Bitcoin Developers Kick Off Quantum-Safety Track With BIP-360

Bitcoinistcom
BTC3,73%

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin’s quantum-security discussion just gained a concrete new artifact in the code-and-spec pipeline: an updated draft of BIP-360 has been merged into the official Bitcoin Improvement Proposals repository, proposing a Taproot-adjacent output type designed to limit exposure to future quantum key-recovery attacks.

The change matters less because it “solves” quantum risk today, and more because it formalizes a specific, opt-in path that preserves Taproot’s script-tree functionality while removing the spending route considered most problematic under a quantum-threat model.

Bitcoin Devs Make First Formal Quantum-Resistance Move

Anduro, a research-focused platform incubated by Marathon Digital (MARA), said on X that the merged update “introduces Pay-to-Merkle-Root (P2MR), a proposed new output type that omits Taproot’s quantum-vulnerable key-path spend while preserving compatibility with Tapscript and script trees.”

Related Reading: Bitcoin Is ‘No Longer Digital Gold,’ Deutsche Bank Strategist SaysIn BIP terms, the proposal is scoped as “Consensus (soft fork)” and defines P2MR as a new SegWit v2 output that commits directly to the Merkle root of a script tree, rather than to a tweaked public key as in Pay-to-Taproot (P2TR). The practical implication is straightforward: P2MR outputs can only be spent via script-path logic; the key-path spend is removed entirely.

The BIP’s abstract frames the goal in terms of minimizing changes while providing an option set for users who want additional protection:

“This document proposes a new output type: Pay-to-Merkle-Root (P2MR), via a soft fork. P2MR outputs operate with nearly the same functionality as P2TR (Pay-to-Taproot) outputs, but with the key path spend removed.”

It adds that the intended protection is against “long exposure attacks by Cryptographically Relevant Quantum Computers (CRQCs),” as well as “future cryptanalytic approaches that may compromise the elliptic curve cryptography (ECC) used by Bitcoin.”

A key element of the BIP is definitional discipline: it distinguishes “long exposure” attacks (where public keys are available on-chain for extended periods) from “short exposure” attacks, which would target public keys revealed briefly in the mempool during an unconfirmed spend.

The document is explicit that P2MR is not a complete quantum shield. “It is worth noting that proposed P2MR outputs are only resistant to ‘long exposure attacks’ on elliptic curve cryptography; that is, attacks on keys exposed for time periods longer than needed to confirm a spending transaction,” the BIP states.

“Protection against more sophisticated quantum attacks, including protection against private key recovery from public keys exposed in the mempool while a transaction is waiting to be confirmed (a.k.a. ‘short exposure attacks’), may require the introduction of post-quantum signatures in Bitcoin.” The authors add they “intend to offer a separate proposal for this purpose upon further research.”

That split is also why the proposal emphasizes tapscript compatibility. It positions P2MR as a script-tree output type that could, if Bitcoin ever adopts post-quantum signature opcodes, provide a cleaner upgrade runway than older script mechanisms that don’t support tapscript’s evolution path.

Anduro highlighted that the change is designed as a soft fork and “does not affect existing Taproot outputs.” P2MR would be a new output type (with bech32m addresses starting with bc1z) rather than a retrofit of existing bc1p Taproot UTXOs.

Related Reading: Bitcoin Whale Exchange Outflows Spike: Sign Of Dip Buying?The proposal also doesn’t pretend the swap is free. By removing key-path spends, P2MR gives up Taproot’s most compact witness path (a single Schnorr signature). The BIP estimates that a minimal P2MR spend witness is 37 bytes larger than a Taproot key-path spend, though it can be smaller than an equivalent Taproot script-path spend because P2MR’s control block omits an internal public key.

Privacy shifts too. Because every spend is script-path, P2MR users necessarily reveal they are spending from a script tree—something Taproot key-path spends can avoid signaling.

Anduro said the update also “addresses criticism about Bitcoin devs not taking the quantum threat seriously,” and noted the addition of Isabel Foxen Duke as co-author to make the BIP clearer “to the general public, not just the Bitcoin developer community.”

BIP-360 remains in “Draft” status. But its merge into the canonical repository is still a meaningful process marker: it moves the quantum-safety conversation from abstract worry and mailing-list hypotheticals toward a specific consensus change proposal that wallets, libraries, and reviewers can now analyze line-by-line.

If the debate has a next phase, it’s likely to center on whether “prepared not scared” opt-ins like P2MR are sufficient groundwork or whether Bitcoin will eventually need to grapple directly with post-quantum signatures and the operational realities of migrating value at scale.

At press time, BTC traded at $66,558.

Bitcoin price chartBitcoin must reclaim the 200-week EMA, 1-week chart | Source: BTCUSDT on TradingView.comFeatured image created with DALL.E, chart from TradingView.com Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

Bitcoin Depot 推出企业级金融服务平台 ReadyBucks

Gate News 消息,3 月 10 日,纳斯达克上市的比特币 ATM 运营商 Bitcoin Depot 宣布推出企业级金融服务平台 ReadyBucks,为小企业、零工经济从业者及独立承包商提供营运资金支持。据 Globenewswire 报道,ReadyBucks 目前已在美国多个州上线,后续计划逐步扩展至更多地区。

GateNews8m geleden

美股上市公司 Hyperscale Data 比特币持仓增至 617.16 枚,市值约 4070 万美元

Hyperscale Data 在 3 月 10 日宣布,其比特币持仓增至 617.1605 枚,总值约 4070 万美元。子公司 Sentinum 持有 569.9670 枚比特币,ACG 购得约 47.1935 枚。公司目标为将比特币价值提升至 1 亿美元。

GateNews35m geleden

Glassnode:近60万枚BTC在回调中被买入,6万至7万美元区间持仓占流通供应8%

3月10日,Glassnode数据显示,比特币回调至7万美元时,交易者逢低买入近60万枚BTC,总价值约424.8亿美元。当前6万至7万美元区间的持仓成本显著增加,流通供应中约8%为该区间买入。

GateNews36m geleden

伯恩斯坦维持 Circle 跑赢大盘评级,目标价 190 美元,上涨空间达 70%

伯恩斯坦分析师对稳定币发行商Circle维持看涨观点,目标价190美元,预计上涨70%。分析指出稳定币与加密市场逐渐脱钩,USDC供应已反弹至约780亿,稳定币整体供应达到1840亿。

GateNews38m geleden

某长期套利巨鲸转向单边看空,空单总持仓规模达 3490 万美元

近期,0xcac巨鲸地址的持仓结构发生显著转变,转向单向加仓空单,当前BTC和ETH现货约1100万美元,空单规模达3490万美元。主要头寸中20倍BTC空单浮盈548%,20倍ETH空单浮盈1886%。

GateNews47m geleden
Opmerking
0/400
Geen opmerkingen