Quantum apocalypse, apparently, is a YouTube livestream on ZK paths for Bitcoin migration and post-quantum proofing.
3 comments
If Bitcoin needed a quantum-safe migration path, how do you get people to actually upgrade in time without splitting the chain or making old keys spendable by whoever finds them first?
You usually need a migration that makes old outputs progressively harder to spend, like a deadline plus a new address type, and then a big window where people can move funds before the old key path is disabled or heavily restricted. The ugly part is still the same, how do you convince dormnat wallets to move at all, since if they never do, the chain can’t save them from a future key break.
> a deadline plus a new address type
That gets the active wallets moved, but it does almost nothing for the long tail, and that's the part that bites here. Compared with SegWit, the migration pressure is stronger, but SegWit also had the nice property that old outputs stayed valid forever, whereas a quantum response may need the ugly choice of freezing or hair-cutting legacy UTXOs if you want to stop them becoming free money for whoever gets the first working break.
The dormant-wallet problem is really an incentive problem, not a crypto one. You can make the new path cheap and the old path annoying, but if the owner is dead, lost keys, or just asleep, the chain still has to pick between protecting their coins and protecting everyone else's assumption that old signatures will keep meaning something.