a16z crypto|Aug 25, 2026 15:53
Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens?
In this new lecture, Stanford cryptographer @danboneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing.
The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired.
00:00 Why blockchains need to prepare for quantum computers
03:05 Why Bitcoin may bet on hash-based signatures
06:25 The “big footgun” in stateful signatures
08:58 A quantum-safe signature that takes one billion hashes
14:13 Inside SLH-DSA’s virtual tree
20:30 How Bitcoin and Ethereum could make the switch
23:48 What happens when a wallet loses its state?
32:47 Can threshold signing survive the quantum transition?
36:39 How to hide lattice cryptography from the blockchain
38:49 Why threshold one-time signatures seem impossible
45:36 How context prevents forged signatures
49:37 The forgotten idea behind Winternitz signatures
54:50 Turning one-time signatures into threshold signatures
1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks?
1:06:26 Abandoned bitcoin and Satoshi’s recovery problem(a16z crypto)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink