Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens?
In this new lecture, Stanford cryptographer @danboneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing.
The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired.
00:00 Why blockchains need to prepare for quantum computers
03:05 Why Bitcoin may bet on hash-based signatures
06:25 The “big footgun” in stateful signatures
08:58 A quantum-safe signature that takes one billion hashes
14:13 Inside SLH-DSA’s virtual tree
20:30 How Bitcoin and Ethereum could make the switch
23:48 What happens when a wallet loses its state?
32:47 Can threshold signing survive the quantum transition?
36:39 How to hide lattice cryptography from the blockchain
38:49 Why threshold one-time signatures seem impossible
45:36 How context prevents forged signatures
49:37 The forgotten idea behind Winternitz signatures
54:50 Turning one-time signatures into threshold signatures
1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks?
1:06:26 Abandoned bitcoin and Satoshi’s recovery problem
1/ Can AI agents build formally verified software repositories? Introducing Vero: the first benchmark for joint implementation and proof synthesis at the repository level. As AI agents write a growing share of our software, we need more than just working code; we need machine-checked guarantees of correctness and security. In Vero, we find that repository-scale verified code generation is still out of reach: the strongest frontier agent fully verifies only 27 of 43 real-world repositories.
Website: https://t.co/LhDcK3gnLT
Goodbye, Poseidon!
An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography.
Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs.
In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs.
The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive.
We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June.
With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value.
Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028.
As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming.
On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow.
Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :)
Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more.
Ultimate security. Uncompromising performance. Full programmability.
Believe in something. Believe in hashes.
@iamnotnicola AI can both break and defend cryptography!
The latter is quite crucial, as you may already know, with:
- formal verification,
- better study / established hardness evidence for long-standing assumptions,
- better schemes using conservative assumptions
First Principles Ep. 6 with Shafi Goldwasser
What if you could prove something is true without revealing why it’s true? Turing Award winner Shafi Goldwasser tells the origin story of zero-knowledge proofs: how a playful question about playing poker securely over the telephone led her, Silvio Micali, and Charles Rackoff to rethink what a mathematical proof could be.
Goldwasser traces those ideas through interactive proofs, the sum-check protocol, SNARKs, and the systems now used to verify computation and preserve privacy on blockchains.
She also reflects on why breakthrough ideas are often rejected at first, how toy problems can produce foundational theories, and whether AI systems should have to prove their answers.
Hosted by @Tim_Roughgarden with @SuccinctJT
00:00 Intro
03:36 How mental poker inspired zero-knowledge proofs: Proving that something is true without revealing the underlying information
06:30 The simulation paradigm and the meaning of “zero knowledge”
08:33 Why the original paper was repeatedly rejected
10:33 How interactive proofs became more powerful than conventional proofs
13:36 The road to modern SNARKs
19:02 Why the sum-check protocol is so useful for verifiable computation
25:31 Why many so-called “zk proofs” are not actually zero knowledge
34:06 Why toy examples, playfulness, and narratives can produce deep theory
37:23 The role of rigor and computational assumptions in cryptography
42:44 Applying zero-knowledge proofs to law, evidence, and secret software
45:23 Training AI systems to provide proofs alongside their answers
54:27 Why genuinely new ideas are often difficult for experts to recognize
AI now generate proofs, and producing "papers" is easy. The real bottleneck is understanding them: how can we quickly digest a proof, identify its key ideas, and develop a feel for the argument? Traditional line-by-line reading and checking no longer scales.
I came up with a prompt that I have found very helpful and wanted to share. I tested it on several counterexample constructions and on one of my technically involved papers, and it did a good job. Here is an example from a Grok chat: https://t.co/3kh6FEojgL
The prompt can certainly be improved and adapted, for example, you can adjust number of slides at the end depending on your background. So feel free to experiment with it.
I would also be very interested to hear how others are approaching this challenge.
-----
PROMPT:
My goal is to understand this attached proof, or, I would say, to learn it. To achieve this goal, here is what I want you to do.
Write everything in Beamer slides.
First, formulate the question and explain every term introduced in it so that a first-year graduate student can understand the statement of the question. Keep it as a standalone problem, but write all the necessary assumptions (do not skip any assumptions). Try not to introduce too many new symbols or notation; this is absolutely unnecessary.
Give a short explanation of where this problem originates and, very briefly, why it was asked or why it was believed to be true. Highlight the most important reasons on the slide (perhaps put those reasons in a box).
As a sanity check, to convince the reader that something like this should be true, give an important but simple example (or several such examples), including all the detailed calculations involved, if possible, to show that the statement indeed seems to be true. If it is not possible to include all the calculations, then please provide at least the most important ones. If other examples should be given, perhaps highlighting other endpoint behaviours of the question, please provide those examples as well.
In case there is an opportunity to draw an analogy with something else, please do so, but very briefly.
Next, I want to see the bottleneck: what fails with the most straightforward approach and why it does not work. For example: “If we try this, then we get stuck with this.” If we start in that way, then this seems difficult to do, or it is not clear how to proceed.
Provide a high-level explanation of the actual correct solution: how we are going to start solving the problem, what we are going to do first, what the main steps will be, and which step will be a new addition that did not appear before, i.e., which step is a genuinely new contribution that made it possible to solve the problem. Emphasize by putting it in a box, the main idea that was introduced to solve the problem. The goal is to understand how we overcome the bottleneck. You can skip the technical calculations at first unless certain identities play a pivotal role in the proof. If a calculation is straightforward and technical, you can simply state it as a fact. Thus, split the solution into a series of facts and identities. Each fact should be standard and technical to check. In case you also need to state a nontrivial fact that is not standard, please add more details about where it comes from.
After providing the high-level solution, please provide a detailed, step-by-step proof with all the technical computations. Do not compress the arguments. It should be easy to check every single line without a calculator, pen, or paper, simply by reading the line. At the same time, try to keep things short.
Graphs or pictures of the functions help in understanding the solutions. It is difficult to create good pictures, but try to do your best, and if you think a picture could help, please provide some graphs or drawings.
Here is the paper. The slides should around 20 pages long.
All versions of HAWK rely on the supposed hardness of examples of "LIP", a problem whose Hamming-weight analog was broken decades ago by Sendrier in almost all cases. Here's my posting four years ago saying that the first "LIP" paper was setting off alarm bells.
Quantum computers will break certain cryptographic protocols, but some will stay safe.
Which cryptography is quantum-resistant and which isn't, and why? Watch my explanation
OpenScience: an open-source Claude Science for researchers.
"give it a goal, and it works through the research loop the way a capable collaborator would".
250+ skills. Shouldn't be hard to run on Codex subscription using `codex exec`
📄Academic papers are basically a citation "conversation."
I built a tool that pulls folders from your Zotero library and maps citation relationships between your saved papers.
Just needs your Zotero ID + API key.
No LLM tokens, fully FREE.
https://t.co/2KIzN4P38a
OpenDraft: "Claude Code for research papers".
19 specialized agents doing research in parallel. Open source.
Could be handy in assisting with lit reviews.
Link to github repo in reply below:
Akademisyenler için Claude Code’u nasıl kullanacağınıza dair basit bir giriş.
Alessandro Spina'ya ait sunum slaytları ve GitHub deposu.
🔗 https://t.co/FCfOers2Lw