Post
Topic
Board Development & Technical Discussion
Merits 4 from 2 users
Re: J. Lopp's Post-Quantum Migration BIP
by
Medusah
on 28/07/2025, 08:43:58 UTC
⭐ Merited by vapourminer (2) ,d5000 (2)
On the current quantum-resistant algorithms, Lopp doesn't believe any is good enough for Bitcoin. He even said "they suck" if I remember it correctly. They take up too much space. The signatures and keys are longer and they are slower to verify. He clarified that the idea of the BIP is not to choose a post-quantum algorithm, but how to get the community to migrate to a new system asap after one is chosen.

These are the proposed solutions:

The least worst, in my opinion, is FALCON-512.  Easier to verify (0.6x), and "only" 10x in size, in comparison with Schnorr.  It will be 24x slower to sign it, but that's completely fine, IMO.