How Bitcoin Survives Quantum Computers (ft. Dan Boneh)

How Bitcoin Survives Quantum Computers (ft. Dan Boneh)

Source: YouTube · a16z crypto · published Aug 22, 2026 · 1:09:38

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Dan Benet argues that hash-based signatures are the pragmatic choice for Bitcoin and Ethereum’s post-quantum transition due to their reliance on established assumptions, while introducing a novel hybrid method that uses lattice cryptography for thresholding to preserve signature efficiency 2:22.

Key Takeaways:
• Hash-based signatures are favored for Bitcoin and Ethereum because they eliminate the discrete log assumption and avoid new cryptographic risks, unlike lattice-based schemes which face community resistance 3:05.
• Stateful hash-based signatures (like XMSS) offer short signatures but require strict state management; Benet mandates hybrid deployment with ECDSA to prevent key compromise if state is lost before Q-day 7:51.
• Bitcoin’s "Shrinks" proposal utilizes a dual-key system: a long-term stateless key for emergency recovery and a short-term stateful key for daily transactions, significantly increasing signature size 21:06.
• Benet presents a new thresholding approach where the final signature remains hash-based, but the thresholding mechanism uses lattice cryptography, enabling large-scale thresholding without exposing the structure on-chain 36:36.
• Addressing abandoned assets requires complex recovery mechanisms, such as using commitment schemes to prove ownership of pre-quantum keys once ECDSA is revoked 6:41.

The transition to post-quantum security is inevitable; while hash-based signatures present engineering challenges regarding state management and size, they provide the most robust foundation for future blockchain security.

Sources:

  • 2:22 Overview of post-quantum signature families and the shift toward hash-based crypto.
  • 3:05 Reasons why hash-based signatures are becoming the standard for Bitcoin and Ethereum.
  • 7:51 The critical danger of stateful signatures and the need for hybrid schemes.
  • 21:06 Explanation of Bitcoin's "Shrinks" proposal and its dual-key structure.
  • 36:36 Introduction of the new lattice-based thresholding method for hash-based signatures.
  • 6:41 Discussion on the technical challenges of handling abandoned assets post-quantum.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. So, always a great week at A6Z crypto when Dan Benet comes and visits. Uh, so legendary cryptographer, longtime Stanford professor, mentor to hundreds of people in the crypto space I would say and as always talking about something super super timely and relevant postquantum signatures. Dan, >> awesome. Thank you. Thank you, Tim. And uh always a pleasure to visit the lab. For those of you watching the video, uh this lab is phen phenomenal. If you have an opportunity to visit the lab, you should jump on it and uh take any chance you get to visit this place. Okay. So, uh today I wanted to talk about uh basically this question of postquantum signatures uh for for blockchains. The talk is going to have uh two parts to it. Uh the part that's uh that's new is going to is joint work wit…