為 Web3 打造未來。探索後量子密碼學(PQC)如何將區塊鏈從量子威脅中拯救出來。加入這場進化吧。
Future-proofing Web3.Exploring how Post-Quantum Cryptography (PQC) saves Blockchain from the quantum threat.
🚨JUST IN: Bitcoin Core developer Luke Dashjr says changing Bitcoin's proof-of-work is "the only option" if BIP 110 fails.
Critics warn if six mining pools can block the proposal, Bitcoin's decentralization is "effectively lost."
Meanwhile, Bitcoin briefly topped $65,340, its highest since July 27, before pulling back near $65,000.
$IONQ "AI is just the warm-up. Quantum is coming 'like a freight train'.
@IonQ_Inc CEO @NiccoloDeMasi says the 10-year Q-Day horizon is now 10 quarters.
50 minutes on the true tech revolution on TPPF Spotlight.
⬇️📹
#IonQ#Quantum
@dallairedemers launched unofficially a concept
"Trilemma of bitcoin migration to quantum resistant":
Bitcoin can NOT SIMULTANOUSLY keep the 3:
1, the most amount of users' address,
2, PoW
3, 1MB block-size.
to mostly migrate half-succeed,
quit 3rd above is the trade-off must.
"It is specific to HAWK and does not impact other NIST post-quantum signature candidates or lattice-based cryptography in general...reviewing specifications like HAWK with AI will be a powerful tool in the development of novel cryptographic standards. "
https://t.co/YjeEZlZrXv
🚨 AI is rapidly reshaping the security landscape, and it may reshape cryptography as well.
If you were optimistic about the standardization prospects of the Hawk signature scheme, this is worth paying attention to. In a recent scientific paper, researchers at Anthropic show that AI-assisted cryptanalysis can dramatically reduce the complexity of a known private-key recovery attack against Hawk. Hawk is one of the candidates in NIST's additional call for post-quantum digital signature standardization.
On paper, Hawk was a very attractive candidate. It produces very compact signatures and, unlike Falcon, avoids floating-point arithmetic, making implementations simpler and potentially more robust.
Importantly, this result does not weaken lattice cryptography as a whole. Instead, it targets Hawk's newer security assumptions, which have not been scrutinized for as long as the more established assumptions underlying schemes such as Dilithium.
The same paper also reports a modest improvement in the best-known cryptanalysis of reduced-round AES. Even highly studied cryptographic primitives are not immune to new scientific advances enabled by AI.
One lesson is becoming increasingly clear: crypto-agility, the ability to replace cryptographic algorithms without redesigning entire systems, may soon become a fundamental requirement for secure software.
I'm looking forward to seeing crypto-agility on Bitcoin :-)
JUST IN: Cardano co-founder Hoskinson says Bitcoin could lose the number one spot if it can't adapt to quantum computing.
He says Bitcoin's governance makes it "frozen in time" and unable to coordinate the upgrades needed to defend against quantum computing.
BIG BREAKTHROUGH:
🚨 Scientists just unveiled the world's first commercial 512-qubit diamond quantum computer that runs at room temperature.
"A German startup SAXON Q has commercially launched its SXQ128 and SXQ512 quantum computers, featuring 128 and 512 physical qubits, respectively."
"The company says these are the first diamond nitrogen-vacancy (NV) quantum processors to scale beyond 100 qubits, operating entirely at room temperature without cryogenic cooling."
"Instead of dilution refrigerators or liquid helium, the systems use nitrogen-vacancy (NV) centers in synthetic diamonds to control electron and nuclear spins. "
"Each Quantum Core delivers 8 fully entangled qubits on the SXQ128 and 16 fully entangled qubits on the SXQ512, powered by a modular multi-core architecture."
"The processors achieve up to 99.92% quantum gate fidelity, averaging fewer than one error per 1,000 operations, while fitting inside standard server racks and running on normal electrical power with no specialized environmental controls."
"SAXON Q also claims its systems deliver 6× to 10× better energy efficiency than GPU clusters running equivalent workloads."
"To manufacture the chips, the company developed a patented sulfur co-implantation process, increasing diamond qubit creation yield from the industry's typical 1-10% to over 85%, enabling scalable production."
"Backed by 220+ patents and patent applications, SAXON Q says its roadmap extends toward 10,000-qubit architectures and eventually chip-scale quantum coprocessors."
SXQ128 systems will begin shipping within three months, while SXQ512 deliveries are scheduled for Q2 2027.
Acceleration is everywhere!
I’ve been chatting with the @BlackRock digital assets team about quantum for well over a year now… I was very glad to see them make public statements on this issue last month and honored to host what I believe is their first video interview on the subject
On 1 October 2025 I presented the double threat, why DATs and Quantum were the biggest threats to Bitcoin. Bitcoin was at $118K and 5 days from the cycle ATH and MSTR was at $340. Today Bitcoin is down -50% and MSTR -73% primarily on the back of these two threats alone. Unfortunately neither have been adequately addressed.
$IONQ
@IonQ_Inc just published on quantum error correction. Mark Webster and Nicolas Delfosse.
I made a video to make it simple, and it holds in one image: a teacher grading a whole class with a single stencil, instead of one paper at a time. Three minutes and the paper clicks. Watch it.
Their method: only cat states, plus a "scheduler code" that measures many logical operators together and decodes every outcome at once.
Their numbers: up to 74x on random Clifford circuits, 5x on Toffoli gates.
Fewer resources per logical operation is the overhead curve bending, and IonQ owns this work in house.
https://t.co/NU6Dk7Y4Xd
$IONQ #IonQ #Quantum #QuantumErrorCorrection
There are continual advances in lattice attacks (see https://t.co/zfrgCutuOV) but I don't think https://t.co/Ni3LeiSkOP qualifies as one of them: it's basically just standard enumeration (picking a random node in the enumeration tree) after standard sieving as preprocessing.
BITCOIN RAILS #69: ZERO-KNOWLEDGE PROOFS FOR POST-QUANTUM BITCOIN | with Benedikt Bünz
🔗 YOUTUBE: https://t.co/yBr6w1NbjB
🌿 SPOTIFY: https://t.co/HWNxcR6cgG
While many Bitcoiners remain hopeful the network will embrace zero-knowledge proofs for protocol-level use cases, practical adoption has remained limited outside of BitVM and a handful of experimental proposals.
Most of the world’s ZKP research has circled around Ethereum and other ecosystems, where significant resources have been dedicated to advancing these systems, particularly for scaling and privacy applications.
One of the most notable contributors to this research is @benediktbuenz — professor of cryptography at NYU and collaborator of @danboneh, who together inarguably form one of the strongest blockchain-applied cryptography teams in the world.
The pair recently announced they’ll be leading the new post-quantum cryptography unit @lclhostresearch — the first dedicated PQ research effort within a major Bitcoin development organization.
With Benedikt leading the charge on the use of zero-knowledge proofs for post-quantum mitigation, the question emerges: will the post-quantum transition be the catalyst to finally bring zero-knowledge proofs to Bitcoin's core protocol?
In more detail, Benedikt and I discuss:
- Why ZKPs haven’t been widely adopted by the Bitcoin technical community — and why the threat of quantum computers may change that posture going forward
- How ZKPs could be used for signature batching to address larger post-quantum signatures in Bitcoin’s post-quantum era
- Why Bitcoiners will likely prioritize hash-based signatures as an initial post-quantum scheme — rather than more efficient but less proven alternatives (e.g., lattice-based)
- How ZKPs have evolved over the last decade and may finally be ready for Bitcoin’s strict requirements around trust assumptions
- Why Benedikt and Dan are teaming up with @lclhostresearch to create the first post-quantum cryptography unit within a major Bitcoin development organization + what they hope to accomplish
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs @LayerTwoLabs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on @SuiNetwork — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox @BitBoxSwiss — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 — Intro
00:22 — Benedikt's background
04:10 — How Benedikt got into Bitcoin and cryptography
07:42 — First ZK project: proving exchange solvency after Mt. Gox
16:01 — ZK proofs explained
27:43 — How security gets popular & ZK proofs in Bitcoin
35:49 — Other applications of ZK proofs for Bitcoin
40:15 — Why ZK proofs haven't been adopted in Bitcoin
50:46 — Why the Bitcoin post-quantum transition needs ZK proofs
01:07:00 — Cryptographic agility and why lattices win
01:18:00 — The size problem and how SNARKs solve it
01:33:57 — Proving a Bitcoin block in a laptop in 1.5 seconds
01:37:12 — Bitcoin as the primary quantum target
01:40:47 — ZK proofs for seed phrase recovery
@isabelfoxenduke@nic_carter Thanks for the reply. 😊I’ll check out @nic_carter’s episode later. I'm a bit worried that Bitcoin won't have enough time to upgrade and migrate. Both hash-based and lattice-based signatures are really tough to implement on Bitcoin.
⚛️ Most of the industry has not priced this in yet: Quantum-resistant signatures and threshold signing (what people loosely call MPC) do not play well together. And the places we lean on threshold signing hardest are exactly where post-quantum cryptography helps least.
- Threshold signing lets a group share one key so any agreed subset produces a single, ordinary signature, with no one ever holding the whole key. It is load-bearing infrastructure for custody today. But most post-quantum families were never designed for it. As we migrate to PQC, a capability the ecosystem depends on does not migrate with it for free.
- Hash-based signatures simply cannot be thresholdized. This should bother the Bitcoin and Ethereum crowd. Hash-based signatures are the most conservative, most trusted post-quantum option we have, exactly the profile a chain wants for a multi-decade guarantee. And they do not thresholdize. There is no structure to split a hash-based key and recombine it into one signature. It is a pity, because this is the family the most security-conservative chains would naturally reach for.
- ML-DSA is the one that gives us a path
Outside the blockchain world, ML-DSA (FIPS 204) will be the default signature standard. It is also the one post-quantum scheme that looks like it can support threshold signing at all. At first glance it looks easy, because its response is linear in the secret:
z = mask + challenge × secret
Same shape that makes threshold Schnorr and BLS clean. But here, it is not that clean. And that is where it gets interesting.
- The real obstacle is rejection sampling, not linearity
ML-DSA keeps signatures small with a tiny mask. Too small to fully hide the secret, so the naive z leaks a little of the key on every signature. The fix is to throw away the leaky attempts. It's called "rejection sampling".
Alone, trivial. You check in private and bin the bad ones unseen. Split across a group, it breaks. The reject decision depends on the combined z, so everyone reveals their piece before anyone can judge the attempt, and the binned attempts are precisely the leaky ones. The decision needs the total, the total needs the reveal, and the reveal is a leak. A second check on the commitment w protects the other half of the key (s2) and has the same problem.
- There is a solution, honest about its limits
A recent paper solves this for up to six signers. The core idea: make every piece safe to reveal before it is revealed. Four moves:
1) Give each signer a short key piece it owns, so it can run rejection sampling privately.
2) Split rejection into a private per-signer stage plus a public stage on the total.
3) Add noise to w so the one unavoidable early reveal leaks nothing.
4) Use a ball-shaped safe zone plus parallel attempts to keep the success rate practical.
The output is a standard ML-DSA signature, accepted by an unmodified verifier, no trusted setup, secure even if all but one signer is compromised. Honest caveats: it scales to about six signers before cost explodes, and the signatures are distinguishable from single-signer ones.
We wanted a clean, secure setup, we end up with something as clunky as ECDSA threshold setups...
- Two things are true at once. ML-DSA gives us a real path to post-quantum threshold signing for the classical world. The most conservative post-quantum choice, hash-based, gives us none.
And none of this changes the thing I keep repeating: threshold signing distributes keys, not trust. If the endpoints can be compromised, splitting a key across them just distributes the attack surface. Post-quantum or not, key generation and signing still belong on certified secure hardware with a trusted display. WYSIWYS does not become optional because the primitive got quantum-resistant.
For the deep version, with the actual geometry and worked examples, @conordeegan wrote the best explainer I have seen: https://t.co/uNFT3B8GQw