Bitcoin Forum
May 13, 2026, 08:34:00 PM *
News: Latest Bitcoin Core release: 31.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Avoiding An Unnecessary Quantum Freeze  (Read 374 times)
hmbdofficial
Member
**
Online Online

Activity: 182
Merit: 44


View Profile
May 08, 2026, 05:23:42 AM
Merited by stwenhao (1)
 #21

Quote
wouldn't a Quantum Computer still crack those wallets?
It could crack the private keys, but not the seeds.
Thats practically saying it could just crack one address since it can’t crack the seed, the effect might be minimal I think. Since it’s only the seed phrase that can generate the extended private key.
Wind_FURY
Legendary
*
Offline

Activity: 3640
Merit: 2184



View Profile
May 11, 2026, 11:33:19 AM
Merited by stwenhao (1)
 #22

Quote
wouldn't a Quantum Computer still crack those wallets?

It could crack the private keys, but not the seeds.


Then doesn't that mean the "you need ECDSA, and a Quantum Signature to move it" scheme is irrelevant from the viewpoint of the attacker?

Quote
wouldn't a Quantum Computer still crack those wallets?
It could crack the private keys, but not the seeds.

Thats practically saying it could just crack one address since it can’t crack the seed, the effect might be minimal I think. Since it’s only the seed phrase that can generate the extended private key.


If it could crack one address derived from the seed, then it could crack all addresses derived from that seed.

   ¯\_(ツ)_/¯

stwenhao
Hero Member
*****
Offline

Activity: 691
Merit: 1808


View Profile
May 11, 2026, 11:59:28 AM
 #23

Quote
Then doesn't that mean the "you need ECDSA, and a Quantum Signature to move it" scheme is irrelevant from the viewpoint of the attacker?
It is relevant, because the attacker would be able to break only ECDSA, but not the quantum part, which could require for example knowing the seed.

Quote
If it could crack one address derived from the seed, then it could crack all addresses derived from that seed.
Of course. But the attacker still wouldn't know the seed. And if it will be required in that "quantum part", then only the real owner would be able to make it.

Think about it for a moment: if the real owner knows the seed, and the attacker cannot get it, without breaking hash functions behind it (which is different case than breaking elliptic curves), then it can be used to check, if a given signature is made by the attacker, or by the real owner.

Quote
Thats practically saying it could just crack one address
No, because if committing to the seed will be part of the "quantum path", then only the real owner would be able to do that.

In general, the main downside of using that approach, is that not all public keys are derived from seeds, some of them are just randomly generated, if some user is not using any kind of HD wallet. If not that, then it would be much easier to reach consensus here, and simply require committing to the seed for all old addresses. But because there are non-HD keys in use, that approach would make them unspendable (or rather: as hard to spend as "bitcoin eater", and similar addresses: it would simply require breaking the cryptography behind converting seeds to keys).

Proof of Work puzzle in mainnet, testnet4 and signet.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!