Bitcoin's Quantum Migration Could Take Years, Warns Ledger CTO
Charles Guillemet, Ledger's chief technology officer, has warned that Bitcoin's migration to a post-quantum world could take years. He emphasized that Bitcoin does not face an immediate quantum-computing threat but needs to prepare for the future.
Guillemet analyzed SHRINCS, a proposed hash-based signature scheme designed specifically for Bitcoin. While it offers 128 bits of classical security and 64 bits of quantum security, it is still in draft form without a full security proof. Existing Bitcoin wallets use ECDSA and Schnorr signatures, which could be broken by a quantum computer running Shor's algorithm.
The proposed post-quantum implementation, SHRINCS, has significant implications for wallet functionality and user experience. Stateful signatures are much larger than current Schnorr signatures, requiring no reuse of one-time signing keys. This means that restoring funds from an old backup or cloned devices could result in loss of funds.
The complexity of migrating to a post-quantum world is compounded by existing wallet functionality and hardware limitations. Some post-quantum implementations may have increased hashing, memory, and signing times compared to current Bitcoin transactions.