled, long-term coherent qubits, so a 512-qubit computer (unlike 53-qubit Sycamore) for doing what we can do already and 2048 qubit computer for actually breaking something (or, more realistically 4096 qubit computer for 2048-bit RSA).
Scott Aarson wrote a piece that touches on this https://www.quantamagazine.org/why-is-quantum-computing-so-h...
> Nic Carter pointed out that quantum breaks would be gradual rather than sudden.
It's likely cracking quantum error correction won't be a gradual process. Instead one day it won't work, and the next day it will be possible to build very big quantum computers.
I don't think that means QC will be a major problem for crypto. It's not like there aren't fixes already, and they've proved themselves to be collectively very adept at changing protocols and algorithms. Hell one of the changes they made to bitcoin is to add flag bits and a voting protocol that made future changes easier.
The public key is only written to the blockchain when you spend coin from that address, so at that point a QC can attack the key. Thus it's important to never re-use an address once you've spent from it and always spend the entire amount by using a newly generated change address.
As Canada points out[1], there is a window when it's revealed to the mempool but not yet committed to the blockchain. During that time, even a single-use address is not QC safe.
It would be an expensive endeavor since it involves throwing away solved blocks, but could of course package many QC safe(r) transactions so probably a profitable service in a QC compromised era.
How does that work? Anytime you spend coins from an address you hope you spend the exact correct amount that was already there? You pay 2x transaction fees to have to transfers - payment as one and remainder as the other and hope they both pop in the same block?
You can also send the change to a new address instead, which is how single use wallets work. You generate a new wallet, send the change to the new wallet and replace usage of the old wallet with the new one.
Another possible way would be to use a rotatable key derivation algorithm, where you can provide the 12 word phrase plus a number n, and it will provide you a different wallet for each value of n. Of course the key derivation algorithm must be quantam secure for the security benefit to apply in this context.
As long as most of us do this before the attacks are practical and widespread, no problem. But when do we stop accepting transactions with ECDSA keys? I suppose at some point someone will try move 500,000 BTC from addresses that have been dead since 2010. Hopefully we'll have a consensus by then.
As to the surprise attack scenario, I find it uncompelling. The only ones who could fund that in the near future are nations, and one thinks they'd have better things to do with a top secret trump card like that, than to attempt to very publicly steal money with it.
Why? Are you saying you'll need a bunch of new addresses? I think you'll only need 1 new address. Are you saying the addresses or stored private keys will be gigantic? I don't think that needs to be the case. Current addresses are just hashes, they can stay hashes and thus be small. Private keys don't need to be stored, only a seed needed to generate a private key needs to be stored.
In either case, you'd absolutely not want to reuse the phrase. AFAIK BIP-32 does not have security guarantees such that you can't find the seed from a set of private keys.
It shouldn't be too hard to come up with a consensus right? All the stakeholders would benefit old coins being lost forever (because the value of their holdings would go up), and there's no point in opposing it when you can just shuffle your old coins to using post-quantum signatures.
No inherent problem. The protocol could have a built-in discount. Maybe the block cap should be increased to compensate. Questions like that are not so easy to get consensus on.
Why would you bother?
The outcome is the same, either the user gets locked out of their coin or hackers gain access to the coin, meaning the user is locked out of the coin. There isn't a solution that doesn't resolve in one of those and if you aren't able to protect the user by doing it, why spend the effort?
OTOH the typical cybercriminal wouldn't have access to quantum computers for a while so this is a pretty unscary prospect either way, for now.
If you have a mossad problem, big integers were never going to save you from that before or indeed, after QC.
One of the things frequently intentionally neglected in Bitcoin discussions, is that it will die. It is guaranteed to die. It's a human invented digital technology, there is no long-term scenario where we don't kill it off through replacement and or competition. We'll be constantly inventing new cryptos, that process will never stop. The odds of Bitcoin maintaining its crown long-term are not good, for all sorts of reasons (not least of which are vast dilution through competition and regulation; eg nations heavily restricting foreign/external cryptos and only allowing official national fake crypto currencies (digital currencies), as China is speeding toward). We can and will replace Bitcoin with something better. And then we'll replace that too.
People that are irrationally, emotionally bound up in Bitcoin will fight you to the death to deny that. Bitcoin is not a forever technology, it's transitory. But who gives a shit about Bitcoin per Bitcoin, click, click, no more Bitcoin, I just moved my Bitcoin over to X blah coin that is better. The coins don't matter unto themselves, they're merely vessels for holding or moving value, nothing more. A crypto investor should always be prepared to abandon ship for something superior and maintain a rational independence from becoming emotionally biased toward a given coin. It's no different than understanding to not fall in love, so to speak, with stocks (or commodities, and so on).
The tragedy of Bitcoin is that as it fades away and gets replaced, it'll leave a giant environmental blackhole in its wake. There will be a question as to whether it was a mistake (was there a better alternative beginning technology for cryptos), or whether it was absolutely necessary to learn from to spark the field (and if so, was it necessary to go so far with it before abandoning it).
Besides the replacement factor, there is no scenario where major world governments allow Bitcoin to replace central bank controlled fiat currencies. Give up a huge source of their power, give up the ability to free-spend, 'print,' steal & paper over fiscal mistakes via inflation? Ha, yeah right. It's hilariously trivial for major governments to dictate financial matters within their own borders. Outlaw Bitcoin and throw a bunch of people into prison for using it and they'll instantly see 99%+ compliance, that's how easy it is to relegate Bitcoin to the fringe. All the largest economies are already priming their moves to squeeze crypto via intensifying regulation, to make sure it stays in the corner where they're willing to tolerate it.
Bitcoin is a speculative bubble and not much else.
The only hope it has is to be adopted as a reserve currency (not just legal tender) by many countries, and thus cement its value and then people will really be using it as a currency albeit on secondary layers, most likely provided by a number of centralised “PayPal-like” entities.
I don’t have faith in Lightning Network. Spend $50 to lock up $5000 where someone else can close you down and cost you $50 and you run around trying to find peers and be your own bank? No thanks.
So Bitcoin is a call option on this “hyperbitcoinisation” and anything less means it’s completely dead or just an occasional decentralised ponzi.
You sound like someone who sold all his BTC in 2012 and bought a 2nd hand Honda Civic with the proceeds, thinking you'd beaten the system.
This is why altcoins haven’t displaced Bitcoin: touting technological advancements over and above the benchmark set by Bitcoin is more or less irrelevant, except to the extent the narrative underlying it produces a network effect to compete with Bitcoin’s. But there’s no logical reason why Bitcoin’s network effect should ever be exceeded — Bitcoin has the first-mover advantage, and is the most widely recognized cryptocurrency, with the safest and simplest technical implementation which is clearly capable of meeting the needs of cryptocurrency users. Speculative value storage is the only real world use case of cryptocurrency, and Bitcoin does it better.
https://blog.cloudflare.com/the-tls-post-quantum-experiment/ is a great read about a sample deployment of this by Cloudflare.
So if we're being risk-averse and having the worst-case in mind, it's time to get the ball rolling now.
You know that we can just barely (maybe) demonstrate quantum supremacy at this point right? Anything below this mark can be done on some rental AWS time and anything beyond that mark will be a serious challenge worthy of Google or Baidu's teams.
I guess what I'm saying is that I don't think you have what you think you have.
I would encourage you to seek to be more open minded.
Just like every other existential threat to bitcoin QC will threaten other more important things, like infrastructure, first.
It's a non-threat.
It seems like the only options is to either just let it happen or make those bitcoins disappear.
And then the community could decide “if you didn’t update your addresses before quantum computer attacks were viable, even though you had 5 years to do it with strong evidence that it would be necessary eventually, and lost your coins as a result, then sucks to be you”
You wouldn't need to break in and take anything. Just create some transactions in an open ledger.
ie a global internet disaster.