A Quantum Fork is Coming to Bitcoin | Alex Pruden & Philip Martin
- Two papers published weeks before this April 2026 recording collapsed the quantum threat timeline and triggered the current panic cycle. Google Quantum AI, including cryptanalyst Craig Gidney, argued that targeting ECDSA specifically—not legacy RSA—makes the attack "much more imminent," while a Caltech-rooted neutral-atom team argued Shor's algorithm may run on as few as 10,000 reconfigurable qubits versus the prior 500,000–1M estimate; IBM already has ~1,000-qubit systems and entanglement demos near 7,000, leaving roughly one order of magnitude to cryptographic relevance.
- Bitcoin is the uniquely exposed asset:
10% of supply is Satoshi's presumed-dead coins ($150B at a ~$1.5T market cap), and ~35% of all BTC has exposed public keys. Alex Pruden's view is that "there's going to be a fork here… I think it's inevitable"—a freeze camp and a no-freeze camp, with the market resolving it like Bitcoin/Bitcoin Cash, except this time "there's some potential real security implications" rather than free upside on both chains. - Philip Martin's personal view (explicitly not Coinbase's): freeze the vulnerable coins but build a recovery path. "It doesn't make sense to me that we would have that much value up for grabs by the first person who can break a key"—lock them, then let holders reclaim by proving seed-phrase access. Coinbase itself will "upgrade all the keys that we have" once a viable path exists and otherwise "listen to our customers"; Pruden's framing is that exchanges, ETF issuers, and balance-sheet holders are the freeze camp, since economic nodes "have the most to lose."
- Even a successful migration is ugly: the FALCON/FN-DSA signature discussed is ~10x current ECC size, threatening throughput and "another block size debate," and the host cites Google's post on its "nightmarish complexity." Worse, Google's proposed machine runs Shor's algorithm in 9 minutes against Bitcoin's 10-minute blocks, enabling mempool front-running of clean addresses—at which point "migration is kind of just going to turn into a giant bidding war of fees."
- Stablecoin issuers face a special quantum urgency—not the bank accounts, but the on-chain admin keys, which Pruden calls potential "nation-state level targets." His scenario: an attacker who wants to disrupt the US financial system mints "$300 trillion dollars of USDT," breaks a peg, and cascades through interconnected DeFi à la the Kelp DAO bridge drain—potentially causing billions in losses and extreme disruption.
- On timing the guests split productively: Coinbase's paper calls the date "largely irrelevant" because the fix takes so long you must start now, while Project 11 publishes 2029 optimistic / 2033 base / 2042 pessimistic cases to counter the lazy "it's always 20 years away." Both endorse Mosca's inequality— weigh defender migration time against attacker arrival—and Pruden warns there may be no public "ChatGPT moment": cryptanalysis-relevant progress is government/DARPA-funded and "very likely to happen behind closed doors," as Google already withheld its circuit.
- The through-line for allocators: quantum plus AI-scale attack models (the "Mythos" discussion) push crypto toward more permissioned, geographically fractured systems. Martin argues that more permissioning is inevitable in a world of sovereign states, while Alex resists "heavyweight permissioned DeFi blockchains" but says losing ~$1B/year to attacks "is just untenable"; Alex's middle path is USDC-style freeze-by-exception and account abstraction, while the host points to quantum-first chains like Zcash trading on the PQ narrative. Martin warns a major trust breach could mean institutions can no longer touch Bitcoin.
1. Two papers just collapsed the qubit bar by an order of magnitude
- The trigger for Nick Carter's "Bitcoin Core is sleepwalking towards collapse" discourse, per Pruden: Google Quantum AI (with cryptanalyst Craig Gidney) showed that targeting ECDSA specifically—rather than the older RSA focus of prior work—plus assumptions about the machines actually being built makes the threat "much more imminent than we potentially first thought." Notably, the paper was "1/4 quantum computing paper and 3/4 survey of the digital asset space," explicitly urging migration to post-quantum cryptography.
- Paper two, from an S-tier Caltech physics team behind a neutral-atom startup called Aor Atomic, founded by people including Dylan Blowstein: Shor's algorithm "may be possible with as few as 10,000 neutral atom reconfigurable qubits" versus the prior 500,000–1M estimate. With IBM at ~1,000 qubits and ~7,000-qubit entanglement, "you're kind of like an order of magnitude at least" from cryptographic relevance.
- Martin's caveat that frames the whole episode: everything here is speculative—"reasonable people [can] have wildly divergent views about what's true… in a way that I think I've rarely ever seen."
2. The threat is all of modern cryptography—but blockchains can't call the bankers
- Martin widens the aperture: a cryptographically relevant quantum computer (CRQC) breaks "the ability to use the internet safely"—finance, government, everything—and much deployed hardware isn't crypto-agile. Will IoT chips run PQ algorithms? Will manufacturers upgrade? "Maybe yes, maybe no… this really truly when it comes to pass will be Y2K would be underestimated."
- Pruden's key distinction: traditional finance runs on trusted parties who can revert—"a bunch of important bankers sitting around being like, hey, whoever did that last entry, erase that"—so profiting from an attack on SWIFT is harder. On blockchains "the authorization to move funds is entirely cryptographic," one-factor by design, which makes both migration and mitigation uniquely hard.
- The ball is already rolling elsewhere: roughly a third to half of internet traffic is secured with hybrid cryptography implementing PQC, and banks are migrating. Bitcoin alone lacks even a roadmap—most chains have one, and at least a couple have PQ testnets live.
3. The vulnerable pot: not just Satoshi's ~$150B, but 35% of supply
- The framing the hosts test: Satoshi's ~1.7–1.8M coins (~10% of a ~$1.5T market cap) become "the biggest pot of money on the internet that you can go attack" if the rest of Bitcoin upgrades and they don't. Pruden's correction is load-bearing: "upgraded" is the wrong voice—"you must upgrade, right? Not your keys, not your crypto." Roughly 35% of all Bitcoin has exposed public keys today. Project 11 maintains a searchable "risk list" at project11.com, and some exchanges with weaker practices than Coinbase have left significant value exposed.
- Martin's personal position (prefaced hard: "this is not Coinbase's view"): "we have to prevent a quantum computer from stealing it," paired with recovery schemes—proving access to seed phrases—so genuine holders can bring frozen coins back to life.
- The philosophical knot Pruden identifies: digital-gold supply integrity (a quantum thief dumping "a tenth of all gold" destroys store-of-value confidence) collides with Satoshi's founding property-rights ethos. Bitcoin's uniquely large value and age make it "a uniquely difficult conversation" that slows threat recognition.
4. Pruden's call: a fork is inevitable, and the economic nodes have the most to lose
- His view, with its stated hedge: "there's going to be a fork here. I think it's inevitable… ultimately the market will determine which of those is more valuable." But unlike Bitcoin/Bitcoin Cash—where "everyone gets two of whatever they had before," pure upside—here there are real security implications, so the split won't be clean.
- The player map: a thinned-out core-dev bench (many 2017-era figures gone; Adam Back/Blockstream, Greg Maxwell, and Matt Corallo remain), institutions with far more skin in the game than a decade ago, miners who "are going to do what they think everyone else wants," plus a long tail of loud ideologues who are "kind of spoilers for doing something pragmatic"—the same constituency that arguably won the block-size wars while outnumbered in capital.
- Pruden's framing: freeze camp = institutions, ETF issuers, exchanges, and custodians who "can't tolerate client-asset risk"; no-freeze = maxis and ideologues—and if Coinbase points its custodied coins at one chain, "that's basically your decision." Martin's answer on how Coinbase would choose: weigh customers and stakeholders "very very heavily," and either way upgrade all Coinbase-held keys once a viable path exists. The host argues that the catastrophic tail risk makes upgrading economically rational.
5. The steelman against freezing: where do you draw the confiscation line?
- Pruden's honest counter: Satoshi's coins are "kind of a straw man." About 15% of Satoshi's coins make up about two-thirds, according to Chainalysis, of the lost coins; "how lost are the lost coins?" is itself a question. On the margin, a long-term holder and someone who lost their keys may be impossible to distinguish.
- The liability nightmare: suppose BIP-361's author presses merge, miners comply, and someone wakes up to find their Bitcoin inaccessible—"do they have a legal claim against the author of that bit or the person that pressed the button? I don't know." And a generous 10-year claim window reintroduces the very risk it's meant to solve, since a relevant quantum capability may exist within it.
- On execution: Bitcoin has no foundation, just "this never-ending political battle of who gets to be spokesman" (Pruden cautiously invokes a New York Times report suggesting Adam Back may be working on something). Pruden's test from having shipped an L1: "there's a big gulf between the white paper and the thing that is secure that can secure trillions of dollars… right now we're in the idea phase."
- One elegant hybrid he floats: roll unclaimed frozen coins into the security budget, pre-funding the post-emission era—but he assigns it low probability because "this is just a huge controversial rats nest… people will just be happy to be done with whatever a simple thing."
6. Even success is painful: signature complexity, fee wars, and the 9-minute machine
- Martin's post-upgrade warning: the smallest of the larger PQ signatures are ~10x current ECC size, which "is going to impact throughput, or it's going to kick off another block size debate." The host identifies the signature under discussion as FALCON/FN-DSA, says it will probably be standardized under that name, and cites Google's post on its "nightmarish complexity"—"you think DeFi hacks were hard now to prevent, wait till people are trying to roll something like that into production."
- The slow-clock/fast-clock distinction matters for everyone, not just dormant coins: Google's proposed architecture runs in 9 minutes against Bitcoin's 10-minute block time, so even a never-exposed public key can be front-run in the mempool the moment it transacts. "Once you get to that point, migration is kind of just going to turn into a giant bidding war of fees." Pruden personally believes fast-clock architectures lag slow-clock ones—but concedes "no one really knows... for how long that will be true."
- On claim windows, Martin's operational realism: "I don't know if there's a big difference between giving 1 year and 5 years"—90% of migration happens in the first month, then a "super long drippy tail." The hard problem is reaching everyone who needs to take individual action, including people with a Ledger in their home safe.
7. The do-nothing scenario: it's the trust breach, not the dump—and rivals smell blood
- Host war-gaming: does Bitcoin fade into irrelevance if 10–20% of supply gets accessed and dumped? Martin separates the mechanical price hit from the real threat: "the impact on the trust of the network… Does this mean that institutions can no longer touch the asset? And if so, what's that going to mean for the future of Bitcoin?"
- The host flags the competitive angle: protocols see differentiation in being PQ-first—"Zcash is one that I think has leaned into this… there's a lot of truth to it."
- On the adjacent existential question, Martin favors tail emission: inflation as a percentage can trend toward zero while a constant inflation rate gives miners a planning basis—"either you have to assume that the coins just keep going up in value and the hash rate stays the same, or you have to assume that there's some continued emission. You don't really get both." Alex says he doesn't disagree, but notes the original theory was that fees would replace block rewards; both treat the security budget as important to Bitcoin's continued transability.
8. Stablecoin admin keys are nation-state targets—and the permissioning drift is coming anyway
- Pruden on why Project 11 gave stablecoins their own section: the bank account is safe in this framing—"a quantum computer can't reach into the bank account and manifest the dollars"—but issuer admin keys are "definitely critical infrastructure, and potentially nation-state level targets." His chaos scenario: mint $300T of USDT, break a peg, and let ripple effects tear through interconnected DeFi as with the Kelp DAO bridge drain—"incredibly disruptive" even if it does not have a lasting real-financial impact.
- The freedom debate, with Martin's origin story intact: Martin entered crypto working with Syrian refugees in the Middle East, but "the freedom cuts both ways—it's also freedom for North Korea to fund its nuclear program." His conclusion: in a world of sovereign nation states ("the US government could throw me in jail… but the Ethereum network can't really do that to me"), "you're inevitably going to see more permissioning" and perhaps fracturing "across geographical lines."
- Alex's line in the sand: people will always write insecure code, so flag risky contracts rather than gatekeep them—"I don't want to live in a world where we have a bunch of heavyweight permissioned DeFi blockchains… [but] losing a billion dollars a year to these things is just untenable," otherwise crypto becomes "just bank 2.0."
- Pruden's middle path against the host's assume-users-get-hacked push: USDC-style freeze-by-exception (act on the guilty) versus banking's prove-you're-not-guilty onboarding—"even though it seems like a small difference… it's one of the reasons stablecoin transactions really took off"—plus account abstraction so grandmother-grade and entrepreneur-grade authorization can coexist.
9. Timelines, closed doors, and deleting your fingerprints
- The timeline disagreement is mostly about framing: Coinbase's paper calls the timeline "largely irrelevant"—"it doesn't matter to me if a quantum computer shows up in 2030 versus 2040, we have to start the work today," and "once you start throwing dates around you start to argue about the dates." Project 11 published 2029 optimistic / 2033 base / 2042 pessimistic precisely because "people are kind of lazy… it's 20 years away cuz it's always 20 years away." Both invoke Michele Mosca's inequality: attacker arrival time must be weighed against defender migration time, so "start preparing today" without panic.
- On quantum's ChatGPT moment they split cleanly: Martin expects visible supremacy in simulation/drug discovery; Pruden's darker take—cryptographically relevant progress "is very likely to happen behind closed doors." Pruden says Google already withheld its circuit, proving in zero knowledge that it used only X operations, and the industry's funding is dominated by governments and DARPA-equivalents buying cryptanalysis they'd "ideally like to keep a secret for as long as possible."
- The Elizabeth Holmes delete-everything tweet—which the host thought was in response to the Mythos model—gets called "hyperbolic" by Martin. Mythos is too huge to run open-weight on reasonable hardware within 12 months ("perhaps this is a question of timeline rather than destination"), and such models favor defense because defenders have system context attackers lack. Alex's counterpoint from lived experience: deletion is impossible—he says he believes his fingerprints were stolen in the 2011 OPM hack ("how do I delete my fingerprints?")—so the practical answer is multilayered security, multifactor authentication, and no single point of failure.
- Closing exchange: will Satoshi's coins ever move? Pruden: "I think no"—but he knows quantum builders who view them as "lost treasure," which is exactly why the risk isn't abstract. "So I don't know… but maybe."
Full transcript
I'm very excited about this one. I'm really excited to have the chief security officer of Coinbase, Philip Martin, as well as Alex Pruden, the founder and CEO of Project Eleven, with us. This is going to be the security podcast, but maybe even one step deeper than that.
I don't know if you guys have been reading Nic Carter's post about quantum and Bitcoin, where we're all screwed here. I wanted to bring the 2 smartest security people I know on to figure out what we're going to do about quantum and Bitcoin. Philip, Alex, welcome.
Thanks for having us.
1. The Quantum Computing Risk
Great to be here. Yeah, excited about this.
I think maybe the best play is for me to ask a ton of really dumb questions in this episode, so be prepared, because I'm way out of my depth talking about quantum. I'd love to hear from you guys about why this is the moment in time we're recording this, April 2026, when quantum suddenly feels like it's here.
I think Nick said Bitcoin Core is sleepwalking toward collapse. Why is this the time period when everyone is starting to talk about this?
I can take maybe just a first pass. I think the primary reason is that 2 papers came out a couple of weeks ago. One was from Google Quantum AI Lab. They're building a quantum computer, and they also have people working on cryptanalysis, namely a gentleman named Craig Gidney.
This lab came out and basically said, “Hey, if you look at targeting elliptic-curve cryptography specifically, past work in quantum cryptanalysis focused on an older cryptosystem, RSA. But if you target ECDSA specifically and layer on some assumptions about the type of computer we're building, then potentially this is a much more imminent threat than we first thought.”
There are a bunch of impacts across the cryptocurrency space. I think this was one of the more notable parts of the Google paper: it was 1/4 quantum-computing paper and 3/4 survey of the digital-asset space and all the various ways that things were vulnerable. It explicitly said, “Hey, there's an urgency to migrate to post-quantum cryptography.” That was paper 1.
Paper 2, which was independent of this, was from a team out of Caltech. It was from S-tier physicists, and the company was called Aor Atomic, founded by people including Dylan Blowstein. They came out with a paper that said Shor's algorithm may be possible with as few as 10,000 neutral-atom, reconfigurable qubits.
For context, the prior state of the art was between 500,000 and 1,000,000 qubits, which was what people thought we needed. So, they took the bar that you had to clear to potentially break public-key cryptography and brought it all the way down to 10,000.
For context, IBM has a system with around 1,000 qubits, and they've entangled systems with up to around 7,000 qubits. So, you're at least an order of magnitude away in terms of the number of physical qubits you would need to potentially be cryptographically relevant.
Those 2 papers kicked off a press cycle, and now I think suddenly everyone is waking up to it and saying, “Oh, man, we should figure something out here.”
Yeah, I think they're right. The interesting thing about this whole space is that everything is so speculative. Alex very correctly said a bunch of things like, “It might, it could, we think that maybe,” right?
That leads reasonable people to have wildly divergent views about what's true in this space in a way that I think I've rarely ever seen before.
Maybe before going too deep into Bitcoin, can we just talk about the cryptographic system that everything runs on, including our financial system? It seems like that's at risk.
By the way, not just with quantum, but Santi and I have been talking about Anthropic, ChatGPT, OpenAI, and what's happening with Microsoft a little bit on the podcast. It seems like there are these 2 threats, quantum and AI.
Maybe before going too deep into Bitcoin, can you guys tell me what your mental model is for how you're thinking about the financial system and the security of the financial system getting upended right now?
It's not even the financial system. It's modern cryptography that's at threat, or at least a class of modern cryptography is at threat today with quantum computers.
The ability to use the internet safely rests on modern public-key cryptography, which a cryptographically relevant quantum computer—that's the term we use to talk about this—would fundamentally break. That's financial systems, government, basically everything.
Alex talked about crypto-agility a second ago, which I think will be important moving forward. But the thing is, a lot of stuff that's built today is not agile and can't be agile. You look around your house—how many IoT devices are there?
It's an open question whether the chips in those devices are going to be able to use post-quantum algorithms. I don't know. Maybe yes, maybe no. Are the manufacturers actually going to upgrade them? I don't know. Maybe yes, maybe no.
When it comes to pass, this will truly be Y2K, and Y2K would be underestimated, in my view.
Well, Philip, I have a dumb question here. We have all these devices. I'm recording this with a microphone, I've got the computer, I've got IoT devices, and maybe someone has an Amazon Alexa. Do you have to replace every single device? Is this a hardware upgrade or a software upgrade?
It depends on how they implement it under the hood. It could be either.
Alex, go ahead.
Yeah, I wasn't going to comment on the hardware or software. I was just going to make a quick comment on the financial-system point that you brought up.
I think it's true that there's a lot of risk to the broader financial system that uses the internet. The vulnerabilities are more around how the financial system is embedded inside the internet, basically—largely, not entirely.
I think the distinction between the broader financial system and what we're going to talk about, which is blockchains, is that these systems already rely very heavily on trust. There's a trusted set of parties that maintain the ledger, so to speak, or the data.
In theory, an attack could be very disruptive on SWIFT, for example. But in theory, there are a bunch of important bankers sitting around saying, “Hey, whoever did that last entry, erase that and let's go back 1.”
Reverting an attack, or preventing someone from being able to profit from an attack on the broader financial system, is easier—or, stated more clearly, it would be harder for someone to profit from an attack on the broader financial system. It's not impossible, just harder.
That's as opposed to blockchains and digital assets, where the authorization to move funds is entirely cryptographic and has to be 1 factor, right? If it was multifactor with trusted parties, then it's kind of harder. I mean, it's less decentralized, right?
That's maybe an overgeneralization, but I think sometimes people overemphasize or are hyperbolic around this idea that if a quantum computer comes out, the world is going to end and everything is going to fall down. I don't necessarily think that's true.
Everything has to migrate. Banks are already migrating, as is the broader internet. Around 50%—I can't remember, Philip may know the exact number—somewhere around half or a third of all internet traffic is already secured using hybrid cryptography, which implements PQC.
2. Bitcoin’s Quantum Risk
The ball is rolling, and I think blockchains are in this unique position where they're super reliant on cryptography for their security. Migrating to a safe form of cryptography and/or mitigating an attack is just harder.
As we're recording, there's been a spike in DeFi hacks that's unrelated to Bitcoin. If you look at them, they're not all the same, but this latest one seems like perhaps some things could have been avoided if you had timelocks or a bit more in the way of rate limits.
I guess that seems obvious in hindsight, but one of the things in crypto is that you see a lot of builders being extremely philosophical and ideological and perhaps not too practical.
The question is more around, I think, Bitcoin. This is the heart of the discussion of this pod, but how would you describe the sentiment out there? You talk about the traditional internet moving now 50% to kind of get ahead of this. Where are you in terms of sentiment? How's the community adapting? Is the alarm fully being sounded, and are people reacting to this, or are they not moving as fast as you'd want?
Yeah, my opinion—and Alex may have a different one—is mixed. I think we can talk about Bitcoin specifically, although obviously this impacts the whole spectrum of blockchains. Some blockchains are moving quite quickly, right? There are at least a couple, I believe, that have testnets up that are using post-quantum cryptography. Almost everybody has a roadmap, with the exception, I would say, of Bitcoin.
I think there’s a broad spectrum of opinions within the Bitcoin community on the timeline, as well as the risk of quantum computers. I think Nick Carter has done some good stuff on this that he’s put out, looking at where everyone stands, to the extent it’s possible to see.
I have nothing to add other than to say that I think Bitcoin is a hard topic. One of the reasons I think it’s a hard topic in Bitcoin—and I’m sure we’ll cover this more later—is there’s this philosophical issue at play where a lot of the older UTXOs, like Satoshi’s, are thought to be irrecoverable. Satoshi may be dead, so all that value is just—what do you do with it? Do you basically prevent a quantum computer from stealing it by burning it, or do you just let the quantum computer take it? There are these 2 things about Bitcoin where that’s a really deep philosophical divide.
One is this concept of Bitcoin as digital gold, right? The integrity of this supply should not be violated. Theoretically, someone could just go and steal and then sell on the open market 10% of all gold. That’s probably going to have a major price impact, impacting people’s confidence in the future ability of this to be a store of value.
3. Fidelity Crypto Ad
The other aspect, though, is Satoshi, right? He created Bitcoin as a direct answer to what he saw was a corruption and mismanagement in the broader financial system. This property-rights idea—“not your keys, not your crypto”—was a deeply rooted philosophical thing. I think this has made the conversation in Bitcoin particularly difficult. Bitcoin is kind of unique in this way: it has this uniquely large amount of value, and it’s been around the longest. So, this is a uniquely difficult conversation there, which makes the conversation harder. I think it makes people a little bit slower to want to recognize this is a potential threat.
4. What To Do With Satoshi’s Coins?
Yeah, let’s go down the Satoshi rabbit hole. To tee up this conversation, Bitcoin’s market cap is $1.5 trillion today or something like that. Satoshi’s coins are roughly 10%. The question in the quantum world is, the Satoshi coins and a lot of Bitcoin might get upgraded. There might be a hard fork, and the Satoshi coins might get upgraded—or most of the Bitcoin will get upgraded, but the Satoshi coins maybe don’t get upgraded.
So, there’s this $150 billion pot that people can attack. It’s like the biggest pot of money on the internet that you can attack today. So, the question is, what do you do with these Satoshi coins? Philip, is that kind of the right framing?
Yeah, basically. I think Alex is right that there are basically 2 choices: you lock them in some way, or you leave them up for grabs. There are a bunch of different nuanced approaches people have suggested within those 2 buckets: lock them, but recover them in some way if you can prove some knowledge, that kind of thing. Neither choice is obviously the clear winner.
Let’s go deeper. What do you guys think should happen?
Oh, man, you’re really just teeing us up to get flamed by the community.
I know, seriously. Nick can’t take all the heat, so go for it, Philip.
Look, I’ll just preface this: this is my personal opinion, right? This is not Coinbase’s view on any of this. My personal opinion is it doesn’t make sense to me that we would have that much value up for grabs by the first person who can break a key with a quantum computer.
I think we have to do that in a way that respects the ability of the people who own those coins to actually come back and claim them if we at all can. There have been schemes proposed, like proving access to seed phrases, and I think there are some possibilities in that world. My personal vote is that we have to prevent a quantum computer from stealing it, and then we have to make some way for those coins to be brought back to life in the event that the holder is actually able to recover them.
Yeah, I’ll maybe preface my answer by just making 1 or 2 points, and then I’ll give you my answer. First off, it’s not just the Satoshi coins that are vulnerable, right? You said something very important a minute ago that I think is worth clarifying. You said coins will get upgraded. I think the right verb should be the active form: you must upgrade, right? Not your keys, not your crypto.
Anyone with a UTXO today, to be quantum-secure, must do something, right? This is the issue. It’s not that, for whatever reason, Satoshi’s keys or UTXOs are hidden behind some wall of fire. It’s that we think Satoshi is dead, so they’re just not going to be able to do the thing themselves.
To be clear, even though Satoshi’s supply roughly equates to about 10% of the overall supply, and there’s a spread across many UTXOs, about 35% of all Bitcoin today has exposed public keys for a variety of reasons. Potentially, all of those are at risk, too.
There are some other exchanges out there that, I would say, do not have as good security practices as Coinbase and have left a significant amount of value at risk. If you want to see all of the various Bitcoin that’s at risk, we have a risk list on project11.com where people can enter an address or even scroll through the top holders.
So, there’s a lot of value, and potentially people have to migrate it. To Philip’s point, what do you do if Satoshi’s not going to migrate? My view is there’s going to be a fork here. I think it’s inevitable, because these philosophical issues—I don’t really see how you resolve them.
Forking is a mechanism by which blockchains potentially deal with this divide, and it’s not the end of the world, right? We had Bitcoin and Bitcoin Cash, an irreconcilable divide between 2 camps around block size. I think it’s not unreasonable to expect this will happen again. Ultimately, the market will determine which of those is more valuable. Or maybe both of them have some residual value. I don’t know. I think it’s ultimately just going to end up as a fork. I would be surprised if it didn’t.
Who are the major players that could matter in the conversation? In 2017, we’d been here before, with difficult decisions in the Bitcoin network, as far as I can remember. Who are the major players here that matter in the conversation?
I’ll start with this one. Yeah, I think there’s a historical group of core developers, which, just to be clear, has evolved over time. If you go back to 2017 and the conversations of that era, many of the characters who participated in those have moved on.
There are still some core developers, obviously—Adam Back at Blockstream, and Greg Maxwell’s around, Matt Corallo’s around. There are some folks who have been around for a while, but there are not as many as people would probably expect from the era of 2017.
The core developers certainly matter. Institutional adoption of Bitcoin is much, much higher than it was 10 years ago. These institutions obviously have skin in the game, right? They certainly matter. I think those are probably the 2 primary groups.
Although maybe I’ll add a third, which is miners. Miners ultimately, I think, are going to do what they think everyone else wants. I don’t know. Maybe that’s not true, but that’s sort of my take.
And I do think there are loud members of the community who are not in any of those 3 categories, and I think they’re kind of spoilers for doing something pragmatic. To be charitable to them, they’re defending what they see as the core principle of Bitcoin and why they signed up to hold it. So I would maybe just say there’s a long tail of community members who really believe in these deep principles of Bitcoin, in one way or the other, and just have an opinion.
By the way, Alex, didn’t they win the 2017 block-size wars? They were kind of outnumbered in capital, but I don’t know if that’s the right framing of history. You could argue that, right?
Certainly. The narrative is that the miners and big, bad corporations got together and tried to increase the block size, and the community rose up and won. That’s the popular narrative for obvious reasons in that community. But, yeah, no, look, I think their voices are probably not to be underestimated. Again, this is why I think you can’t rule out the possibility that ultimately there could be a chain fork, and then the market will just resolve it at some point. I don’t know.
So, is it fair to say it’s the economic nodes—the exchanges and custodians, the ETF issuers, and the balance-sheet holders like MicroStrategy—that are going to make this decision? Is that right?
Well, I’ll answer, and then, Philip, you can decide if you want to take that as well. Look, I think they’re going to make a decision around what they want to do with their assets, and, given how important stakeholders they are, that decision may influence what everyone else does. But I don’t think necessarily no one can decide for Bitcoin, right? I do think, though, that if you look at the pure amount of capital, it’s inarguable that the economic nodes have the most to lose, potentially. So I think they’re definitely going to be involved in this.
I think this is a different thing. Maybe, as Alex says, you compare it to Bitcoin Cash. In that case, it was kind of like, everyone gets 2 of whatever they had before, so there’s only upside to doing both. Whereas here, there are some potential real security implications, so I don’t think it’s quite as clear-cut that everyone’s just going to go one way or the other. I don’t know.
Yeah, no, I think that’s exactly right. No one can make a decision and make it stick. I think it’ll be a community-driven process. But I think Philip is also right—the economic nodes have the most to lose, right? So I think they’re going to be, and I think we’ve started to see this, the ones who are most interested in driving a solution.
To me, it feels very obvious what’s going to happen, right? There’s going to be a freeze camp and a no-freeze camp. The freeze camp is going to be the institutions, the ETF issuers, the exchanges, and the custodians, because they can’t tolerate client-asset risk. Then there’s going to be a no-freeze camp, which is going to be the maxis, the community, and the ideologues. That’s great; you need both sides. But no one can choose. If Coinbase says, “Hey, all of the Bitcoin held at Coinbase is now going on this chain,” then that’s basically your decision.
Philip, I guess I know this is Philip’s decision and not Coinbase’s—you’re speaking for Philip, not Coinbase—but how do you guys make this decision at Coinbase?
It’s going to be really tough. I think we’re ultimately going to do what’s right. We’re here because of our customers, right? We’re ultimately going to listen to our customers and our stakeholders and weigh that very, very heavily. Either way, once there’s a viable upgrade path, we’ll obviously upgrade all the keys that we have to make sure they’re using post-quantum cryptography. But this will be something that we listen closely to our customers and stakeholders on.
I’m sorry, guys, but this doesn’t sound controversial at all to me. If you’re Saylor, BlackRock, or Coinbase—to your point, Philip—you’re going to do this because the asymmetry of not doing anything and having someone steal Satoshi’s coins is catastrophic to the network.
To your point, it’s not just Satoshi’s coins, Alex. It’s, you know, up to what, 30% of the supply?
Yeah, good luck. Not doing that is a tail risk for Bitcoin. Attach any probability to that happening over the next 5 to 10 years, and you still get to the economically rational decision if we’re all here talking about the game theory of upgrading now.
The question is, who is going to put forth this upgrade? Is that maybe more the nuance? Do we agree that this is the best upgrade, or are we going to see a couple of proposals? I just don’t know much about what’s going on here.
Let me steelman it. I think everything you laid out was very logical. Let me steelman the other side a little bit from a slightly different perspective—not as a philosophical perspective. Satoshi’s coins are kind of obvious, right? We think they’re dead, but about 15% of Satoshi’s coins make up about 2/3, according to Chainalysis, of the lost coins. How lost are the lost coins? That’s kind of a question.
So when you cross that—Satoshi’s coins, okay, maybe fine—but, again, that only accounts for about 1/3 of all the coins that are supposed to have keys. So where do you draw the line on effectively confiscating Bitcoin that hasn’t moved in a while?
This is the way to wake them up, right? If we want to truly understand how many of these Bitcoins are lost or will come up, and maybe we’ll find out who the real Satoshi is, if they’re not dead or their hard drives aren’t in a landfill, this is actually a really fascinating way of doing that.
But now imagine you’re someone working on this. Let’s just say the core developers, such as they are, all come together and say, “We believe in this. We’re going to do this,” and there’s a pull request. bit 361 actually has a bit for this now. Let’s say—I won’t name him, because he’s getting enough flame on X—but the author of BIP-361 is the person to press Merge. The pull request is merged, miners all agree, and everything happens for this freeze. Someone wakes up someday and says, “Hey, my Bitcoin are no longer accessible.” Do they have a legal claim against the author of that bit or the person who pressed the button? I don’t know, right? There’s a lot here.
People have talked about there needing to be a time frame. Let’s say we give people 10 years. That’s all fine, of course, but 10 years from now, we’re talking about the real risk that a potential S-C-R-T exists, right? So I think the challenge is not so much Satoshi’s coins—they’re kind of a straw man. I think it’s more about, on the margin, who is a long-term holder and who just lost their keys. It’s unknowable, right? And I think that’s why it’s tough.
To your question of who does it: Bitcoin is also unique in the sense that there’s no foundation associated with upgrading it, right? There’s this never-ending political battle over who gets to be a spokesman for Bitcoin. If The New York Times is to be believed, Satoshi Nakamoto—I mean, Adam Back—may be working on something, but others may have ideas.
There’s a bit of chaos, and there have been a number of proposals over time. We outlined many of them in our blog; we have a whole rundown, but this has been talked about for years. The question is: Who galvanizes the effort and the resources required to take this from an idea to a reality? I’ve been part of the team that launched a layer-1 blockchain, and there’s a big, big gulf between the white paper and the thing that is secure, that can secure trillions of dollars. To me, right now we’re in the idea phase. There are people who have ideas, but I think we’re still pretty far from someone saying that they’re going to do it.
By the way, though, that’s true of all networks. Philip mentioned that there are people with road maps; those are all great. Very few teams—there are a handful, but very few—have actually taken any concrete steps toward making the ideas realities, although everything, of course, has to start as an idea.
Yeah, and it’s very interesting because there’s a whole separate set of problems after you upgrade to a quantum-proof signature scheme. For example, the signatures are much larger. The smallest of the larger ones is, I think, 10 times—if I remember my numbers correctly—the size of the current ECC signature.
That's going to impact throughput, or it's going to kick off another block-size debate. By the way, you mentioned the DeFi hack.
That 10-times-the-size signature that Philip is mentioning is called FALCON, or FN-DSA, which is what we'll probably standardize it as. Google wrote an entire blog post about the nightmarish complexity of implementing that. You think DeFi hacks were hard to prevent before? Wait until people are trying to roll something like that into production.
As Philip correctly highlighted, we're going into a world where there's a whole bunch of painful trade-offs that these protocol teams are really going to have to figure out. But I want to go to DeFi and stablecoins in a second. One more Bitcoin question for you guys: Is there a third option here?
Let's say—if it sounds like both of you have a view—Philip, you didn't fully give yours. It sounds like Alex gave a very strong view that we should freeze the coins, and I think you're maybe more in that camp, Philip?
I think Alex didn't give his view on whether it should be frozen or not. He very skillfully danced around that one.
Okay, you dodged. So you both dodged. Anyway, we've got the freeze and no-freeze camps. Is there a third option? Or would your view on this change if, let's say—I think what everyone's scared of is that China or North Korea are going to win the quantum race and take these coins.
But what if you knew that Coinbase had developed a quantum computer, or the US government had developed one and would get the Bitcoin coins? Now you kind of get court-appointed receivership of however many Satoshi coins there are—2 million, or 1.7 or 1.8 million coins—and this turned into the Strategic Bitcoin Reserve. They said, “We're never going to sell it.” Is that option 3? Would you guys be okay with that? Would you be like, “Oh, interesting. I'm kind of down with that”?
That's kind of a sci-fi option, if I'm being honest. That's pretty out there in terms of reality. I think Nick has written that. By the way, I have a really fun short story where he outlines this. Also, Kyle Samani, formerly of Multicoin Capital until he retired, tweeted exactly this about a year ago.
I agree with all of them. There are just so many what-ifs, right?
Yeah. If you're going to pin me down and say, “What's the third option that I think is viable?” one other issue people talk about with Bitcoin is what happens when the security budget runs out. Option 3 is kind of a confiscation option, but with a less—I mean, maybe less confiscatory—approach: you roll Satoshi's coins into the back end of that.
To me, if you're going to confiscate, that's probably the best way, or maybe the best way, because then you at least buy yourself time for this other really controversial conversation. I don't know. Maybe that's a—
Are you saying the Bitcoin network is going to have stock-based compensation?
Uh-oh, man. I'm getting enough of this. Santi, don't put that on me. No, but people should go listen to the episode we recorded with James Prestwich, who I think has been one of the strongest advocates for putting the security-budget question front and center—discounting it to today.
I hadn't thought about this, but it's quite an elegant solution. If the statute-of-limitations window is, say, 5 years to claim, then you have that in the treasury, and then you disperse those to fund the security budget after all the emissions dry up. That's actually a really elegant solution.
What probability do you ascribe to that mechanism actually going into production?
Probably low, mainly because I think this is just a huge, controversial rat's nest. When the fighting is all over, people will just be happy to be done with whatever simple thing they can agree on.
I think it's elegant, but it may just be too much for people to accept all at once, because you're already asking them to accept a lot of changes. I think it's relatively unlikely, but I agree with you: it's a somewhat elegant solution.
One follow-up to this: say this is actually viable and gets traction. How would you think about the period in which holders can upgrade? You don't want to be too slow—the pace is sort of a function of how quickly you think we're going to get to quantum state, right?
If it happens and you still have the claim period, that could be a risk in and of itself. If you give 10 years, that's probably too much. If you give 5 years or 3 years, how do you think about that timeframe?
I think it's going to be less about the timeframe and more about how you get the message out broadly and aggressively. I don't know if there's a big difference between giving 1 year and 5 years in terms of the number of people who are actually going to take action.
It's going to depend, and what we're going to see, because we always see this, is that 90% of it will happen within the first month or something. Then there'll be a super-long, drippy tail of stuff that will last probably forever, or at least as long as the window is open.
The hard part isn't setting the window; it's figuring out how we get in front of everyone who needs to take individual action. For everyone who's not on an exchange or with a custodian—everyone who has a Ledger in their home safe, back in the corner somewhere—how do we make sure all of them know they have to do something?
I think one important thing to note is that, in this whole discussion, we've kind of baked in the assumption that quantum computers are going to be so-called slow-clock systems, right? Let me quickly define this, because this was relevant to the Google and Aor Atomic papers.
There's a concept of a slow-clock quantum computer and a fast-clock quantum computer. One of the reasons the Google paper was potentially quite disruptive was that they posited their machine could run in 9 minutes. Theoretically, the machine they laid out, if we built it, could run in 9 minutes.
Why is that a problem? Bitcoin's block time is 10 minutes. So you now have a situation in which, Santi, you put out a transaction—you're doing everything right, and your public key isn't exposed—but now you want to send some Bitcoin to your mom or something like that. I can front-run you in the mempool with a higher fee, right?
Once you get to that point, migration is going to turn into a giant bidding war of fees, if you think about it. I think it's important to call out that I personally believe the fast-clock architectures are going to follow the slow-clock architectures for a variety of reasons.
However, I don't think anyone really knows how long that will be true, and that's really related to the question of how quantum computing will develop. It's kind of an unknown, but certainly we have to ultimately add all of this post-quantum cryptography for everyone to leverage.
Then there's the additional question of people who aren't going to move at all. Maybe that's the first thing that gets affected, but there are both aspects to this, right? It's not just Satoshi's coins; potentially, it's everyone's.
Impossible to know what Satoshi would do, but I would say he would probably want to see the network live. Are we all in agreement that if we don't do anything, there's a higher probability of Bitcoin fading into irrelevance? If you don't do anything, action dictates that you have to address this, and you probably have to address it within 12 to 18 months.
Wait, Santi, why do you think it fades into irrelevance? I feel like the worry is that someone—let's say someone trying to get 10% of the coins—dumps the coins and the price gets absolutely decimated. But I'm not sure it would fade into irrelevance.
Yeah, I'll say it this way. Maybe I'll make this point. Will it fade? I mean, this is your—we're kind of war-gaming. I will say this: There are networks and protocols out there that see an opportunity to differentiate themselves by having post-quantum cryptography first.
Zcash is one that I think has leaned into this, right? It's definitely a narrative that a lot of folks around the Zcash community are pushing, and I think there's a lot of truth to it. There is a sense of opportunity, I think, from other protocols, and I don't think that can be denied.
But let’s go to that extreme, Yanni, because I actually think it’s a good question. What happens if we don’t do anything? What is the status quo? If you don’t do anything, between 10% and 20% of the supply could potentially be accessed by someone, and they dump it, or I don’t know what they do. As soon as those coins move, it will wreak havoc. Once that is sold or whatever, in my mind, that’s probably pretty detrimental to the network. But I don’t know if it survives—maybe it does. I hadn’t thought about that. Philip or Alex.
Yeah, I mean, that’s certainly the fear, right? There are two things. One, there’s the obvious economic impact of selling that many Bitcoins. But two, there’s the impact on the trust of the network, which I think is actually the threat—the long-term impactful thing that happens. And I think it’s just really hard to know in advance what that impact will look like practically, right? How much trust is lost and breached there? Does this mean that institutions can no longer touch the asset? And, if so, what’s that going to mean for the future of Bitcoin? Those are all open questions.
5. How Does DeFi Mitigate Hacks?
So, I was going to say, Yanni, this naturally takes us to DeFi because, for me, these are protocols that have more freedom to upgrade, but they have probably challenging issues in their own right. Some of them don’t have as big of a security budget; they have way more surface area. I go back to: Is the solution, I guess, in all this discussion, given what’s going on with quantum, with AI, and stuff like Methos[?], are you on the spectrum from super-ideological to more permissioned, with more controls and guardrails? Has your position changed one way or the other? Because, Philip, you said something important: Ultimately, Coinbase wants to protect your customers. No one likes to see these $200 million, $300 million, $400 million hacks, and every year we kind of have close to $1 billion in customer funds lost going to Lazarus.
Yeah, I’ll jump in quickly. Look, Santi and I have known each other for a long time, and you may remember that I got interested in this space working in the Middle East with Syrian refugees. I think an aspect of cryptocurrencies that really appealed to me and led me to want to work in it was the ability for people who didn’t have any other option to transact, save, or transfer their value out of a war zone, out of a hard situation.
There’s this element of financial freedom that is just a really powerful part of the narrative that has brought many of us to work on this. That said, the freedom cuts both ways. As you just pointed out, it’s also freedom for North Korea to fund its nuclear program, and there’s nothing we can do about it because, again, if we wanted to do something about it, then we would basically revert to the exact same financial system that maybe excludes the people that I wanted to help.
Again, this is a tough philosophical question. Practically, though, ultimately we live in a world of nation-states with sovereign governments, and I think it’s a little bit optimistic—maybe overly optimistic—to assume that there’s just going to be some super financial system that every government agrees to be a part of and doesn’t want to try to control in some way. A government—the US government—could throw me in jail if they want. But the Ethereum network can’t really do that to me.
For that reason, because we all live in a world of sovereign nation-states that can exert the rule of law over their borders, I think you’re inevitably going to see more permissioning. What I think that also implies is you’re maybe going to see some fracturing across geographical lines for these various systems at some point.
I think that’s right. I think that’s exactly right. I also think that people are always going to write insecure code, right? It’s just never going to stop. They’re going to write insecure code, put it in smart contract code, and toss it onto a network somewhere. Where that starts to become a problem is where there’s real value in that protocol, right?
So, how do we get better at not preventing people from writing bad code, but flagging it when it gets on a network? We need to make it very clear to people who would interact with it: Hey, you might want to tread carefully here, because this is—whatever the problem is with it—vulnerable, new, untested, or it’s a rug pull; it might happen, whatever.
That, to me, has been very interesting because I don’t want to live in a world where we have a bunch of heavyweight, permissioned DeFi blockchains. I don’t think that’s the spirit of crypto. I don’t think it’s fundamentally going to result in a better system than what we have today. But we do need to make sure that we can cut down attacks. Losing $1 billion a year to these things is just untenable.
Might there be a nuance where I think of crypto as lowering the barriers to entry and the switching costs, even though you are not fully permissionless, but you have some guardrails? Look, USDC and Tether both can freeze your assets, and the consumer just goes to where the most liquid coin is, or the coin that has the most brand. There’s a very small subset of people who actually truly care philosophically.
There’s a whole subset of people who are unbanked and don’t have access to the dollar, and, for better or worse, the dollar continues to be the most sought-after store of value. But if people are going to—if we agree that digital systems like DeFi are interesting to people because they make it more accessible—you ought to layer in some way more protections. Way more, because the end user is unsuspecting. It’s just not as sophisticated, and the threats are only going to increase far more than the end customer can catch up to by leveling up their OPSEC.
To me, that always forces us back to: If we really want this industry to grow, you have to assume that people are not going to level up their OPSEC. Just assume that you’re going to get hacked, and work backwards from there. And that takes you to a more permissioned system, right? Where you can, to your point, Philip, freeze stuff and roll it back.
Yeah, no, I think everything you said is right, but I think there’s no one-size-fits-all, right? A lot of it really depends on exactly how much, and who, and what, and how important.
I still like to believe that even—I mean, USDC is kind of a good idea, or a good example, in the sense that, yes, they can freeze your assets, but it’s by exception, right? You have to basically be proven wrong. The way bank accounts work is kind of like you have to prove you’re not guilty to get one, basically. Whereas, to freeze assets, these issuers, practically speaking, do it if you are guilty.
Even though it seems like a small difference, I think it’s actually quite important and impactful, and it’s one of the reasons why you’ve seen stablecoin transactions really take off. So, I think that’s an example of how you can kind of have a best of both worlds, potentially.
Then I just wanted to point out one other thing, which is that we’re still in the pretty early innings of people really interacting with finance via cryptography, right? Obviously, the cryptography we’re going to use is going to change as post-quantum, et cetera, but I still think there’s a lot of really low-hanging fruit to improve security on the UX side.
One great idea that the Ethereum folks came up with was this concept of account abstraction, right? You can basically separate authorization at the chain level from authorization at the wallet level, and you can create much more complex authorization flows that maybe are a bit—maybe that part is semi-permissioned—but what you do for your grandmother could be different from what someone who is an entrepreneur somewhere wants to do.
Yeah, I know. There’s a whole bunch of flavors of this. It doesn’t have to get baked into each app necessarily, and it can get baked into these various wallets. I mean, that’s a broad generalization, but I’m confident that we will continue to get better as a space at this—or I’m hopeful, maybe.
6. Are Stablecoins At Risk To Quantum?
Alex, you guys dedicated a whole section to stablecoins, and Philip, I think you guys didn’t focus on that as much, more maybe focused on just the industry and Bitcoin in general. I’m curious why—curious how you guys think about stablecoins in terms of the risk here, given what you’re talking about with quantum.
So, I think first off, as we move from Bitcoin to everything, I want to be clear: I don’t think every system has its risks, and I don’t really think one is better than the other. I think they’re just a different set of risks, okay? Stablecoins are permissioned, or maybe less at risk from a quantum attacker, in the sense that money sits in a bank account.
And so a quantum computer can't reach into the bank account and manifest the dollars in someone's hand across the world, right? The bank account is safe. What is at risk is potentially the on-chain stuff. So what would happen, potentially? Well, you could do the same thing you would do in Bitcoin or another network, which is steal someone's USDT or something.
But I think the real challenge for custodial-style stablecoins is these admin keys we're talking about, right? Those are definitely critical infrastructure and potentially could be nation-state-level targets. If you had a quantum computer that you weren't even looking to steal Bitcoin with, but maybe wanted to mess with the US financial system—especially as more and more dollars go on-chain—that would be a way to create chaos. Given how much DeFi there is, and one of the big selling points of DeFi is that you have transparent contracts all over the place, interconnected, you take down—I mean, it's just like we saw with the Kelp DAO hack that you're referencing, Santi. The Kelp DAO bridge got drained, with ripple effects across a whole bunch of other DeFi protocols.
I think you can imagine a world where, let's just say, someone mints 300 trillion dollars of USDT, or USDP or something, and then breaks a peg somewhere. There are a whole bunch of ripple effects that ultimately maybe won't have a real financial impact, but they could still be incredibly disruptive and cause the loss of billions of dollars of value. For those reasons, we think of stablecoin issuers as having maybe a unique—or maybe I'll put it this way: I think there's a special urgency for them to consider how they're going to protect those keys from a quantum attacker. So yeah, that's my view. I don't know if Philip wants to add to that.
I feel like that's the thing that's great, and I totally agree. Yeah. Philip, maybe from the Coinbase view, what are you most worried about? This idea of Bitcoin, or just running an exchange, or stablecoins or DeFi—on-chain stuff? What are you most worried about?
Gosh, the answer is all of it. That's the honest answer. Fundamentally, my job is about protecting Coinbase and our customers. My focus is always going to go first to how we make sure that Coinbase, from an internal systems and practices perspective, is ready for this well in advance of there being any risk.
7. ZKsync Ad
As a person who's been in this industry for a decade as of last week, I really care that the blockchains evolve to get this right and make good choices and good trade-offs—not just in terms of the cryptographic algorithms they choose and how we deal with throughput, but also how we do all that while retaining the core philosophy that makes this space not just bank 2.0.
8. How To Secure Your Privacy
I'm going to pull up an Elizabeth Holmes tweet here. I didn't think I'd do this on this episode, but I do want to get your guys' take. This is more of the personal side of things. Elizabeth Holmes, for people not watching YouTube, said, “Your search history. Delete your bookmarks, delete your Reddit, medical records, 12-year-old Tumblr—delete everything. Every photo on the cloud, every message on every platform, none of it is safe. It will all become public in the next year. Local storage and compute.”
I think this was in response to a more Mythos-level model being released and maybe open-sourced. Philip, I'm curious to get your take on this.
So this is hyperbolic.
And this is hyperbolic?
Yes.
Why do you say that?
Two things. One, Mythos is a huge model, right? That requires an incredible amount of resources to run. It is not practical in the next 12 months, in my opinion, that we're going to have open-weight models that are runnable on reasonable hardware. Now, we will eventually, right? Perhaps this is a question of timeline rather than destination.
I think models like it are going to favor the defense versus the offense. I think that's true because, as a defender, I have so much more context on how our systems work than attackers do. I think that's going to let me get a lot more out of that model than an attacker is going to get by pointing it at an API endpoint and saying, “Go forth and now,” right?
As these models become more accessible, you have to make the assumption that there's a reasonable security team on the other side, right? So maybe the non-hyperbolic version of that tweet is: make sure you know who your counterparts are, where your data is, and where you do not believe them to be good custodians of that data. You should absolutely take action to remove your data from those hands.
Yeah. Alex, in your personal life, do you do things that maybe the normal citizen would say, “That's a crazy level of precaution”?
I used to work at a privacy protocol, so I obviously am passionate about personal privacy. I do a number of things in my own life. I run a bunch of stuff locally instead of relying on services that some people might pay for from the cloud, for example.
But look, I think the other reality is—read the Elizabeth Holmes tweet—it's just not possible. First off, it's not even possible to delete all of your data. How do I even get it? People have written whole articles about these data brokers of people. I had a security clearance when I was in the military, and my fingerprints were stolen, I think, in 2011 as part of the OPM hack. So how do I delete my fingerprints that were stolen in 2011? You just can't, right?
Moreover, we all lead increasingly digital lives, and to Philip's point, I think he's absolutely right: We need to be responsible about who our counterpart is and where our data is. But I think there's also some degree of acceptance that some part of your identity is going to get out there. This is why multilayered security architectures are just the best way to go, right? Theoretically, if you have a failure on one layer or a breach of one system, it doesn't break everything else, or it doesn't mean all of your accounts are therefore pwned, right?
So that's probably the most practical advice here for anyone: multifactor authentication, no single point of failure to the greatest extent possible, and then minimize, if possible, your exposure. There's just no way you're going to avoid all of it, probably.
9. What's The Timeline For Quantum?
Can I push you both to get a little more specific on the timeline? Reading both your papers, I think you might disagree on this, right? Philip, in the Coinbase paper on the timeline, I think you said it was largely irrelevant, or maybe not as important. You actually used the words “largely irrelevant,” whereas Alex, you had a 2029 optimistic case, 2033 as kind of the base case, and 2042 as the pessimistic case. Can I push you guys to tell us: When does this really matter?
The reason we say it's fundamentally irrelevant is because this process takes such a long time, and we have so little clarity that it doesn't matter to me if a quantum computer shows up in 2030 versus 2040. We have to start the work today. In that sense, maybe having a definite timeline is better from a motivating-people perspective, or it gives us a goal, but in my view, it's like trying to chase a date—a red herring.
Yeah, I don't think I disagree much with that. I actually think part of the reason why we put timelines in our report is partly because I think it was to push people. There are 2 reasons. One is that I think people are kind of lazy a lot of the time with their estimates for these things, and they're just like, “It's 20 years away,” because it's always 20 years away. That's as deep as they ever get. I think the reason why we put these predictions in our report was that we have these various aspects of the analysis that we try to rigorously distill into a real timeline.
That said, I think there's a lot of uncertainty, as Philip mentioned. But I think there's an aspect of wanting to show people that there's a trajectory for quantum computing to develop, and the question is how quickly we will go along it. The other piece—and I think this dovetails back to Philip's point—is that there's a great framework that I really like called Mosca's inequality. Michele Mosca is a quantum cryptographer at the University of Waterloo.
And then one thing he points out is: You can’t just consider the timeline for the attacker to get this capability; you have to consider the defender and how long it’s going to take to prepare for that attack, right? And so you have to consider both things together—you can’t just consider one in isolation. Echoing what Philip said, I don’t think there’s—just to be on the safe side and not end up in a scenario where the attacker has this capability before we’re ready—given the uncertainty here, it probably makes rational sense for everyone to start preparing today. It doesn’t mean we have to panic, but it means we should start preparing.
Yep, exactly right. In my experience with this, once you start throwing dates around, you start to argue about the dates.
Yeah, and that just—fundamentally, it doesn’t matter. The discussion is about what to do about it. Is there going to be a ChatGPT moment? What’s the ChatGPT moment for quantum going to be?
I think it’ll probably be in the simulation space, where we will see, somewhere around drug discovery, something like that will be a use case where there’s some element of useful quantum supremacy shown, as opposed to the toy stuff that has been shown so far.
Well, I may have a different take. Maybe we’ll have to agree to disagree here. I think you’re not going to see it. I think real quantum development, from this point forward as it pertains to cryptographic relevance, is very likely to happen behind closed doors. The Google paper even hinted at this.
In fact, the short circuit—they explicitly didn’t reveal it. They proved in zero knowledge that it only consisted of X many operations. They explicitly said this is because they don’t want this knowledge to be out there for the world.
If you look at the funding for these quantum companies and look, practically speaking, they sell services for optimization, and there’s some other stuff. The vast majority of funding for this industry comes from the government, DARPA, and the equivalent agencies around the world. I think the vast majority of money going into this space is for cryptanalysis, and obviously that capability is something that the funders of these things would ideally like to keep secret for as long as possible.
It’s not that I necessarily think we won’t see evidence in the simulation space or otherwise that there’s progress, but I just don’t know if we can count on it. I think there are also a lot of reasons to believe that it’s possible these thresholds get crossed effectively behind closed doors and we never know that they do.
Yeah, I agree that’s absolutely possible as well. Just going back to something that we touched on, the security budget factors into the timeline a bit too. I don’t want to make this whole pod about that, but I think it’s quite a bit of a threat. How does Bitcoin continue in the absence of block rewards, and what’s your guys’ take on that?
My personal view is I tend to agree with you. I’ve always kind of believed that at some point, 50 years from now, when mining is truly unsustainable, or there’s so much demand from data center and AI-type use cases that, obviously, below a certain security budget, you’re not going to have the same trust that you would want for a system that you claim is digital gold.
I think the natural solution is just to tag on a tail emission, have inflation as a percentage trend toward zero over time, but maybe have a constant inflation. That way there’s a way for miners to plan. That’s obviously controversial in many parts of the Bitcoin community.
I think ultimately it’s not going to be for any of us to decide. Unless this quantum thing ends up being part of that, but assuming that doesn’t happen, I think future generations of Bitcoin are going to have to grapple with this. It’s hard to say, but I kind of agree with you that ultimately the trust we have in Bitcoin is dependent on the security budget.
Either you have to assume that the coins just keep going up in value and the hash rate stays the same, or you have to assume that there’s some continued emission. You don’t really get both. However that happens, I guess we’ll just have to wait and see.
I don’t disagree with any of that. I think the original theory was there’d be enough value in the fees at that point that they would take the place of the block rewards. But I agree with the assertion that it’s very important to Bitcoin’s continued transability.
As we get to close out the episode, what is the best way for Bitcoin holders to follow what’s going on? We haven’t talked about Taylor. We’ve talked about who matters here, but who are the folks that haven’t been as vocal that you think are going to play a bigger role going forward?
In terms of how to stay abreast of this, I don’t know if there’s any one simple answer to that question. What you’re going to see from Coinbase going forward is a lot more about the quantum risk, both from a technical perspective, like the paper that we released, as well as from a nontechnical perspective, and really talking across all the chains, right? Not just Bitcoin, because the whole ecosystem matters.
But today, I don’t think there’s a place that anyone can just go and be up to speed.
Yeah, I think a lot more people are starting to talk about this, which is great. I want to particularly call out Coinbase and the work that Philip and his team are doing. They’re leaning forward into this, whereas a lot of other exchanges are not.
For example, they have this Quantum Advisory Council consisting of a lot of really impressive folks. They’re doing research on this topic, which is amazing, and I hope that encourages other stakeholders to do the same. Ultimately, if we believe in the philosophy of decentralization, to some extent, it’s incumbent upon all of us to contribute. I think Coinbase has just done a really good job leading the way here.
10. Fidelity Crypto Ad
Obviously, Project Eleven—this is our whole MO. People can certainly read up on a lot of what we’ve written. I’m encouraged that the dialogue is starting to really take off, and I hope it continues to. I think people shouldn’t shy away from this topic; they should embrace learning more about it. It’s pretty dense, but I think it’s one of the most important topics of our time in crypto.
Before we drop, do you think Satoshi’s coins move?
I think no. Maybe I’ll say this: I know there are people building quantum computers who may be interested in it, but they view it as lost treasure, right? There’s this idea: Is this lost treasure that we could get?
Whether or not that’s a good legal theory, I think there is discussion about that, and I think that’s sort of why I don’t think this risk is entirely in the abstract. I think people have to grapple with this as a potential tangible risk, and therefore we need to account for that in our planning. So I don’t know, but maybe.
Cool. Philip, Alex, thank you guys.