TFTC: A Bitcoin Podcast - #733: The Truth About The Quantum Threat with Brandon Black
Episode Date: April 4, 2026Marty sits down with Brandon Black to discuss the realistic timeline of quantum computing threats to Bitcoin, the gap between theoretical breakthroughs and physical implementation, and why rushing pos...t-quantum cryptographic upgrades may be unnecessary and risky. Brandon on X: https://x.com/reardencode Rearden Code GitHub: https://github.com/reardencode STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/VJ2dABShBz Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Bitkey https://bitkey.world/ Bitcoin 2026 - Las Vegas http://bit.ly/3NA9xQh OPNEXT https://tinyurl.com/tftc2026 Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/
Transcript
Discussion (0)
you've had a dynamic where money's become freer than free
if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting
like safe haven i believe that in a world where central bankers are tripping over themselves to
devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean
And that's part of the bull case for Bitcoin.
If you're not paying attention, you probably should be.
Brandon, welcome to the show, sir.
Thanks. Good to see you, man.
Good to see you.
I'm very happy to get you on to talk about quantum, the risk, the perceived risk, the perceived reality.
What is the reality?
Maybe that's where we'll start.
And I'll reiterate what I was saying right before I hit record, which is it's hard as somebody who's not a quantum physicist, is not a cryptographer to really get a grasp of what the true reality with advances in quantum computing are and specifically how they relate to Bitcoin's security in the short, medium and long term.
uh and i've watched you on the front lines of of sort of debating the merits of the advancements
in quantum physics over the last year i actually listened to your podcast that you did with uh
gwerdy last year i thought that was really good and that helped me um that helped help me get a
better understanding of your perspective but i think um starting with this question of how can
you be confident on one side of the other how can you be confident that it's not as
big of a risk quantum computing is to Bitcoin today.
And then conversely, like, why do you think people are saying we need to rush to become
quantum resistant or as confident as they are right now?
Yeah, I mean, I think the thing that gives me confidence, and I said on Guardian, I think
I still stand by it.
You know, I can't I have an emotional confidence that we're 50 to 100 to forever years from
a quantum computer breaking a meaningful cryptographic system but that's not scientific
that's that's a gut feeling looking more kind of in a scientific lens at it we we live in a world
constrained by the reality of physically building things and it's hard to physically build things
that doesn't make any particular physical building challenge impossible but the i think the quantum
field is full of these, you know, we'll call it if this is possible, then all we have to do is
build it kind of perspectives. And they totally just deny the realities of the difficulty in
building physical things that manipulate tiny subatomic particles, or in the case of neutral
atoms, you know, individual atoms being manipulated by laser tweezers, I think they're called or
optical tweezers. Like, these are incredibly difficult things to build, and especially
difficult to scale, right? Let's say you can build the first optical tweezer and manipulate one atom.
Okay, now you want to build a grid of thousands of atoms and manipulate all of them with different
tweezers at the same time. Think about how that difficulty scales. And so maybe it's possible,
which is the thing I have to acknowledge when I'm being reasonable as opposed to emotional about
this. But the difficulties are dramatically underplayed. And that's what the evidence shows.
I think that's what people kind of don't acknowledge as the reality. When they look
at quantum, they're like, oh, all we have to do now is scale it up. But we've been working on
quantum as a species for 40 years or something, as long as I've been alive. And every time they
go to scale it up, they hit new difficulties that they weren't expecting. That's the evidence we
have is it's been over and over and over and over for decades that scaling up is hard. That doesn't
mean it's impossible, but the hardness is what gives me that confidence, is that based on the
evidence we have seen for decades, repeatedly and consistently, they may find a way to scale it up,
but it's going to be clawed out by individual small improvements over years and years and years.
And at some point, they might hit on a technology that will work. And when they do, we'll see that
technology go from five logical qubits incoherence for a while to 10 incoherence for a similar length
of time to 20 to 40 etc we'll see doublings like we saw with transistors of the same technology
progressing through a scaling roadmap and then we'll be able to say oh now it's doubled three
times it took 2.5 years each time to double the number of logical qubits in this technology okay
So at that rate, we'll get to a cryptographically relevant computer in Y years.
But until we see a roadmap like that, that's the successful scaling in one technology,
the evidence is it's going to be just hard fought, tiny wins, new technologies.
And there's just no evidence that it's going to come anytime in the next decade or really
any time in the next 20 years.
So that's where my confidence comes from.
On the flip side, because you asked the other side of the question too, I think the other
side gets their confidence from the let's say the impressiveness of the wins they do get
these are incredibly difficult mathematically challenging algorithms and designs and the folks
working on them are some of the most brilliant people in the world and and they go through the
fundamental physics of our world they go down to the very smallest subatomic particles they figure
out how things work and then they say oh my god i figured out that we can do this in this easier
way or in this faster way or this new method of manipulating subatomic particles and those
discoveries are absolutely amazing and they're they're the cutting edge of humans understanding
our own world like there's there's nothing more impressive than that and so it's a reality that
these are these are the most brilliant people doing incredible work to understand our world
and people get really excited about that and so that's where they get their confidence is that
the most brilliant people are working on that problem but that doesn't change like there's
still the separation between the it's it probably literally possible which is their perspective i
don't think it is but in their world it's probably possible and these fundamental understandings of
the universe give them confidence that it's going to be solved in the real world in physical devices
and that's the so the way i understand it let me know if i'm wrong because i did see
you retweet my understanding of it the other day which is like hey i think it's very obvious that
in the theoretical realm of like what is possible they are making advancements and the biggest
sort of chasm that exists in reality which i think you just described but trying to
distill it down for an eli5 for people listening is that yes we're making these theoretical
advancements of what we can do however there is a chasm between what we can do and the physical
reality of building machines that can actually sustain an uptime and persistence to make that
theoretical advancement a applicable reality yeah exactly and i think that in quantum there's this
like extra well there's extra detail to it which is um it's often possible to build call it the
toy example of something where you know that we've seen superconducting qubits we've seen
neutral atom qubits we've seen uh shooting the other technology that's kind of commonly pushed
right now but there's a bunch of different technologies that where they've built a built
a few useful qubits and done something interesting with it um but again the the specific thing that
happens is is that taking that and going to the next step and building twice as many qubits or
four times as many qubits and and they keep running into problems there um so so that i
think that's also where they get their confidence is oh we built that thing the physics described
it we built it but then they tried to build a slightly bigger one and they hit a brick wall
and we even saw like the way these things are published the majorana paper from microsoft
kind of glossed over that and and when you dig deeper the the physical device that they were
publishing about had a single i think a single physical qubit or or something of that like tiny
tiny nature it's like oh they built the first qubit of this type using that's the tech i want
to mention uh using a majorana particle okay super cool you got one bit of that now what
happened trying to scale up and why has it now been almost a year since that result with no one
building a two majorana qubit device like what's the deal well i think this is important detail to
dive into too is like the difference between a logical qubit and a physical qubit and the
relationship between the two because from what i understand logical comes down to the math and
what you can do and the physical is like all right like how do you organize all that and make it
a computer an operating software whatever it may be yeah you're right and it's a complicated thing
where depending what your physical underlying technology is that affects the relationship
between the physical and the logical qubit so there's like different avenues of research
happening in in quantum there's the mathematical research which is assuming we have logical qubits
mathematically how do we apply that to solving real world problems that's what google published
about this week right they published a paper that says here's some new mathematics we could apply
to running shore's algorithm on logical qubits that makes it take fewer logical qubits to
execute shore's algorithm and in this case also fewer steps of computation um that's the math
side but that all runs on logical qubits and then the question is how do you organize some physical
device into logical qubits on which you can run math. And that's where the physical qubits come
in. So the other paper that came out this week on neutral atoms was a new way of error correcting
physical qubits to make useful mathematical logical qubits. They, within the context of this
neutral atoms architecture that uses the optical tweezers to move atoms around, because they can
physically move the qubits around they can grab a physical atom that's a qubit and has been
entangled in some way with some other qubit and they can move it to another part of the chip that's
or the device that's the the cool thing about it because of that they can do what's called non-local
error correction and the theory described in this paper is that because they can do non-local error
correction because the physical qubits can be moved by optical tweezers they can do what they
call high rate error correction where uh rather than having to have like a dedicated cluster of
error correction uh qubits call it for each logical qubit you've got like a bunch of physical qubits
error correcting each other to get one logical qubit instead in this neutral atom architecture
with the optical tweezers they can in theory uh have one cluster of like error correcting
qubits that corrects a whole bunch of kind of active computing qubits and that's why they got
that remarkable result in the paper of basically if this high rate non-local error correction works
we can go down from 500,000 to 10,000 physical qubits needed to implement Shor's algorithm and
that's basically my summary of a lot of these quantum papers is if this thing that hasn't ever
been done works then we can do this easy thing and that's yeah so that's where the relationship
is and how why you see these radically different relationships between number of physical qubits
and logical is because it depends dramatically on what types of error correction you can do on
this physical architecture and whether those work and you need to do the error correction because
these physical qubits are beholden to entropy right yeah they're notoriously flaky yeah and
so that that like on the physical qubit side like we're still trying to figure out a way
how to make it so they don't deteriorate in real time right and then also in this neutral atom
architecture, again, because they can physically move qubits, they have in the paper, they accept
that physical qubits will deteriorate. And they design a theoretical neutral atom quantum
computer that has a reservoir of pre-coherent backup qubits that they can grab with the
optical pleasers and stuff into the circuit to replace one that deteriorates. So exactly as you
said, these physical qubits, they tend to break down. And so the big question is, how do we
stabilize them and make it so that we can kind of continue doing computation on them? And different
researchers in different parts of the quantum field have different methods of kind of holding
that shit together for longer. And how much energy does all that take?
Yeah, I mean, that's the other big question that I think Bob McElworth and I were talking about on
X This Morning right before this. You know, if you even if you linearly scale up the energy
needed um it's still huge he was saying it's something like 100 megawatts based on his
calculations you need to cram into whatever device if you linearly scale up the energy
needed per qubit and based on current technologies um but my point i think is a valid point if you
think about the complexity of moving around more and more qubits in the neutral atom architecture
or in cooling more and more qubits it's not going to be a linear scaling and we've seen this even
with classical computers, that the more dense you make devices, the more leakage you have,
and therefore the more energy it takes per bit to keep it cool for supercomputer architecture.
And so even let's say it's linear, it's still a ton of energy to cram into a device.
And if it's nonlinear, it may become completely intractable to power a device that can do
meaningful quantum computing.
So freaks, guess what? Just booked my tickets to Vegas headed for Bitcoin 2026. It's that time of
the year, April 27th to 29th in Las Vegas. I'm going to be there. A ton of people are going to
be there. You better get your ass there. You know what? People are calling it bear market. These are
the best conferences. I've been going since 2019 when it was in a parking garage in San Francisco.
If you want to get the best possible ticket prices, make sure you use our link and the code
tftc you go to 2026.b.tc use the code tftc you'll get 10 off you can bundle with a hotel room to
save big and make the most of your experience staying on site at the venetian that is where
i will be ticket prices are increasing so make sure you get yours today join bitcoiners from
all around the world it's a global endeavor it's a it's a pilgrimage if you will for the ultimate
networking experience there's gonna be a ton of people there you can hear from the biggest names
in the industry sailor's gonna be there matt and i and the pubkey boys and the bugle boys we're
going to have live hot style takeover that's going to be there too all in the venetian everybody's
meeting up it's going to be fun get there 2026.b.tc use the code tftc at signup sup freaks up next the
bitcoin scaling conference where bitcoin developers meet institutional capital is coming to new york
next month join bitcoiners from blockstream chaincode brink and more at the can't miss
summit at the intersection of bitcoin tech and finance this conference has one of the best signal
to noise ratios and that's why i'll be joining block space's third annual bitcoin tech conference
on April 16th at the New York Times Center in Midtown Manhattan. There's only room for 200
attendees and they've already sold more than 100 tickets of their open spots. So you've only got a
few weeks to get your travel plans in order from New York. With the ticket, you get access to the
best programming and Bitcoin tech from BitVM to BitChat, catered lunch and access to the PubKey
after party. Wearing the hat, PubKey after party. Up next is where builders meet capital, founders
find funding and companies source top talent. Plus meet institutional investors and developers
from blackrock hc wainwright and bitcoin infrastructure corp if you're at a venture
fund or another finance firm this is the event to learn more about the quantum computing leading
edge bitcoin tech and topics that will define bitcoin's futures go to opnext.dev for tickets
and use the code tftc to get 25 off a general admission or vip ticket to the event again that's
up next dot dev go tftc for 25 off a ticket i'll see you there again going back to the confidence
of the other of the other side like what do you what do you think what do you think is driving
because that's i mean i guess the whole conversation as it pertains to bitcoin is this
perceived urgency that is being thrust on the developer community specifically to to upgrade to
a quantum resistant cryptographic primitive um that would that would secure uh private keys
uh so that they're they wouldn't succumb to it to an attack via a quantum computer and
that that's been like the confounding uh not confounding but it's been sort of the
the thing that's really perturbed me is like that you have this very confident and um
somewhat uh manic i think manic is a good way to describe it a
group of people are saying we need to fix this devs do something right now and it's frustrating
for two reasons number one quantum has been thought about within bitcoin since satoshi was
around i mean he mentioned it um if you've been reading mail if you've been reading the mailing
list and looking at some of the research being done like there are people um trying to figure
out like okay if quantum computers do come what's the best way to transition to a quantum resistant
address structure uh and there are a ton of not only coordination issues but standardization
issues that exist there's a ton of uh for lack of a better term tech tech debt that exists like
if you are going to transition to a quantum resistant address structure that is going to
disrupt a lot of the uh a lot of the infrastructure that's been built today so you talk about the
lightning network uh psbts multisig all this stuff like you need to think through like how do we
transition to this address structure with without disrupting all that if possible and if that is
going to be disrupted like what do we do uh and the the my biggest worry is that you rush a change
uh and it just not only disrupts all of that standardization that infrastructure that's been
built to date but you haphazardly rush to to a change that has been well thought through well
tested and leads to a bigger fallout in terms of disruption to the network than having done
nothing because quantum potentially doesn't manifest on the time scale that these people
are saying it will.
Yeah, I mean, I think it's a legitimate risk.
And frankly, it's why it's one of the reasons I try to stay on top of all of this, because
let's we should be realistic here.
The most likely outcome is that at some point, SECP256K1 or elliptic cryptography in general
will fail.
Like that's the most likely outcome.
I don't think personally that it's quantum that's going to break it, but cryptosystems have failed over the years.
We've seen it, and it seems likely that at some point it will.
So what do we do about that?
And so I try to stay up on what the other kind of new cryptographic research is so that when there's something suitable for Bitcoin that can support all the infrastructure we have, wallets and lightning and everything that you mentioned, we should actually add it to Bitcoin.
And we should maybe even do that before there's a real threat so that people have options.
And that's fine.
That's good.
There was a whole discussion on the mailing list about the benefits and downsides of having options.
And I think Peter Willa is a bit concerned about people having options because there could be fighting over what the correct option to use is.
I'm less concerned about that because we already have that essentially where some custodians use MPC that's kind of cross crypto.
I think Coinbase does and others, but some custodians use on-chain multi-sig, right?
That's fine.
It's okay for different people to choose different trade-offs and how they secure their coins.
So yeah, if we have suitable cryptography, we should totally put it in Bitcoin.
And there's a decent argument to say that we're getting very close to having something suitable to add, at least as a backup in the work that Jonas Nick and blockchain research and others are doing.
So I'm not out here saying we shouldn't do anything about the potential break of SecBee 256k1.
And I think that's where, kind of to your point, these confident, almost manic people in the quantum side are like, devs do something.
Well, the devs are doing something.
Even people like me that don't believe in quantum at all are out there doing research and evaluating research on what we could use as another crypto system for Bitcoin.
And to chill out, I guess.
Well, not only that, it's like you're they're treating Bitcoin core like any Bitcoin developer is a monolith, like go do something.
it's like well there's there's only so many people are qualified to understand like quantum physics
and the cryptography sec p256k1 like that's like a very niche part of like the bitcoin
development process like obviously you have the p2p layer you have the wallet layer you have the
gui you have many different facets of of the protocol that make up bitcoin and like finger
wagging at the whole dev community like do something it's like well not everybody within
the developer community is going to be able to do anything about this because they're not
like their their core competency isn't the cryptography and taking it further like making
the crypt cryptography quantum resistant like there's very few people that are equipped to
work on this particular problem and to your point and what i've been saying for the last six months
since this this has become a huge meme is like the people who are um equipped and able to do
this work or seem to be working on it maybe it's not the pace that you want but you can't
pull out a whip and make them work faster nor would you want to like yeah there's a great post
uh stew stew txo out there uh but there's other like since since this post it was in december
uh there have been five new uh post quantum cryptographic algorithms published and zero
new numbers factored by an actual quantum computer and i just thought that was that was so great it's
like so so really we're we're upset about the rate of progress when month to month to month we're
seeing new algorithms that are kind of progressing the state of the art for post-quantum cryptography
in bitcoin and no new physical quantum devices being built that run real algorithms that could
maybe even someday break bitcoin uh no i think the progress is at a good pace we might even be
over investing if you if you ask my honest opinion yeah well i think i saw something yesterday where
somebody's saying like you could do the factoring of these numbers by hand faster than the quantum
computers could right now yeah i checked with my six-year-old and i see seven now anyway uh
and he can he can factor more numbers than a quantum computer for sure i actually just set
my six-year-old up with the synthesis math tutoring that app and he's been playing with it
I actually did see him factor some numbers this morning
that were faster than a quantum computer.
But again, so the Google paper specifically,
I think it's another thing to touch on,
is the fact that they didn't actually release the results.
They released the zero-knowledge proof that they had done something
and said, basically framed it as like,
we didn't want to release the results of this
because we don't want black hat quantum developers
to get access to this and um to to go build a computer that disrupts the world and then um
the advocates for this paper were saying well now this this is the warning like they're they're not
going to tell us the the advancements that they're making because they're worried about
releasing them to the public because it'll be used against us by nefarious
actors um is this a marketing scheme a way to develop a budget or do you think there's
some legitimacy here that the smartest people in the world work on this problem are truly worried
that we're hitting an inflection point a tipping point that could accelerate the progress being
made within quantum computing so it it's it's a really interesting problem to think about
i i had that moment of pause as well when i read the google paper um the thing about the google
paper, though, is that there is no fundamental physical change that they're publishing. Like I
said, they published a mathematical change, which reduces the number of, sorry, it reduces the
complexity of the physical device you need to build in order to run this algorithm. But no one
actually made a more complex physical device. So Alex Pruden, who I'll be debating at Bitcoin++
Plus in a couple of weeks, I think actually looked pretty cogently about this.
Of the pro quantum guys, he's one of the more pleasant to talk to.
So I'm glad I'll be talking to him at Bitcoin Plus Plus.
And he was pointing out that let's let's say, you know, right now we're at five ish logical
qubits have been demonstrated in a very short, like microsecond duration coherence.
OK, well, what if through the mathematical improvements, we get to the point where it
only takes just 256 logical qubits in coherence for only five milliseconds in order to run
Shor's algorithm on a Bitcoin private key or public key to get that private key.
You know, if they, on the mathematical side, compress the time and the number of qubits
so much, then we could see a situation where it's very much in reach of the physical progress.
So if physical progress is zero, but the mathematical progress is extreme, we could
see it break kind of in that direction, where the mathematical progress brings it down to
the point where the physical guys have a very short step to take.
And that's a great point.
Now, that said, the Google paper puts us about six orders of magnitude away from the needed
coherence time and about three orders of magnitude away in the number of qubits that need to
be in a physical device.
So I don't know how you want to look at those two different dimensions of orders of magnitude, but we're somewhere between six and nine orders of magnitude of improvement on the physical side away from implementing Google's paper.
So we need to be really realistic that, yes, eventually the mathematical progress could bring it into reach of the physical, but we're still very far away from that.
I guess that begs the question, what are the advancements from an order of magnitude perspective on the physical side been like in recent years?
like is that a big a big leap um it's obviously it is but have the advancements over the last 10
years was it 100 orders of magnitude away five years ago was it a thousand and are we now getting
to the point where six to nine may seem big but it's not that big we haven't i mean even the the
best kind of longest held stable devices have up to a couple thousand physical qubits which is
maybe a one or two orders of magnitude improvement in the last 10 years um but but i i hesitate to
even say that because i think it paints it a little bit too rosily for the physical quantum
guys um because the the biggest improvements have come by implementing whole new architectures
And so there's no evidence right now that any single architecture can increase the number of physical qubits. And that's where I think the pro-quantum manic folks get way over their skis. They're like, all we have to do is scale up.
but you can't just scale up when every scale up that you're doing so far for the last many
decades has been because you developed a whole new architecture right you're like you're just
discovering a whole new set of problem spaces because you're developing a whole new architecture
still uh and so i made it very clear in like when would i start to think we need to take action in
bitcoin and that's when we see a single quantum architecture increase the number of qubits you
can hold incoherence for a longer time, over several cycles, at least two, we need to start
seeing a trend in one architecture scaling up. And then maybe it becomes just a scaling problem
where we just have to do the decades long industrialization to go order of magnitude,
order of magnitude, order of magnitude. Now we need to start taking action. But until you see
that they're like, oh, okay, maybe maybe this one is going to be the one. But until there's evidence
that it actually scales why would you take any action we don't have the evidence to say to
justify action yeah and that's where it gets very confusing i think that's um in the most
disconcerting thing observing this over the last year as is the narrative around the quantum
threat to to bitcoin has um hit the market is like again i'm not a quantum physicist i'm not
a cryptographer i um know enough to understand like i can explain like a logical qubit does like
the theoretical algorithm the physical um qubit sort of creates the space where that stuff is
is um is computed for lack of a better term and i understand that there is a coordination on the
physical side and energy needed and it seems clear to me that it's not where it needs to be and not
anywhere close to where it needs to be to effectively run this stuff persistently to
wage the necessary attacks but then again going back to the confidence game and um i hate to say
like the sky is falling sort of um perspective uh that is very reminiscent of like climate change
and things that i'm just using like psyop pattern recognition and it feels like that to me it could
be wrong using heuristics here um again don't understand the math and not a physicist by any
means study like economics um but yeah i think that's the narrative side of things it's very
very easy to socially attack people and it feels i'm not saying that i i do believe the the other
side is earnest in their beliefs and that that's like the interesting part of this whole discussion
and observing it over the last year is like they're so ardent on their beliefs and people
who are just skeptical like hey i believe that you're genuine but i'm not seeing it and uh there's
this there's this like narrative leverage this asymmetric leverage they have because they can
project fear onto the market and if you're not afraid you're you're not doing enough and you're
actually stupid yeah i think it's the classic the classic fud game um and then it does make it hard
to distill so i that's again like i didn't want to be i'm not a quantum physicist by the way i'm
just a person with engineering background and with a lot of experience for many decades of
reading research papers so so i i come at it not as an expert in in the particular field but
as someone experienced in reading papers and kind of understanding the real implications of what some
new publication means um so yeah so i think one thing i want to say from from what you're just
saying is that i recommend really that everyone go read the papers because in many cases the papers
that underlie the the big manic posts about quantum the sky is falling the papers are much
more conservative in what they claim now this google one is kind of an exception to that but
I think that's also a good way to gauge the progress in quantum computing is, is look at
what the actual results in the papers are that justify these very high excitement posts in social
media and in kind of science journalism, let's call it. And what you'll find is that the real
results being published in the academic papers are small, like little nuanced improvements in
things. And again, this Google paper is kind of an exception to that, but the vast majority are,
especially on the physical side, actually, I think exclusively that's true on the physical side,
they're these small progressive improvements. And so you can kind of tell where we are in
quantum computing by the fact that what gets the hype in the social media and science journalism
side are these tiny little improvements on the physical side. Okay, so if that's what gets the
hype then we are a long way from getting all the way there because when we're getting close you're
going to see the majorana article the majorana particle architecture scaled up again and now
went from x logical qubits to y for the third time in three years and we're going to see like
oh these are big improvements the the they're they're building devices that can run shore's
algorithm on bigger and bigger uh even if they don't really run it to be to be fair they don't
have to run the actual algorithm, but the physical device is capable of running it on a key this big
on a key that big, you know, you'll see, I guess, bigger results actually being published with less
hype. And right now we're seeing tiny results published with huge hype. And that's one of the
ways to kind of tell how far we are and how much it is just hype. So freaks, this rip of TFTC was
brought to you by our good friends at BitKey. BitKey makes Bitcoin easy to use and hard to lose.
It is a hardware wallet that natively embeds into a two or three multi-sig.
You have one key on the hardware wallet, one key on your mobile device, and Block stores
a key in the cloud for you.
This is an incredible hardware device for your friends and family, or maybe yourself
who have Bitcoin on exchanges and have for a long time, but haven't taken a step to self
custody because they're worried about the complications of setting up a private public
key pair, securing that seed phrase, setting up a pin, setting up a passphrase.
again, BitKey makes it easy to use, hard to lose. It's the easiest zero to one step, your first step
to self-custody. If you have friends and family on the exchanges who haven't moved it off, tell
them to pick up a BitKey. Go to bitkey.world. Use the key TFTC20 at checkout for 20% off your order.
That's bitkey.world, code TFTC20. What's up, freaks? When you take Bitcoin seriously,
you start with custody. You want to control your keys, avoid single points of failure,
and make sure your savings cannot disappear because you or someone else screwed up. That
is what Unchained has been focused on since 2016. Unchained is the leader in collaborative multi-sig
custody and Bitcoin financial services that keep you in control. They secure over $12 billion in
Bitcoin for more than 12,000 clients. That means about one out of every 200 Bitcoin sits inside
an Unchained vault. Their model is simple. You hold two keys, they hold one key. It always takes
two keys to move Bitcoin, meaning their single key can't access your Bitcoin on its own. Just
resilient, shared custody that gives you institutional-grade security while keeping
you sovereign. Unchained also lets you trade straight from your vault, access Bitcoin-backed
commercial loans, open a Bitcoin IRA where you hold your own keys, and set up personal, business,
trust, or retirement vaults. They even offer inheritance solutions built for long-term
hodlers. Or opt for the highest level private client service with Unchained Signature and get
a dedicated account manager, discounted trading fees, exclusive access to events and features,
and much, much more. If you want a partner that helps you secure and grow your Bitcoin without
giving up control, go to Unchained.com and use the code TFTC10 at checkout to get 10%
off your new bitcoin multisig volt that's tftc10 at unchained.com yeah and again i think really
nailing down the the risk of trying to rush a change to bitcoin to appease the people who think
that this is coming uh faster than than others believe it is um what are the risk of of upgrading
to something uh in haste because you're worried about this and alternatively not alternatively
but on top of that like is there a line in the sand we can we can draw it's like hey we we hear
your concerns we'll take this seriously we'll begin we'll continue the research that we've
been doing and um make sure that we advance that but if we get to 2030 and we're at this state of
quantum research we're not going to take you seriously anymore like what is the line in your
sand oh that's a good question i haven't really thought about it from that angle of of yeah like
when do we stop paying attention like when like it's like Greta was like Greta Thunberg again
using the climate change analysis and analogy was in 2015 she was like by 2022 Miami's going
to be underwater it's like 2022 came and went Miami's not underwater so okay we can't take
you seriously anymore what is what is that what is that line in this conversation yeah I think
with quantum it's really hard because the reality is again I think quantum is not physically
possible, but I can't, that's an emotional thing. So we can't really do that because there could
always be a new architecture developed that makes it possible, something we haven't thought of
before. But I think the good news is that, as I said, something's eventually most likely going
to break our existing crypto. And so we need to keep doing this research and building new crypto
systems for bitcoin regardless of quantum and we should keep doing it at the right pace uh and so
like one of the ways to i think ease the tension here is to say look bitcoin actually is developing
towards quantum resistance regardless of your level of concern or my level of concern i'm not
concerned you are it doesn't matter bitcoin is developing towards quantum resistance you know
um biff 360 paid a merkle route is advancing i think it's fairly likely to get activated on the
network, which opens up the door to building quantum resistant new crypto into Bitcoin,
right? So that's like step one is actively happening. And why is it happening? Because
it's actually a good change for Bitcoin. And pretty much everyone in the Bitcoin developer
community, there's like a couple of very tiny exceptions. But really, pretty much everyone's
on board with that change. And it does move in the direction of quantum resistance. Does it matter
that it's quantum resistant? Not to me, but it does to some people. And that's okay. And we'll
see that continue right there's as as other cryptographic research is done and as we get
to the point where some alternative cryptographic primitive is appropriate for bitcoin i think it's
absolutely a good thing and i think almost everyone agrees to have
people to give people different ways to secure their coins depending on their goals
right so someone who's trying to secure their bitcoin for some kind of uh dynasty trust let's
say, they might want to put it in a way where it's secured by both elliptic curves, and let's say
hash based signatures, because they want to not they don't care about the signing cost when they
go to spend that Bitcoin, they care that it is almost 100% secure for 100 years. And you really
can't get 100 year security from one cryptographic assumption, you need a couple of and so I think
bitcoin is going to go that direction i think like that's that's my take is just let's do the
right thing for bitcoin and in the long term the right thing for bitcoin is also going to happen
to make quantum resistance an option uh we just don't need to to rush and as you said there's a
there's a big risk to rushing you know satoshi notoriously chose a elliptic curve specifically
that wasn't published by nist to help mitigate the risk of kind of a backdoor crypto going into
bitcoin um and right now people are like no let's push this nist published post-quantum
architecture into into bitcoin and everyone who knows what satoshi did is is kind of no let's not
let's not put the nist thing in let's develop something from our own first principles that's
appropriate for bitcoin and when we have something good we'll put it in yeah and that seems to be
what jonas and mccall are doing with shrinks plus yeah jonas published uh shrimps uh last week
which is sort of an advancement of shrinks plus because the way i understand it shrimps
um if you were just doing pure shrinks plus private key um but transferring a private key
or recovering a private key on another physical device would be quite burdensome but shrimps
makes it so you can begin recovering seeds on multiple devices using the same seed phrase
in a way yeah exactly i actually wrote it wrote it up for optech so check out optech tomorrow
morning and i summarize shrimps and also some other work on post-quantum crypto by conduition
about isogeny based crypto for optech and that'll come out tomorrow morning so there's two new
post-quantum uh systems detailed in optech tomorrow by me like so you i'm the anti-quantum
guy but i'm out there actively doing the the work to publicize the post-quantum stuff because like
i said we need it eventually regardless of quantum and so what are your thoughts on shrinks plus and
shrimps like is it a solution or is it a step towards the solution they're like okay you know
So it would significantly impair the development of things like Lightning and PayJoin and Taproot and all the cryptographic primitives that we rely on, Frost and Mucig, and even the MPCs that are kind of non-Bitcoin specific for multi-signature and threshold signature.
Any of these would still significantly impair those.
um so i think jonas's work and blockchain research in mikhail is exceptional and it's
definitely moving the state of the art forward but as of now i would be hesitant to put any of
these in bitcoin um because of the combination of their size which would impair the number of
transactions we could do if we were to use them and the fact that they're not really compatible
with our existing wallet infrastructure that people are depending on um i wouldn't be upset
If other people in the developer community thought they were a good thing to add, especially if we're thinking about, as I said, a world where we do have multiple crypto systems available in Bitcoin and people can choose whether they secure their coins with one, the other, or both, potentially.
I'm not going to be mad if they go in in that context.
uh i think the shrimps in particular shows a lot of promise in that it
i guess the the way i would put is that it's close to compatible you know it works decently
well with as you said being able to restore seeds on multiple devices and the ways we use bitcoin
for real uh while still being not so huge that it completely destroys the usability of the chain
or requires massive block size increases or something uh so i love the direction that
jonas and crew are working there and i hope that it just continues and we kind of take our time
getting something better than these before i put it in that's my hope yeah and then there's the
whole discussion around hash based and lattice based i know jonas and mikhail are working on a
lattice based um research paper right now and so what's the i guess what's the um consensus or
lack of consensus around which direction to go in when given those two directions,
when given those two options? I think the consensus right now is if for some reason
we decide to or need to do something in the near term, let's say the next five years,
it would probably be something hash based because it doesn't require any new cryptographic
assumptions. It relies on things we already trust and know in Bitcoin. With the downside that hash
has has certain downsides in terms of calculating keys that make it harder to use with our existing
infrastructure in various ways um so yeah so hash based would be the thing to do soon
lattice based requires some new cryptographic assumptions but has definitely certain benefits
in terms of the the flexibility of the math i don't understand it as well if i'm being honest
i haven't read deeply about it um and then the other the other piece actually the fraptech
tomorrow is about isogeny based crypto which is a whole different kind of crypto that also is
quantum resistant but also requires a new cryptographic assumption but it works on elliptic
curves still but using a different kind of key that's not vulnerable to quantum uh so i think
if it's not hash based we don't know what it would be it could be lattice it could be isogeny it
could be something else and research should continue and is continuing to kind of get to
the point where we could do something other than hash based and my again my hope is that
we have much more time than the quantum uh doomsayers are predicting and we can get to a
really good alternative crypto system um that broadly works within the bitcoin ecosystem and
supports all the stuff we want you know whether it be signature aggregation or silent payments or
or hd wallets like whatever the stuff we wanted we want a crypto system that supports that
um and i think the research is going quite rapidly towards having some options there in the next
let's say maybe 10 years yeah and so it seems very reasonable it seems like a very reasonable
approach to upgrading bitcoin and again that's been the most frustrating thing it's like devs
do something bitcoiners aren't focused on this it's like the research is being done like what
i mean i can't speak for them but that's what i've been trying to figure out is like
what pace would be sufficient for you guys like what changes do you want to see and then there's
a circular logic where it's like hey we're working on this like give us feedback on um the the work
that we're doing whether or not you think it's sufficient for the security that you deem necessary
for these quantum advancements that are being made and if you don't agree like do you have a
solution and if so will you propose it and they're like we can't propose it because bitcoin core is
controlled by a cabal of five or six developers so we'd never even propose it because we get
rejected immediately it's like well is is this productive at all like what is going on here
yeah yeah and i think what what they're actually saying and what they're reflecting when they say
that is that they're they know their crypto proposal would be rejected for for good technical
reasons and so it's not it's not oh core is this cabal it's really uh bitcoin core holds the line
on the quality of technical contributions accepted so high that nothing right now, no
new crypto system for Bitcoin right now meets the bar.
And that bar, of course, can move if the threats to Bitcoin's existing crypto system get closer.
And so that's, I think, where the disconnect is, let's say, is that no one in the Bitcoin
kind of core maintainership has yet come out and said, the sky has fallen, quantum is in
three years, we have to do something now.
and if we had to do something right now then some of these existing crypto systems would be
but the cabal won't accept them because they're not really good enough and they'd only be accepted
if it was an eminent imminent threat well what is good enough in the eyes of the people who do
believe it's an imminent threat do they have solutions because that's the one i haven't seen
like a yeah they've said basically that we should just take a sphinx plus into bitcoin even though
the signatures and keys would be combined like 10 kilobytes per spend or
something like that.
And like,
that's not a completely unreasonable argument if the thing really was around
the corner.
Now Sphinx plus is a NIST standard under the name SLH DSA.
I think it is.
So,
so like the question is,
is the sky falling enough that we would accept an unmodified NIST standard
into Bitcoin?
with these significant tradeoffs and having like 100x the the the key signature size versus our
current crypto system and i think as we discussed at length here the sky is not falling nearly
enough uh to accept that kind of a trade-off okay so it's not that's the one thing i've been wondering
i thought like i mean you mentioned alex pruden he's with project 11. um they're helping blockchain
systems uh transition to post-quantum or i believe working with slana and ethereum i i was curious
if they had a specific um solution that they're they're putting forth for bitcoin that um
i don't know if they specifically have one yeah that's targeting bitcoin directly they they
published a paper on some improvements they've worked out i think it was lattice based where
where it does support a lot of the bitcoin wallet infrastructure um like i said lattice has
more key math ability than hash based stuff um so yeah i think if they were to propose something
for bitcoin it would be probably lattice based and the bitcoin folks would currently say
the lattice stuff is too new and we don't yet fully trust the cryptographic assumptions it makes
for bitcoin we'd want to see more time more more threat modeling more proofs more different systems
based on these same assumptions that all are shown to work you know that's the kind of thing
we want to see for bitcoin uh we don't want to put a new system in that's that's vulnerable to
some classical attack in the attempt to defend against a quantum attack yeah and this was similar
to what would happen i mean you mentioned ecdsa was chosen for a certain reason snore was on the
table but i believe it was patented at that point and i think satoshi even said hey it probably
needs more time to be in the wild before we adopt something like snore and then what was it 13 14
years in to the protocol snore was included into um including into bitcoin yeah exactly
There's a track record here that Bitcoin, it's so strange when they're like, Bitcoin should this, that, that other thing.
And demonstrably, Bitcoin has a conservatism that is appropriate and will adopt new cryptographic primitives or assumptions as appropriate to the protocol.
um one thing that relates here is it's interesting to see the difference between centralized things
and decentralized right so centralized systems can just upgrade their crypto they can take a
new assumption and if it goes bad they can turn it off and that's a low cost thing when you're
a centralized system and so they they have a different math here where if it's easy to change
because you're a centralized system then the risk of taking a bad assumption is much lower because
you can just change again but bitcoin isn't like that right bitcoin is a massive global distributed
decentralized network and so the costs of taking a bad crypto system into bitcoin are much higher
than for something like solana or for google internally or some web server you know some
web server turns on slhdsa today they can turn it off tomorrow and that's okay for them we can't do
in bitcoin no we can't and that's i again the more frustrating and bitcoin gets picked on that's
like and that like being honest and i'm happy you said that because that's one thing um that i think
bitcoiners who don't believe it's a big risk like the whole line of like and i used to say this to
hand up of uh of if quantum comes like bitcoin's not the only thing at risk like yes that's true
but to your point like all these centralized systems can trivially incorporate and um
rip out these cryptographic systems rather trivially because they're centralized like
bitcoin does have a big um unique problem in the sense that it's a distributed system we need to
a consensus once we put something in it's hard to take it out and um the risk factors to bitcoin are
are certainly unique and arguably higher than they are to other systems
yeah so we have to pay attention and we have to move at the appropriate time for sure yeah and
to your point about lattice space i just wanted to bring this up that's why i'm looking at my
other screen over here because we wrote about it yesterday but um going back to like lattice
based schemes and the fact that they're not as battle
tested as some hash based solutions. So lattice based
schemes offer advantages and verification speed and signature aggregation, but the carry tradeoff,
they rely on newer mathematical assumptions that haven't been battle tested as
long as hash functions. In fact, NIST tested 69 post-quantum Canada
algorithms during its standardization process, and two of them,
Rainbow and Psyche, were broken with classical computers during testing.
um and so that's four what would that be that would be like five four four and a half percent
or less than that like three and a half percent of these or maybe like yeah three and a half
of these uh of these post-quantum lattice-based systems were proven to be insecure and so like
that's if you're going to incorporate a lattice-based system into bitcoin you have a three
and a half percent risk of it being uh insecure i think that's pretty high for a trillion dollar
network as well yeah for sure and that's i mean this gets back to
what i was saying earlier like what's the line in the sand like how do we have a
a more level-headed conversation about all this with with the uh the people who are
convinced that this is coming faster than than we are yeah i mean my best way is is to to
rely on on evidence-based decision making and that's why i keep posting kind of every few
months i guess i probably post something about i'll worry about quantum when i see like here's
a list of things and i think it's uh scaling over two generations less than exponential scaling in
the time needed to solve progressively larger keys on the same crypto on the same quantum system
and um beating classical in any cryptographically relevant even small size problem and and to date
none of those three things have happened in any quantum architecture and and so there's there has
to be evidence we we can't as i i joke about it being unicorn fart based engineering but
the reality is that anybody can fud anything about Bitcoin. And if we can be caused to make
a change to the protocol based on claims and not evidence, then Bitcoin is vulnerable to
the most obvious of attacks, right? Bitcoin can't be subject to change without evidence that it
needs to. That simply doesn't make sense. And so we can set a pretty clear evidentiary standard
for when a quantum architecture
shows these three or maybe four,
like people can argue about
exactly what the criteria are,
but we can set pretty darn clear standards
for the evidence required
to start taking immediate action.
And of course, in the meantime,
we're going to take progressive action anyway.
So it's not like this is a,
oh, we're going to do nothing until,
it's just, we're going to take
a slow and steady approach
until there's this level of evidence
that we have to move faster.
Yeah.
And do you think,
what yeah we have to think of opportunity cost too right like what else could be could we be
working on in bitcoin that is necessary in a low-hanging fruit that um undeserved attention
to the quantum question could take away from yeah that's a really important point and i think even
more than not working on the right things it's it's essentially flooding the amazing innovations
that are still kind of nascent, not widely deployed in Frost and Silent Payments and
Mucig and even DLCs, you know, all of these things are classical elliptic curve based
protocols that are really valuable for Bitcoin.
You know, Craig Raw is working on getting Silent Payments into Sparrow Wallet recently.
Coldcard just shipped Mucig2 support.
And these things strictly depend on the existing elliptic curve cryptography.
And they're great.
There are huge improvements in the usability of Bitcoin in a couple of different ways.
I'm not going to get into them because it's not important right now.
But when you're saying we need post-quantum tomorrow, people just say, well, then why would I bother developing silent payments or Mucig when we're going to replace the existing crypto in a year?
You shouldn't, if that was true.
And so I think it is very important that we push back on this quantum FUD and say, look, as of now, there's no evidence that we'll be kind of replacing the basic elliptic curve cryptography in the next decade.
So we should keep building silent payments and music and frost and DLCs and everything based on the existing cryptography.
It's going to be around for a long time.
So keep building.
Yeah.
It's also tiresome.
Do you think this is a social attack or?
man i don't know intentional intentional social attack i guess if you believe the quantum's not
not uh coming as quickly as they believe it is a social attack but i guess the question is intent
i i tend to be optimistic on people's motivations and that's i don't i don't think so i think it's
it's more just that that people love to panic and i mean we've seen that in the real world in so many
ways in recent years the the need to panic i think it relates to the fact that life is too soft
people don't do hard things and so they they need to find things to be worried about to
to satisfy their their nature their natural like evolutionary need to be worried about something
uh and so we just get prone to panic and it's easy to to rile people up with this stuff
yeah um any parting parting notes here anything we didn't touch on that we should probably mention
as it relates to this quantum discussion.
Oh, I already shilled it once, but I'll shill again. Read Optech. I write the Changing Consensus
section of Optech every month, and I think it'll actually put you more at ease about quantum,
because we cover quantum a lot in there, and you'll see the kind of remarkable progress being
made, which very likely means that long before, possibly never, but long before even a realistic
time frame for quantum assuming it started scaling today i think long before it gets to a production
uh relevant quantum computer we'll have a better system in bitcoin like it's happening actively
well this will be published the day after optex published so you're not uh you're not um
spoiling anything is there any specifics you want to expand on there oh sure um so i read
this developer Conduition has been posting a lot about cryptography to the Bitcoin mailing list
recently and to Delving Bitcoin. And he did this big write-up earlier this month or last month,
I guess, about isogeny-based crypto that I mentioned earlier. And he basically made the
argument that Bitcoin developers should be paying attention to it. And so I read his whole thing
and wrote a summary for Optech about it.
And isogeny-based crypto is very interesting
because unlike hash-based or lattice-based crypto,
it's only about twice the size on-chain
of the existing elliptic curve stuff.
And part of that is because it's also elliptic curve-based.
But unlike our existing stuff,
it doesn't depend on the hardness of reversing points
to keys, to secret keys, in order to be secure.
It has a totally different security assumption.
It just based on the same shapes of curves on a,
on a graph.
Right.
And so I think that is very promising.
And I think people should read conductions whole post if they're kind of
even technically interested in this kind of stuff.
Cause he,
he does a great job of,
of bringing it down to a place where Bitcoiners who kind of understand
elliptic curve cryptography,
the classical kind can also understand isogeny based cryptography.
And yeah,
But because it also works on elliptic curves, some of the machinery we already have in Bitcoin could be applicable to it. So we kind of take a new cryptographic assumption for the hardness, but we can use some of the same optimized elliptic curve math that we have already to work on these systems.
and so that might be promising for bitcoin um you know if i'm being totally honest about it i i
would guess that if isogeny based crypto were to come to bitcoin we would probably still want to
do something that's not elliptic curve based as well as a backup so that if there's a fundamental
break in elliptic curves themselves which there hasn't been any evidence of it yet um we'd have a
fallback fallback um but it's just promising to see a totally different avenue that's not lattice
not hash also being brought to the fore and i'm glad i got to write about it oh yeah do you think
there's enough um top tier cryptographers well versed on these subjects focused on bitcoin
do we need more uh not an isogeny based crypto yet and that's exactly what conduit writes about
is that more bitcoin folks should be looking at this and and seeing if it's suitable because if
it's suitable it would have a lot of really good properties that that apply to bitcoin and let us
keep using bitcoin the way we want to yeah it's great to know thank you for uh all your work on
the front lines of having the conversation and uh helping add context because again as somebody
who's not well versed in quantum physics and uh knows enough to be dangerous when it comes to
cryptography it is uh i don't want to say it's easy to get bamboozled but it's easy to begin
questioning and you should always question but um getting a well-rounded perspective on both sides
of this quantum debate as it pertains to bitcoin i think it's important you've been doing an
incredible job of providing much-needed context thank you yeah i love fun busting it's been a
hobby for a long time so glad to be out there doing it on a new topic awesome uh where can
people find out more about what you're working on yeah check me out on x usually at reardon code
um i sometimes post on the mailing list as well and um if you're building a wallet i offer
consulting reviews and stuff for bitcoin wallets and similar kind of on-chain bitcoin stuff uh
and you can just hit me up on on x about that my dms are always open all right awesome brandon
i hope you enjoy uh enjoy your day and uh hopefully we can do this again you too man
well uh great talking we'll draw a line in the sand we'll say if uh quantum hasn't progressed
in six months six months yeah i'm kidding um peace and love freaks okay thank you for listening to
this episode of tftc if you've made it this far i imagine you got some value out of the episode
if so please share it far and wide with your friends and family we're looking to get the
word out there also wherever you're listening whether that's youtube apple spotify make sure
you like and subscribe to the show. And if you can leave a rating on the podcasting platforms,
that goes a long way. Last but not least, if you want to get these episodes a day early and ad
free, make sure you download the Fountain podcasting app and go to fountain.fm to find
that $5 a month, get you every episode a day early, ad free, helps the show, gives you incredible
value so please consider subscribing via fountain as well thank you for your time and until next time
