After half a year of discussing quantum threats, the thinking has basically been “how to stop it”—freeze old exposed addresses and quickly switch to quantum-resistant signatures. @projecteleven This time they asked a different question, and I think it’s closer to reality: if quantum can already forge your signature, how do you prove the coins are still yours and move them away?


They released a prototype of a zero-knowledge proof. The idea is: you don’t reveal the private key; you only prove that you know the key “one level above” that address in the wallet’s derivation tree, and that this key can derive the address. It’s like using the HD wallet’s derivation path as an ID—quantum can’t forge that layer.
Proof generation takes 243 milliseconds and verification takes 40 milliseconds, running on an M5 MacBook Air with 4 CPU cores, with no need to use the GPU. Compared with the earlier 14.6-second solution that relied on a GPU, it’s about 16x faster. It’s essentially bringing “post-quantum self-rescue” from the lab onto a laptop.
But there’s a critical weakness—right where the value is highest: it can’t save Satoshi’s ~1.1 million BTC. Because the old P2PK addresses were created before HD wallets existed, there’s no “upper-layer derivation key” to prove, and the public key is already exposed on-chain. This method is = unsolvable for those.
And the official statement is also very straightforward: it’s an early prototype, un-audited; now it still can’t be used to recover assets on any real chain.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned