₿ellsDesigner 🔔 retweeted
A new estimate puts breaking Bitcoin’s signature curve at 19,397 physical qubits. Previous trapped-ion estimates were 1.2–9.4 million. Not because somebody suddenly built a quantum computer 100× better. Because the estimated cost of fault tolerance collapsed. And it wasn’t the only paper this month. Days later, another team estimated RSA-2048 could be factored with roughly 120,800 superconducting qubits in about one month. Neither machine exists today. But that’s not the interesting part. The interesting part is where all those qubits went. 1/ Bitcoin’s curve IonQ compiled Shor’s algorithm against secp256k1 — the elliptic curve behind Bitcoin signatures — down to a proposed trapped-ion architecture: • 19,397 physical qubits • 1,457 logical qubits • ~39 million Toffoli gates • 25.7 days per attempt The paper gives a 40.7% conservative success bound and a 63.3% heuristic estimate. Earlier trapped-ion estimates for the same problem were in the 1.2–9.4 million physical-qubit range. 2/ RSA-2048 Iceberg Quantum took a very different route using superconducting hardware: • 120,820 physical qubits • ~1 month runtime • 10⁻³ assumed physical error rate • 1 μs error-correction cycles Two different cryptographic targets. Two very different quantum architectures. Both now landing in roughly the same order of runtime: weeks, not years. 3/ Where the numbers went Many older resource estimates relied heavily on 2D surface codes for quantum error correction. Surface codes are attractive because they can work with local connectivity. But the physical-qubit overhead is enormous. Both new architectures instead make heavy use of much denser quantum LDPC codes. IonQ gives a particularly striking comparison. Storing roughly 1,500 logical qubits with its surface-code comparison would require about: 243,000 physical qubits just for memory. Its complete qLDPC-based machine — including memory, computation, routing and magic-state infrastructure — comes out at: 19,397 physical ions. Its Q102 code encodes 22 logical qubits into 102 data qubits. Iceberg uses a different construction protecting 16 logical qubits with 510 data qubits, or 1,020 physical qubits when syndrome ancillas are included. The hardware didn’t suddenly leap forward. The fault-tolerance stack got cheaper. That distinction matters. 4/ The necessary reality check These are engineering blueprints, not working quantum computers. IonQ assumes two-qubit error rates around 10⁻⁴ across a large fault-tolerant trapped-ion machine involving thousands of ions, transport and repeated error correction. That has not been demonstrated at this scale. Iceberg assumes 10⁻³ physical errors, 1 μs cycles and degree-8 fixed connectivity, while extrapolating the performance of its full-size code from smaller simulations. And all fourteen authors of the secp256k1 paper work at IonQ. Its hardware assumptions deserve the same scrutiny we would apply to any vendor-authored roadmap. So no: this does not mean Bitcoin can be broken today. But dismissing these papers because the machines don’t exist yet misses the more important signal. Hardware capability is moving upward while the estimated resource threshold for an attack is moving downward. Both sides of the equation are moving. 5/ What does a 26-day attack actually mean for Bitcoin? At this runtime, it is not a practical 10-minute mempool race. The more interesting targets are coins whose public keys are already exposed while the coins remain at rest: • early P2PK outputs • bare multisig • Taproot outputs • reused addresses whose public keys have already been revealed Glassnode recently estimated that roughly 6.04 million BTC — 30.2% of issued supply — is currently exposed at rest under this broader definition. About 1.92M BTC is structurally exposed through output types such as P2PK, P2MS and P2TR. Another 4.12M BTC comes from operational exposure such as address reuse. An attacker doesn’t need to outrun the next block when the relevant public key has already been sitting on-chain for years. 6/ The real problem: migration debt The exact quantum threshold will keep moving. Someone may publish a 10,000-qubit architecture next year. Someone else may discover an overlooked engineering cost and push the estimate back upward. The number is uncertain. The migration problem is not. Moving a live decentralized monetary network from elliptic-curve signatures to post-quantum signatures means much more than choosing another cryptographic primitive. It touches: • wallet and address formats • transaction sizes • validation costs • software compatibility • hardware wallets and custody infrastructure • and legacy UTXOs whose owners may never migrate That is cryptographic migration debt. Tidecoin took a different path. When Tidecoin launched on December 27, 2020, transaction signatures already used Falcon-512 instead of elliptic-curve cryptography. Falcon was later selected by NIST and is now being standardized as FN-DSA. So Tidecoin does not have a legacy ECC transaction-signature set that must someday be swept into post-quantum addresses. Choosing a post-quantum algorithm is only part of the problem. The harder part is surviving the migration. Tidecoin started on the other side of it. The Tide was early.
2
13
25
903
₿ellsDesigner 🔔 retweeted
A new paper (IACR ePrint 2026/2069, "Default Correct") shows how a clock glitch can make ML-KEM/Kyber accept any ciphertext, leading to secret key recovery. We reviewed our implementation against it right away. Tidecoin uses ML-KEM-512 to encrypt P2P connections. The attack needs physical access to the device's clock line and thousands of decapsulations with the same key. It can't be done over the network. Our node generates a fresh ML-KEM key for every connection and uses it for exactly one decapsulation. So even an attacker with physical access has no long-lived key to recover. Tidecoin is not affected. No major ML-KEM library has published a fix for this yet. We're watching upstream closely and will add further hardening. Thanks to the researchers at IIT Bhilai.
2
6
25
550
₿ellsDesigner 🔔 retweeted
People keep telling me @tidecoin has no real edge because “every chain will go quantum‑proof anyway”. Tidecoin is already post‑quantum from block 0 built on Bitcoin Core v30 The next upgrade (already built & tested) brings Litecoin merged mining, Falcon‑1024, ML‑DSA, SHA‑512 scripts and strict PQ validation live in one shot. That makes $TDC the strongest post‑quantum PoW design in the market.
2
14
27
588
Tidecoin is the post-quantum bitcoin
dogecoin is the bitcoin of memecoins
7
18
278
While other chains plan for a future migration, @tidecoin launched with post-quantum security from block zero.
1
6
20
225
₿ellsDesigner 🔔 retweeted
$QRL holders need to ask themselves one question: If XMSS means stateful one-time signatures, finite per-address signing capacity, and larger-signature tradeoffs, what exactly is the long-term edge over a Bitcoin Core-based chain that has run Falcon-512 from genesis since 2020? Narrative is one thing. Architecture is another. @tidecoin $TDC
4
10
19
2,254
Built on Bitcoin Core. Secured with post-quantum cryptography. That’s the @tidecoin approach.
2
7
25
294
₿ellsDesigner 🔔 retweeted
Tidecoin lore hits different now. In 2020, the idea was simple: When the quantum threat became real, there should already be a Bitcoin-like supply of quantum-resistant coins in the wild. Not launched after the panic. Not migrated during the panic. Already mined. BTC: ~20M issued. TDC: ~18.8M issued. The clock was the thesis.
1
14
41
1,484
₿ellsDesigner 🔔 retweeted
Falcon is the quiet part of post-quantum crypto. Not the loudest signature scheme. The compact one. Falcon-512: 666-byte signatures. NTRU lattices. NIST-selected. Built for chains where every byte lives forever. Most blockchains still need a migration story. Tidecoin doesn’t. Genesis: December 27, 2020. Falcon from block zero.
2
7
31
1,051
₿ellsDesigner 🔔 retweeted
While @solana just chose Falcon for post-quantum security… Tidecoin has been running Falcon 512 natively from genesis since Dec 27, 2020. ✅ 5+ years live ✅ 2.3M+ blocks secured ✅ Zero incidents ✅ Smallest PK+sig (~1,563 bytes) ✅ NIST Category 1 quantum resistance
4
18
42
1,049
₿ellsDesigner 🔔 retweeted
A new era is coming soon.. @tidecoin
2
13
26
604
Most people still have no idea what’s coming. Very soon, Tidecoin won’t just be “a PQ chain” — it will activate 4 additional post-quantum signature schemes and push quantum resistance across the full stack. A lot of people are going to be very surprised. $TDC
Post quantum chains, 2026 reality check: $ALGO: Live PQ on mainnet since 2022, 140k+ txns $QRL: Fully PQ since genesis, smallest ecosystem $IOTA: PQ feeless data, no smart contracts Which approach do you think wins long term?
9
18
444
The next standard in crypto will be who was built for the post-quantum era. That’s why the industry will end up looking at @tidecoin. $TDC
3
8
19
335
The quantum computing narrative is about to go from “someday” to “too late.” Most of crypto is still treating post-quantum security like a migration problem for later. @tidecoin has been post-quantum since genesis, with a network that has run continuously since December 27, 2020. It keeps the Bitcoin Core architecture, but replaces ECDSA with Falcon-512 from block zero. No premine, no ICO, no retroactive patchwork, just a chain built for the threat before the market cared. If the market finally wakes up to quantum risk, it may have to rediscover $TDC.
10
21
260
₿ellsDesigner 🔔 retweeted
Bellscoin @BellsChain is the best undiscovered story in the entire meme space. It is the father of Doge and shares the same genesis message, “Nintondo,” because Dogecoin was forked from Bellscoin. It is also merge mined with Litecoin and Dogecoin, giving it one of the highest hash rates in the space. All confirmed by the founder of Dogecoin.
Replying to @Sizzouu
it was inscribed in the genesis block of bellscoin as a nod to nintendo / animal crossing then since dogecoin was a quick fork of bellscoin it’s also in doge’s genesis block xD
18
43
89
5,539
₿ellsDesigner 🔔 retweeted
Replying to @ViaBTC
The risk is immediate - not only from quantum computers breaking keys today, but also from Harvest Now, Decrypt Later. Adversaries record transactions now and crack them later. The Federal Reserve flagged this for blockchain specifically (FEDS 2025-093). BIP-361 is a proposal. Tidecoin has been signing every transaction with FALCON-512 (NIST FIPS 206) since December 2020. 5+ years in production, 2.4M+ blocks, zero incidents. The question isn't whether PQ migration is possible - it's why it hasn't started yet.
6
16
314