<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>0xberil_</title>
        <link>https://paragraph.com/@0x5ed6f668e541108399fEfDaef7da4e9E32902B46</link>
        <description>undefined</description>
        <lastBuildDate>Wed, 26 Aug 2026 18:40:26 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>0xberil_</title>
            <url>https://storage.googleapis.com/papyrus_images/0bc8747e2758ce89144cee386333441e6baa4b9128419a34665f15916ea9c9fe.jpg</url>
            <link>https://paragraph.com/@0x5ed6f668e541108399fEfDaef7da4e9E32902B46</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[congrats, your ai agent just hired a scammer 🗑️]]></title>
            <link>https://paragraph.com/@0x5ed6f668e541108399fEfDaef7da4e9E32902B46/erc-8004</link>
            <guid>AGUgKWem9ZuaPTyvWGxL</guid>
            <pubDate>Thu, 15 Jan 2026 19:54:39 GMT</pubDate>
            <description><![CDATA[your AI agent just paid 50 USDC to another agent for portfolio analysis. turns out the agent is fake. took your USDC, delivered trash, gone. congrats. nothing stops this until there's trust infra. ERC-8004 launches tomorrow, january 16 to fix this. let's see if it actually works.]]></description>
            <content:encoded><![CDATA[<p>your AI agent just paid 50 USDC to another agent for portfolio analysis.</p><p>turns out the agent is fake. took your USDC, delivered trash, gone.</p><p>congrats.</p><p>nothing stops this until there's trust infra.</p><p>ERC-8004 launches tomorrow, january 16 to fix this. let's see if it actually works.</p><h2 id="h-the-problem" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>the problem</strong></h2><p>we have all the pieces for agent-to-agent coordination:</p><ul><li><p>Google's A2A for messaging</p></li><li><p>Anthropic's MCP for context</p></li><li><p>Coinbase's x402 for payments</p></li></ul><p>agents can talk. they can share data. they can send money.</p><p>what they can't do? verify literally anything about each other.</p><p>your DeFi protocol's agent needs portfolio analysis. finds another agent offering the service. how do you know:</p><ul><li><p>it's not some dude running a python script from his basement</p></li><li><p>it's actually done this successfully before</p></li><li><p>it won't just take your USDC and ghost</p></li></ul><p>right now? you don't.</p><p>you either trust a centralized platform (lol), manually check every agent (doesn't scale), or just take the risk.</p><p>none of these work when you're trying to build an actual agent economy.</p><h2 id="h-enter-erc-8004-three-registries" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>enter ERC-8004: three registries</strong></h2><blockquote><p>in August 2025, Marco De Rossi (MetaMask), Davide Crapis (Ethereum Foundation), Jordan Ellis (Google), and Erik Reppel (Coinbase) got together and said "let's standardize this."</p></blockquote><p><strong>the solution: three onchain registries.</strong></p><p>at its core, ERC-8004 extends existing agent communication protocols (A2A, MCP) with three lightweight onchain registries:</p><ul><li><p>Identity Registry: gives every agent a portable, verifiable identity</p></li><li><p>Reputation Registry: records feedback from clients who worked with the agent</p></li><li><p>Validation Registry: enables third-party verification of the agent's work</p></li></ul><h2 id="h-identity-registry-prove-you-exist" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>identity registry: prove you exist</strong></h2><p>every agent gets an NFT-based identity (ERC-721).</p><p>the identity includes:</p><ul><li><p>agent name and what it actually does</p></li><li><p>communication endpoints (A2A, MCP, whatever)</p></li><li><p>wallet addresses across chains</p></li><li><p>which trust models it supports</p></li></ul><p>this solves discovery. before ERC-8004, finding agents across different platforms was impossible. now there's a global directory.</p><p>portable identity. survives platform shutdowns. can't be censored.</p><h2 id="h-reputation-registry-prove-youre-not-a-scammer" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>reputation registry: prove you're not a scammer</strong></h2><p>after each job, clients leave feedback. 0-100 score, tags, detailed data.</p><p>catch: only clients who actually worked with the agent can review. the agent pre-authorizes feedback through a cryptographic signature.</p><p>no spam. no fake reviews. only real transactions.</p><p>feedback lives onchain. permanent audit trail. can't delete it. can't modify it. reputation becomes portable capital.</p><p>agent builds good reputation on one platform? takes it everywhere else.</p><h2 id="h-validation-registry-prove-you-did-the-work" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>validation registry: prove you did the work</strong></h2><p>for high-stakes tasks, reputation isn't enough. you need cryptographic proof.</p><p>validation registry supports multiple methods:</p><ul><li><p><strong>crypto-economic validation</strong>: stakers re-run your job and risk their stake on the result</p></li><li><p><strong>zkML proofs</strong>: zero-knowledge proofs that computation was done correctly</p></li><li><p><strong>TEE attestations</strong>: trusted execution environments verify the work</p></li><li><p><strong>trusted judges</strong>: for subjective tasks that need human arbitration</p></li></ul><p>ERC-8004 doesn't force you to use one method. it just standardizes the interface so everything works together.</p><p>choose your trust level based on the task. ordering pizza? reputation is fine. managing $10M DeFi position? maybe get that zkML proof.</p><h2 id="h-how-it-actually-works" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>how it actually works</strong></h2><p>scenario: you're running a DeFi protocol, need treasury analysis.</p><p><strong>step 1</strong>: query Identity Registry for agents tagged "DeFi analysis"</p><p><strong>step 2</strong>: filter by reputation - 90+ score, minimum 20 completed jobs</p><p><strong>step 3</strong>: check Validation Registry - which ones have zkML-verified previous work?</p><p><strong>step 4</strong>: narrow down to 3 qualified agents</p><p><strong>step 5</strong>: connect via A2A, negotiate (70 usdc, 24 hour delivery)</p><p><strong>step 6</strong>: pay via x402 micropayments</p><p><strong>step 7</strong>: receive analysis, verify quality</p><p><strong>step 8</strong>: leave feedback onchain.</p><h2 id="h-x402-the-payment-layer" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>x402: the payment layer</strong></h2><p>x402's been all over CT lately. pay-per-request micropayments for agents. not gonna explain HTTP 402 history again.</p><p>what matters here is how it composes with ERC-8004.</p><p><strong>where ERC-8004 and x402 compose</strong></p><p>the full agent stack:</p><p><em>discovery (ERC-8004) -&gt; reputation (ERC-8004) -&gt; validation (ERC-8004) -&gt; payment (x402) -&gt; feedback (ERC-8004)</em></p><p>all the pieces exist. communication protocols (A2A, MCP), identity and reputation (ERC-8004), payments (x402) - everything's composing.</p><p>all the layers the agent economy needs are finally working together.</p><h2 id="h-the-risks-because-of-course-there-are-risks" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>the risks (because of course there are risks)</strong></h2><p><strong>1.reputation laundering</strong></p><p>identity is an NFT. NFTs transfer.</p><p>scam scenario: agent does simple tasks for 6 months, builds reputation to 95. sells the identity NFT. new owner uses it for fraud.</p><p>victims see "reputation 95, 100 successful jobs" and trust it.</p><p>solutions being discussed: reputation decay after transfer, operator change flags, clear warnings. not standardized yet.</p><p><strong>2. security stops being optional</strong></p><p>agents holding budgets become targets. software exploits, but also physical threats. wrench attacks already happen.</p><p>agent controls 10,000 USDC budget. who holds the keys? human operator? they're the weak point. fully autonomous? software exploit risk.</p><p>quantum computing in a few years? current cryptography assumptions break.</p><p>solutions needed: spending limits, anomaly detection, privacy-preserving transactions, time-locked withdrawals.</p><p>not nice-to-have. required.</p><p><strong>3. sybil attacks</strong></p><p>bad actor creates 1,000 fake agents. they hire each other, leave each other glowing reviews, farm reputation.</p><p>three months later: 1,000 agents with "90+ reputation," all fake.</p><p>current mitigation: filter by client address reputation. reviews from new wallets? suspicious. reviews from established protocols? more trustworthy.</p><p>not perfect. established wallets can be bought. cat and mouse game.</p><h2 id="h-the-honest-take" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>the honest take</strong></h2><p>the trust problem is real. agents can't coordinate at scale without identity, reputation, and validation infrastructure.</p><p>ERC-8004's design is solid. minimal, open, composable. the team is strong. the tooling is coming together.</p><p><strong>but will it actually get adopted?</strong> tbd.</p><p><strong>do centralized alternatives win?</strong> OpenAI launches agent store, everyone uses that instead?</p><p><strong>is UX good enough?</strong> normal users won't touch this if it's too technical.</p><p><strong>does the economic model work?</strong> micropayments sound great until you're paying transaction fees on every interaction.</p><p>some verticals make obvious sense:</p><ul><li><p><strong>DeFi</strong>: validation necessary</p></li><li><p><strong>API orchestration</strong>: complex workflows where agents hire specialists</p></li><li><p><strong>compliance/analysis</strong>: niche services where track record matters</p></li></ul><p>these could see early traction because value prop is clear.</p><p>for everything else? we'll find out.</p><p>the infrastructure exists now. six months ago it didn't.</p><p>maybe ERC-8004 becomes the standard. maybe v2 iterates and wins. maybe something else emerges.</p><p>but the conversation started. the problem is recognized. solutions are being built.</p><p>tomorrow, we'll know.</p>]]></content:encoded>
            <author>0x5ed6f668e541108399fefdaef7da4e9e32902b46@newsletter.paragraph.com (Beril)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/1b5ed6af70c2011455cc1ebeed089e1d7adc2f65ad59b07403a9c98f0ebf8434.jpg" length="0" type="image/jpg"/>
        </item>
        <item>
            <title><![CDATA[Can Quantum Kill Crypto?
]]></title>
            <link>https://paragraph.com/@0x5ed6f668e541108399fEfDaef7da4e9E32902B46/can-quantum-kill-crypto</link>
            <guid>DwBQLDw8DpNrQPr1xZmS</guid>
            <pubDate>Mon, 24 Nov 2025 19:01:24 GMT</pubDate>
            <description><![CDATA[TL;DR:Google's Willow chip just crossed a 30-year threshold. We're at 105 qubits now and millions needed to break crypto. Vitalik Buterin sees 20% chance before 2030.$40B/year being spent globally on quantum research; breaking ECDSA estimated to cost $10B1-4 million BTC (20% of supply) directly at risk due to exposed public keys, including Satoshi's coins. ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR:</strong></p><ul><li><p>Google's Willow chip just crossed a 30-year threshold. We're at 105 qubits now and millions needed to break crypto. Vitalik Buterin sees 20% chance before 2030.</p></li><li><p>$40B/year being spent globally on quantum research; breaking ECDSA estimated to cost $10B</p></li><li><p>1-4 million BTC (20% of supply) directly at risk due to exposed public keys, including Satoshi's coins. Requires controversial hard fork to upgrade; "ossification" philosophy makes changes difficult</p></li><li><p>On the Ethereum side, public keys have been hashed from day one, only exposed during transactions (narrow attack window).  Account Abstraction enables signature upgrades without protocol changes, and only 0.1% of ETH supply is vulnerable compared to Bitcoin's 20%.</p></li><li><p>Beam Chain is planned for a 5 year timeline, targeting quantum resistance everywhere by ~2030. Ethereum is already working on upgrades for BLS signatures for consensus, blobs with post-quantum commitments, and Verkle trees using Poseidon hash functions.</p></li><li><p>Quantum isn't killing crypto today, but upgrading blockchains takes years. Protocols that can adapt will survive while rigid ones face existential crisis, and the real race is on: who builds a scalable quantum computer first, and will crypto be ready?</p></li></ul><h1 id="h-part-1-if-bitcoin-dies-crypto-dies-with-it-really" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 1: "If Bitcoin Dies, Crypto Dies With It" Really?</strong></h1><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/a9191e1e130796630948d730483b8d81cea5ca46ff3f5c9a8cf4a06702ee7fd5.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAgCAIAAACO148VAAAACXBIWXMAAAsTAAALEwEAmpwYAAAKBUlEQVR4nC2UW1DTBxbGTy5cAvmHBELu9ztJCCEJCZBwCZArJNwJQUJogJCkCRKUYKsEBAGtgpSgyEaMSltXu1pqrdXdqe46uu3abqe7StvZ7mz34uzOvnR2ZqdP+9CduDtzns7Db775vu8cmLHTZl3shS7BSidz3mt48d3ff/zPj99//8P8iHOulbbQypgxlybqyZN6QlRHiOgIQS1iYaBdLFQ3B9svwvqlhWPlBWPlyEEt/qCGEKooHJYXwEKvcHlAstIvOReQLQ0b//bdP374/t+vR4ONakmtQjhslsw5GMlm6pSR+H+uluBgY7o42H5Brlec65fhImp8tBIf1yGTOiSiLhiRF8CiR3x6SLY+rNqJaFcC9c+e/Xn+8JS8FKUT0NScUlOlYsgsnW0iTRtJcQMhpkeiVYiTi+nhYgeEuV5hrk+aH1EjBzWFcR0SNxCilfhgeQEs9gqXPeL1oCodLl/01378+KvM8ckv1wNfbE7uxlqblbzWWlminpSoJUWr8LEaQlSPtLLRvVy0V4z18LEDorwxFRLTIHEdMlVdFNMQQsqX0BN9ovWgajusXPBXf/GHf97YWLyT9N5ficac1cMmsd8oP97CntTjQ5X4iA6ZrELaOJgeNqafj82ihbmjSlysEj+pxU/XFMU0yLgCB8e7uUvel9Bo+fxg1dcv/vXxjbcyr7Y9ODF++8TEuq8h5TGl2suiOlxEg7yqRSaq8E42upuF6uNiu1ioPgE6IMuPqvExTVZpVI0fl+fDbDvrhIe/GpBvh+SzHt0vPv/L/pMHv18NZKLdT9+cSPmMywcaZhpZh/WFETU+XIlEtcj/oN0sTAcT08NF+yR540okqkYm9UhEjc8G9bqLnezkrnjFZwe5wTrWwslzt259+NN4V6rPnIm2vjGgd2r5OBQ08HKCClwwy80q7WCi3Qxw08BNxwwIc4NyXLgCf1CLH1cWBGQF8LqbPW2nHbHT5hzkXhlhuNvZ0dE5aK769FTg9Jgt2ig8POQFyAUAVi4ckGDHVDgbA+1moNpo4KBkp4+L9ctwo3JcVIOMKHHDklw40sqYslLiZvJMA9GjJNRpywGgv290YyoUMnGvL00/+OgLAU8MAPk5SL+GE1Dk2+hoFw1lJ4O1BFrI0MFADwjzfOKcYDkuoCgYFOVA3E6dslBiJuLBaqSyFAWAAoDE9OnLKyunB1s+e/T8ya++odL5AFAmYPaaNH1CjIUKTjI0vSS2lICLCn0ctJePfUWG80tzvQIsTFhoE83UUA1hspFfwWeT8ASLvtrq9K0nlw4P+e+8/8nc7BqTwROwqExqUb1KVicsqSNDMxnMZDAXQ0Mx2ErATYceFmpQhPUKsT1sDATrKEFTUdgsaNJVcGlEg7LMqFIX0yRh7yvvXtn58O79iYlDt2/ffvjw4dOnn62tntndvfr509/8/N5HTawiAxaMBWAmgpMCLjr08lA93GyAMFhVNGIgNMiopSXEarlYymOSyeRStqy2vHJtMZlOX/T5hs+ePpXe2kptpF5LJCYnJs6unlk/tVLPpxspefVUpLkYXLTs9HBRLgY4aQBuGa5dkuPQyQxlsnBvd61KsbWx9tcXLy5lMl/t77+3t/f48eNnz59/+8c/bW+nr+5effZ8/8knn2Yymf2vv/nd8/1b7+3VlWJtxWCnQBcHrKVgIQOYKGAkQ3e9qVYut1epmrUVQ+7Wnq7exgbreGDE1mzp6/WEA77pV0c8HW1drbZkPDzh93QZtRPerglvZ6TLaaaAmwWdbFQXF2OjgaUUQFsANYWgJ+braAW1NGxtEUaNAj4AF0CCAhMeqnHQxkeNmUThprID0rxBMQzL0XETMi5HBWQQ0eTNORgnOniLLt5CK3fKVBozlkJ1ITQVoWoJ0CgodgiIRgLKWAjGQlDnQ10pyiPC9Ynyj3nMlzZPn1qcXRlxzTbT5hzMk92CBQdn3s5ccvPOesQbPumGr+xNn/S4k5N0csGIB1sx2kRCO5X0TiXVTEYb8dllZT7UU9A+Sb5Xy7z/3l46fdHV0X179/IJj2beSTvTK15q4y46OMvtvA2f7CdjFVujmu0x9Zk+6ckeCZiLwFEC5mJsj4btq2JZqDmNBDARoAoHLbScobLC+Wjgkyefrq2u6nS65ePHb20mlzrYa/3SVY94tU+8PiBJ+eU7UcPFWO1OuOqcX5V6RZ2FOsloczG2W8Mc1rPt1BwLERoJYMCDjYE+bJV9cGM3fXEnFo0qFAqNTn/z8ubbCcdqH2/TK9n0y7YCyq2A6lKsOjNRtxs3XYxWp2PV0FSEeakU06OhDesZDjrGSsq6XFMIdg6kxt3bG+vVNTUqlYpIJALA0GDvndOjKb80HapMh7U7WVzN9aTznWO2mwvOt4807840QWMR2lGMqidBn5oyXEW1U7NQCymbVSsPs+w1Pbz7/ur6utFoZDAY4Ujs+pXtm8sHdiZrLh80ZuI1mUTD1ZnGa0nnu8sde8vt147aL880ZO2zk6COAL0ayrCO4qBi7MXQQgRDAbTxcydNrBvrc48ePbp37146vZ1MJt9NHdudac5MGTJx426ibjfReCXRmDnccGOxbW+l89qs7a0j1mwTLaRsVXvKyUMaso2MshRnz1lfAA5u3rAUe24m/OThL1OplM1mPZaYur4cPD8q300YL4xr0+GqnVj11amG9JTx2rx9b6lt96jl6hFLFtdEBD0eOuSkAxVEawm6hQhmJNv5Vi6mW4gN+QPf/varm9euHT2S+PjOhzaTdtLJ25nQpfqFmx7eWr9oO6hJxwzvJK23llp3Z8yZaXO2/I0EVBUe3BL8gILQUoJuKoT6AtAhUMEklYvFlZqavZ/d3f9y//4Hdx8++LVcJi8mEnVlnFYtK9RIX3zZ062Q5vKRxptL9ouH6tNTpqx3JjxU4cEhQrolBHMRqIswLAqJxaKxeQKFolIilh2aOnYhdSGTvrK5mSmTltHpLBqdzWTzKXS2VU3fGBRtBJRbUf2NZPOFaM35iAF0uOxP1BWClV/gEuKNBOCUFNPZbB6XJxQK5VK1TFze0d63cGxu8djc8dk3xGIZi8lhMplCnpDF5AiYJSc6eRsj8lW/8u3XzJtB3fpYZfYca3CgxoGZne/g4XR4YNHpPJ6IzxOUyZVSsVIhr2yos7icbrvVGg4dEomkJWQyg0Hj8YRcDg+PzwubGVsh5UlfWSZuOBtQnfErQZUD+lxQ5kIdPcdCz5EQoEypGB0dGx0Zb2/vDIXCkUjM7xtJJGaOHk3GJxOBwKjL1T44OOjz+TraOwFyXJWl58cUZwLKi3H9SZ9i0SMGGYAKA2IUGErRJjJwkRwKjcbhcERCiUQik0vVCoWmTKGxW62Ho9M2m1smKxeLpAKBUCgUcdh8NJbQICOdH1OsBcrP+stm3fzZdv5/Acmm+BSZr25BAAAAAElFTkSuQmCC" nextheight="1268" nextwidth="1116" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>For the past year, one question has consumed the crypto ecosystem: </p><blockquote><p>Can quantum computers one day destroy Bitcoin, Ethereum, or all modern crypto?</p></blockquote><p>The question isn't new. But in the last two years, it's reignited in both academia and on X. Why?</p><p><strong>December 2024:</strong> Google CEO Sundar Pichai announced Willow, a new quantum chip. "We've solved a 30-year challenge," he said.</p><p><strong>November 2025:</strong> At Devconnect Buenos Aires, Vitalik Buterin, referencing Metaculus predictions, said he sees "about a 20% chance of a cryptographically relevant quantum computer before 2030."</p><p><strong>Scott Aaronson</strong> - a theoretical computer scientist with 20 years of experience in quantum computing - <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://scottaaronson.blog/?p=9325">wrote on his blog:</a></p><blockquote><p>"Given the current staggering rate of hardware progress, I now think it's a live possibility that we'll have a fault-tolerant quantum computer running Shor's algorithm before the next U.S. presidential election."</p></blockquote><p>So quantum computers are no longer the "distant future" of science, they're a topic strategically affecting the sector today.</p><h3 id="h-google-willow-panic-button-or-milestone" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Google Willow: Panic Button or Milestone?</strong></h3><p>Scott Aaronson calls Google's Willow chip an "engineering milestone."</p><p>What exactly happened?</p><p>For 30 years, we knew in theory: if you can make clean enough quantum bits (qubits), you can correct errors and keep the system stable longer. But it took 30 years to actually demonstrate this in practice.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/39e0f8a96081801e13596ffce821a1d5d40fbdf9f799de5d77ea30097565ad2d.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAASCAIAAAC1qksFAAAACXBIWXMAAAsTAAALEwEAmpwYAAAGQklEQVR4nIWUa0yb1xnHXzC2wfZ79Z3XjuPra2P7tV98ibk1NgRCGlKSgqFOzcXcEtPBsBmBWIAxOCYQi5aGBBzj2ImTkkBIk6yjkVJllyZVtU77sKYXqZkUae02aUo+dFq+MhnSbd/2109Hev465/8cnUc6AJ1OL6DR8vKA/Lx8+v9RAZ1ewGDSCwuZTCadwXzlMpjMHQp3yLkFNFp+HvBKHJTPYMMwxmNxIAazkE6n02j5+Xl5/wstp/ydlbZzfLfc3Qb8N2tHBTQak8WGecUiXSV5yA+MjEdOTcUEEqWWsmsou0StL5ZrRFKFAN/DE4kRLh9BMQiGORDE5oB0JiuPxixisTkQBEIozBViIilfqsUJh6as0drQX9c77z59I5h8Etl4Eb+/nXi0DcTPX9z69WcCiaLrxIljno6y2ga9w2lwuMiKGqPDZXC4jDmcRodLSVU2eTyRmdNveHptde017sBhX6RpaNkbutk3+0kw8adQ9vupjeeRjRexey9nNn+M3v5n7M5LQKRQFSs1Bxvd67e33l/JtPsDEoKUEJSEIEvsVSX213bTVVRVi9f7QXbx5triaHj8iMdf3TxwqH28aWDBHbzsDa33RO/7Fx4Hk09Opb+bWPthcu0fUzefz2z+CKjMJomGOOL2PHj4eOvBp9n1u/HzybHJ2ckzcXPFgRJ7ldHh1Fgq27t92cy5tevvJldjm5sXly4s1Db76zzBxu6ZpqGl1pGML3zXf+7hzxb/EEx+PX79WSj7l/Hs36ZuPge0lEmm1R5sPHZj/c76rY86/IEDje5W38mTwxM210GdtUJrrezo6UolYqvJ2Orq3PKFSDp1Nrkaf3956bB30OUONvfPtwyttIXWeqO/9Md/+87iF6Hs07GrT8cyz0JX/goQJKk0GpWkibBYdbZyDWVXGCxCVUljndNkdaipCk+bN52cTSVi6dTstavx1UQ0m5lPp87d2lyNnJ1rG5hq8IVbhxa9w+nO8K0TsY/8C5/+IvlkOPnVcOqb0ct/BjSkUWk0KM2kiixVm60ayqamyuxO13ygbeb0zwlblZqq6OnvvpaZu3QxspqILi+FM6nZ5QtTa9fPL7wXP+odfO3YQHXLqdd9seMj6e7IZk90a+jCF4M5/hhY+RJQGfRKvV5pNKjMlJqyERa7TE/NTQ5mFkPb/3qSWZlv87S0tjT39HenE9HLydjyUiSTmr2WORuLhVwNrftqWroCZzYffnvp9u87xlJvjaS7wrcG4g/88Uf+hcf+xc8BhU6n1OsVRoPCaFSRFrXZqiKtvtaGYMfR33243N3lcR2o1VnLCUt5eCqw9O5kYin8QWZucipgc9Uaymv2VR/tDUT//nL76YvtDx898w4nj49eOTF9pyu61R190HfuN8BegtjtIdcbFEaTkjTJ9aVWW2mVrWSgx6O3V+7V2whLudFeqaIcweGTVy5Nh8eHzGX7CUuZqWy/1Vn/urtvdGbl1OyVsfj68eDS2yPJvumNvujdzulf+abv5xrI9blXUplNKrI0NwnKJlNrEAQsxou11L7cVEjbzvBtVbW1za1N5rIqNWXXlTp01nK9ff8hd9fkfOJi9uMzl+4d8U2/+c57naGrnRM32ic2OsL3ACGOC3FcIC4WisVCsVggEnGFYp5AgCAQxsV4QiEmeAVPKEJ4AjbCRwVCgRgXiHG+GBdJZCKpkieWY2K1VOswO49Za7zVbw7WeSca+xfdwTTAgUDwFVAOGAJhGIJhNocDQiCMojCKwSiGoFgRjGhVe+ocOvkeHEQxhMuDMS6MYlKFxv1We8vbPntlDQ9XCaVakcwokhtFCrNEWwFAMATtJP4HEM7dHcdFfD4XQZFdE0ERuURUv0/jq6danUa5RAQiCIJiMMYtlimd1fWH3nCX76/n4hq+VCdWkAIZyZOZeDIzwOGwOBw2CIGcn2CDIIqifD4X46Jw7h/NmQiKVJcq623q6lLlYYfGaVby+VwYRdgcmCghR0YnPG09zgOHBeK9XJGchxNcnMDEaqxYA7BYhSwOu4hVxOawWT/BLCpiMBkMJqOIxSpks7gYopIKS9W4nZDaCamjROYokWlkYgiGC1mgVK462T/U2dtPWspAWACiQpgrhvkSmC9FBHv+DRyl3RjePZPuAAAAAElFTkSuQmCC" nextheight="720" nextwidth="1280" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Willow contains 105 quantum bits. And for the first time, it proved something: as you scale up the system (use more bits), you actually get better performance. That means crossing a critical threshold.</p><p>But - and this is an important "but" - this still isn't enough to break ECDSA.</p><p>Breaking ECDSA (the encryption Bitcoin and Ethereum use) requires millions of quantum bits. Willow has 105. So there's still a massive gap.</p><p>An analogy: the first airplane was the Wright Brothers' plane that stayed airborne for 12 seconds. It was important, but not enough for transatlantic flights. Willow is like that - an important step, but not yet at the "crypto is dead" point.</p><p>So the question is no longer "is this possible?" but "when will it happen and who will do it first?"</p><h3 id="h-how-much-money-is-in-this" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>How Much Money Is in This?</strong></h3><p>The estimate shared at the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://q2b.qcware.com/conference/2024-paris">2024 Q2B conference</a>: globally, about $40 billion per year is being spent on quantum research.</p><p>If you want to set up a serious quantum experiment today, you need to put a few hundred million dollars on the table. This is no longer a university lab thing, it's the domain of tech giants and governments.</p><p>To build a machine that can break ECDSA - Bitcoin and Ethereum's encryption? Steve Brierley's (founder of quantum company Riverlane) estimate: <strong>$10 billion</strong>.</p><h3 id="h-so-when-will-it-really-happen" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>So When Will It Really Happen?</strong></h3><p>Three major figures in crypto have three different answers:</p><p><strong>Adam Back</strong> (early Bitcoin developer, Blockstream CEO): "We're 20-40 years away. No point panicking now."</p><p><strong>Nick Szabo</strong> (architect of pre-Bitcoin digital currency projects): "Yes, cryptography will break someday. But the real danger isn't quantum. It's government regulations, bans, pressure. Those are much closer and more real."</p><p><strong>Vitalik Buterin</strong> (Ethereum founder): "There's a 20% chance before 2030. That might sound small, but upgrading a blockchain isn't like updating a browser. Years of testing, community decisions, risks... You can't just say 'we'll deal with it when it comes.'"</p><h1 id="h-part-2-what-does-the-quantum-threat-actually-mean" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 2: What Does the Quantum Threat Actually Mean?</strong></h1><p>The impact of quantum computers on cryptographic systems has been debated for a long time. But these discussions often stay at a surface level like "will Bitcoin break?" The real issue is how durable the mathematical structures securing blockchain protocols today will be in the post-quantum era.</p><h3 id="h-current-blockchain-security-model" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Current Blockchain Security Model</strong></h3><p>Both Bitcoin and Ethereum's security today relies on elliptic-curve digital signature algorithms. On Bitcoin's side, ECDSA (secp256k1); on Ethereum's side, both ECDSA and the BLS used for validator signatures.</p><p>With classical computers, getting from a public key to a private key would take longer than the age of the universe to compute. That's why there's no risk to ECDSA or BLS today.</p><h3 id="h-shors-algorithm-quantums-cryptography-weapon" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Shor's Algorithm: Quantum's Cryptography Weapon</strong></h3><br><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5f19a813c87a96e9fd7dfe05a807c970714a5f2f205be95b6b2e8ac277d37a72.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAALCAIAAACRcxhWAAAACXBIWXMAAAsTAAALEwEAmpwYAAADtElEQVR4nE2TTWgjZRzG34uIF6+uR08eehEV9OJlQUHsRZFe9KQoKCgiuIIfXdwtKIK4LlVRwe6S0qy1267V7TZNJ2az02Y6bZKZyXwlk8nHzJvM5M3M5HNmmLwziWQj6MNzev4PPIcffzC9r0kUTqIwxOMoCoPAj3DouSOOLTi2PZ1OQoyj2RVHGE+i8H4SRlE0DsZBMMYYDwZ9plDo9rrT/ynE4SSagOl0MokizzE9x0SNsnBGVvj8AEHPafVNzbOahioXabJIk5rMz2uB5zUUTVf1bDpLk3Q2TUlcyWrZLbX50uOPLgDw5ENgAYCDzfh0OgXdTnNgG8HQcRGUmPzO1s34+sbO9jafP/O7yHNMS69yZxSdJthjwlBLlq5GGGcO7924Hr+9s8fleEMze6jfs4aNcu0R8J9+ubQ8G9Crksiedg1N4ZnE3p2NWGz92jVV5CxdhYpgaxX+jMod3Uv+eUsvFW2tIuZPLITyFLMdW+Po3NlxntgnUomUKlXbTfuZcw+cA+CJh8FjAOz9tjUbaNZLIksjvdbRK+nk3t7uzubGeo46gookM1Q2nTz+O5FNE5nkHV0R+6bmNGuwrjE021KbQ2tIk6eZw8yv3/3A5/hJNPn+4oXXn1vYjf38xdtLHaPrDl3g9e2x27MNGFtbu3z5y5WVr+LxGwrPeJYxQJC4fWv/j5u5o4wqcgPU9Kym55g4GIusxOV4IS/kqAJJkNuxzQLNdKAlseLq8kdXP//gYGu9Y3Q91wOdkWU6pu8gF8GeoaGGgqryHKY7Q226VqsuFHiatHT132Q4slp2G7Z7qM9QzNULnx78uFYT1YEzwB5eeee19185n00kho7vDkcgzaaTBQL7I9QoS/kslT44IvYLx3fnMy6Cp2TqiNg/ySQ5KmPpqt9FgedZLbsDOxW5dumzi4tPPfvJ4qv83Wz6kHr+/JtPv/DGe2+9iz1saKbv+iDDZTYTv2uSeEqm6jJbE1mZoRkqo3B5TeKgInA0WRVZTS5q8gwyVIRKWWlDVBbVv3YTq9+uLr24+M3Hy8HAW71yHYAHX176UBAqdstqQ+S5PjjMEQenyWDQ00tFVJVRVdZLxSJNlhi6LhSUAn2SSmgSC0tFWCpadcWzmu5wOB/gGUlkJfaElbiSIlSyKerK1z8JObEqqYZmmvX2DLLpmG2nE+FxGLhh4M/dbulQa1QrZVUp11Q18Gcn7I+wP5rVcOi7Pg7w3FCDSllRykq9Wuug9uy9/cB3fd/1Qxz+A+IXVtO3SAFwAAAAAElFTkSuQmCC" nextheight="361" nextwidth="1032" class="image-node embed"><figcaption htmlattributes="[object Object]" class=""><strong>Classical vs Quantum factorization:</strong> Shor's algorithm provides exponential speedup over classical methods, making ECDSA vulnerable once large-scale quantum computers arrive.</figcaption></figure><p>The quantum threat, as Scott Aaronson explains, comes especially from Shor's algorithm. Shor's algorithm provides exponential speedup on the discrete logarithm problem that schemes like ECDSA and BLS rely on.</p><p>While classical methods require exponential time to factorize an n-digit number, Shor's algorithm solves it in just n^2 steps. This means a sufficiently powerful quantum computer could have a capacity unreachable by classical computers in deriving a private key from a visible public key.</p><p>But as we mentioned earlier, for this capability to emerge, a few hundred qubit prototypes aren't enough. You need millions of error-corrected, stable qubits.</p><h3 id="h-grovers-algorithm-effect-on-proof-of-work" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Grover's Algorithm: Effect on Proof-of-Work</strong></h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b384299365a4a5ea1d0823253dc2169afc4c09230779275d004b5d1bf143ea6d.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAASCAIAAAC1qksFAAAACXBIWXMAAAsTAAALEwEAmpwYAAADmElEQVR4nJ1Vf0wTdxR/k02jZIvzR9zENIw2Dtpo5KAlvRUp2xDBIiYabTQaXShhOITEhfIHFcQ/lOnKRoiJOPGiDqPRlIAxGGKj0EqhEIeJGhQUWeh6Fg5Lb3fl2y/c0t4kbkGv8f3x8s33++598j6f9+6BEJ1hjP0RY1mWYRiMcZQfwry3s4IQwjgUyYIxno1cdrtcN9vbGxoaHE5ngGWFSIz4hFAIoVC0ABjPYDwzdxYEgf7L8/TxQ4yCFeby1NRU/yTz54tno8+HZmfCr28Gz50lKngxRh+pO1dTT3Ec397ljltPxifrln9JFJSZGYbRZOUr1Hol+Y2p/OiYd3xkzFt5qvFkY7NYsQTABMMMDw01XbZBrBw+Xetw9uaZDkN8GhA5oNAZTGZ3/wAQm0H5Nai+BZnmNHW1/uzvELbl7v6BgN8vARCcng7yfHffg+StB9T533npicKKE5CgXZiSDXJyZ4nFS7+M1eSCKhM2ZEGSvrWj87bDHafblmH83kv7RNKkKXrNKRYEobCyFhK0McRmSNDuLqvmOH6JOgeSMsIYifrr7XdEtd+WZH4AjLGPmfIxk4IgFFX+BHJyUVoeKEgRYLE6F4jsBRoDKP8FGH81NcVNz0YDwPPBEJq23+v7kNj0SdqW0TFPQcVxkKnhCw3Ea3aVVnm89KLUHICVAKsgXt3a0XnD7oBliphE0jfffMwj8pPBwfOXbfDZOpCl3O1yGUsssIaAj+Jg9YY8U3m3yx1DZAMsBlgCspTfLl3/tfEiwAr4XHXP5fZLiiyaj5m8YLt1qbUjTJHlJMjJWG3+fyhKTAdlBiRubL3teOUPULZbto6uqNpUFECsVPQFFccjIoe7aHdZdYD9OyyyKvMDIhuS9NciGszFS1MkCjU86imuOvXD0boQxsVVVlCQC9W5oNDt/fEYx/EfpxlAlbmA2ARK/c07PcOjHmPJkdLqn99n0DqdPdsLzbA6OdyXa1Ky9h1y9faDSg9yEtbqQKZuvHjtlzMXIoO2tNf9h/Sghf9xCLkHHmXtKzWYymnfeN25K9odRQaT+StjcU39+QlmMmf/Yf2eksy9ZenGg86+B50999ONB3eVVtG0T5qi/4nBcVyQ5xFCHMdhjBFCon/T3pFBAmBkZMRisVit1ra2NoqiWlpampqaKIpqbm622+3Hampqa2utVitN0+8JIAiCuGS4iLEsK/oAyyKEGIYR98+7l88/3oA1uGK2pNgAAAAASUVORK5CYII=" nextheight="1080" nextwidth="1920" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">Unlike Shor, it only offers quadratic speedup, making it less threatening to proof-of-work systems.</figcaption></figure><p>Shor's algorithm is very dangerous for ECDSA because it provides exponential speedup - it shrinks the problem astronomically.</p><p>But the algorithm to be used for PoW (Grover) isn't that powerful. It only speeds things up by a square root.</p><p><strong>A simple example:</strong></p><p>Say you need to try 1 million combinations to break an encryption.</p><ul><li><p><strong>Classical computer:</strong> will try 1 million</p></li><li><p><strong>Quantum computer: </strong>will try 1,000 (√1,000,000 = 1,000)</p></li></ul><p>Good speedup, but not that destructive.</p><p>Also, quantum computers still bring a lot of "overhead." Error correction mechanisms are so heavy they eat up that speedup in practice.</p><p>In conclusion: For Bitcoin mining, the quantum threat isn't as urgent as signature breaking. It's a much longer-term issue.</p><h3 id="h-what-is-q-day" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>What Is Q-Day?</strong></h3><p>"Q-Day" is often misunderstood. It's not the day Bitcoin or Ethereum breaks. Rather, it represents a threshold where signature schemes considered secure today could practically become vulnerable to attack.</p><p>As Vitalik Buterin emphasizes, this threshold doesn't mean chains will collapse; but it shows that the transition process to quantum resistant alternatives for structures like ECDSA and BLS needs to begin.</p><h1 id="h-part-3-bitcoins-existential-crisis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 3: Bitcoin's Existential Crisis</strong></h1><p>Bitcoin faces a two-front war against the quantum threat: ECDSA signatures and PoW. Both are at risk in different ways.</p><h3 id="h-ecdsa-and-vulnerable-coins" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>ECDSA and Vulnerable Coins</strong></h3><p>Let's start with Bitcoin's biggest open wound: 1-4 million Bitcoin are directly vulnerable.</p><p>Where does this number come from?</p><p><strong>Satoshi's 1 million coins:</strong> In Bitcoin's early years, Satoshi mined about 1 million Bitcoin. These coins never moved and use an old Bitcoin script version, the public key is directly on-chain.</p><p><strong>Other lost/exposed coins:</strong> Today, there are about 4 million Bitcoin total in addresses with known public keys. Some are active, but most are lost or forgotten accounts.</p><p>Today, these 1-4 million Bitcoin are worth hundreds of billions of dollars.&nbsp;</p><p>And when quantum computers arrive, all these coins become pirate treasure.</p><h3 id="h-how-long-to-break-a-key" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>How Long to Break a Key?</strong></h3><p>Initial estimates: one week.</p><p>But Steve Brierley's estimate: a few seconds.</p><p>Scott Aaronson said: "It varies wildly depending on architecture. Superconducting qubits: gate times 1000x faster. That's why you can get wildly different estimates."</p><p>If breaking a key takes a few seconds: an attacker could steal thousands of Bitcoin addresses in a day.</p><p>If it takes a week: one big target at a time.</p><h3 id="h-quantum-issuance" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>"Quantum Issuance"</strong></h3><p>Satoshi's coins aren't in one place. They're spread across dozens of addresses, each with 50 Bitcoin. Because back then, each block gave miners 50 Bitcoin.</p><p>Justin Drake has an interesting observation: This could be seen as a kind of "quantum reward."</p><p>Bitcoin's security depends on miners buying hardware and burning electricity. They need to be paid for this. Bitcoin's block reward is declining, and if transaction fees don't rise enough (by 2 orders of magnitude), security needs a solution.</p><p>If breaking a Satoshi address takes 1 day, 50 Bitcoin get "unlocked" per day. This becomes an incentive for quantum hardware and electricity, contributing to the network's security.</p><p>Of course, this is quite ironic: securing Bitcoin by slowly hacking its own lost coins.</p><h3 id="h-to-upgrade-or-not-to-upgrade" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>To Upgrade or Not to Upgrade?</strong></h3><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/d99e17dfff440f1285c6a476629c68511ffce0b05e04c6b8be8d5d83403e5ee7.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAABYlAAAWJQFJUiTwAAAGH0lEQVR4nDWPe1CSCRTFbwYiPnpvmJWaCGopZqZiSommpPlOsDYDFTGttHzkIzUVUEAtET9TxMBqN4MiU1tdKx1TrLQ0oJxtdmbb2ZwU12b3j9pttmb22+lrduY3Z+4f59x7LpjNlmem5cnZxckZy7R5eWbOYjYtGE0Ls3MLM3OWJy8Wxk2LhjnL4xdL0+bfZ8zLs6Ylk9FiNFlmjPNTxsXJmeXJ2eUJ4+LY8zcPjYsTxrcG4/xj89tp09tp07z550UQS+9W1Pc3iG6oyxU9Bed6czNGj6YMcJJuHE67zD+hKKsXNfUVt46UKoZKmgarm+4LhQOS2n6RaLBUNFRZPygV3WwTXmsrRxoqO8USbYWst6hhsLBpqLRpsETaJ267A0jHsE6umc3hvQinmrxXm90dXro7vPJebdpmP7LZRu+3Vc3L0CC3Ll25L9GMy9WTSPNYKzJ68VK/vlE1nid4zAl6yfJ4FUae2Ue9z/TVcQ91NV6WaR4LuwzijlFFzwTcadCMxMcObyTcI9kMbiD0rrPWr7XuX0+Y8nX4wKO+TnTpcMY3MHe2VtXI1RNt6ql2ZEyD3H9wXjrJ8n9CtjNsIY6QbMYdiY+cbZ97Oxj81rT7uamKKy62D4u6DG1aA3Qnc5S2OJUtTmOPV9rivsx2+OuO1h/yqWgXE1XtXTobhIQ6VqUm1zfrWxUDDZWqntOletrWbge8do11twNeY49X2+Mf+NuhTTQUYRiinSqo6y5U1V28YlDqDFBN3aK0xUlxVlKclQSjfqXV05T1aIvvvxIqKqOiiqDXsqjKo/6s6IiUlJRE+s667SS1Pb6NiGshrERscIgNTkXC/1Hkiip3oM2eqCJs7AyjMD2Bf7JaKJZDmdtqBQFXDlAIUABQBCDCWy0UkVH5jk8yyiex+z9V5D9lOzV5lMDdhNDQzYm0FRc24dqJOKHVivMrvlACoN1tgyK7P8kon+son4Qe85KAYweINJ+NMVF0EHpuqF9pdQIg938KAX4q9kGVYe+kge+1uehA+ZI88d1dSc05ThidlBdAUG3FKwi4EqxQPoAA4BZz1edOxvsGyke5P9oR81ERcUsWGxC4ihXlCeWb1+UAHANIB8gC4APwABTBG9+1sy9nhFy/jKCff32q4F+pzqyp4sYGOMq8bVUOX7bzALKxQlkAYmfCYmP4gpKNLo4+kpctacqm+i540VZHRNMgl7SKA5AKwAY4DHAUGxIB1DHOt8/SFQWRP4oTLR1Hh2tZUXRiJnNbvROxFLMdwlSAXWIDNAevn7iY0C1Jq2S4znfwRJl+NB8bZpwPnPRwPrlmbTy2NA4gEiMeQOqDmztPnaulLkvpqDrh7RVuKZfKi3DPsrPiA+SttD6IRb62OQiQjYfRPPeRM25vqv3RnjR9OXNf6NoYjj+cigw9sckpCiAMgIERhlX7gfONReb5V7vv36qwF7UMYbxL2t6N2YfD2V5kNoDUy4OFOcMxDQOQeNv9Uuv6Qen/UbX/t6YodU5IbDgl/hgL0hNjdgHQAYIBAjANAeA7Qk/Sll62y7109wendynYZMYmiPAj5Waz+bGRUdiXwQCBGAEA+wFUTNK4gDpe4G6qDbqURKWvg+hIr8yiNMjhZYS7baYAeAB4AngD0AAOuUJTjBOSsKMzxfM7no+cRy7OYQiKM7PP5guOsbl7d9MAvAB8MbwBQqxAxLRXHfRSJXte5brLkh353wal5rGzq06BoELBLayJS44L37Xdx8GOAuCGheNJwCEDjwr5IXZ5mYE8ecuhzrvpyI0jJXW88zVxaWw3InELgCvA18gBJzgZaJsfal8Tay88HpzVKItGujO6dJDe1pva2Z/b11s2pDulaTxyLiNNkJTA2rPfl0LbsIoC4ALAyDwe3P80SPcstsfAvjSUiGgFPVcLv28VyIvTq7KSDkfv30PbQ3XabgM7AMgAzOw8us4UpDVHDhohVTnM7ZkUP3x6un8g7aYmQS1OUhfm6KpPac9ldxQI6vgJAk68sCVQO03XG0P1U3HqsfybjxoM0/n9tznXW2I1Fbw+Ye4dcbGuJr+9hFfCjUyOZjVfC9bPBd58sufu9H8CPXY8dGye8gAAAABJRU5ErkJggg==" nextheight="450" nextwidth="858" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Bitcoin has a technical solution: migrate to a new generation of quantum resistant encryption.</p><p>But this requires a hard fork.</p><p>One of Bitcoin's core values is "ossification". Freeze the protocol as much as possible, don't change it. Every change raises the question "who decides?" And for Bitcoin, this is an existential issue.</p><h3 id="h-lost-coins-problem" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Lost Coins Problem</strong></h3><p>Even if Bitcoin upgrades, the 1-4 million lost coin problem won't be solved.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/73e1adcf19c76c9d24d3cd6e1fee75909673408e0f1b4b425562810104673c99.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAATCAIAAAB+9pigAAAACXBIWXMAABYlAAAWJQFJUiTwAAADLklEQVR4nK1VS2sTURQ+KxciLlWkoqJQFHwgiH/AhRtbqVo3irgQN66tdGEXSmx8LBRtqWBRRKy1UrBFweKrbYy2NGqbtDE2mcm8MplM5s5Mk5n0TidXZqZMk6aIr49hOFzu3O9855zvDpCVYLsg/wPgR6qq8UJGURRs4dlUaiYexxjb/4YqgmwuF5tJcFlJE4QWWN918BAhZKFUsv4BVQReZQghiKKaAC7AmjIhXDar6vr/KZFPoKbTxwAuw2Ylne4+eSoxMuJIwfjvCcpuJGTEyNcpihcVV0H7xvrwrduNAEOtraptzySTuq5b+M9QpaBoGPm8Yi7YajrtEGyon+i61wAwHAi8aWu7Ub/P1DRP5h8rMAzTa4htLZaoCSBYt2O8o7MBIHT9xuVVWxsBdJ7/S4IfsymkOtnNl0rlGoLR4LWb2/c0AeiC4Dfj913iEMymKE3XxawUCo8nKGapB3fuNAC8CwSCdTubABDLMpJEc5yF8QLGFsbeLGI38IruB1U9iMbiSFWd7NxC1Sq47hJIk1OXYFPf6TPO+MqyViwuuMeVCfGn3rIsR5z3+Ao8x1aOqdfk8Y7Owy6Bp4APhxsBrqzexk9MBHbt/zE0lEMoFo1i7Dif5TjDML5NTiqKMmeatCjiWqN5tPlk8oSr4NPdu0cAPlwN3tyyuxkgHQ4fB7i998Bwe9Bb7znafBHWUqFQG6zrP3su8uDheYBo3/PpgYEXLS1FhKp84AFb1pymjvX3M5GISNOjjx4rLBsdHvkyOFhEKPS0l4l8lRgm3PuskJcjL1997unVc9n397tTH8NC/Pvbji7Est9eD4096ZlDqFzjZIcrm5NZSbbtciyRlDXnnqB40SaEz4i8nCfEWddME6nqdJIihDC8wDj77QRFFywLIXWaov0hqy4RISzH84JICNE1Pa8ofmNommU53sLWzPcEUtX50vxkbNowzDTD0gxLCOGFjJzPE0LErGQYZtWY+rmznDCbov1Dbbvsrdu2rbpG4YWMlJP9DaVSic842VR8svReQUHBMH7toMXr1v1zzBUKlYt+L5edsLxEv0Mg5eRoLK5UFPAX+AkQeUMjfVkGlAAAAABJRU5ErkJggg==" nextheight="786" nextwidth="1328" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">Nearly 3 million BTC have been inactive for 10+ years, including Satoshi's estimated 1 million coins. These long-dormant coins with exposed public keys are the most vulnerable to quantum attacks.</figcaption></figure><p>What can be done?</p><p><strong>Option 1:</strong> Do nothing. Leave coins as they are. Whoever builds the first quantum computer wins.</p><p><strong>Option 2:</strong> Freeze coins. Make these addresses unspendable through a fork.</p><p><strong>Option 3:</strong> Burn coins. Delete them from the system entirely.</p><p><strong>Option 4:</strong> Prove ownership with seed phrase. Freeze coins until real owners show their seed phrase.</p><p>But option four doesn't work for Satoshi. Because Satoshi probably used randomly generated keys without a seed phrase system. Today's 12-word system came later.</p><p>Every option interferes with property rights. For Bitcoin, this is hard to accept.</p><p>The emergency intervention for a software bug in 2010-2011 was very different from today's Bitcoin world where Michael Saylor and institutions have invested big money.</p><h3 id="h-mining-and-centralization-risk" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Mining and Centralization Risk</strong></h3><p>Grover's algorithm only provides square root speedup for mining. So it's not that destructive.</p><p>But the real risk is different: first-mover advantage.</p><p>Justin Drake's analysis: "If only a few entities in the world have scalable quantum computers, these entities can mine much more Bitcoin than everyone else."</p><p>Eventually, if everyone gets access to quantum computers, mining difficulty automatically adjusts and balance is restored. But the transition period is problematic.</p><p>No single entity should ever control 51% of the network. But there will probably be a "first mover." Among those who follow, there could also be big performance differences. Maybe 10x, maybe more…</p><p>For a few years, there could be a single dominant power.</p><p>What could this power do?</p><p><strong>Scenario 1:</strong> Control the network cheaply. Get all mining rewards, but adjust difficulty so you don't burn much energy.</p><p><strong>Scenario 2:</strong> Establish a transaction fee monopoly. A policy like "pay 3% per transaction" (like Visa). Or 30% like Apple.</p><p><strong>Scenario 3:</strong> Decide to kill Bitcoin. First, open billions of dollars in short positions in the open market (there's $40 billion in Bitcoin derivatives today). Then attack the network, block transactions. Attack cost: $1 billion, gain: $100 billion.</p><p>Of course, these are just theoretical scenarios.</p><h1 id="h-part-4-ethereums-5-year-master-plan" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 4: Ethereum's 5-Year Master Plan</strong></h1><p>Ethereum is in a very different position from Bitcoin. Because Ethereum has been preparing for this day for a decade.</p><h3 id="h-why-is-ethereum-ready-from-the-start" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Why Is Ethereum Ready from the Start?</strong></h3><p>The first difference: In Ethereum, address = hash(public key).</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/7a2130eda2776adf20d59c9739da029297bc236df91281b4daf37b672ecf1214.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAANCAIAAABHKvtLAAAACXBIWXMAAAsTAAALEwEAmpwYAAAC2klEQVR4nI2RMUgbURjHb8jQblmEGxwCGY5ehxuucmDsaR/Uq89qhliEGPC0ocRCxVJo0Q7PuiQmMa1pX1sS9CqKIBKiHVIl6A19hV6hN4S2txwIWbWQJQ6x9Yp3kgarJT/e8D3e+77f4/0pQkgul/N4PIIgIIREUQQA+P1+SZJYlnUKn8/ndrtdLhdFUbekboqiWJYF4AaEUBRFCCHP8xzH+Xw+pwVCyHFcLpcjhFCGYVhNoOu6oigIofFHT+KJhK7rzXQZhnEqqFartVqtalO7AMsm8nAymZybjcWmpqai0ShCKJPJIIQikbFAIBAOh/f3952B5wjq5sbasreO/uDgZ/DueH7j/U6xSAhRbXRdV1W1UCgQQgqFQqVSqT/oRFAulzc3N10uF8uyEEKGYSiK8nq9LS0tHo+Hpmm3280wDE3Tra2tnZ2drkuXb3Z3S5LEcZwgCLIs0zTt9XoFQfDaAABomqYoihBSLpdPBLquQwhDoRBCSJIkAEA4HAYA8DwvyzLP89DGcQwNBR2lKIoMw/j9/sHBQUEQeJ4HAEQiY6IoOkMMwzBNs9mQTdOUZTkajWUX3yGEmuz6m8FFwTZiXzsafzz9bGYGY5zJZKYRIoTUIzzDOYIzqTaKfx0dWZZ1eHgYDE/EE8mFxcX8Rh5j/P3bN8uynNN/i9OQi8Uiz/OhUAgAIIpiwIZhmEGbkdHR4b5+uaNjpKvrDn9ttPf2A9h7X5Im+vqnR+XJYHBiYOCe1B1qb++/cnVqeDjS0xNqbx/u6vq0tWXu7VGlUqlSqWiaZhiGpmm6rpdsNE1zCtM0ye4uTqVezSVxKrWiKC9mY/Ozs5n0/HI229Z2/W365eJrnI7H0/F4FuMsxjiVeh6L7Wxv/6h/UfP8Pj62LOsD+ZJQ1nI7H5/OvUkoa8XPXy8MGWOsqmrxvxRsthrW2vp6ZkFRlpZz+byytLyyutp46ixVVTHGfwAMWk7La9TnbQAAAABJRU5ErkJggg==" nextheight="409" nextwidth="990" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>In Bitcoin, old coins keep the public key directly onchain. In Ethereum, the public key has been hashed from day one. The public key only gets exposed when you send a transaction.</p><p>This significantly narrows the attack surface. For a quantum thief, there's only a few minute window while the transaction waits in the mempool and until it's included in a block.</p><p>If Scott Aaronson's estimate is correct (breaking a key takes a week), then no inflight transaction can be broken.</p><p>But if Steve Brierley is right (a few seconds), then this protection isn't enough either.</p><h3 id="h-ethereums-4-vulnerable-points" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Ethereum's 4 Vulnerable Points</strong></h3><p>Ethereum has 4 areas that need upgrading to become quantum resistant:</p><p><strong>1. BLS Signatures (Beacon Chain)</strong></p><p>Ethereum's proof-of-stake consensus uses BLS signatures. The advantage: it can compress thousands of signatures into one.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/19bf6f50e9e3eb427d4b5f69c875bc691f5adb7276cc3b4a8e12dba602cdb174.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAUCAIAAABj86gYAAAACXBIWXMAAAsTAAALEwEAmpwYAAADMElEQVR4nKVVTUwTQRT+EnsyUbl7IcbICRPjTU6iSf2JgFEwaKlQKYIFwxZZW3RhYwsoanUV2oAm1bSxCQqRixcOJHogkRM9iDEpJhJTTEGrWAgL3TFvt5T+gNT48mXy3vtm5pt5b7YF28gkSRoZGWGMybLMGBsbG2tra9N8xlgkEkn6Xq9XkiS2uSEjluVlxphOt624+DBjLBb7zRhrbxcAbabCmBIMTsrysjazrLRUo7QwFwE6ml5/TDuXrIajo6MFBQWqXixjfgYlp1u2gLIQ/aYocvHhop5uMR5fWoh+i8eXhl+92JO/m7HVH9/Di7H5JFTKr1HzkZmVFfkvN1AYY3Ozkw864b6Hi2fQbEbvHbicNArXUHGS8i5nGlKp3jsYfSMZDDUc19TU1FRbWxsIBILBYJpAJPxe5CHyaDSguQaClSDyaK2HpTIRpiJJ3eTguI5Bnx0pptPpsgUmHHZ0daD+HCxV5Ig8OgXYLDCeSIQiD6c94XR1oOUyLp1OUNNTL+OKsry8qDUgGo1mlujr57deN3z9hEEfjYHnND7rw1AAL57C66aNzpXiWgP6XOszB3148hgfg/64oqgPbL0ZaQKzM+OP71I173bQOPCQdvHcp1DqxBOJQpGn3QUr9UCjXLdI+FEPQlOD6larmzY5Ep4QeThsVNaWS+TYLDTaG2EuQ7eQqLtWIsFKFF+HujPkCFYq0dYCDjvaW1F2hJCseHU5ThyCtQG31IylhrqqsdXlOF5ES7QebC1wW6AHmg/sA625yVEFCndiJ3Bh7RIXK0hMu8deYDtgb85ZQCtRo4EO67xBvoYeEQY9rlZTsltIJJ03qIacmvw3gSsXaK/W+gRsFnq4ri70PyLt1DxnIsqh3mZ6amgLgdmZccFKy6xmmM+uo64ClUfheUAw6NMo81mabLMQQh8CWwhE5z/5B+jV+wYyMeTbYW2AqRLDvl3P3ZnsMzch/OVdcqtsgb+ZrH44zRx3qqQkGeZo2QJKNmT1t37//sK8vLy1P4kNpuUosIHNz80dPHCg3+MJ+P2vh4dnw+H/ucEG9uvnz5N6vcloNBmNVefPT4dCuQv8AcD9IunTeGAPAAAAAElFTkSuQmCC" nextheight="766" nextwidth="1216" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Problem: Not quantum resistant.</p><p>Solution: There are alternatives that do the same job but are quantum resistant. Ethereum Foundation researchers are working on it.</p><p>When the update happens it will become clearer that proof of stake is much more secure against quantum than proof of work.</p><p><strong>2. ECDSA (Accounts)</strong></p><p>Similar situation to Bitcoin, but Ethereum has 2 advantages:</p><p><strong>Advantage 1 - Account Abstraction:</strong> In Ethereum, accounts can choose their own signature methods. So the transition to quantum resistant signatures can begin without a major protocol change.</p><p>Tradeoff: Post quantum signatures are ~10x larger. 10x more gas fees.</p><p>Solution: These large signatures can be compressed with SNARKs.</p><p><strong>Advantage 2 - Automatic Transition System:</strong> A smart mechanism is being considered: When the existence of a small quantum computer is proven (small enough not to be dangerous yet but enough to say "quantum has arrived"), the system can automatically switch to secure mode. No one needs to decide.</p><p><strong>3. Blobs (KZG Commitments)</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b4edc421529d65ff64bb7b92a6436d9442f03a3d42dce0d3798232124712d578.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAASCAIAAAC1qksFAAAACXBIWXMAAAsTAAALEwEAmpwYAAAD6UlEQVR4nJWUUWjbRhjH7ac8+cF0DRgMfjAY/BjIg0sKYx4YloCghhU08EMS3OGCH5TWC37Qg50IorVqmqx4mUu5siso2HNFMzWT57QzYU47N86DoUljJ3OWaLQKc4hpo26V4xvWFS3JkkJ+D8ed9N33v/v+d2dCp6SpaaeKNyGEVFUFAKTT6WKxmNepVqsIIU3TmtohEEL7rZbRxzFGa3w5GNAWqFarZrPZ4/G43W673W6xWCiKOjLNYEdRthVlt9Go1+sNvT3SURSl0WgY8W0BjCiKeO1lncVSKZfNzjx4kMtm72cy9zOZJwsLCKGrg4OdZ858dPas2Wy22Wwul6ujo8NsNuOOy+VyOBwEQfA8f0hAVdVoNBoOh0mSJAgiGAxGo9GrQ0MX+j7z9/V9fO6c9/z54StXEELTqRRFUZFIhKbpaDRKURTLfs0wTCwWp2k6EokAABRFqdVq7wX2W/t4a3h8uOaaUXFN097s7cmy/LeqGpvGiSRJugtATee/Uhol2tisBb8cJMkvvF4vofO5Tjgc7u3tJQhiYGDA7/d7vd5QKETTdLlcxuvYb7WyuVylUhmJxwOBQLFYTKfTqqoecc4kyzIAgOd5URR5nk8mkzw/nU6nAAAcx+FfAIDrHPd8eRkh9O7tW4TQ3uvXO6/+HBuixkdGbt+5822iDc/z/z8X7z3QNG1Jp1gsyrKMPsib3d2FmZnvb8ELn16c4L6Z+m7qxo1xLHBMibCmqENRFAAAQrhYWnzx+0r20Wzmh8zj/GNRFFOp1Pz8vFyprD5bevrwx7u3heeVP8TZh7m5R3hl+XweAPAhAUmSsADP84ulxa2XtV9+zQ1/NcxxHMuyNE3fg3BjefnVxtr6ujz70xOE0D0IFUXBiRqNxvEl0rQmQqherwuCIEnS3Fw2PnoLwmxTay4Uyv+8a19nVVUbOvut1tbLvyDMbm228+Ip/f39gUAgkUgIgnCiBwfRtObq6qYoFsbGoCQ9LZVexOOjXu8nFEXNzT37Ofvb9vYOjoSHdwAhPEZAEOavXbvJMKMcxzEMw7IshJBlxyYmxpPJRDI5xbJjyWQSQihJknEicCJBEPL5fFGnUCgAAI4RmJ7OBIOXgsGg3+8PhUKBQICiKJIkg8FLodDlUOgySZKxWHx9bQ2fLuMBxHUrFArlchmbvLKycozJCLXvKrbB5/NZrVafz4eflO7ubtx2dnba7Xa3220ymSwWi8fjsdlsVqvV6XTiSJPJ5HA4urq6YrHYiR4oimI6AZdOT0+P0+ns0XE6nR4dgiAcOgRBLC0t1ev1EwU0TUskEizLMgwDAJicnDSGB5/f0/IvDdsM48ekHtAAAAAASUVORK5CYII=" nextheight="774" nextwidth="1400" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Blobs use elliptic curve-based KZG, not post quantum secure.</p><p>Justin Drake isn't happy with current blobs. Too big, not variable size, blob sharing and packing complications.</p><p>New concept is Blob Abstraction. A smarter, smaller, more efficient system. Both better and quantum resistant. Timeline same as Beam chain (4-5 years) but different stack layer.</p><p><strong>4. Verkle Trees</strong></p><br><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/01e214beb1a2c29cfe1f1d5437d8723be4f513ed3b44e9a703ba67b4882c29bc.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAUCAIAAABj86gYAAAACXBIWXMAAAsTAAALEwEAmpwYAAADYUlEQVR4nLVVXWgUVxS+RRBa3+qDBdtX82IfVKj6YKEKTbSIKKhUmta1iLquhRFiRBxN0od5cQht/Is+pVDEeVCj6SI4ypIXx6wbV5mN8RrJRbO36Wzu/uTM/tyZ7U7ZvesyptF0wX4Mw5mZc+a73/m5F3nNgNfQVAhayKHSsHKz9oa23Ru3tk9R670RcM6zuRyATWlyHE8cPNq178iJaCxOaTI3CwD2goLmJ2CMkRqe46epFCWTE1bKsgt2oZivaarMzub+pMSypiYnXwhPxlgTBOEaYrHozq0rP/4AdYTaJPknVEPg0A+JxPjtP7R1a5Ys+xB1n2iPjcbD4bBhGPOqeasCSinG+IZ2qUPaq4d/165dadvRuufHb/XIHc/z8LPEhV9PnezcHzPujD/DQsF/JRD5oZT6A169fOU6rrABgBAyJwRjPCdkLgHnXKza7+c6Tt6uVjKby5qmyTkvV8oY41Kp6DpOqVQslYrlSlmECxpCiJ+mSsA5z6QzjLFCseC9HZRSVgOl9B1ueTvvTwACgLHE2G9XBtoPtkuyNEEmXMfN5rJQhT2TSp77Rf5ZDj56eA/AHkskTNNkjOXt/LQ1rZ4/c6y7Y0gf4pwDQO/F3n2hvb0XVJGMkQcjAIAYY7FobPv320STXB649Dj+RNO04eHI/fsjg9cGVn++eNlH6PLZ44ODNw3DwBhr2lXDeKBdv4qWVkPWt66Px+O3hm4u+kT8A0VjUV3XNU1jjNVrUCgW0pl0OpP2p49WkXR4gZdgZsYihABAw4FzPm1NW6m/rFR9sNOZNMvMZHOZ+YvsBwCYptnI9d+V6oYBAKIFvGZQJyhXyuLyPI8QgjEGgNqXius4op1Em4pOEzr8Uf9+nEcB5/wdQ98A53wqOfV6BQvgDQJKaTgc1nV9dHTUMAxd103TNAxj0/avEEKrN66KDN9t+WIFQmjt12sjkUgTBEKyyLIYFpEoSikh5LsDe5a3LP9yy4Ynicff7Nr8Wcunm3e2EUJcxxUnhL/yjWOjPgfe/wzkeV5/f7/8Gn19faFQSJZlVVUlSVIURZblYDAYPHy4p6dHluVAIKAoSiAQ6OruUhTl9KnToVBIkqTOzk5VVcVdqkFV1ToBAIhtoHGfYzRs/5uGv98Qm4RIrGiWfwDWFopIXAWldwAAAABJRU5ErkJggg==" nextheight="868" nextwidth="1397" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>This is about how Ethereum organizes all accounts and balances. The current system is quantum resistant. But a more efficient system was being considered that system isn't quantum resistant.</p><p>New plan is a system combining the advantages of both. Both efficient and quantum resistant: Poseidon hash function.</p><h3 id="h-lost-coins-01percent-vs-20percent" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Lost Coins: 0.1% vs 20%</strong></h3><p>Bitcoin has 1-4 million lost coins (20% of total supply).</p><p>Ethereum? Estimates suggest only a few hundred thousand ETH (around 0.1% of total supply).</p><p>This huge difference means Ethereum might not have to make hard decisions like "should we burn or freeze coins?" Social intervention might not be necessary for such a small percentage.</p><h3 id="h-beam-chain-lean-zk-friendly-quantum-ready" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Beam Chain: Lean, ZK-Friendly, Quantum Ready</strong></h3><p>Vitalik's vision: "Quantum resistance everywhere"</p><p>Not just signatures; consensus, data structures, zk proofs... Everything will use long lived, quantum resistant cryptography. The goal is to consolidate 20 years of innovation and research into a single system.</p><p>Justin Drake says the quantum narrative will age like fine wine, over the years. There's no need to rush, getting the Beam chain right is more important. The goal is post quantum cryptography within five years.</p><p>The US technology standards body (NIST) has set a similar timeline: ECDSA deprecation recommended in 2030, banned for regulated institutions in 2035.</p><h2 id="h-part-5-quantum-money" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 5: Quantum Money</strong></h2><p>Quantum computers might not just threaten crypto, they could create something entirely different.</p><p>There's a fundamental rule in quantum physics: the No-Cloning Theorem. You literally can't copy a quantum state, trying to measure it destroys it.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/398b65ce5862c4af9b3a830cd744ea5252c48d65f8a3d82c66c54862d24048e9.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAYCAIAAAAUMWhjAAAACXBIWXMAAAsTAAALEwEAmpwYAAAGeElEQVR4nJVVf2wb1R2/SRWCthISY9K0dn8kqAO0AENhrRap0n4xsa2IgICJFgRtZ6CM1mviJiuIbs2PFkN8jnvXxHYSO4kvcXwhuTR9hdqm3SPN1e1dae6y+hLV5za+RskLJDfFlypJI+eQ75USsv6zj55O7/t9793n3vf7+X6P8HobKMpDUR6apijK09zS1NbeiucrRyDQTNMUSbpWOlea9W6y3v29VYryeL0NRCZzXVGShmHwPI/Q1OlPTzHBwJAkiaKo67qmaQghVVXj8bMp9ZphGAihycmJmZlpXdfnFxbm5m7qFgzDmF9YwHNsKoqiqilCki5DCHVd72bZlta2Xz32yKb1hD/Y3uT3z2azS7mcaZrR2BniB0Rh4Y8oumEpl8stLyOETpwElfv+Vrl3T2c4zLJse2vw1W3PNAcCkiRhDp5PCMIFQlGu8Pygrussy+4vK+8INsV7OoeTyTpX3f533ir5RdHTJb988tGfFRc/UVDwU4Igni7Z8vDGHx93u5x17h2lf+zw0x6KttlsziO1lbtfbQ2FIpEuXdcRQqIoStLl7wg4jiNJF4Rwbu5mIpFo9HrhmTP9PZ+cOxs/WnWYIIi1a9fSnnp+YMBHH+MH/l1TUxuLxQzDoGnabrcDAGazWZZlAQC6rs/MTK8mAADIsgwhxE98+L+zs/MLC6qqAgvJZBLHHSHE87xsAULI87yiKMPDwxBCRVEQQrquryYQRREhdC2dlmVZVVVsqqqqaZqV5Liqpg0ji02c/JmZaYSQZgGHBZt3J+A4rptl7Xb7B4cOkaSLZdn5hYWsMWeaJjgVJQiisPBBF+m5OT+/lMshNBUMBo9R1DGKoi0Eg0EX6SZJF5bfXULEcZzDcaC5yS8J509Ho41e7763/rql6JHfbC4u2lS4ectTmzY9RBDErzcXb7z/Ppqs+9hFVvx9ryScd5Fum82W/6a25p7e3kCg5e5J7mZZX3PLkYNlZdufuz4+SdPUxcT5z09/Jl5I1LtdOMm+huPDQ5fDofbBARhsC+3b9VrYT3d2RQ4ePMiGOyt27zgJTp3o67vLDQzDAACkUmok1B6k3V8ODQEAcsvLs9lsbnl5LJM50dcXi8WuplK3bi3hglIUBedDlmWcWDzH+TAMQ8xDIFKpUQCAz+c7TtNNfj/DdHR2RXw+Hw4rBsMwAACO41qD/wdCoZCiXMnfQBRFrJyxTEbJI6neRsrS4XAikQgG2ziu/87qWCZzNZXCE1VVLb+Cz4yMjKpqfkkUxTyBJEkQfsFxfYMDMBRovigImqZZ0k4wDMPzPG4V69cRxU893BJoNc1lUbzERcKfx+OxWOyTDgZ3GkmShiQpHo9DCIckiecTEMLbOYAQHv3QWbb3Xeehf3gomiRJu93e1JgXX3V1VfX7Fc9ve+bxx39eULCxYMNPXin9s91uP7DHRn780datW//p2IdlWlZeTnvcziO1z5WW+hro2poqlmVvhwhC6HQ6AQBjmQxjodHrbaPdTf58Ysgj1S8++yxBEOvWrd/+0guHKspIkkwmkwAAh8MxlslwFhp9/khrC+1x/auqmgu3tXgb+wGQJCkfIlEUeD6BJYEDei2dxkKWZdk0zYnJSY7rAeDk+MSEaZq4XHE9a9oYFo+qqtMzM/gNCE3hXpIPkUWQrz1c35qmMQyDewB+0bV0WtPG0unrCH311dSUZWrjN27gDbgzkyQpy7JhZL+e/hohNH7jBm7XeZliArwbQvjlpUvRaPzswDmc3sXFRdM0Ifzi3nuIkpInAfjMtIA/KJFIXBQE+UoSt0hBEBMXBesGeWKe579HgH8JNTW17zn2v/7CtvZQ6LjbteuVl/a/vetPv/9dUdFDGzb88P571ux9c2fpH34bDrXdurXkcBx4v7KyfM9um81WVV3zQYXjzR1/OR2NfvvD+R8ChmHc7nphEPrJoz6fr9nbUP7u24ffq3x9+8tr1tz7wAMPvmPbWVdz+LUXn+/pCi8uLjocjk/7+3tDLTvfeKPO5RIGoav2cE9v72oCnk/g4sY3HRkZ/U9SgRDeCZGqqk6nk6apkZFRHCLDMPArrqZS18fHOY6TZXliclIQRFVVDQu3CaxWcZJhOlgLHMexLNuNjRWIxaIAgFVOLNBulj3R14cnHNdzZzUS6crXQSo1qihXBOECHjw/iMcdz7f+czx/bpVz5X58ZOVBSbqcSo1+A7WuX7JsbbOzAAAAAElFTkSuQmCC" nextheight="487" nextwidth="649" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Since the 1960s, physicists wondered: could this create physically uncopyable digital money? Stephen Wiesner proposed the first scheme, but you had to take the money back to the bank for verification.</p><p>In 2009, Scott Aaronson solved this: publicly verifiable quantum money. Anyone can verify, but no one can duplicate.</p><p>The physics does the security work. No mining. No validators. No blockchain growing forever.</p><h2 id="h-scotts-bitcoin-story" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Scott's Bitcoin Story</h2><blockquote><p>Scott Aaronson has an interesting memory from 2010:</p></blockquote><p>"I was giving talks about quantum money. People came up and said 'there's Bitcoin.' I thought: blockchain grows forever, nobody wants that. I never considered buying any."</p><p>He was wrong about Bitcoin's success. But was he wrong about the idea?</p><p>Here's the thing: Quantum money doesn't have smart contracts or programmability.  Just pure value transfer.</p><p>So it's not a replacement for Ethereum. <strong><em>But for Bitcoin's original vision, pure digital cash, no trusted third parties?</em></strong></p><p>Maybe the final boss of digital money isn't even here yet.</p><h1 id="h-part-6-conclusion-adapt-or-die" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Part 6: Conclusion - Adapt or Die</strong></h1><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/b007966bca8cc6c4e28c8e78adfc3970aa431eacedb73623345449f4de385b1e.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAIAAAD8GO2jAAAACXBIWXMAAAsTAAALEwEAmpwYAAALMklEQVR4nE1VeVQTdx4f6z5buwJSK0FUzgTISTI5uBLuI+SaTEIQKyriUTxoQcuhKJciKBAQM4RkQkgclkgs69Yeq+tiLQurEggknEXWWlsqaFvrc622Htk34LZ97/Pmj/nNm8/n+/nM9zOAZfap5ZvfYcXxxLIA6+wT6+wv1tlfLLNP/3Ln5+4fXSnZBe6EIGD5amC51yJe+7MX8Lqn+9vrvIPoBBKNyElmxMMeXjQPt60e7tAS95WA9d7LP+Ls/MvOOdfZedfFHx5g8y7rvRcLeNk19/z8Q5dif00gKwFYsgJY4g4s9cABvAks8SDxUiJFeXGpJ+LiNUywhOC19Q0g1H2Z2G1FHGCdf7GIs/PPu+897Z7/9cqDu1P/7bv7uOuLH+98dP9J55zLOvfccvfZhUcurnjj2350jzVEAFjgWOKxzH0NITDMjy0IZaVH0JG1wTyP1cHLVnuu848L9Kkm+DNeEZybf95x1/Xp9w/vPT777HnTkK3o+vUSl6vu60cffXT/cdfcC8vdXy88cnHEGQDg7h3IWLWestSNsNzT542Va7z8KcH0OK8ACsgo9yfz31pHciP4BoVupLN3gHGZCwRzz63zL7rnn9550vPD/bKLl4qPVuQ1NRwcGCh5+KBq5ud/Xbj/eHGCCFnWn9y8PX1I/gy+f5jAnyEgBDL8GdEUIjOUncoV7GMlZBK5Sd4BDCIzbnUA2Y8hAM7Nv7TOv7DMPbPOPXvw0mofOpyVtTMvN+dgYb4c2nRzumz618Ez37ks3z1ZJFju6ePlT13tSyYE0EIihFS+nCaQg0xKkI9fUEAwicRmRIip0RL8KEJIiRIBXXefdX3367n7rk/uPXzo+vs3M8eOVVaVlR6qLCurLDt8f7ba+eiaZc51bv7F+Z9copwiv9DIwDB+EBgXir9dSuHE0llcHkiN4tB5bJovwdPXJ5AWKaLwxdRoMV0AAQnYYdhae+b29+d/cGE3+zTn8z7+EPmrpcmKqS90Nle054ENmzMtp8989dNnT1zJW3ODeWmsJBUjLp0eqyCHpwSHRTBBZiSHLODz4uMiwznMABIlOCwilJtMj1WExWcAQHY08F48oSIzqHwnsCtesCm5NG9jYZ6qJE9l0hWVV77rrYoAMlnUo9uQqZnYTdkkXiqZn+bLYLOSMoksHmG9N5lBEvBpvCiqII4TzWcSGezAsFgqX0oViMGEDQDADwISKKTN0VCJrLhxJ9qcZ2kvatcVaury2rXFdeU7Q0Ts16RsQBLKqtvLhSSrAgLWMRmrSGtpsRA9XrU+JITg7RZCJxJpAcFUX4kkSioOF8THr6XSVgaG0GIzgO3l73RfqOy7fGKkT3Meq2g+kVdRnN14LO9EaW7Z+1t3bUjbqkgoLdi8NTOp6pNPwtLEAAC86f3W64QVnmvWeK0PXOrpsfR1gBTinyDiU9lkcliQWBqdrhTk50HKDD6NxwW+nTFfvVSPNOU31uQfPpCzJ0eeIY/J2pSU+W6KcFtM/DZ+wm6B7LBIWpT07ofV7CKJjzLUPzNsvYKyVkkmiIkekT5vUb19gggUFjFKwA6iBpHZZJ/Atewo2ubNyYX7VUA3Vqmp2b9vi7S+Kre+ekdV6TtbalWUhuRAjZCFQuwOJcWiJJsgqgkK1qWwO2Bel4p7VgVicLg5PeGEPByBOG3yEETs90Gk4EAitDVRmh4fmxxJCg1asWoFBQwB8o9nq05lyk5CFy8dv+U0jg/rRu2tXZcqcrFtIWohUy8TlkKJTelMM8xDIFAno+kgNiIB2yCWWphYIuEissBWUVb7Zss/qwZsGodd6+xHWg0f8HbH+CUFewd4A3S9NLRVGNwmiWmUnLlQOj2oHxvU3hxCbzkM7Z8eiUbklJqUSFTOMcOEzvSNByPP5INlJ+JD9VCUUUFsFXMbxY2d+21Xm2bshkk7OtKrUXcfiDMqOUaYY1GA1akAz5zOMcJsvYyGiKiatNru/WP9mr6rdTf6Ts2MGC71VG/Btvjr0kCNOKs+taaAe/B4fAoKhRlhoiYtrVZ+8WLNV872keuaKYdhzKbd05Gztk1ERaUgImGbYZ5RCYCYEsRgEFNwzApWizQIER3Ccod61cM2zai9dXrEMDWor7W8H9wkOtoo7C4TpJ5IXGdJJ1cnfdC0bfxG662x9tFB7digbuSaJkefFXVIsvfIHv5RSZgRAjEFVycHOG0KEIU4RhjULdDqZaEt4gMt253XNEP9p522lkkH+u2YWW8t9DLIlA0pIiSNrE5rt5Z8OaCfGEbH7TqnTTPSd3pX+7ag5jT5yU3Sqg08tQg0wSAG8/QwwDYp2HpZGCJhtUhZRpiByUGLYmWV4PCp7ZODrWP21gm7bnwYvWnTFzRnh1XweRXxhrMlMyMG/GgYnRjW3RzSHTDuCGwVMdVCil5ExmSsTiXbDDMx+QKBWQFiMNMI0RAJiEJJyIZYRMXuTCfWJHWdPzLlwDVO2HUTw7qhPk1yWVpxy447o+39VxtHbdphm2agt77OtI+IiDhGmN4oZBlhtknBMcIstZCFysLRBQK2Cb/LNSmoxxJlexVwkYpplFLMcNKRtJFreHqTI+jEMDozZrRf04zadFMOw5TDMGrTjg9pL39azTmaGoYp2GaY26EEUYiFiHFXTLhunl7+agJGp4KMQYFaIbFVxDTLmXoZz6jwKo+p1e370o5e/6Jx4tUc6OiiM3bdtNMwO3WmDM1dV5PAw1X+AXoZy/j/DDiYEtRLIytSs+tz8zUHojQQDRFT1cIoLH19c2pO3cZbTuPnl6tHbBp8DscrgikH+vnFBkc/Ij0k8qtN5GG4ShC/KliojI6IQVQOYjBXL8cJmMeTBDGRhTv3lRQUJJVIyUgaqJOyNFIfdUpmjer2aPuEQz++IHngi1O23qZpp8Fp03Z3lP3twwrGPn5gQyp3QSULkTCMUq5JEa1XgJ2K3wlYKOS3OwLcIQCPJTHbINw0E0w7JfZFRJknVbae5n9faZwc1o1cR3YKKUWboqYchvEh/ZQDHbNpw/Pj/dWpvA4l7okJr5PikyXl+4sFhak42W9fEWhS0IxSJibHV7xFCuqkEZhiVXlM/vEsR39LX0/95Aj6nzFD4W7pezvEX0+Zxu26MXvrt5NnSpq2u5XFRFhUDLM8Si3LyE5XbVYm7ZHSdkQwENGrkNlmmIMpOIsOGmEaImbopAxETCrg/+Ozmq8nzZMOdHIEHR/Upp5sDSrT9fVqZhzomF1/e7z9/IVKj91cPFgzzNbLw5tkxNpE7+o4kloImn6zyAjh7dgiBfWyMBQKqEygNAjfPsSv1O66NWZ02BA8AIfB0X86trI5oEzfc1k9M2aYsONbdnusPeeIcllxJE8voxxLwF3qSA/vSOcubDJOsKgabFtsCwmISMK7MvzUifIjUueA5vOe6ht96olh3aTDMHn9VHJuASlj7+CVummncdSmddq0Nx2GoT4NdEhKqIrnmdNBvZRWk0w6HEuvSQLbZDjBqwwwGJ9xcVlMCvrBhIufHXcOILa+0/Zrmgm7bnIEnXIYrO2HWmp3j9pbJ4d1N3qb7Nc0TluLc1AzNYTKSiVu5TFcnYyiEYWohQuGw3jZLWQgX1hmmGOGmW2Q+z5OI5o3+yWGfyoj6LQDd2PaYei/om5rq0eQ2ksfq2ecePtPOQzOwZbentrRQe1Qv0ZYkLosl81CIU4n/j8AMTlbLwd4ZhUHU3IwJRdTsVBo9R7e4VO7ZpyGUbzI0PFhna3v9OigbtKJ9l5tMKIlaGtxb0/T9JhhfOGBiYWyctq1X022911pCN0W6VuVwMOUHHM6/loU/h+j1HsVp9Q6WgAAAABJRU5ErkJggg==" nextheight="416" nextwidth="416" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h3 id="h-three-visions-one-truth" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Three Visions, One Truth?</h3><p>Adam Back: "Quantum is far away, no panic."<br>Nick Szabo: "The real threat is state pressure, not quantum."<br>Vitalik: "Maybe it's far, but upgrading blockchain takes years, we should prepare now."</p><p>They all agree on one point: <strong>Modern cryptography won't last forever.</strong></p><blockquote><h3 id="h-if-bitcoin-dies-crypto-dies" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">"If Bitcoin Dies, Crypto Dies"</h3></blockquote><p>When quantum arrives, this phrase will probably turn into:</p><p><em>"If crypto survives, it'll be thanks to those who could adapt."</em></p><h3 id="h-when-is-the-awakening" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>When is The Awakening?</strong></h3><p>We're at 1 logical qubit now. Millions needed for danger.</p><p>There will probably be a "game of chicken": ignore, ignore, ignore... then panic.</p><p>What could the first signal be? Maybe an unexpected movement of Satoshi's 50 BTC address.</p><h3 id="h-crypto-isnt-dying-its-evolving" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0"><strong>Crypto Isn't Dying, It's Evolving</strong></h3><p>Quantum isn't today's crisis. But it's a stress test that will show which protocols are truly long-lived.</p><p>Crypto already knows how to upgrade: we moved from PoW to PoS, adopted rollups, did hard forks.</p><p>Quantum is just the next exam.</p><p><strong>It's not about who's immortal, but who can adapt in time.</strong></p><hr><p><strong>References:</strong></p><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.youtube.com/watch?v=5DRDjeMmOPw&amp;t=1666s"><strong>Will Quantum Computing KILL Bitcoin?!</strong></a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.bankless.com/read/bitcoins-quantum-threat-isnt-eths-problem"><strong>Bitcoin's Quantum Threat Isn't ETH's Problem</strong></a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.google/technology/research/google-willow-quantum-chip/">Meet Willow, our state-of-the-art quantum chip</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://coinledger.io/research/how-much-bitcoin-is-lost"><strong>How Much Bitcoin is Lost Forever?</strong></a></p></li><li><p><a target="_blank" rel="bookmark" class="dont-break-out" href="https://scottaaronson.blog/?p=9325"><strong>Quantum computing: too much to handle!</strong></a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://vitalik.eth.limo/general/2021/06/18/verkle.html"><strong>Verkle trees</strong></a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://vitalik.eth.limo/general/2024/10/14/futures1.html"><strong>Possible futures of the Ethereum protocol, part 1: The Merge</strong></a></p><br></li></ul><br>]]></content:encoded>
            <author>0x5ed6f668e541108399fefdaef7da4e9e32902b46@newsletter.paragraph.com (Beril)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/8de7911f6c2c43e2e4fd7e0756d4e1238ee431780897a0f5b4b5bd7529484a02.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>