TFTC: A Bitcoin Podcast - #733: The Truth About The Quantum Threat with Brandon Black

Episode Date: April 4, 2026

Marty sits down with Brandon Black to discuss the realistic timeline of quantum computing threats to Bitcoin, the gap between theoretical breakthroughs and physical implementation, and why rushing pos...t-quantum cryptographic upgrades may be unnecessary and risky. Brandon on X: https://x.com/reardencode Rearden Code GitHub: https://github.com/reardencode STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/VJ2dABShBz Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Bitkey https://bitkey.world/ Bitcoin 2026 - Las Vegas http://bit.ly/3NA9xQh OPNEXT https://tinyurl.com/tftc2026 Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/

Transcript
Discussion (0)
Starting point is 00:00:00 you've had a dynamic where money's become freer than free if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting like safe haven i believe that in a world where central bankers are tripping over themselves to devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean And that's part of the bull case for Bitcoin. If you're not paying attention, you probably should be. Brandon, welcome to the show, sir. Thanks. Good to see you, man.
Starting point is 00:00:41 Good to see you. I'm very happy to get you on to talk about quantum, the risk, the perceived risk, the perceived reality. What is the reality? Maybe that's where we'll start. And I'll reiterate what I was saying right before I hit record, which is it's hard as somebody who's not a quantum physicist, is not a cryptographer to really get a grasp of what the true reality with advances in quantum computing are and specifically how they relate to Bitcoin's security in the short, medium and long term. uh and i've watched you on the front lines of of sort of debating the merits of the advancements in quantum physics over the last year i actually listened to your podcast that you did with uh gwerdy last year i thought that was really good and that helped me um that helped help me get a
Starting point is 00:01:36 better understanding of your perspective but i think um starting with this question of how can you be confident on one side of the other how can you be confident that it's not as big of a risk quantum computing is to Bitcoin today. And then conversely, like, why do you think people are saying we need to rush to become quantum resistant or as confident as they are right now? Yeah, I mean, I think the thing that gives me confidence, and I said on Guardian, I think I still stand by it. You know, I can't I have an emotional confidence that we're 50 to 100 to forever years from
Starting point is 00:02:15 a quantum computer breaking a meaningful cryptographic system but that's not scientific that's that's a gut feeling looking more kind of in a scientific lens at it we we live in a world constrained by the reality of physically building things and it's hard to physically build things that doesn't make any particular physical building challenge impossible but the i think the quantum field is full of these, you know, we'll call it if this is possible, then all we have to do is build it kind of perspectives. And they totally just deny the realities of the difficulty in building physical things that manipulate tiny subatomic particles, or in the case of neutral atoms, you know, individual atoms being manipulated by laser tweezers, I think they're called or
Starting point is 00:03:03 optical tweezers. Like, these are incredibly difficult things to build, and especially difficult to scale, right? Let's say you can build the first optical tweezer and manipulate one atom. Okay, now you want to build a grid of thousands of atoms and manipulate all of them with different tweezers at the same time. Think about how that difficulty scales. And so maybe it's possible, which is the thing I have to acknowledge when I'm being reasonable as opposed to emotional about this. But the difficulties are dramatically underplayed. And that's what the evidence shows. I think that's what people kind of don't acknowledge as the reality. When they look at quantum, they're like, oh, all we have to do now is scale it up. But we've been working on
Starting point is 00:03:44 quantum as a species for 40 years or something, as long as I've been alive. And every time they go to scale it up, they hit new difficulties that they weren't expecting. That's the evidence we have is it's been over and over and over and over for decades that scaling up is hard. That doesn't mean it's impossible, but the hardness is what gives me that confidence, is that based on the evidence we have seen for decades, repeatedly and consistently, they may find a way to scale it up, but it's going to be clawed out by individual small improvements over years and years and years. And at some point, they might hit on a technology that will work. And when they do, we'll see that technology go from five logical qubits incoherence for a while to 10 incoherence for a similar length
Starting point is 00:04:34 of time to 20 to 40 etc we'll see doublings like we saw with transistors of the same technology progressing through a scaling roadmap and then we'll be able to say oh now it's doubled three times it took 2.5 years each time to double the number of logical qubits in this technology okay So at that rate, we'll get to a cryptographically relevant computer in Y years. But until we see a roadmap like that, that's the successful scaling in one technology, the evidence is it's going to be just hard fought, tiny wins, new technologies. And there's just no evidence that it's going to come anytime in the next decade or really any time in the next 20 years.
Starting point is 00:05:14 So that's where my confidence comes from. On the flip side, because you asked the other side of the question too, I think the other side gets their confidence from the let's say the impressiveness of the wins they do get these are incredibly difficult mathematically challenging algorithms and designs and the folks working on them are some of the most brilliant people in the world and and they go through the fundamental physics of our world they go down to the very smallest subatomic particles they figure out how things work and then they say oh my god i figured out that we can do this in this easier way or in this faster way or this new method of manipulating subatomic particles and those
Starting point is 00:06:02 discoveries are absolutely amazing and they're they're the cutting edge of humans understanding our own world like there's there's nothing more impressive than that and so it's a reality that these are these are the most brilliant people doing incredible work to understand our world and people get really excited about that and so that's where they get their confidence is that the most brilliant people are working on that problem but that doesn't change like there's still the separation between the it's it probably literally possible which is their perspective i don't think it is but in their world it's probably possible and these fundamental understandings of the universe give them confidence that it's going to be solved in the real world in physical devices
Starting point is 00:06:44 and that's the so the way i understand it let me know if i'm wrong because i did see you retweet my understanding of it the other day which is like hey i think it's very obvious that in the theoretical realm of like what is possible they are making advancements and the biggest sort of chasm that exists in reality which i think you just described but trying to distill it down for an eli5 for people listening is that yes we're making these theoretical advancements of what we can do however there is a chasm between what we can do and the physical reality of building machines that can actually sustain an uptime and persistence to make that theoretical advancement a applicable reality yeah exactly and i think that in quantum there's this
Starting point is 00:07:38 like extra well there's extra detail to it which is um it's often possible to build call it the toy example of something where you know that we've seen superconducting qubits we've seen neutral atom qubits we've seen uh shooting the other technology that's kind of commonly pushed right now but there's a bunch of different technologies that where they've built a built a few useful qubits and done something interesting with it um but again the the specific thing that happens is is that taking that and going to the next step and building twice as many qubits or four times as many qubits and and they keep running into problems there um so so that i think that's also where they get their confidence is oh we built that thing the physics described
Starting point is 00:08:21 it we built it but then they tried to build a slightly bigger one and they hit a brick wall and we even saw like the way these things are published the majorana paper from microsoft kind of glossed over that and and when you dig deeper the the physical device that they were publishing about had a single i think a single physical qubit or or something of that like tiny tiny nature it's like oh they built the first qubit of this type using that's the tech i want to mention uh using a majorana particle okay super cool you got one bit of that now what happened trying to scale up and why has it now been almost a year since that result with no one building a two majorana qubit device like what's the deal well i think this is important detail to
Starting point is 00:09:06 dive into too is like the difference between a logical qubit and a physical qubit and the relationship between the two because from what i understand logical comes down to the math and what you can do and the physical is like all right like how do you organize all that and make it a computer an operating software whatever it may be yeah you're right and it's a complicated thing where depending what your physical underlying technology is that affects the relationship between the physical and the logical qubit so there's like different avenues of research happening in in quantum there's the mathematical research which is assuming we have logical qubits mathematically how do we apply that to solving real world problems that's what google published
Starting point is 00:09:54 about this week right they published a paper that says here's some new mathematics we could apply to running shore's algorithm on logical qubits that makes it take fewer logical qubits to execute shore's algorithm and in this case also fewer steps of computation um that's the math side but that all runs on logical qubits and then the question is how do you organize some physical device into logical qubits on which you can run math. And that's where the physical qubits come in. So the other paper that came out this week on neutral atoms was a new way of error correcting physical qubits to make useful mathematical logical qubits. They, within the context of this neutral atoms architecture that uses the optical tweezers to move atoms around, because they can
Starting point is 00:10:43 physically move the qubits around they can grab a physical atom that's a qubit and has been entangled in some way with some other qubit and they can move it to another part of the chip that's or the device that's the the cool thing about it because of that they can do what's called non-local error correction and the theory described in this paper is that because they can do non-local error correction because the physical qubits can be moved by optical tweezers they can do what they call high rate error correction where uh rather than having to have like a dedicated cluster of error correction uh qubits call it for each logical qubit you've got like a bunch of physical qubits error correcting each other to get one logical qubit instead in this neutral atom architecture
Starting point is 00:11:26 with the optical tweezers they can in theory uh have one cluster of like error correcting qubits that corrects a whole bunch of kind of active computing qubits and that's why they got that remarkable result in the paper of basically if this high rate non-local error correction works we can go down from 500,000 to 10,000 physical qubits needed to implement Shor's algorithm and that's basically my summary of a lot of these quantum papers is if this thing that hasn't ever been done works then we can do this easy thing and that's yeah so that's where the relationship is and how why you see these radically different relationships between number of physical qubits and logical is because it depends dramatically on what types of error correction you can do on
Starting point is 00:12:11 this physical architecture and whether those work and you need to do the error correction because these physical qubits are beholden to entropy right yeah they're notoriously flaky yeah and so that that like on the physical qubit side like we're still trying to figure out a way how to make it so they don't deteriorate in real time right and then also in this neutral atom architecture, again, because they can physically move qubits, they have in the paper, they accept that physical qubits will deteriorate. And they design a theoretical neutral atom quantum computer that has a reservoir of pre-coherent backup qubits that they can grab with the optical pleasers and stuff into the circuit to replace one that deteriorates. So exactly as you
Starting point is 00:12:57 said, these physical qubits, they tend to break down. And so the big question is, how do we stabilize them and make it so that we can kind of continue doing computation on them? And different researchers in different parts of the quantum field have different methods of kind of holding that shit together for longer. And how much energy does all that take? Yeah, I mean, that's the other big question that I think Bob McElworth and I were talking about on X This Morning right before this. You know, if you even if you linearly scale up the energy needed um it's still huge he was saying it's something like 100 megawatts based on his calculations you need to cram into whatever device if you linearly scale up the energy
Starting point is 00:13:38 needed per qubit and based on current technologies um but my point i think is a valid point if you think about the complexity of moving around more and more qubits in the neutral atom architecture or in cooling more and more qubits it's not going to be a linear scaling and we've seen this even with classical computers, that the more dense you make devices, the more leakage you have, and therefore the more energy it takes per bit to keep it cool for supercomputer architecture. And so even let's say it's linear, it's still a ton of energy to cram into a device. And if it's nonlinear, it may become completely intractable to power a device that can do meaningful quantum computing.
Starting point is 00:14:22 So freaks, guess what? Just booked my tickets to Vegas headed for Bitcoin 2026. It's that time of the year, April 27th to 29th in Las Vegas. I'm going to be there. A ton of people are going to be there. You better get your ass there. You know what? People are calling it bear market. These are the best conferences. I've been going since 2019 when it was in a parking garage in San Francisco. If you want to get the best possible ticket prices, make sure you use our link and the code tftc you go to 2026.b.tc use the code tftc you'll get 10 off you can bundle with a hotel room to save big and make the most of your experience staying on site at the venetian that is where i will be ticket prices are increasing so make sure you get yours today join bitcoiners from
Starting point is 00:15:02 all around the world it's a global endeavor it's a it's a pilgrimage if you will for the ultimate networking experience there's gonna be a ton of people there you can hear from the biggest names in the industry sailor's gonna be there matt and i and the pubkey boys and the bugle boys we're going to have live hot style takeover that's going to be there too all in the venetian everybody's meeting up it's going to be fun get there 2026.b.tc use the code tftc at signup sup freaks up next the bitcoin scaling conference where bitcoin developers meet institutional capital is coming to new york next month join bitcoiners from blockstream chaincode brink and more at the can't miss summit at the intersection of bitcoin tech and finance this conference has one of the best signal
Starting point is 00:15:39 to noise ratios and that's why i'll be joining block space's third annual bitcoin tech conference on April 16th at the New York Times Center in Midtown Manhattan. There's only room for 200 attendees and they've already sold more than 100 tickets of their open spots. So you've only got a few weeks to get your travel plans in order from New York. With the ticket, you get access to the best programming and Bitcoin tech from BitVM to BitChat, catered lunch and access to the PubKey after party. Wearing the hat, PubKey after party. Up next is where builders meet capital, founders find funding and companies source top talent. Plus meet institutional investors and developers from blackrock hc wainwright and bitcoin infrastructure corp if you're at a venture
Starting point is 00:16:15 fund or another finance firm this is the event to learn more about the quantum computing leading edge bitcoin tech and topics that will define bitcoin's futures go to opnext.dev for tickets and use the code tftc to get 25 off a general admission or vip ticket to the event again that's up next dot dev go tftc for 25 off a ticket i'll see you there again going back to the confidence of the other of the other side like what do you what do you think what do you think is driving because that's i mean i guess the whole conversation as it pertains to bitcoin is this perceived urgency that is being thrust on the developer community specifically to to upgrade to a quantum resistant cryptographic primitive um that would that would secure uh private keys
Starting point is 00:17:04 uh so that they're they wouldn't succumb to it to an attack via a quantum computer and that that's been like the confounding uh not confounding but it's been sort of the the thing that's really perturbed me is like that you have this very confident and um somewhat uh manic i think manic is a good way to describe it a group of people are saying we need to fix this devs do something right now and it's frustrating for two reasons number one quantum has been thought about within bitcoin since satoshi was around i mean he mentioned it um if you've been reading mail if you've been reading the mailing list and looking at some of the research being done like there are people um trying to figure
Starting point is 00:18:00 out like okay if quantum computers do come what's the best way to transition to a quantum resistant address structure uh and there are a ton of not only coordination issues but standardization issues that exist there's a ton of uh for lack of a better term tech tech debt that exists like if you are going to transition to a quantum resistant address structure that is going to disrupt a lot of the uh a lot of the infrastructure that's been built today so you talk about the lightning network uh psbts multisig all this stuff like you need to think through like how do we transition to this address structure with without disrupting all that if possible and if that is going to be disrupted like what do we do uh and the the my biggest worry is that you rush a change
Starting point is 00:18:53 uh and it just not only disrupts all of that standardization that infrastructure that's been built to date but you haphazardly rush to to a change that has been well thought through well tested and leads to a bigger fallout in terms of disruption to the network than having done nothing because quantum potentially doesn't manifest on the time scale that these people are saying it will. Yeah, I mean, I think it's a legitimate risk. And frankly, it's why it's one of the reasons I try to stay on top of all of this, because let's we should be realistic here.
Starting point is 00:19:29 The most likely outcome is that at some point, SECP256K1 or elliptic cryptography in general will fail. Like that's the most likely outcome. I don't think personally that it's quantum that's going to break it, but cryptosystems have failed over the years. We've seen it, and it seems likely that at some point it will. So what do we do about that? And so I try to stay up on what the other kind of new cryptographic research is so that when there's something suitable for Bitcoin that can support all the infrastructure we have, wallets and lightning and everything that you mentioned, we should actually add it to Bitcoin. And we should maybe even do that before there's a real threat so that people have options.
Starting point is 00:20:16 And that's fine. That's good. There was a whole discussion on the mailing list about the benefits and downsides of having options. And I think Peter Willa is a bit concerned about people having options because there could be fighting over what the correct option to use is. I'm less concerned about that because we already have that essentially where some custodians use MPC that's kind of cross crypto. I think Coinbase does and others, but some custodians use on-chain multi-sig, right? That's fine. It's okay for different people to choose different trade-offs and how they secure their coins.
Starting point is 00:20:49 So yeah, if we have suitable cryptography, we should totally put it in Bitcoin. And there's a decent argument to say that we're getting very close to having something suitable to add, at least as a backup in the work that Jonas Nick and blockchain research and others are doing. So I'm not out here saying we shouldn't do anything about the potential break of SecBee 256k1. And I think that's where, kind of to your point, these confident, almost manic people in the quantum side are like, devs do something. Well, the devs are doing something. Even people like me that don't believe in quantum at all are out there doing research and evaluating research on what we could use as another crypto system for Bitcoin. And to chill out, I guess. Well, not only that, it's like you're they're treating Bitcoin core like any Bitcoin developer is a monolith, like go do something.
Starting point is 00:21:40 it's like well there's there's only so many people are qualified to understand like quantum physics and the cryptography sec p256k1 like that's like a very niche part of like the bitcoin development process like obviously you have the p2p layer you have the wallet layer you have the gui you have many different facets of of the protocol that make up bitcoin and like finger wagging at the whole dev community like do something it's like well not everybody within the developer community is going to be able to do anything about this because they're not like their their core competency isn't the cryptography and taking it further like making the crypt cryptography quantum resistant like there's very few people that are equipped to
Starting point is 00:22:26 work on this particular problem and to your point and what i've been saying for the last six months since this this has become a huge meme is like the people who are um equipped and able to do this work or seem to be working on it maybe it's not the pace that you want but you can't pull out a whip and make them work faster nor would you want to like yeah there's a great post uh stew stew txo out there uh but there's other like since since this post it was in december uh there have been five new uh post quantum cryptographic algorithms published and zero new numbers factored by an actual quantum computer and i just thought that was that was so great it's like so so really we're we're upset about the rate of progress when month to month to month we're
Starting point is 00:23:14 seeing new algorithms that are kind of progressing the state of the art for post-quantum cryptography in bitcoin and no new physical quantum devices being built that run real algorithms that could maybe even someday break bitcoin uh no i think the progress is at a good pace we might even be over investing if you if you ask my honest opinion yeah well i think i saw something yesterday where somebody's saying like you could do the factoring of these numbers by hand faster than the quantum computers could right now yeah i checked with my six-year-old and i see seven now anyway uh and he can he can factor more numbers than a quantum computer for sure i actually just set my six-year-old up with the synthesis math tutoring that app and he's been playing with it
Starting point is 00:23:56 I actually did see him factor some numbers this morning that were faster than a quantum computer. But again, so the Google paper specifically, I think it's another thing to touch on, is the fact that they didn't actually release the results. They released the zero-knowledge proof that they had done something and said, basically framed it as like, we didn't want to release the results of this
Starting point is 00:24:23 because we don't want black hat quantum developers to get access to this and um to to go build a computer that disrupts the world and then um the advocates for this paper were saying well now this this is the warning like they're they're not going to tell us the the advancements that they're making because they're worried about releasing them to the public because it'll be used against us by nefarious actors um is this a marketing scheme a way to develop a budget or do you think there's some legitimacy here that the smartest people in the world work on this problem are truly worried that we're hitting an inflection point a tipping point that could accelerate the progress being
Starting point is 00:25:04 made within quantum computing so it it's it's a really interesting problem to think about i i had that moment of pause as well when i read the google paper um the thing about the google paper, though, is that there is no fundamental physical change that they're publishing. Like I said, they published a mathematical change, which reduces the number of, sorry, it reduces the complexity of the physical device you need to build in order to run this algorithm. But no one actually made a more complex physical device. So Alex Pruden, who I'll be debating at Bitcoin++ Plus in a couple of weeks, I think actually looked pretty cogently about this. Of the pro quantum guys, he's one of the more pleasant to talk to.
Starting point is 00:25:51 So I'm glad I'll be talking to him at Bitcoin Plus Plus. And he was pointing out that let's let's say, you know, right now we're at five ish logical qubits have been demonstrated in a very short, like microsecond duration coherence. OK, well, what if through the mathematical improvements, we get to the point where it only takes just 256 logical qubits in coherence for only five milliseconds in order to run Shor's algorithm on a Bitcoin private key or public key to get that private key. You know, if they, on the mathematical side, compress the time and the number of qubits so much, then we could see a situation where it's very much in reach of the physical progress.
Starting point is 00:26:34 So if physical progress is zero, but the mathematical progress is extreme, we could see it break kind of in that direction, where the mathematical progress brings it down to the point where the physical guys have a very short step to take. And that's a great point. Now, that said, the Google paper puts us about six orders of magnitude away from the needed coherence time and about three orders of magnitude away in the number of qubits that need to be in a physical device. So I don't know how you want to look at those two different dimensions of orders of magnitude, but we're somewhere between six and nine orders of magnitude of improvement on the physical side away from implementing Google's paper.
Starting point is 00:27:12 So we need to be really realistic that, yes, eventually the mathematical progress could bring it into reach of the physical, but we're still very far away from that. I guess that begs the question, what are the advancements from an order of magnitude perspective on the physical side been like in recent years? like is that a big a big leap um it's obviously it is but have the advancements over the last 10 years was it 100 orders of magnitude away five years ago was it a thousand and are we now getting to the point where six to nine may seem big but it's not that big we haven't i mean even the the best kind of longest held stable devices have up to a couple thousand physical qubits which is maybe a one or two orders of magnitude improvement in the last 10 years um but but i i hesitate to even say that because i think it paints it a little bit too rosily for the physical quantum
Starting point is 00:28:18 guys um because the the biggest improvements have come by implementing whole new architectures And so there's no evidence right now that any single architecture can increase the number of physical qubits. And that's where I think the pro-quantum manic folks get way over their skis. They're like, all we have to do is scale up. but you can't just scale up when every scale up that you're doing so far for the last many decades has been because you developed a whole new architecture right you're like you're just discovering a whole new set of problem spaces because you're developing a whole new architecture still uh and so i made it very clear in like when would i start to think we need to take action in bitcoin and that's when we see a single quantum architecture increase the number of qubits you can hold incoherence for a longer time, over several cycles, at least two, we need to start
Starting point is 00:29:15 seeing a trend in one architecture scaling up. And then maybe it becomes just a scaling problem where we just have to do the decades long industrialization to go order of magnitude, order of magnitude, order of magnitude. Now we need to start taking action. But until you see that they're like, oh, okay, maybe maybe this one is going to be the one. But until there's evidence that it actually scales why would you take any action we don't have the evidence to say to justify action yeah and that's where it gets very confusing i think that's um in the most disconcerting thing observing this over the last year as is the narrative around the quantum threat to to bitcoin has um hit the market is like again i'm not a quantum physicist i'm not
Starting point is 00:30:02 a cryptographer i um know enough to understand like i can explain like a logical qubit does like the theoretical algorithm the physical um qubit sort of creates the space where that stuff is is um is computed for lack of a better term and i understand that there is a coordination on the physical side and energy needed and it seems clear to me that it's not where it needs to be and not anywhere close to where it needs to be to effectively run this stuff persistently to wage the necessary attacks but then again going back to the confidence game and um i hate to say like the sky is falling sort of um perspective uh that is very reminiscent of like climate change and things that i'm just using like psyop pattern recognition and it feels like that to me it could
Starting point is 00:30:55 be wrong using heuristics here um again don't understand the math and not a physicist by any means study like economics um but yeah i think that's the narrative side of things it's very very easy to socially attack people and it feels i'm not saying that i i do believe the the other side is earnest in their beliefs and that that's like the interesting part of this whole discussion and observing it over the last year is like they're so ardent on their beliefs and people who are just skeptical like hey i believe that you're genuine but i'm not seeing it and uh there's this there's this like narrative leverage this asymmetric leverage they have because they can project fear onto the market and if you're not afraid you're you're not doing enough and you're
Starting point is 00:31:44 actually stupid yeah i think it's the classic the classic fud game um and then it does make it hard to distill so i that's again like i didn't want to be i'm not a quantum physicist by the way i'm just a person with engineering background and with a lot of experience for many decades of reading research papers so so i i come at it not as an expert in in the particular field but as someone experienced in reading papers and kind of understanding the real implications of what some new publication means um so yeah so i think one thing i want to say from from what you're just saying is that i recommend really that everyone go read the papers because in many cases the papers that underlie the the big manic posts about quantum the sky is falling the papers are much
Starting point is 00:32:32 more conservative in what they claim now this google one is kind of an exception to that but I think that's also a good way to gauge the progress in quantum computing is, is look at what the actual results in the papers are that justify these very high excitement posts in social media and in kind of science journalism, let's call it. And what you'll find is that the real results being published in the academic papers are small, like little nuanced improvements in things. And again, this Google paper is kind of an exception to that, but the vast majority are, especially on the physical side, actually, I think exclusively that's true on the physical side, they're these small progressive improvements. And so you can kind of tell where we are in
Starting point is 00:33:18 quantum computing by the fact that what gets the hype in the social media and science journalism side are these tiny little improvements on the physical side. Okay, so if that's what gets the hype then we are a long way from getting all the way there because when we're getting close you're going to see the majorana article the majorana particle architecture scaled up again and now went from x logical qubits to y for the third time in three years and we're going to see like oh these are big improvements the the they're they're building devices that can run shore's algorithm on bigger and bigger uh even if they don't really run it to be to be fair they don't have to run the actual algorithm, but the physical device is capable of running it on a key this big
Starting point is 00:33:59 on a key that big, you know, you'll see, I guess, bigger results actually being published with less hype. And right now we're seeing tiny results published with huge hype. And that's one of the ways to kind of tell how far we are and how much it is just hype. So freaks, this rip of TFTC was brought to you by our good friends at BitKey. BitKey makes Bitcoin easy to use and hard to lose. It is a hardware wallet that natively embeds into a two or three multi-sig. You have one key on the hardware wallet, one key on your mobile device, and Block stores a key in the cloud for you. This is an incredible hardware device for your friends and family, or maybe yourself
Starting point is 00:34:35 who have Bitcoin on exchanges and have for a long time, but haven't taken a step to self custody because they're worried about the complications of setting up a private public key pair, securing that seed phrase, setting up a pin, setting up a passphrase. again, BitKey makes it easy to use, hard to lose. It's the easiest zero to one step, your first step to self-custody. If you have friends and family on the exchanges who haven't moved it off, tell them to pick up a BitKey. Go to bitkey.world. Use the key TFTC20 at checkout for 20% off your order. That's bitkey.world, code TFTC20. What's up, freaks? When you take Bitcoin seriously, you start with custody. You want to control your keys, avoid single points of failure,
Starting point is 00:35:12 and make sure your savings cannot disappear because you or someone else screwed up. That is what Unchained has been focused on since 2016. Unchained is the leader in collaborative multi-sig custody and Bitcoin financial services that keep you in control. They secure over $12 billion in Bitcoin for more than 12,000 clients. That means about one out of every 200 Bitcoin sits inside an Unchained vault. Their model is simple. You hold two keys, they hold one key. It always takes two keys to move Bitcoin, meaning their single key can't access your Bitcoin on its own. Just resilient, shared custody that gives you institutional-grade security while keeping you sovereign. Unchained also lets you trade straight from your vault, access Bitcoin-backed
Starting point is 00:35:44 commercial loans, open a Bitcoin IRA where you hold your own keys, and set up personal, business, trust, or retirement vaults. They even offer inheritance solutions built for long-term hodlers. Or opt for the highest level private client service with Unchained Signature and get a dedicated account manager, discounted trading fees, exclusive access to events and features, and much, much more. If you want a partner that helps you secure and grow your Bitcoin without giving up control, go to Unchained.com and use the code TFTC10 at checkout to get 10% off your new bitcoin multisig volt that's tftc10 at unchained.com yeah and again i think really nailing down the the risk of trying to rush a change to bitcoin to appease the people who think
Starting point is 00:36:26 that this is coming uh faster than than others believe it is um what are the risk of of upgrading to something uh in haste because you're worried about this and alternatively not alternatively but on top of that like is there a line in the sand we can we can draw it's like hey we we hear your concerns we'll take this seriously we'll begin we'll continue the research that we've been doing and um make sure that we advance that but if we get to 2030 and we're at this state of quantum research we're not going to take you seriously anymore like what is the line in your sand oh that's a good question i haven't really thought about it from that angle of of yeah like when do we stop paying attention like when like it's like Greta was like Greta Thunberg again
Starting point is 00:37:13 using the climate change analysis and analogy was in 2015 she was like by 2022 Miami's going to be underwater it's like 2022 came and went Miami's not underwater so okay we can't take you seriously anymore what is what is that what is that line in this conversation yeah I think with quantum it's really hard because the reality is again I think quantum is not physically possible, but I can't, that's an emotional thing. So we can't really do that because there could always be a new architecture developed that makes it possible, something we haven't thought of before. But I think the good news is that, as I said, something's eventually most likely going to break our existing crypto. And so we need to keep doing this research and building new crypto
Starting point is 00:38:03 systems for bitcoin regardless of quantum and we should keep doing it at the right pace uh and so like one of the ways to i think ease the tension here is to say look bitcoin actually is developing towards quantum resistance regardless of your level of concern or my level of concern i'm not concerned you are it doesn't matter bitcoin is developing towards quantum resistance you know um biff 360 paid a merkle route is advancing i think it's fairly likely to get activated on the network, which opens up the door to building quantum resistant new crypto into Bitcoin, right? So that's like step one is actively happening. And why is it happening? Because it's actually a good change for Bitcoin. And pretty much everyone in the Bitcoin developer
Starting point is 00:38:46 community, there's like a couple of very tiny exceptions. But really, pretty much everyone's on board with that change. And it does move in the direction of quantum resistance. Does it matter that it's quantum resistant? Not to me, but it does to some people. And that's okay. And we'll see that continue right there's as as other cryptographic research is done and as we get to the point where some alternative cryptographic primitive is appropriate for bitcoin i think it's absolutely a good thing and i think almost everyone agrees to have people to give people different ways to secure their coins depending on their goals right so someone who's trying to secure their bitcoin for some kind of uh dynasty trust let's
Starting point is 00:39:29 say, they might want to put it in a way where it's secured by both elliptic curves, and let's say hash based signatures, because they want to not they don't care about the signing cost when they go to spend that Bitcoin, they care that it is almost 100% secure for 100 years. And you really can't get 100 year security from one cryptographic assumption, you need a couple of and so I think bitcoin is going to go that direction i think like that's that's my take is just let's do the right thing for bitcoin and in the long term the right thing for bitcoin is also going to happen to make quantum resistance an option uh we just don't need to to rush and as you said there's a there's a big risk to rushing you know satoshi notoriously chose a elliptic curve specifically
Starting point is 00:40:15 that wasn't published by nist to help mitigate the risk of kind of a backdoor crypto going into bitcoin um and right now people are like no let's push this nist published post-quantum architecture into into bitcoin and everyone who knows what satoshi did is is kind of no let's not let's not put the nist thing in let's develop something from our own first principles that's appropriate for bitcoin and when we have something good we'll put it in yeah and that seems to be what jonas and mccall are doing with shrinks plus yeah jonas published uh shrimps uh last week which is sort of an advancement of shrinks plus because the way i understand it shrimps um if you were just doing pure shrinks plus private key um but transferring a private key
Starting point is 00:41:06 or recovering a private key on another physical device would be quite burdensome but shrimps makes it so you can begin recovering seeds on multiple devices using the same seed phrase in a way yeah exactly i actually wrote it wrote it up for optech so check out optech tomorrow morning and i summarize shrimps and also some other work on post-quantum crypto by conduition about isogeny based crypto for optech and that'll come out tomorrow morning so there's two new post-quantum uh systems detailed in optech tomorrow by me like so you i'm the anti-quantum guy but i'm out there actively doing the the work to publicize the post-quantum stuff because like i said we need it eventually regardless of quantum and so what are your thoughts on shrinks plus and
Starting point is 00:41:55 shrimps like is it a solution or is it a step towards the solution they're like okay you know So it would significantly impair the development of things like Lightning and PayJoin and Taproot and all the cryptographic primitives that we rely on, Frost and Mucig, and even the MPCs that are kind of non-Bitcoin specific for multi-signature and threshold signature. Any of these would still significantly impair those. um so i think jonas's work and blockchain research in mikhail is exceptional and it's definitely moving the state of the art forward but as of now i would be hesitant to put any of these in bitcoin um because of the combination of their size which would impair the number of transactions we could do if we were to use them and the fact that they're not really compatible with our existing wallet infrastructure that people are depending on um i wouldn't be upset
Starting point is 00:42:59 If other people in the developer community thought they were a good thing to add, especially if we're thinking about, as I said, a world where we do have multiple crypto systems available in Bitcoin and people can choose whether they secure their coins with one, the other, or both, potentially. I'm not going to be mad if they go in in that context. uh i think the shrimps in particular shows a lot of promise in that it i guess the the way i would put is that it's close to compatible you know it works decently well with as you said being able to restore seeds on multiple devices and the ways we use bitcoin for real uh while still being not so huge that it completely destroys the usability of the chain or requires massive block size increases or something uh so i love the direction that jonas and crew are working there and i hope that it just continues and we kind of take our time
Starting point is 00:43:53 getting something better than these before i put it in that's my hope yeah and then there's the whole discussion around hash based and lattice based i know jonas and mikhail are working on a lattice based um research paper right now and so what's the i guess what's the um consensus or lack of consensus around which direction to go in when given those two directions, when given those two options? I think the consensus right now is if for some reason we decide to or need to do something in the near term, let's say the next five years, it would probably be something hash based because it doesn't require any new cryptographic assumptions. It relies on things we already trust and know in Bitcoin. With the downside that hash
Starting point is 00:44:41 has has certain downsides in terms of calculating keys that make it harder to use with our existing infrastructure in various ways um so yeah so hash based would be the thing to do soon lattice based requires some new cryptographic assumptions but has definitely certain benefits in terms of the the flexibility of the math i don't understand it as well if i'm being honest i haven't read deeply about it um and then the other the other piece actually the fraptech tomorrow is about isogeny based crypto which is a whole different kind of crypto that also is quantum resistant but also requires a new cryptographic assumption but it works on elliptic curves still but using a different kind of key that's not vulnerable to quantum uh so i think
Starting point is 00:45:28 if it's not hash based we don't know what it would be it could be lattice it could be isogeny it could be something else and research should continue and is continuing to kind of get to the point where we could do something other than hash based and my again my hope is that we have much more time than the quantum uh doomsayers are predicting and we can get to a really good alternative crypto system um that broadly works within the bitcoin ecosystem and supports all the stuff we want you know whether it be signature aggregation or silent payments or or hd wallets like whatever the stuff we wanted we want a crypto system that supports that um and i think the research is going quite rapidly towards having some options there in the next
Starting point is 00:46:11 let's say maybe 10 years yeah and so it seems very reasonable it seems like a very reasonable approach to upgrading bitcoin and again that's been the most frustrating thing it's like devs do something bitcoiners aren't focused on this it's like the research is being done like what i mean i can't speak for them but that's what i've been trying to figure out is like what pace would be sufficient for you guys like what changes do you want to see and then there's a circular logic where it's like hey we're working on this like give us feedback on um the the work that we're doing whether or not you think it's sufficient for the security that you deem necessary for these quantum advancements that are being made and if you don't agree like do you have a
Starting point is 00:46:55 solution and if so will you propose it and they're like we can't propose it because bitcoin core is controlled by a cabal of five or six developers so we'd never even propose it because we get rejected immediately it's like well is is this productive at all like what is going on here yeah yeah and i think what what they're actually saying and what they're reflecting when they say that is that they're they know their crypto proposal would be rejected for for good technical reasons and so it's not it's not oh core is this cabal it's really uh bitcoin core holds the line on the quality of technical contributions accepted so high that nothing right now, no new crypto system for Bitcoin right now meets the bar.
Starting point is 00:47:43 And that bar, of course, can move if the threats to Bitcoin's existing crypto system get closer. And so that's, I think, where the disconnect is, let's say, is that no one in the Bitcoin kind of core maintainership has yet come out and said, the sky has fallen, quantum is in three years, we have to do something now. and if we had to do something right now then some of these existing crypto systems would be but the cabal won't accept them because they're not really good enough and they'd only be accepted if it was an eminent imminent threat well what is good enough in the eyes of the people who do believe it's an imminent threat do they have solutions because that's the one i haven't seen
Starting point is 00:48:26 like a yeah they've said basically that we should just take a sphinx plus into bitcoin even though the signatures and keys would be combined like 10 kilobytes per spend or something like that. And like, that's not a completely unreasonable argument if the thing really was around the corner. Now Sphinx plus is a NIST standard under the name SLH DSA. I think it is.
Starting point is 00:48:53 So, so like the question is, is the sky falling enough that we would accept an unmodified NIST standard into Bitcoin? with these significant tradeoffs and having like 100x the the the key signature size versus our current crypto system and i think as we discussed at length here the sky is not falling nearly enough uh to accept that kind of a trade-off okay so it's not that's the one thing i've been wondering i thought like i mean you mentioned alex pruden he's with project 11. um they're helping blockchain
Starting point is 00:49:31 systems uh transition to post-quantum or i believe working with slana and ethereum i i was curious if they had a specific um solution that they're they're putting forth for bitcoin that um i don't know if they specifically have one yeah that's targeting bitcoin directly they they published a paper on some improvements they've worked out i think it was lattice based where where it does support a lot of the bitcoin wallet infrastructure um like i said lattice has more key math ability than hash based stuff um so yeah i think if they were to propose something for bitcoin it would be probably lattice based and the bitcoin folks would currently say the lattice stuff is too new and we don't yet fully trust the cryptographic assumptions it makes
Starting point is 00:50:25 for bitcoin we'd want to see more time more more threat modeling more proofs more different systems based on these same assumptions that all are shown to work you know that's the kind of thing we want to see for bitcoin uh we don't want to put a new system in that's that's vulnerable to some classical attack in the attempt to defend against a quantum attack yeah and this was similar to what would happen i mean you mentioned ecdsa was chosen for a certain reason snore was on the table but i believe it was patented at that point and i think satoshi even said hey it probably needs more time to be in the wild before we adopt something like snore and then what was it 13 14 years in to the protocol snore was included into um including into bitcoin yeah exactly
Starting point is 00:51:16 There's a track record here that Bitcoin, it's so strange when they're like, Bitcoin should this, that, that other thing. And demonstrably, Bitcoin has a conservatism that is appropriate and will adopt new cryptographic primitives or assumptions as appropriate to the protocol. um one thing that relates here is it's interesting to see the difference between centralized things and decentralized right so centralized systems can just upgrade their crypto they can take a new assumption and if it goes bad they can turn it off and that's a low cost thing when you're a centralized system and so they they have a different math here where if it's easy to change because you're a centralized system then the risk of taking a bad assumption is much lower because you can just change again but bitcoin isn't like that right bitcoin is a massive global distributed
Starting point is 00:52:15 decentralized network and so the costs of taking a bad crypto system into bitcoin are much higher than for something like solana or for google internally or some web server you know some web server turns on slhdsa today they can turn it off tomorrow and that's okay for them we can't do in bitcoin no we can't and that's i again the more frustrating and bitcoin gets picked on that's like and that like being honest and i'm happy you said that because that's one thing um that i think bitcoiners who don't believe it's a big risk like the whole line of like and i used to say this to hand up of uh of if quantum comes like bitcoin's not the only thing at risk like yes that's true but to your point like all these centralized systems can trivially incorporate and um
Starting point is 00:53:08 rip out these cryptographic systems rather trivially because they're centralized like bitcoin does have a big um unique problem in the sense that it's a distributed system we need to a consensus once we put something in it's hard to take it out and um the risk factors to bitcoin are are certainly unique and arguably higher than they are to other systems yeah so we have to pay attention and we have to move at the appropriate time for sure yeah and to your point about lattice space i just wanted to bring this up that's why i'm looking at my other screen over here because we wrote about it yesterday but um going back to like lattice based schemes and the fact that they're not as battle
Starting point is 00:53:52 tested as some hash based solutions. So lattice based schemes offer advantages and verification speed and signature aggregation, but the carry tradeoff, they rely on newer mathematical assumptions that haven't been battle tested as long as hash functions. In fact, NIST tested 69 post-quantum Canada algorithms during its standardization process, and two of them, Rainbow and Psyche, were broken with classical computers during testing. um and so that's four what would that be that would be like five four four and a half percent or less than that like three and a half percent of these or maybe like yeah three and a half
Starting point is 00:54:29 of these uh of these post-quantum lattice-based systems were proven to be insecure and so like that's if you're going to incorporate a lattice-based system into bitcoin you have a three and a half percent risk of it being uh insecure i think that's pretty high for a trillion dollar network as well yeah for sure and that's i mean this gets back to what i was saying earlier like what's the line in the sand like how do we have a a more level-headed conversation about all this with with the uh the people who are convinced that this is coming faster than than we are yeah i mean my best way is is to to rely on on evidence-based decision making and that's why i keep posting kind of every few
Starting point is 00:55:22 months i guess i probably post something about i'll worry about quantum when i see like here's a list of things and i think it's uh scaling over two generations less than exponential scaling in the time needed to solve progressively larger keys on the same crypto on the same quantum system and um beating classical in any cryptographically relevant even small size problem and and to date none of those three things have happened in any quantum architecture and and so there's there has to be evidence we we can't as i i joke about it being unicorn fart based engineering but the reality is that anybody can fud anything about Bitcoin. And if we can be caused to make a change to the protocol based on claims and not evidence, then Bitcoin is vulnerable to
Starting point is 00:56:15 the most obvious of attacks, right? Bitcoin can't be subject to change without evidence that it needs to. That simply doesn't make sense. And so we can set a pretty clear evidentiary standard for when a quantum architecture shows these three or maybe four, like people can argue about exactly what the criteria are, but we can set pretty darn clear standards for the evidence required
Starting point is 00:56:41 to start taking immediate action. And of course, in the meantime, we're going to take progressive action anyway. So it's not like this is a, oh, we're going to do nothing until, it's just, we're going to take a slow and steady approach until there's this level of evidence
Starting point is 00:56:53 that we have to move faster. Yeah. And do you think, what yeah we have to think of opportunity cost too right like what else could be could we be working on in bitcoin that is necessary in a low-hanging fruit that um undeserved attention to the quantum question could take away from yeah that's a really important point and i think even more than not working on the right things it's it's essentially flooding the amazing innovations that are still kind of nascent, not widely deployed in Frost and Silent Payments and
Starting point is 00:57:31 Mucig and even DLCs, you know, all of these things are classical elliptic curve based protocols that are really valuable for Bitcoin. You know, Craig Raw is working on getting Silent Payments into Sparrow Wallet recently. Coldcard just shipped Mucig2 support. And these things strictly depend on the existing elliptic curve cryptography. And they're great. There are huge improvements in the usability of Bitcoin in a couple of different ways. I'm not going to get into them because it's not important right now.
Starting point is 00:58:01 But when you're saying we need post-quantum tomorrow, people just say, well, then why would I bother developing silent payments or Mucig when we're going to replace the existing crypto in a year? You shouldn't, if that was true. And so I think it is very important that we push back on this quantum FUD and say, look, as of now, there's no evidence that we'll be kind of replacing the basic elliptic curve cryptography in the next decade. So we should keep building silent payments and music and frost and DLCs and everything based on the existing cryptography. It's going to be around for a long time. So keep building. Yeah. It's also tiresome.
Starting point is 00:58:39 Do you think this is a social attack or? man i don't know intentional intentional social attack i guess if you believe the quantum's not not uh coming as quickly as they believe it is a social attack but i guess the question is intent i i tend to be optimistic on people's motivations and that's i don't i don't think so i think it's it's more just that that people love to panic and i mean we've seen that in the real world in so many ways in recent years the the need to panic i think it relates to the fact that life is too soft people don't do hard things and so they they need to find things to be worried about to to satisfy their their nature their natural like evolutionary need to be worried about something
Starting point is 00:59:28 uh and so we just get prone to panic and it's easy to to rile people up with this stuff yeah um any parting parting notes here anything we didn't touch on that we should probably mention as it relates to this quantum discussion. Oh, I already shilled it once, but I'll shill again. Read Optech. I write the Changing Consensus section of Optech every month, and I think it'll actually put you more at ease about quantum, because we cover quantum a lot in there, and you'll see the kind of remarkable progress being made, which very likely means that long before, possibly never, but long before even a realistic time frame for quantum assuming it started scaling today i think long before it gets to a production
Starting point is 01:00:11 uh relevant quantum computer we'll have a better system in bitcoin like it's happening actively well this will be published the day after optex published so you're not uh you're not um spoiling anything is there any specifics you want to expand on there oh sure um so i read this developer Conduition has been posting a lot about cryptography to the Bitcoin mailing list recently and to Delving Bitcoin. And he did this big write-up earlier this month or last month, I guess, about isogeny-based crypto that I mentioned earlier. And he basically made the argument that Bitcoin developers should be paying attention to it. And so I read his whole thing and wrote a summary for Optech about it.
Starting point is 01:00:58 And isogeny-based crypto is very interesting because unlike hash-based or lattice-based crypto, it's only about twice the size on-chain of the existing elliptic curve stuff. And part of that is because it's also elliptic curve-based. But unlike our existing stuff, it doesn't depend on the hardness of reversing points to keys, to secret keys, in order to be secure.
Starting point is 01:01:24 It has a totally different security assumption. It just based on the same shapes of curves on a, on a graph. Right. And so I think that is very promising. And I think people should read conductions whole post if they're kind of even technically interested in this kind of stuff. Cause he,
Starting point is 01:01:41 he does a great job of, of bringing it down to a place where Bitcoiners who kind of understand elliptic curve cryptography, the classical kind can also understand isogeny based cryptography. And yeah, But because it also works on elliptic curves, some of the machinery we already have in Bitcoin could be applicable to it. So we kind of take a new cryptographic assumption for the hardness, but we can use some of the same optimized elliptic curve math that we have already to work on these systems. and so that might be promising for bitcoin um you know if i'm being totally honest about it i i would guess that if isogeny based crypto were to come to bitcoin we would probably still want to
Starting point is 01:02:21 do something that's not elliptic curve based as well as a backup so that if there's a fundamental break in elliptic curves themselves which there hasn't been any evidence of it yet um we'd have a fallback fallback um but it's just promising to see a totally different avenue that's not lattice not hash also being brought to the fore and i'm glad i got to write about it oh yeah do you think there's enough um top tier cryptographers well versed on these subjects focused on bitcoin do we need more uh not an isogeny based crypto yet and that's exactly what conduit writes about is that more bitcoin folks should be looking at this and and seeing if it's suitable because if it's suitable it would have a lot of really good properties that that apply to bitcoin and let us
Starting point is 01:03:09 keep using bitcoin the way we want to yeah it's great to know thank you for uh all your work on the front lines of having the conversation and uh helping add context because again as somebody who's not well versed in quantum physics and uh knows enough to be dangerous when it comes to cryptography it is uh i don't want to say it's easy to get bamboozled but it's easy to begin questioning and you should always question but um getting a well-rounded perspective on both sides of this quantum debate as it pertains to bitcoin i think it's important you've been doing an incredible job of providing much-needed context thank you yeah i love fun busting it's been a hobby for a long time so glad to be out there doing it on a new topic awesome uh where can
Starting point is 01:03:55 people find out more about what you're working on yeah check me out on x usually at reardon code um i sometimes post on the mailing list as well and um if you're building a wallet i offer consulting reviews and stuff for bitcoin wallets and similar kind of on-chain bitcoin stuff uh and you can just hit me up on on x about that my dms are always open all right awesome brandon i hope you enjoy uh enjoy your day and uh hopefully we can do this again you too man well uh great talking we'll draw a line in the sand we'll say if uh quantum hasn't progressed in six months six months yeah i'm kidding um peace and love freaks okay thank you for listening to this episode of tftc if you've made it this far i imagine you got some value out of the episode
Starting point is 01:04:40 if so please share it far and wide with your friends and family we're looking to get the word out there also wherever you're listening whether that's youtube apple spotify make sure you like and subscribe to the show. And if you can leave a rating on the podcasting platforms, that goes a long way. Last but not least, if you want to get these episodes a day early and ad free, make sure you download the Fountain podcasting app and go to fountain.fm to find that $5 a month, get you every episode a day early, ad free, helps the show, gives you incredible value so please consider subscribing via fountain as well thank you for your time and until next time

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.