#Quantum and #Bitcoin enthusiast❤️Quantum Awareness ❤️ No quantum security, no future ❤️ No investment advice here❤️AI Creator ❤️Love peace and freedom❤️

🚨#Bitcoin will go to zero as the U.S. government phases out the elliptic curve algorithms it uses. If Bitcoin doesn't transition to #quantum-resistant, it will inevitably cause irreversible losses to investors. 😭 #Whistleblower NIST IR 8547 LINK👇 nvlpubs.nist.gov/nistpubs/ir…
20
36
100
47,004
₿/Quantum safe ❤️ /Jason❤️ retweeted
Which accepted post-quantum cryptography standards survive to the end of this year? Yes, I mean with AI grinding applied to cryptography. After this week's OpenAI drop of 722 open-problem results, is it a fair question? 722 results and zero on crypto. Not interesting, or too interesting? Q-day was supposed to require a quantum computer ;) I will bet 10 million dollar on: SHA-256 make it to New Year's Eve. (Lattices might be drinking alone.)
3
4
9
537
Things are about to get interesting! #Bitcoin
Made with AI
3
77
₿/Quantum safe ❤️ /Jason❤️ retweeted
Upgrade everything
2
14
894
Replying to @ChrisPeikert
@ChrisPeikert ,one of the top-tier lattice-based experts, did explain "Now AI will help speed up that process more systematically." after @claudeai attacking Hawk months ago, while @hashbreaker has nevr say AI will bring lattice algos a GNFS-level attack. x.com/VitalikButerin/status/…
1
1
3
115
₿/Quantum safe ❤️ /Jason❤️ retweeted
Quantum computers could solve advanced physics questions and bring breakthroughs in medicine and national security. But, qubits are fragile, lasting milliseconds before their quantum state collapses. Fermilab physicists are working to extend this coherence time.
7
13
80
3,386
₿/Quantum safe ❤️ /Jason❤️ retweeted
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography. The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices. (and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation) So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math. The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be? This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-. For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption. And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10. To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety. And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all. Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems. For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size). Concrete TLDR, my own personal views: * Hash-based > lattice-based, in those situations where hash-based is possible at all * For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ... * For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism. * If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**. * For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money" firefly.social/post/x/210783…
450
740
4,388
598,309
Disagree with @drakefjustin The possibility of ECDSA breaks before Q-day, in the worst case in months, is tend to be infinite zero. Especially by a large GPU cluster, which can NOT be done via Shor's Algo which is the only way .
Stop reusing addresses to protect individual property is fine while even a single pub key of anyone cracking then that whole entire system will soon be deemed collapsed, right? In that insight, actually, that "don't reuse" wastes. eh?
3
6
178
Wow, is something big about to happen? #Bitcoin
The U.S. government continues to move funds, transferring another $566M over the past 10 hours, including 4,632 $BTC($384.5M), 119M $USDT, and 750 $WBTC($62.34M).
1
1
8
281
I see your point, but I wonder if hackers might deliberately avoid those big targets and quietly go after mid-sized wallets instead. That could help them stay under the radar. With so many potential targets, they could gradually siphon off funds and continue profiting without drawing too much attention. 😅. #Bitcoin #Ethereum #BTC #ETH #USDT #BNB #XRP #USDC #SOL #TRX #ZEC #HYPE
While I agree, I think this greatly downplays a risk for stablecoins, tokenized assets and DeFi living on top of EVM. Minting, burning, KYC are all controlled by an elliptic curve key admin and ecrecover. Quantum computer is not going to go hack Bob's wallet. BlackRock BUIDL or Circle admin keys controlling billions are a much juicier target and harder to safeguard.
2
1
7
349
₿/Quantum safe ❤️ /Jason❤️ retweeted
Replying to @drakefjustin
Maybe that’s a good approach. It could significantly spread out the migration load and reduce the risk of severe congestion when Q-Day arrives and a massive number of users try to migrate at the same time. #Bitcoin The following is some material I put together four years ago. I’d appreciate any feedback.
Give institutions and governments a little more time to research whether Bitcoin can successfully migrate to quantum-resistant! This is a list I compiled several years ago outlining the obstacles to Bitcoin’s migration to quantum-resistant. Perhaps I will add a few more fatal obstacles in the future. 1. No suitable quantum-resistant algorithm 2. Hash-based and lattice-based algorithms have excessively large public keys and signatures 3. Migrating to quantum-resistant algorithms could cause severe on-chain congestion and even paralysis 4. Quantum-resistant algorithms result in a significant reduction in transaction efficiency 5. Increased node and transaction fees 6. Who has the authority to freeze or burn Satoshi’s addresses and other lost addresses 7. The aggregation threshold in quantum-resistant algorithms is challenging 8. Taproot makes the transition to quantum-resistant even more difficult 9. High hardware upgrade costs 10. 1MB block size is not suitable for quantum-resistant algorithms 11.Achieving global consensus is extremely difficult and more...
3
10
584
Have you heard of #Raqcoin? It’s not the first quantum-resistant cryptocurrency, but it is the first quantum-resistant cryptocurrency to use a multivariate algorithm. I’m curious to see if any other cryptocurrencies using multivariate algorithms will emerge in the future.
Have you heard of #Raqcoin? As far as I know about #Raqcoin 1. Quantum resistant 2. First Multivariate Digital Signature with #Zipcodinization 3. Zipcodinization, public keys can be compressed to around 100 bytes (Corrections are welcome) 4. Has smaller public keys and signatures 5. 90-year Proof-of-Work 6. Use an early version of the Bitcoin codebase 7. Offline Verification 8. Reduce quarter every 4 years 9. Multivariate Mining (mathematically meaningful) — not Hash Mining 10. Mining with NVIDIA GPUs (seems to also support ASIC miners) 11. Verifying transactions for the same address is faster 12. Under the framework of ABC Coin, whose original parameters had been broken and whose security level was below 1, new parameters 1, 3, and 5 were adopted, and, using algorithm agility, the coin was forked into a new coin, Raqcoin, based on UOV and Rainbow 13. Crypto-agility(UOV& Rainbow ) signature,Convert between addresses of different security levels (7kinds) 14. The mining power has been monopolized by some teams, making solo mining very difficult 15. Total supply is 2.1 billion, with around 1 billion currently mined abcscan.io/#/ 16. Still not listed on exchanges after 8 years GitHub👇 github.com/abcmint/abcmint No investment advice here: don’t buy anything from unknown sources—just study it.
4
7
273
₿/Quantum safe ❤️ /Jason❤️ retweeted
Public blockchains are planning one PQC change. They will need more than one. Crypto-agility on a chain means being able to change the cryptography again, and to retire what it replaced, and no major chain has built it yet. Zcash proved a chain on mainnet can change fast when its developers built the machinery in advance. A researcher found a counterfeiting flaw in its Orchard pool on May 29. The developers disabled the pool on June 2, shipped a corrected circuit on June 3 and sealed the pool behind a new one on July 28. Bitcoin and Ethereum are planning as if the first change were the last: - BIP-360, Bitcoin's post-quantum output type, got its number in December 2024, was merged as a draft this February and has no activation date. - Ethereum's Protocol cluster committed on September 7 to a quantum-resistant layer 1 by December 2029. Frame transactions are scheduled for the Hegotá upgrade, also without a date. Quantum computers are one reason chains will change their cryptography again. New cryptanalysis, AI-assisted attacks, flaws in circuits and libraries, national algorithm choices and deprecation schedules are the others. For EU exchanges and custodians this is already an obligation under DORA's technical standard, which requires an encryption policy that provides for changing cryptography as cryptanalysis develops. If one chain you hold on had to replace its signature algorithm next year, how long would your custody stack need? postquantum.com/post-quantum… #CryptoAgility #PQC #PostQuantum #Bitcoin #Ethereum #Zcash #DigitalAssets #Cybersecurity #CISO
3
4
9
583
Okay, a few other questions: When will Bitcoin start transitioning to be quantum-resistant? What obstacles will it face during the transition? And are the properties of quantum-resistant algorithms actually suitable for Bitcoin?
Q-DAY: It isn’t about whether BTC is quantum hardened in time. It’s WHEN do we see the 1.7M BTC of vulnerable lost coins making their way back onto the market. It’s a downward repricing event. BTC will survive. I’d buy that dip.
8
239
Wow! I don’t think freezing privately owned bitcoin because of the quantum threat is a good option. Are there any better alternatives?
Replying to @willywoo
A lot of bitcoiners I talk to believe we should freeze those coins to prevent a repricing event
5
219
Which quantum-resistant PoS cryptocurrencies are you following?
Made with AI
1
4
8
227
₿/Quantum safe ❤️ /Jason❤️ retweeted
Become the Hero of Your Network Security! Develop the skills to secure your organizations data in the era of quantum computers!
Quantum is Coming! Is Your Network Prepared? To prepare for this new technology that will revolutionize cybersecurity, check out our upcoming class Preparing Your Network for a Post-Quantum World October 13-15 Exclusively at Hackers-Arise hackersarise.thinkific.com/b…
7
29
7,553
₿/Quantum safe ❤️ /Jason❤️ retweeted
Replying to @1096361BTC
Quantum risk is getting harder to ignore
1
3
223
₿/Quantum safe ❤️ /Jason❤️ retweeted
Replying to @1096361BTC
Quantum risk creeping up faster than we think, huh? That Satoshi stash is a wild target.
1
1
303
₿/Quantum safe ❤️ /Jason❤️ retweeted
Five lessons from years inside the quantum threat conversation: 1. Quantum risk becomes unequivocally imminent when you no longer have time to migrate your chain and your users' funds. And no one knows when that is for certain. 2. Shipping a PQ signature scheme is not the same as completing a migration, it is the beginning. 3. Most classical chains will announce readiness long before users make their first transaction. 4. Post-quantum from genesis is the only way to ensure a full user migration, by making sure you never need one. 5. The chains that matter most are the hardest to migrate. The more successful the chain, the broader the scale. The broader the scale, the more work necessary to migrate to post quantum security. Where have you heard, "Post quantum security is absolutely not a threat to our chain, but we're forming a committee just in case"?
2
7
24
617