[BidClub_]
Empire · · 65 分钟

Bitcoin 量子分叉将至 | Alex Pruden & Philip Martin

Alex PrudenPhilip Martin

加密区块链技术
YouTube
TL;DR
  • 在这场 2026 年 4 月录制的节目播出前几周发表的 2 篇论文,压缩了量子威胁的时间线,并引发了当前的恐慌周期。 Google Quantum AI(包括密码分析师 Craig Gidney)认为,专门攻击 ECDSA——而非旧式 RSA——会让攻击“迫在眉睫得多”;一家源自 Caltech 的中性原子团队则认为,Shor 算法所需的可重构量子比特可能只有10,000个,而此前估计为500,000–1M个。IBM 已有约1,000量子比特系统,纠缠演示接近7,000量子比特,距离密码学相关性大约只差1个数量级。
  • Bitcoin 是暴露程度独一无二的资产:约10%的供应量属于被推定已永久失联的 Satoshi 币,按约1.5万亿美元市值计算约为1500亿美元;而约35%的全部 BTC 已暴露公钥。 Alex Pruden 的判断是,“这里会出现一次分叉……我认为这是不可避免的”——一派主张冻结,另一派反对冻结,市场会像处理 Bitcoin/Bitcoin Cash 那样解决分歧;但这一次涉及“潜在的真实安全影响”,而不是两条链都能获得无风险上行空间。
  • Philip Martin 的个人观点(明确不代表 Coinbase):冻结存在漏洞的币,但同时建立恢复路径。 “我无法接受的是,第一批能够破解密钥的人就可以拿走如此巨大的价值”——先锁定这些币,再让持有者通过证明自己能够访问 seed phrase 来取回。Coinbase 自身将在可行路径出现后“升级我们持有的所有密钥”,否则就“听取客户的意见”;Pruden 的框架是,交易所、ETF 发行方和资产负债表持币者属于冻结派,因为这些经济节点“损失最大”。
  • 即便迁移成功,过程也会非常棘手:节目讨论的 FALCON/FN-DSA 签名约为当前 ECC 的10倍大小,可能拖累吞吐量,并引发“又一场区块大小争论”;主持人还引用 Google 对其“噩梦般复杂度”的描述。 更糟的是,Google 提议的机器对 Bitcoin 的10分钟区块只需9分钟就能运行 Shor 算法,从而对干净地址在内存池中抢跑;届时“迁移基本会变成一场巨额手续费竞价战”。
  • 稳定币发行方面临特殊的量子紧迫性——风险不在银行账户,而在链上的管理权限密钥;Pruden 称其可能成为“国家级目标”。 他的情景是:攻击者为了扰乱美国金融体系,铸造“300万亿美元的 USDT”,打破锚定,并像 Kelp DAO 跨链桥被盗那样沿相互连接的 DeFi 体系级联扩散,可能造成数十亿美元损失和极端扰动。
  • 在时间判断上,嘉宾形成了有益分歧:Coinbase 的论文称具体日期“基本无关紧要”,因为修复耗时太长,必须现在就开始;Project 11 则发布了2029年乐观、2033年基准、2042年悲观情景,以反驳“反正总是还有20年”的懒惰判断。 双方都认可 Mosca 不等式——比较防守方迁移所需时间与攻击者到来的时间——而 Pruden 警告,量子领域可能不会出现公开的“ChatGPT 时刻”:与密码分析相关的进展由政府和 DARPA 资助,“很可能在闭门情况下发生”,正如 Google 已经扣下了自己的电路设计。
  • 对资产配置者而言,主线是:量子计算叠加 AI 规模的攻击模型(“Mythos”讨论),会把加密行业推向更强的许可化和地理分裂。 Martin 认为,在主权国家并存的世界里,更多许可机制不可避免;Alex 则反对“重量级许可制 DeFi 区块链”,但表示每年因攻击损失约10亿美元“完全不可持续”。Alex 的中间路线是 USDC 式按例外冻结和账户抽象,主持人则指出 Zcash 等以量子优先为卖点的链正在交易这一后量子叙事。Martin 警告,一次重大的信任破裂可能让机构再也无法接触 Bitcoin。
摘要 · 为研究而整理的核心内容

1. 2篇论文将量子比特门槛压低了1个数量级

  • 据 Pruden 介绍,引发 Nick Carter“Bitcoin Core 正在梦游走向崩溃”(Bitcoin Core is sleepwalking towards collapse)论述的导火索,是 Google Quantum AI 与密码分析师 Craig Gidney 的研究:相较于此前聚焦较老旧 RSA 的工作,该研究专门针对 ECDSA,并加入了对实际在建机器的假设,从而表明威胁“比我们最初想象的迫近得多”。值得注意的是,这篇论文“1/4是量子计算论文、3/4是数字资产行业调研”,并明确敦促行业迁移到后量子密码学。
  • 第2篇论文来自 Caltech 背后的一支顶级物理学团队,团队成员包括中性原子初创公司 Aor Atomic 的创始人 Dylan Blowstein 等人。论文认为,Shor 算法“可能只需10,000个中性原子可重构量子比特”即可运行,而此前估计为500,000–1M个。考虑到 IBM 已有约1,000量子比特系统,并完成约7,000量子比特的纠缠演示,“距离密码学相关性至少大约还差1个数量级”。
  • Martin 给出了贯穿整期节目的限定条件:这一切都仍属推测——“理性的人可能对事实究竟是什么持有截然不同的观点……这种情况我想自己几乎从未见过”。

2. 威胁波及全部现代密码学,但区块链无法召集银行家改账

  • Martin 将问题范围扩大:一台具备密码学相关性的量子计算机(CRQC)会摧毁“安全使用互联网的能力”,金融、政府以及其他领域无一幸免,而且大量已部署硬件并不具备密码敏捷性。物联网芯片能否运行后量子算法?制造商是否会升级?“可能会,也可能不会……等它真正到来时,Y2K 恐怕都会显得被低估了。”
  • Pruden 抓住了传统金融与区块链的关键差异:传统金融依赖可以回滚的可信参与方——“一群重要银行家坐在那里说,刚才是谁记了那笔账?把它删掉”——因此,从攻击 SWIFT 中获利更难。在区块链上,“转移资金的授权完全由密码学提供”,设计上就是单因素授权,这让迁移和缓解风险都格外困难。
  • 其他领域已经开始行动:约1/3至一半的互联网流量正通过采用混合密码学的方式获得保护,其中已经实现了 PQC,银行也在迁移。唯独 Bitcoin 连路线图都没有;大多数其他链已经有路线图,至少还有2个已经上线 PQ 测试网。

3. 脆弱资金池:不只是 Satoshi 的约1500亿美元,还有35%的供应量

  • 主持人和嘉宾检验的框架是:如果 Bitcoin 的其他部分完成升级而 Satoshi 的币没有升级,那么这约1.7–1.8M枚币、约占约1.5万亿美元市值的10%,就会变成“互联网上最大的一笔可供攻击的资金”。Pruden 的纠正至关重要:“升级了”这个说法不对——“你必须升级,对吧?不是你的密钥,也不是你的密码学。”目前约35%的全部 Bitcoin 已暴露公钥。Project 11 在 project11.com 维护了一份可搜索的“风险清单”,而一些操作规范弱于 Coinbase 的交易所已经让大量价值处于暴露状态。
  • Martin 的个人立场前置得非常明确:“这不是 Coinbase 的观点”——“我们必须防止量子计算机窃取这些币”,同时建立恢复方案,让持有者通过证明自己能够访问 seed phrase 来取回被冻结的币。
  • Pruden 指出的哲学困局是:数字黄金的供应完整性,与 Satoshi 创立 Bitcoin 时强调的财产权理念发生冲突。如果量子窃贼倒掉“全部黄金的1/10”,价值储存属性的信心就会被摧毁。Bitcoin 的价值规模和存续时间都独一无二,使这成为“一场独一无二的艰难对话”,也拖慢了市场对威胁的识别。

4. Pruden 的判断:分叉不可避免,经济节点损失最大

  • 他的判断带有明确限定:“这里会出现一次分叉。我认为这是不可避免的……最终,市场会决定哪一条链更有价值。”但 Bitcoin/Bitcoin Cash 分叉时,“每个人都会得到原有资产的两份”,本质上是纯粹的上行选择;这次则存在真实的安全影响,因此分裂不会那么干净。
  • 参与者版图也已改变:核心开发者阵容比过去更薄,许多2017年前后的人物已经离开,但 Adam Back/Blockstream、Greg Maxwell 和 Matt Corallo 仍在;机构的风险敞口远高于10年前;矿工“会做他们认为其他所有人希望他们做的事”;此外还有一批高声量的意识形态拥护者,他们“在采取务实方案这件事上有点像搅局者”——这群人或许正是在资本数量处于劣势的情况下赢下区块大小战争的同一批人。
  • Pruden 的框架是:冻结派包括机构、ETF 发行方、交易所和托管方,因为它们“无法容忍客户资产风险”;不冻结派则是 maxis 和意识形态拥护者。如果 Coinbase 把托管币指向其中一条链,“那基本就是你的决定”。Martin 对 Coinbase 会如何选择的回答是,会“非常、非常”重视客户和利益相关方;无论最终选择哪条链,只要可行路径出现,就会升级 Coinbase 持有的全部密钥。主持人认为,灾难性的尾部风险使升级在经济上具有理性。

5. 反对冻结的最强论点:没收边界该画在哪里?

  • Pruden 坦言,Satoshi 的币“有点像一个稻草人”。根据 Chainalysis,Satoshi 持币中约15%构成了丢失币的约2/3;因此,“丢失的币究竟有多丢失?”本身就是一个问题。在边际情形下,长期持有者和丢失密钥的人可能根本无法区分。
  • 责任归属将成为噩梦:假设 BIP-361 的作者按下合并按钮,矿工予以执行,而有人醒来后发现自己的 Bitcoin 无法访问——“他能否向那段代码的作者,或者按下按钮的人提出法律索赔?我不知道。”即便给予宽松的10年申领窗口,也会重新引入它本想解决的风险,因为具备相关能力的量子计算机可能在这10年内出现。
  • 执行层面上,Bitcoin 没有基金会,只有“这场永无止境的政治斗争:谁有资格担任发言人”。Pruden 谨慎引用《纽约时报》的一篇报道,称 Adam Back 可能正在推进某项工作。根据他交付过一条 L1 的经验,“白皮书和真正安全、能够保障数万亿美元资产的东西之间存在巨大鸿沟……我们现在还处在想法阶段。”
  • 他提出过一种优雅的混合方案:将无人申领的冻结币纳入安全预算,为区块奖励结束后的时代提前提供资金;但他认为该方案概率很低,因为“这就是一个巨大且争议缠身的烂摊子……人们只会希望用某个简单方案赶紧结束”。

6. 即便成功也很痛苦:签名复杂度、手续费竞价战与9分钟机器

  • Martin 警告,升级之后,较大后量子签名中最小的那一类也约为当前 ECC 签名的10倍大小,这“会影响吞吐量,或者引发又一场区块大小争论”。主持人指出,节目讨论的签名是 FALCON/FN-DSA,预计最终会以这一名称标准化,并引用 Google 对其“噩梦般复杂度”的描述——“你现在觉得 DeFi 黑客攻击难以防范,等到人们试图把这种东西投入生产时,只会更难。”
  • 慢时钟与快时钟的区别影响的不只是沉睡币:Google 提议的架构运行 Shor 算法只需9分钟,而 Bitcoin 的区块时间是10分钟,因此即便某个公钥从未暴露,只要它开始交易,就可能在内存池中被抢跑。“一旦到了那一步,迁移基本就会变成一场巨额手续费竞价战。”Pruden 个人认为,快时钟架构落后于慢时钟架构,但也承认,“没人真正知道……这种情况还会持续多久。”
  • 关于申领窗口,Martin 展现了运营层面的现实主义:“我不知道给1年还是5年是否有很大区别。”迁移的90%会发生在第1个月,之后则拖成一条“超长、缓慢滴落的尾巴”。真正困难的是触达所有需要采取个人行动的人,包括把 Ledger 放在家中保险柜里的人。

7. 什么都不做的情景:真正危险的是信任破裂,而不是抛售

  • 主持人进行压力测试:如果10%–20%的供应量被取得并抛售,Bitcoin 会否逐渐失去意义?Martin 将机械性的价格冲击与真正威胁分开:“对网络信任的影响是什么……这是否意味着机构再也无法接触这一资产?如果是这样,这对 Bitcoin 的未来意味着什么?”
  • 主持人指出了竞争层面的机会:各协议都能通过率先采用后量子方案实现差异化——“我认为 Zcash 就是已经押注这一点的协议之一……这其中有很多真实成分。”
  • 对另一个相邻的生死问题,Martin 倾向于持续发行:通胀率作为百分比可以逐步趋近于零,而固定的通胀率能给矿工提供规划依据——“你要么假设这些币会持续升值、哈希率保持不变;要么假设会持续发行。你无法同时拥有两者。”Alex 表示并不反对,但指出原始理论是手续费会取代区块奖励;双方都认为安全预算对 Bitcoin 持续具备交易能力至关重要。

8. 稳定币管理密钥是国家级目标,许可化趋势本来也将到来

  • Pruden 解释了 Project 11 为什么单独设置稳定币章节:在这一框架下,银行账户是安全的——“量子计算机无法伸进银行账户,凭空制造出美元”——但发行方管理密钥“绝对属于关键基础设施,也可能成为国家级目标”。他的混乱情景是:铸造300万亿美元 USDT,打破锚定,再让冲击沿相互连接的 DeFi 体系扩散,类似 Kelp DAO 跨链桥被盗;即便不造成持久的现实金融影响,也会“极具破坏性”。
  • 关于自由的争论,Martin 保留了自己的经历背景:他最初在中东参与帮助叙利亚难民的加密项目,但“自由是双向的——朝鲜也可以借此自由地资助核武器计划”。他的结论是,在主权国家并存的世界里——“美国政府可以把我关进监狱……但 Ethereum 网络基本做不到这一点”——“你必然会看到更多许可机制”,甚至可能沿地理边界发生分裂。
  • Alex 的底线是:人们永远会写出不安全的代码,因此应该标记高风险合约,而不是把它们挡在门外——“我不想生活在一个由一堆重量级许可制 DeFi 区块链组成的世界里……但如果每年因为这些问题损失10亿美元,那完全不可持续”,否则加密行业就会变成“银行2.0”。
  • 面对主持人“应当假设用户会被黑”的主张,Pruden 提出的中间路线是 USDC 式按例外冻结:处理有过错的一方,而不是像银行开户那样先证明自己没有过错——“尽管这看起来只是一个很小的差异……但这正是稳定币交易真正起飞的原因之一”。此外还可以采用账户抽象,让普通用户与企业家使用不同等级的授权方式并存。

9. 时间线、闭门研发与删除自己的指纹

  • 时间线上的分歧主要是表述方式不同:Coinbase 的论文称时间线“基本无关紧要”——“量子计算机是在2030年还是2040年出现,对我来说都不重要,我们今天就必须开始工作”,而且“一旦开始抛出日期,大家就会开始争论日期”。Project 11 发布2029年乐观、2033年基准、2042年悲观情景,正是因为“人们有点懒……反正总是还有20年”。双方都引用 Michele Mosca 不等式:必须将攻击者到来的时间与防守方迁移所需时间放在一起权衡,因此应“今天就开始准备”,但无需陷入恐慌。
  • 关于量子计算是否会出现类似 ChatGPT 的公开时刻,双方观点截然不同:Martin 预计,模拟和药物发现领域会出现可见的能力跃升;Pruden 则给出更阴暗的判断——与密码学相关的进展“很可能在闭门情况下发生”。Pruden 表示,Google 已经扣下自己的电路,并通过零知识证明说明它只使用了 X 次操作;而行业资金主要来自政府和 DARPA 等机构,它们购买的是密码分析能力,并且“理想情况下希望尽可能长时间保密”。
  • 主持人原以为 Elizabeth Holmes 那条“删除一切”的推文是在回应 Mythos 模型,Martin 则认为这“过于夸张”。Mythos 规模过大,无法在12个月内用合理硬件以开放权重方式运行——“也许这问的是时间线,而不是最终目的地”;而这类模型更有利于防守方,因为防守方掌握攻击者没有的系统上下文。Alex 则以亲身经历反驳:删除不可能做到——他相信自己的指纹已经在2011年的 OPM 黑客攻击中被盗,“我怎么删除自己的指纹?”因此现实答案只能是多层安全、双因素认证,以及不设置单点故障。
  • 最后的问题是:Satoshi 的币最终会不会移动?Pruden 的回答是:“我认为不会。”但他认识一些量子计算机开发者,他们把这些币视为“失落的宝藏”,这正是风险并非抽象概念的原因。“所以我不知道……但也许会。”
完整逐字稿
Speaker 1

I'm very excited about this one. I'm really excited to have the chief security officer of Coinbase, Philip Martin, as well as Alex Pruden, the founder and CEO of Project Eleven, with us. This is going to be the security podcast, but maybe even one step deeper than that.

I don't know if you guys have been reading Nic Carter's post about quantum and Bitcoin, where we're all screwed here. I wanted to bring the 2 smartest security people I know on to figure out what we're going to do about quantum and Bitcoin. Philip, Alex, welcome.

Philip Martin

Thanks for having us.

1. The Quantum Computing Risk

Alex Pruden

Great to be here. Yeah, excited about this.

Speaker 1

I think maybe the best play is for me to ask a ton of really dumb questions in this episode, so be prepared, because I'm way out of my depth talking about quantum. I'd love to hear from you guys about why this is the moment in time we're recording this, April 2026, when quantum suddenly feels like it's here.

I think Nick said Bitcoin Core is sleepwalking toward collapse. Why is this the time period when everyone is starting to talk about this?

Alex Pruden

I can take maybe just a first pass. I think the primary reason is that 2 papers came out a couple of weeks ago. One was from Google Quantum AI Lab. They're building a quantum computer, and they also have people working on cryptanalysis, namely a gentleman named Craig Gidney.

This lab came out and basically said, “Hey, if you look at targeting elliptic-curve cryptography specifically, past work in quantum cryptanalysis focused on an older cryptosystem, RSA. But if you target ECDSA specifically and layer on some assumptions about the type of computer we're building, then potentially this is a much more imminent threat than we first thought.”

There are a bunch of impacts across the cryptocurrency space. I think this was one of the more notable parts of the Google paper: it was 1/4 quantum-computing paper and 3/4 survey of the digital-asset space and all the various ways that things were vulnerable. It explicitly said, “Hey, there's an urgency to migrate to post-quantum cryptography.” That was paper 1.

Paper 2, which was independent of this, was from a team out of Caltech. It was from S-tier physicists, and the company was called Aor Atomic, founded by people including Dylan Blowstein. They came out with a paper that said Shor's algorithm may be possible with as few as 10,000 neutral-atom, reconfigurable qubits.

For context, the prior state of the art was between 500,000 and 1,000,000 qubits, which was what people thought we needed. So, they took the bar that you had to clear to potentially break public-key cryptography and brought it all the way down to 10,000.

For context, IBM has a system with around 1,000 qubits, and they've entangled systems with up to around 7,000 qubits. So, you're at least an order of magnitude away in terms of the number of physical qubits you would need to potentially be cryptographically relevant.

Those 2 papers kicked off a press cycle, and now I think suddenly everyone is waking up to it and saying, “Oh, man, we should figure something out here.”

Philip Martin

Yeah, I think they're right. The interesting thing about this whole space is that everything is so speculative. Alex very correctly said a bunch of things like, “It might, it could, we think that maybe,” right?

That leads reasonable people to have wildly divergent views about what's true in this space in a way that I think I've rarely ever seen before.

Speaker 1

Maybe before going too deep into Bitcoin, can we just talk about the cryptographic system that everything runs on, including our financial system? It seems like that's at risk.

By the way, not just with quantum, but Santi and I have been talking about Anthropic, ChatGPT, OpenAI, and what's happening with Microsoft a little bit on the podcast. It seems like there are these 2 threats, quantum and AI.

Maybe before going too deep into Bitcoin, can you guys tell me what your mental model is for how you're thinking about the financial system and the security of the financial system getting upended right now?

Philip Martin

It's not even the financial system. It's modern cryptography that's at threat, or at least a class of modern cryptography is at threat today with quantum computers.

The ability to use the internet safely rests on modern public-key cryptography, which a cryptographically relevant quantum computer—that's the term we use to talk about this—would fundamentally break. That's financial systems, government, basically everything.

Alex talked about crypto-agility a second ago, which I think will be important moving forward. But the thing is, a lot of stuff that's built today is not agile and can't be agile. You look around your house—how many IoT devices are there?

It's an open question whether the chips in those devices are going to be able to use post-quantum algorithms. I don't know. Maybe yes, maybe no. Are the manufacturers actually going to upgrade them? I don't know. Maybe yes, maybe no.

When it comes to pass, this will truly be Y2K, and Y2K would be underestimated, in my view.

Speaker 1

Well, Philip, I have a dumb question here. We have all these devices. I'm recording this with a microphone, I've got the computer, I've got IoT devices, and maybe someone has an Amazon Alexa. Do you have to replace every single device? Is this a hardware upgrade or a software upgrade?

Philip Martin

It depends on how they implement it under the hood. It could be either.

Speaker 1

Alex, go ahead.

Alex Pruden

Yeah, I wasn't going to comment on the hardware or software. I was just going to make a quick comment on the financial-system point that you brought up.

I think it's true that there's a lot of risk to the broader financial system that uses the internet. The vulnerabilities are more around how the financial system is embedded inside the internet, basically—largely, not entirely.

I think the distinction between the broader financial system and what we're going to talk about, which is blockchains, is that these systems already rely very heavily on trust. There's a trusted set of parties that maintain the ledger, so to speak, or the data.

In theory, an attack could be very disruptive on SWIFT, for example. But in theory, there are a bunch of important bankers sitting around saying, “Hey, whoever did that last entry, erase that and let's go back 1.”

Reverting an attack, or preventing someone from being able to profit from an attack on the broader financial system, is easier—or, stated more clearly, it would be harder for someone to profit from an attack on the broader financial system. It's not impossible, just harder.

That's as opposed to blockchains and digital assets, where the authorization to move funds is entirely cryptographic and has to be 1 factor, right? If it was multifactor with trusted parties, then it's kind of harder. I mean, it's less decentralized, right?

That's maybe an overgeneralization, but I think sometimes people overemphasize or are hyperbolic around this idea that if a quantum computer comes out, the world is going to end and everything is going to fall down. I don't necessarily think that's true.

Everything has to migrate. Banks are already migrating, as is the broader internet. Around 50%—I can't remember, Philip may know the exact number—somewhere around half or a third of all internet traffic is already secured using hybrid cryptography, which implements PQC.

2. Bitcoin’s Quantum Risk

The ball is rolling, and I think blockchains are in this unique position where they're super reliant on cryptography for their security. Migrating to a safe form of cryptography and/or mitigating an attack is just harder.

Speaker 1

As we're recording, there's been a spike in DeFi hacks that's unrelated to Bitcoin. If you look at them, they're not all the same, but this latest one seems like perhaps some things could have been avoided if you had timelocks or a bit more in the way of rate limits.

I guess that seems obvious in hindsight, but one of the things in crypto is that you see a lot of builders being extremely philosophical and ideological and perhaps not too practical.

Speaker 1

The question is more around, I think, Bitcoin. This is the heart of the discussion of this pod, but how would you describe the sentiment out there? You talk about the traditional internet moving now 50% to kind of get ahead of this. Where are you in terms of sentiment? How's the community adapting? Is the alarm fully being sounded, and are people reacting to this, or are they not moving as fast as you'd want?

Philip Martin

Yeah, my opinion—and Alex may have a different one—is mixed. I think we can talk about Bitcoin specifically, although obviously this impacts the whole spectrum of blockchains. Some blockchains are moving quite quickly, right? There are at least a couple, I believe, that have testnets up that are using post-quantum cryptography. Almost everybody has a roadmap, with the exception, I would say, of Bitcoin.

I think there’s a broad spectrum of opinions within the Bitcoin community on the timeline, as well as the risk of quantum computers. I think Nick Carter has done some good stuff on this that he’s put out, looking at where everyone stands, to the extent it’s possible to see.

Alex Pruden

I have nothing to add other than to say that I think Bitcoin is a hard topic. One of the reasons I think it’s a hard topic in Bitcoin—and I’m sure we’ll cover this more later—is there’s this philosophical issue at play where a lot of the older UTXOs, like Satoshi’s, are thought to be irrecoverable. Satoshi may be dead, so all that value is just—what do you do with it? Do you basically prevent a quantum computer from stealing it by burning it, or do you just let the quantum computer take it? There are these 2 things about Bitcoin where that’s a really deep philosophical divide.

One is this concept of Bitcoin as digital gold, right? The integrity of this supply should not be violated. Theoretically, someone could just go and steal and then sell on the open market 10% of all gold. That’s probably going to have a major price impact, impacting people’s confidence in the future ability of this to be a store of value.

3. Fidelity Crypto Ad

Philip Martin

The other aspect, though, is Satoshi, right? He created Bitcoin as a direct answer to what he saw was a corruption and mismanagement in the broader financial system. This property-rights idea—“not your keys, not your crypto”—was a deeply rooted philosophical thing. I think this has made the conversation in Bitcoin particularly difficult. Bitcoin is kind of unique in this way: it has this uniquely large amount of value, and it’s been around the longest. So, this is a uniquely difficult conversation there, which makes the conversation harder. I think it makes people a little bit slower to want to recognize this is a potential threat.

4. What To Do With Satoshi’s Coins?

Alex Pruden

Yeah, let’s go down the Satoshi rabbit hole. To tee up this conversation, Bitcoin’s market cap is $1.5 trillion today or something like that. Satoshi’s coins are roughly 10%. The question in the quantum world is, the Satoshi coins and a lot of Bitcoin might get upgraded. There might be a hard fork, and the Satoshi coins might get upgraded—or most of the Bitcoin will get upgraded, but the Satoshi coins maybe don’t get upgraded.

So, there’s this $150 billion pot that people can attack. It’s like the biggest pot of money on the internet that you can attack today. So, the question is, what do you do with these Satoshi coins? Philip, is that kind of the right framing?

Philip Martin

Yeah, basically. I think Alex is right that there are basically 2 choices: you lock them in some way, or you leave them up for grabs. There are a bunch of different nuanced approaches people have suggested within those 2 buckets: lock them, but recover them in some way if you can prove some knowledge, that kind of thing. Neither choice is obviously the clear winner.

Speaker 1

Let’s go deeper. What do you guys think should happen?

Philip Martin

Oh, man, you’re really just teeing us up to get flamed by the community.

Alex Pruden

I know, seriously. Nick can’t take all the heat, so go for it, Philip.

Philip Martin

Look, I’ll just preface this: this is my personal opinion, right? This is not Coinbase’s view on any of this. My personal opinion is it doesn’t make sense to me that we would have that much value up for grabs by the first person who can break a key with a quantum computer.

I think we have to do that in a way that respects the ability of the people who own those coins to actually come back and claim them if we at all can. There have been schemes proposed, like proving access to seed phrases, and I think there are some possibilities in that world. My personal vote is that we have to prevent a quantum computer from stealing it, and then we have to make some way for those coins to be brought back to life in the event that the holder is actually able to recover them.

Alex Pruden

Yeah, I’ll maybe preface my answer by just making 1 or 2 points, and then I’ll give you my answer. First off, it’s not just the Satoshi coins that are vulnerable, right? You said something very important a minute ago that I think is worth clarifying. You said coins will get upgraded. I think the right verb should be the active form: you must upgrade, right? Not your keys, not your crypto.

Anyone with a UTXO today, to be quantum-secure, must do something, right? This is the issue. It’s not that, for whatever reason, Satoshi’s keys or UTXOs are hidden behind some wall of fire. It’s that we think Satoshi is dead, so they’re just not going to be able to do the thing themselves.

To be clear, even though Satoshi’s supply roughly equates to about 10% of the overall supply, and there’s a spread across many UTXOs, about 35% of all Bitcoin today has exposed public keys for a variety of reasons. Potentially, all of those are at risk, too.

There are some other exchanges out there that, I would say, do not have as good security practices as Coinbase and have left a significant amount of value at risk. If you want to see all of the various Bitcoin that’s at risk, we have a risk list on project11.com where people can enter an address or even scroll through the top holders.

So, there’s a lot of value, and potentially people have to migrate it. To Philip’s point, what do you do if Satoshi’s not going to migrate? My view is there’s going to be a fork here. I think it’s inevitable, because these philosophical issues—I don’t really see how you resolve them.

Forking is a mechanism by which blockchains potentially deal with this divide, and it’s not the end of the world, right? We had Bitcoin and Bitcoin Cash, an irreconcilable divide between 2 camps around block size. I think it’s not unreasonable to expect this will happen again. Ultimately, the market will determine which of those is more valuable. Or maybe both of them have some residual value. I don’t know. I think it’s ultimately just going to end up as a fork. I would be surprised if it didn’t.

Speaker 1

Who are the major players that could matter in the conversation? In 2017, we’d been here before, with difficult decisions in the Bitcoin network, as far as I can remember. Who are the major players here that matter in the conversation?

Philip Martin

I’ll start with this one. Yeah, I think there’s a historical group of core developers, which, just to be clear, has evolved over time. If you go back to 2017 and the conversations of that era, many of the characters who participated in those have moved on.

There are still some core developers, obviously—Adam Back at Blockstream, and Greg Maxwell’s around, Matt Corallo’s around. There are some folks who have been around for a while, but there are not as many as people would probably expect from the era of 2017.

The core developers certainly matter. Institutional adoption of Bitcoin is much, much higher than it was 10 years ago. These institutions obviously have skin in the game, right? They certainly matter. I think those are probably the 2 primary groups.

Although maybe I’ll add a third, which is miners. Miners ultimately, I think, are going to do what they think everyone else wants. I don’t know. Maybe that’s not true, but that’s sort of my take.

Alex Pruden

And I do think there are loud members of the community who are not in any of those 3 categories, and I think they’re kind of spoilers for doing something pragmatic. To be charitable to them, they’re defending what they see as the core principle of Bitcoin and why they signed up to hold it. So I would maybe just say there’s a long tail of community members who really believe in these deep principles of Bitcoin, in one way or the other, and just have an opinion.

Speaker 1

By the way, Alex, didn’t they win the 2017 block-size wars? They were kind of outnumbered in capital, but I don’t know if that’s the right framing of history. You could argue that, right?

Alex Pruden

Certainly. The narrative is that the miners and big, bad corporations got together and tried to increase the block size, and the community rose up and won. That’s the popular narrative for obvious reasons in that community. But, yeah, no, look, I think their voices are probably not to be underestimated. Again, this is why I think you can’t rule out the possibility that ultimately there could be a chain fork, and then the market will just resolve it at some point. I don’t know.

Speaker 1

So, is it fair to say it’s the economic nodes—the exchanges and custodians, the ETF issuers, and the balance-sheet holders like MicroStrategy—that are going to make this decision? Is that right?

Alex Pruden

Well, I’ll answer, and then, Philip, you can decide if you want to take that as well. Look, I think they’re going to make a decision around what they want to do with their assets, and, given how important stakeholders they are, that decision may influence what everyone else does. But I don’t think necessarily no one can decide for Bitcoin, right? I do think, though, that if you look at the pure amount of capital, it’s inarguable that the economic nodes have the most to lose, potentially. So I think they’re definitely going to be involved in this.

Philip Martin

I think this is a different thing. Maybe, as Alex says, you compare it to Bitcoin Cash. In that case, it was kind of like, everyone gets 2 of whatever they had before, so there’s only upside to doing both. Whereas here, there are some potential real security implications, so I don’t think it’s quite as clear-cut that everyone’s just going to go one way or the other. I don’t know.

Alex Pruden

Yeah, no, I think that’s exactly right. No one can make a decision and make it stick. I think it’ll be a community-driven process. But I think Philip is also right—the economic nodes have the most to lose, right? So I think they’re going to be, and I think we’ve started to see this, the ones who are most interested in driving a solution.

To me, it feels very obvious what’s going to happen, right? There’s going to be a freeze camp and a no-freeze camp. The freeze camp is going to be the institutions, the ETF issuers, the exchanges, and the custodians, because they can’t tolerate client-asset risk. Then there’s going to be a no-freeze camp, which is going to be the maxis, the community, and the ideologues. That’s great; you need both sides. But no one can choose. If Coinbase says, “Hey, all of the Bitcoin held at Coinbase is now going on this chain,” then that’s basically your decision.

Philip, I guess I know this is Philip’s decision and not Coinbase’s—you’re speaking for Philip, not Coinbase—but how do you guys make this decision at Coinbase?

Philip Martin

It’s going to be really tough. I think we’re ultimately going to do what’s right. We’re here because of our customers, right? We’re ultimately going to listen to our customers and our stakeholders and weigh that very, very heavily. Either way, once there’s a viable upgrade path, we’ll obviously upgrade all the keys that we have to make sure they’re using post-quantum cryptography. But this will be something that we listen closely to our customers and stakeholders on.

Speaker 1

I’m sorry, guys, but this doesn’t sound controversial at all to me. If you’re Saylor, BlackRock, or Coinbase—to your point, Philip—you’re going to do this because the asymmetry of not doing anything and having someone steal Satoshi’s coins is catastrophic to the network.

Philip Martin

To your point, it’s not just Satoshi’s coins, Alex. It’s, you know, up to what, 30% of the supply?

Speaker 1

Yeah, good luck. Not doing that is a tail risk for Bitcoin. Attach any probability to that happening over the next 5 to 10 years, and you still get to the economically rational decision if we’re all here talking about the game theory of upgrading now.

The question is, who is going to put forth this upgrade? Is that maybe more the nuance? Do we agree that this is the best upgrade, or are we going to see a couple of proposals? I just don’t know much about what’s going on here.

Philip Martin

Let me steelman it. I think everything you laid out was very logical. Let me steelman the other side a little bit from a slightly different perspective—not as a philosophical perspective. Satoshi’s coins are kind of obvious, right? We think they’re dead, but about 15% of Satoshi’s coins make up about 2/3, according to Chainalysis, of the lost coins. How lost are the lost coins? That’s kind of a question.

So when you cross that—Satoshi’s coins, okay, maybe fine—but, again, that only accounts for about 1/3 of all the coins that are supposed to have keys. So where do you draw the line on effectively confiscating Bitcoin that hasn’t moved in a while?

Alex Pruden

This is the way to wake them up, right? If we want to truly understand how many of these Bitcoins are lost or will come up, and maybe we’ll find out who the real Satoshi is, if they’re not dead or their hard drives aren’t in a landfill, this is actually a really fascinating way of doing that.

But now imagine you’re someone working on this. Let’s just say the core developers, such as they are, all come together and say, “We believe in this. We’re going to do this,” and there’s a pull request. bit 361 actually has a bit for this now. Let’s say—I won’t name him, because he’s getting enough flame on X—but the author of BIP-361 is the person to press Merge. The pull request is merged, miners all agree, and everything happens for this freeze. Someone wakes up someday and says, “Hey, my Bitcoin are no longer accessible.” Do they have a legal claim against the author of that bit or the person who pressed the button? I don’t know, right? There’s a lot here.

People have talked about there needing to be a time frame. Let’s say we give people 10 years. That’s all fine, of course, but 10 years from now, we’re talking about the real risk that a potential S-C-R-T exists, right? So I think the challenge is not so much Satoshi’s coins—they’re kind of a straw man. I think it’s more about, on the margin, who is a long-term holder and who just lost their keys. It’s unknowable, right? And I think that’s why it’s tough.

To your question of who does it: Bitcoin is also unique in the sense that there’s no foundation associated with upgrading it, right? There’s this never-ending political battle over who gets to be a spokesman for Bitcoin. If The New York Times is to be believed, Satoshi Nakamoto—I mean, Adam Back—may be working on something, but others may have ideas.

There’s a bit of chaos, and there have been a number of proposals over time. We outlined many of them in our blog; we have a whole rundown, but this has been talked about for years. The question is: Who galvanizes the effort and the resources required to take this from an idea to a reality? I’ve been part of the team that launched a layer-1 blockchain, and there’s a big, big gulf between the white paper and the thing that is secure, that can secure trillions of dollars. To me, right now we’re in the idea phase. There are people who have ideas, but I think we’re still pretty far from someone saying that they’re going to do it.

By the way, though, that’s true of all networks. Philip mentioned that there are people with road maps; those are all great. Very few teams—there are a handful, but very few—have actually taken any concrete steps toward making the ideas realities, although everything, of course, has to start as an idea.

Philip Martin

Yeah, and it’s very interesting because there’s a whole separate set of problems after you upgrade to a quantum-proof signature scheme. For example, the signatures are much larger. The smallest of the larger ones is, I think, 10 times—if I remember my numbers correctly—the size of the current ECC signature.

Speaker 1

That's going to impact throughput, or it's going to kick off another block-size debate. By the way, you mentioned the DeFi hack.

That 10-times-the-size signature that Philip is mentioning is called FALCON, or FN-DSA, which is what we'll probably standardize it as. Google wrote an entire blog post about the nightmarish complexity of implementing that. You think DeFi hacks were hard to prevent before? Wait until people are trying to roll something like that into production.

As Philip correctly highlighted, we're going into a world where there's a whole bunch of painful trade-offs that these protocol teams are really going to have to figure out. But I want to go to DeFi and stablecoins in a second. One more Bitcoin question for you guys: Is there a third option here?

Let's say—if it sounds like both of you have a view—Philip, you didn't fully give yours. It sounds like Alex gave a very strong view that we should freeze the coins, and I think you're maybe more in that camp, Philip?

Philip Martin

I think Alex didn't give his view on whether it should be frozen or not. He very skillfully danced around that one.

Speaker 1

Okay, you dodged. So you both dodged. Anyway, we've got the freeze and no-freeze camps. Is there a third option? Or would your view on this change if, let's say—I think what everyone's scared of is that China or North Korea are going to win the quantum race and take these coins.

But what if you knew that Coinbase had developed a quantum computer, or the US government had developed one and would get the Bitcoin coins? Now you kind of get court-appointed receivership of however many Satoshi coins there are—2 million, or 1.7 or 1.8 million coins—and this turned into the Strategic Bitcoin Reserve. They said, “We're never going to sell it.” Is that option 3? Would you guys be okay with that? Would you be like, “Oh, interesting. I'm kind of down with that”?

Philip Martin

That's kind of a sci-fi option, if I'm being honest. That's pretty out there in terms of reality. I think Nick has written that. By the way, I have a really fun short story where he outlines this. Also, Kyle Samani, formerly of Multicoin Capital until he retired, tweeted exactly this about a year ago.

Alex Pruden

I agree with all of them. There are just so many what-ifs, right?

Speaker 1

Yeah. If you're going to pin me down and say, “What's the third option that I think is viable?” one other issue people talk about with Bitcoin is what happens when the security budget runs out. Option 3 is kind of a confiscation option, but with a less—I mean, maybe less confiscatory—approach: you roll Satoshi's coins into the back end of that.

To me, if you're going to confiscate, that's probably the best way, or maybe the best way, because then you at least buy yourself time for this other really controversial conversation. I don't know. Maybe that's a—

Alex Pruden

Are you saying the Bitcoin network is going to have stock-based compensation?

Philip Martin

Uh-oh, man. I'm getting enough of this. Santi, don't put that on me. No, but people should go listen to the episode we recorded with James Prestwich, who I think has been one of the strongest advocates for putting the security-budget question front and center—discounting it to today.

I hadn't thought about this, but it's quite an elegant solution. If the statute-of-limitations window is, say, 5 years to claim, then you have that in the treasury, and then you disperse those to fund the security budget after all the emissions dry up. That's actually a really elegant solution.

Speaker 1

What probability do you ascribe to that mechanism actually going into production?

Philip Martin

Probably low, mainly because I think this is just a huge, controversial rat's nest. When the fighting is all over, people will just be happy to be done with whatever simple thing they can agree on.

I think it's elegant, but it may just be too much for people to accept all at once, because you're already asking them to accept a lot of changes. I think it's relatively unlikely, but I agree with you: it's a somewhat elegant solution.

Speaker 1

One follow-up to this: say this is actually viable and gets traction. How would you think about the period in which holders can upgrade? You don't want to be too slow—the pace is sort of a function of how quickly you think we're going to get to quantum state, right?

If it happens and you still have the claim period, that could be a risk in and of itself. If you give 10 years, that's probably too much. If you give 5 years or 3 years, how do you think about that timeframe?

Philip Martin

I think it's going to be less about the timeframe and more about how you get the message out broadly and aggressively. I don't know if there's a big difference between giving 1 year and 5 years in terms of the number of people who are actually going to take action.

It's going to depend, and what we're going to see, because we always see this, is that 90% of it will happen within the first month or something. Then there'll be a super-long, drippy tail of stuff that will last probably forever, or at least as long as the window is open.

The hard part isn't setting the window; it's figuring out how we get in front of everyone who needs to take individual action. For everyone who's not on an exchange or with a custodian—everyone who has a Ledger in their home safe, back in the corner somewhere—how do we make sure all of them know they have to do something?

Alex Pruden

I think one important thing to note is that, in this whole discussion, we've kind of baked in the assumption that quantum computers are going to be so-called slow-clock systems, right? Let me quickly define this, because this was relevant to the Google and Aor Atomic papers.

There's a concept of a slow-clock quantum computer and a fast-clock quantum computer. One of the reasons the Google paper was potentially quite disruptive was that they posited their machine could run in 9 minutes. Theoretically, the machine they laid out, if we built it, could run in 9 minutes.

Why is that a problem? Bitcoin's block time is 10 minutes. So you now have a situation in which, Santi, you put out a transaction—you're doing everything right, and your public key isn't exposed—but now you want to send some Bitcoin to your mom or something like that. I can front-run you in the mempool with a higher fee, right?

Once you get to that point, migration is going to turn into a giant bidding war of fees, if you think about it. I think it's important to call out that I personally believe the fast-clock architectures are going to follow the slow-clock architectures for a variety of reasons.

However, I don't think anyone really knows how long that will be true, and that's really related to the question of how quantum computing will develop. It's kind of an unknown, but certainly we have to ultimately add all of this post-quantum cryptography for everyone to leverage.

Then there's the additional question of people who aren't going to move at all. Maybe that's the first thing that gets affected, but there are both aspects to this, right? It's not just Satoshi's coins; potentially, it's everyone's.

Speaker 1

Impossible to know what Satoshi would do, but I would say he would probably want to see the network live. Are we all in agreement that if we don't do anything, there's a higher probability of Bitcoin fading into irrelevance? If you don't do anything, action dictates that you have to address this, and you probably have to address it within 12 to 18 months.

Alex Pruden

Wait, Santi, why do you think it fades into irrelevance? I feel like the worry is that someone—let's say someone trying to get 10% of the coins—dumps the coins and the price gets absolutely decimated. But I'm not sure it would fade into irrelevance.

Speaker 1

Yeah, I'll say it this way. Maybe I'll make this point. Will it fade? I mean, this is your—we're kind of war-gaming. I will say this: There are networks and protocols out there that see an opportunity to differentiate themselves by having post-quantum cryptography first.

Zcash is one that I think has leaned into this, right? It's definitely a narrative that a lot of folks around the Zcash community are pushing, and I think there's a lot of truth to it. There is a sense of opportunity, I think, from other protocols, and I don't think that can be denied.

But let’s go to that extreme, Yanni, because I actually think it’s a good question. What happens if we don’t do anything? What is the status quo? If you don’t do anything, between 10% and 20% of the supply could potentially be accessed by someone, and they dump it, or I don’t know what they do. As soon as those coins move, it will wreak havoc. Once that is sold or whatever, in my mind, that’s probably pretty detrimental to the network. But I don’t know if it survives—maybe it does. I hadn’t thought about that. Philip or Alex.

Philip Martin

Yeah, I mean, that’s certainly the fear, right? There are two things. One, there’s the obvious economic impact of selling that many Bitcoins. But two, there’s the impact on the trust of the network, which I think is actually the threat—the long-term impactful thing that happens. And I think it’s just really hard to know in advance what that impact will look like practically, right? How much trust is lost and breached there? Does this mean that institutions can no longer touch the asset? And, if so, what’s that going to mean for the future of Bitcoin? Those are all open questions.

Speaker 1

5. How Does DeFi Mitigate Hacks?

So, I was going to say, Yanni, this naturally takes us to DeFi because, for me, these are protocols that have more freedom to upgrade, but they have probably challenging issues in their own right. Some of them don’t have as big of a security budget; they have way more surface area. I go back to: Is the solution, I guess, in all this discussion, given what’s going on with quantum, with AI, and stuff like Methos[?], are you on the spectrum from super-ideological to more permissioned, with more controls and guardrails? Has your position changed one way or the other? Because, Philip, you said something important: Ultimately, Coinbase wants to protect your customers. No one likes to see these $200 million, $300 million, $400 million hacks, and every year we kind of have close to $1 billion in customer funds lost going to Lazarus.

Philip Martin

Yeah, I’ll jump in quickly. Look, Santi and I have known each other for a long time, and you may remember that I got interested in this space working in the Middle East with Syrian refugees. I think an aspect of cryptocurrencies that really appealed to me and led me to want to work in it was the ability for people who didn’t have any other option to transact, save, or transfer their value out of a war zone, out of a hard situation.

There’s this element of financial freedom that is just a really powerful part of the narrative that has brought many of us to work on this. That said, the freedom cuts both ways. As you just pointed out, it’s also freedom for North Korea to fund its nuclear program, and there’s nothing we can do about it because, again, if we wanted to do something about it, then we would basically revert to the exact same financial system that maybe excludes the people that I wanted to help.

Again, this is a tough philosophical question. Practically, though, ultimately we live in a world of nation-states with sovereign governments, and I think it’s a little bit optimistic—maybe overly optimistic—to assume that there’s just going to be some super financial system that every government agrees to be a part of and doesn’t want to try to control in some way. A government—the US government—could throw me in jail if they want. But the Ethereum network can’t really do that to me.

For that reason, because we all live in a world of sovereign nation-states that can exert the rule of law over their borders, I think you’re inevitably going to see more permissioning. What I think that also implies is you’re maybe going to see some fracturing across geographical lines for these various systems at some point.

Alex Pruden

I think that’s right. I think that’s exactly right. I also think that people are always going to write insecure code, right? It’s just never going to stop. They’re going to write insecure code, put it in smart contract code, and toss it onto a network somewhere. Where that starts to become a problem is where there’s real value in that protocol, right?

So, how do we get better at not preventing people from writing bad code, but flagging it when it gets on a network? We need to make it very clear to people who would interact with it: Hey, you might want to tread carefully here, because this is—whatever the problem is with it—vulnerable, new, untested, or it’s a rug pull; it might happen, whatever.

That, to me, has been very interesting because I don’t want to live in a world where we have a bunch of heavyweight, permissioned DeFi blockchains. I don’t think that’s the spirit of crypto. I don’t think it’s fundamentally going to result in a better system than what we have today. But we do need to make sure that we can cut down attacks. Losing $1 billion a year to these things is just untenable.

Speaker 1

Might there be a nuance where I think of crypto as lowering the barriers to entry and the switching costs, even though you are not fully permissionless, but you have some guardrails? Look, USDC and Tether both can freeze your assets, and the consumer just goes to where the most liquid coin is, or the coin that has the most brand. There’s a very small subset of people who actually truly care philosophically.

There’s a whole subset of people who are unbanked and don’t have access to the dollar, and, for better or worse, the dollar continues to be the most sought-after store of value. But if people are going to—if we agree that digital systems like DeFi are interesting to people because they make it more accessible—you ought to layer in some way more protections. Way more, because the end user is unsuspecting. It’s just not as sophisticated, and the threats are only going to increase far more than the end customer can catch up to by leveling up their OPSEC.

To me, that always forces us back to: If we really want this industry to grow, you have to assume that people are not going to level up their OPSEC. Just assume that you’re going to get hacked, and work backwards from there. And that takes you to a more permissioned system, right? Where you can, to your point, Philip, freeze stuff and roll it back.

Alex Pruden

Yeah, no, I think everything you said is right, but I think there’s no one-size-fits-all, right? A lot of it really depends on exactly how much, and who, and what, and how important.

I still like to believe that even—I mean, USDC is kind of a good idea, or a good example, in the sense that, yes, they can freeze your assets, but it’s by exception, right? You have to basically be proven wrong. The way bank accounts work is kind of like you have to prove you’re not guilty to get one, basically. Whereas, to freeze assets, these issuers, practically speaking, do it if you are guilty.

Even though it seems like a small difference, I think it’s actually quite important and impactful, and it’s one of the reasons why you’ve seen stablecoin transactions really take off. So, I think that’s an example of how you can kind of have a best of both worlds, potentially.

Then I just wanted to point out one other thing, which is that we’re still in the pretty early innings of people really interacting with finance via cryptography, right? Obviously, the cryptography we’re going to use is going to change as post-quantum, et cetera, but I still think there’s a lot of really low-hanging fruit to improve security on the UX side.

One great idea that the Ethereum folks came up with was this concept of account abstraction, right? You can basically separate authorization at the chain level from authorization at the wallet level, and you can create much more complex authorization flows that maybe are a bit—maybe that part is semi-permissioned—but what you do for your grandmother could be different from what someone who is an entrepreneur somewhere wants to do.

Speaker 1

Yeah, I know. There’s a whole bunch of flavors of this. It doesn’t have to get baked into each app necessarily, and it can get baked into these various wallets. I mean, that’s a broad generalization, but I’m confident that we will continue to get better as a space at this—or I’m hopeful, maybe.

6. Are Stablecoins At Risk To Quantum?

Alex, you guys dedicated a whole section to stablecoins, and Philip, I think you guys didn’t focus on that as much, more maybe focused on just the industry and Bitcoin in general. I’m curious why—curious how you guys think about stablecoins in terms of the risk here, given what you’re talking about with quantum.

Alex Pruden

So, I think first off, as we move from Bitcoin to everything, I want to be clear: I don’t think every system has its risks, and I don’t really think one is better than the other. I think they’re just a different set of risks, okay? Stablecoins are permissioned, or maybe less at risk from a quantum attacker, in the sense that money sits in a bank account.

And so a quantum computer can't reach into the bank account and manifest the dollars in someone's hand across the world, right? The bank account is safe. What is at risk is potentially the on-chain stuff. So what would happen, potentially? Well, you could do the same thing you would do in Bitcoin or another network, which is steal someone's USDT or something.

But I think the real challenge for custodial-style stablecoins is these admin keys we're talking about, right? Those are definitely critical infrastructure and potentially could be nation-state-level targets. If you had a quantum computer that you weren't even looking to steal Bitcoin with, but maybe wanted to mess with the US financial system—especially as more and more dollars go on-chain—that would be a way to create chaos. Given how much DeFi there is, and one of the big selling points of DeFi is that you have transparent contracts all over the place, interconnected, you take down—I mean, it's just like we saw with the Kelp DAO hack that you're referencing, Santi. The Kelp DAO bridge got drained, with ripple effects across a whole bunch of other DeFi protocols.

I think you can imagine a world where, let's just say, someone mints 300 trillion dollars of USDT, or USDP or something, and then breaks a peg somewhere. There are a whole bunch of ripple effects that ultimately maybe won't have a real financial impact, but they could still be incredibly disruptive and cause the loss of billions of dollars of value. For those reasons, we think of stablecoin issuers as having maybe a unique—or maybe I'll put it this way: I think there's a special urgency for them to consider how they're going to protect those keys from a quantum attacker. So yeah, that's my view. I don't know if Philip wants to add to that.

Speaker 1

I feel like that's the thing that's great, and I totally agree. Yeah. Philip, maybe from the Coinbase view, what are you most worried about? This idea of Bitcoin, or just running an exchange, or stablecoins or DeFi—on-chain stuff? What are you most worried about?

Philip Martin

Gosh, the answer is all of it. That's the honest answer. Fundamentally, my job is about protecting Coinbase and our customers. My focus is always going to go first to how we make sure that Coinbase, from an internal systems and practices perspective, is ready for this well in advance of there being any risk.

7. ZKsync Ad

As a person who's been in this industry for a decade as of last week, I really care that the blockchains evolve to get this right and make good choices and good trade-offs—not just in terms of the cryptographic algorithms they choose and how we deal with throughput, but also how we do all that while retaining the core philosophy that makes this space not just bank 2.0.

Speaker 1

8. How To Secure Your Privacy

I'm going to pull up an Elizabeth Holmes tweet here. I didn't think I'd do this on this episode, but I do want to get your guys' take. This is more of the personal side of things. Elizabeth Holmes, for people not watching YouTube, said, “Your search history. Delete your bookmarks, delete your Reddit, medical records, 12-year-old Tumblr—delete everything. Every photo on the cloud, every message on every platform, none of it is safe. It will all become public in the next year. Local storage and compute.”

I think this was in response to a more Mythos-level model being released and maybe open-sourced. Philip, I'm curious to get your take on this.

Philip Martin

So this is hyperbolic.

Speaker 1

And this is hyperbolic?

Philip Martin

Yes.

Speaker 1

Why do you say that?

Philip Martin

Two things. One, Mythos is a huge model, right? That requires an incredible amount of resources to run. It is not practical in the next 12 months, in my opinion, that we're going to have open-weight models that are runnable on reasonable hardware. Now, we will eventually, right? Perhaps this is a question of timeline rather than destination.

I think models like it are going to favor the defense versus the offense. I think that's true because, as a defender, I have so much more context on how our systems work than attackers do. I think that's going to let me get a lot more out of that model than an attacker is going to get by pointing it at an API endpoint and saying, “Go forth and now,” right?

As these models become more accessible, you have to make the assumption that there's a reasonable security team on the other side, right? So maybe the non-hyperbolic version of that tweet is: make sure you know who your counterparts are, where your data is, and where you do not believe them to be good custodians of that data. You should absolutely take action to remove your data from those hands.

Speaker 1

Yeah. Alex, in your personal life, do you do things that maybe the normal citizen would say, “That's a crazy level of precaution”?

Alex Pruden

I used to work at a privacy protocol, so I obviously am passionate about personal privacy. I do a number of things in my own life. I run a bunch of stuff locally instead of relying on services that some people might pay for from the cloud, for example.

But look, I think the other reality is—read the Elizabeth Holmes tweet—it's just not possible. First off, it's not even possible to delete all of your data. How do I even get it? People have written whole articles about these data brokers of people. I had a security clearance when I was in the military, and my fingerprints were stolen, I think, in 2011 as part of the OPM hack. So how do I delete my fingerprints that were stolen in 2011? You just can't, right?

Moreover, we all lead increasingly digital lives, and to Philip's point, I think he's absolutely right: We need to be responsible about who our counterpart is and where our data is. But I think there's also some degree of acceptance that some part of your identity is going to get out there. This is why multilayered security architectures are just the best way to go, right? Theoretically, if you have a failure on one layer or a breach of one system, it doesn't break everything else, or it doesn't mean all of your accounts are therefore pwned, right?

So that's probably the most practical advice here for anyone: multifactor authentication, no single point of failure to the greatest extent possible, and then minimize, if possible, your exposure. There's just no way you're going to avoid all of it, probably.

Speaker 1

9. What's The Timeline For Quantum?

Can I push you both to get a little more specific on the timeline? Reading both your papers, I think you might disagree on this, right? Philip, in the Coinbase paper on the timeline, I think you said it was largely irrelevant, or maybe not as important. You actually used the words “largely irrelevant,” whereas Alex, you had a 2029 optimistic case, 2033 as kind of the base case, and 2042 as the pessimistic case. Can I push you guys to tell us: When does this really matter?

Philip Martin

The reason we say it's fundamentally irrelevant is because this process takes such a long time, and we have so little clarity that it doesn't matter to me if a quantum computer shows up in 2030 versus 2040. We have to start the work today. In that sense, maybe having a definite timeline is better from a motivating-people perspective, or it gives us a goal, but in my view, it's like trying to chase a date—a red herring.

Alex Pruden

Yeah, I don't think I disagree much with that. I actually think part of the reason why we put timelines in our report is partly because I think it was to push people. There are 2 reasons. One is that I think people are kind of lazy a lot of the time with their estimates for these things, and they're just like, “It's 20 years away,” because it's always 20 years away. That's as deep as they ever get. I think the reason why we put these predictions in our report was that we have these various aspects of the analysis that we try to rigorously distill into a real timeline.

That said, I think there's a lot of uncertainty, as Philip mentioned. But I think there's an aspect of wanting to show people that there's a trajectory for quantum computing to develop, and the question is how quickly we will go along it. The other piece—and I think this dovetails back to Philip's point—is that there's a great framework that I really like called Mosca's inequality. Michele Mosca is a quantum cryptographer at the University of Waterloo.

And then one thing he points out is: You can’t just consider the timeline for the attacker to get this capability; you have to consider the defender and how long it’s going to take to prepare for that attack, right? And so you have to consider both things together—you can’t just consider one in isolation. Echoing what Philip said, I don’t think there’s—just to be on the safe side and not end up in a scenario where the attacker has this capability before we’re ready—given the uncertainty here, it probably makes rational sense for everyone to start preparing today. It doesn’t mean we have to panic, but it means we should start preparing.

Philip Martin

Yep, exactly right. In my experience with this, once you start throwing dates around, you start to argue about the dates.

Speaker 1

Yeah, and that just—fundamentally, it doesn’t matter. The discussion is about what to do about it. Is there going to be a ChatGPT moment? What’s the ChatGPT moment for quantum going to be?

Philip Martin

I think it’ll probably be in the simulation space, where we will see, somewhere around drug discovery, something like that will be a use case where there’s some element of useful quantum supremacy shown, as opposed to the toy stuff that has been shown so far.

Alex Pruden

Well, I may have a different take. Maybe we’ll have to agree to disagree here. I think you’re not going to see it. I think real quantum development, from this point forward as it pertains to cryptographic relevance, is very likely to happen behind closed doors. The Google paper even hinted at this.

In fact, the short circuit—they explicitly didn’t reveal it. They proved in zero knowledge that it only consisted of X many operations. They explicitly said this is because they don’t want this knowledge to be out there for the world.

If you look at the funding for these quantum companies and look, practically speaking, they sell services for optimization, and there’s some other stuff. The vast majority of funding for this industry comes from the government, DARPA, and the equivalent agencies around the world. I think the vast majority of money going into this space is for cryptanalysis, and obviously that capability is something that the funders of these things would ideally like to keep secret for as long as possible.

It’s not that I necessarily think we won’t see evidence in the simulation space or otherwise that there’s progress, but I just don’t know if we can count on it. I think there are also a lot of reasons to believe that it’s possible these thresholds get crossed effectively behind closed doors and we never know that they do.

Speaker 1

Yeah, I agree that’s absolutely possible as well. Just going back to something that we touched on, the security budget factors into the timeline a bit too. I don’t want to make this whole pod about that, but I think it’s quite a bit of a threat. How does Bitcoin continue in the absence of block rewards, and what’s your guys’ take on that?

Philip Martin

My personal view is I tend to agree with you. I’ve always kind of believed that at some point, 50 years from now, when mining is truly unsustainable, or there’s so much demand from data center and AI-type use cases that, obviously, below a certain security budget, you’re not going to have the same trust that you would want for a system that you claim is digital gold.

I think the natural solution is just to tag on a tail emission, have inflation as a percentage trend toward zero over time, but maybe have a constant inflation. That way there’s a way for miners to plan. That’s obviously controversial in many parts of the Bitcoin community.

I think ultimately it’s not going to be for any of us to decide. Unless this quantum thing ends up being part of that, but assuming that doesn’t happen, I think future generations of Bitcoin are going to have to grapple with this. It’s hard to say, but I kind of agree with you that ultimately the trust we have in Bitcoin is dependent on the security budget.

Either you have to assume that the coins just keep going up in value and the hash rate stays the same, or you have to assume that there’s some continued emission. You don’t really get both. However that happens, I guess we’ll just have to wait and see.

Alex Pruden

I don’t disagree with any of that. I think the original theory was there’d be enough value in the fees at that point that they would take the place of the block rewards. But I agree with the assertion that it’s very important to Bitcoin’s continued transability.

Speaker 1

As we get to close out the episode, what is the best way for Bitcoin holders to follow what’s going on? We haven’t talked about Taylor. We’ve talked about who matters here, but who are the folks that haven’t been as vocal that you think are going to play a bigger role going forward?

Philip Martin

In terms of how to stay abreast of this, I don’t know if there’s any one simple answer to that question. What you’re going to see from Coinbase going forward is a lot more about the quantum risk, both from a technical perspective, like the paper that we released, as well as from a nontechnical perspective, and really talking across all the chains, right? Not just Bitcoin, because the whole ecosystem matters.

But today, I don’t think there’s a place that anyone can just go and be up to speed.

Alex Pruden

Yeah, I think a lot more people are starting to talk about this, which is great. I want to particularly call out Coinbase and the work that Philip and his team are doing. They’re leaning forward into this, whereas a lot of other exchanges are not.

For example, they have this Quantum Advisory Council consisting of a lot of really impressive folks. They’re doing research on this topic, which is amazing, and I hope that encourages other stakeholders to do the same. Ultimately, if we believe in the philosophy of decentralization, to some extent, it’s incumbent upon all of us to contribute. I think Coinbase has just done a really good job leading the way here.

10. Fidelity Crypto Ad

Obviously, Project Eleven—this is our whole MO. People can certainly read up on a lot of what we’ve written. I’m encouraged that the dialogue is starting to really take off, and I hope it continues to. I think people shouldn’t shy away from this topic; they should embrace learning more about it. It’s pretty dense, but I think it’s one of the most important topics of our time in crypto.

Speaker 1

Before we drop, do you think Satoshi’s coins move?

Alex Pruden

I think no. Maybe I’ll say this: I know there are people building quantum computers who may be interested in it, but they view it as lost treasure, right? There’s this idea: Is this lost treasure that we could get?

Whether or not that’s a good legal theory, I think there is discussion about that, and I think that’s sort of why I don’t think this risk is entirely in the abstract. I think people have to grapple with this as a potential tangible risk, and therefore we need to account for that in our planning. So I don’t know, but maybe.

Speaker 1

Cool. Philip, Alex, thank you guys.