Urgent.News

What's breaking now, across thousands of outlets.

Tech

A Quantum-Resistant Signature Doesn’t Make Your Blockchain Quantum-Safe

Quantum-safe blockchain design requires more than replacing ECDSA. This article examines the protocol layers that still matter after post-quantum migration.

A Quantum-Resistant Signature Doesn’t Make Your Blockchain Quantum-Safe

Standards literature often uses “quantum-resistant” and “quantum-safe” interchangeably, but protocol engineers must recognize a key distinction: a cryptographic primitive can resist known quantum attacks while the broader system deploying it might still contain vulnerabilities. This nuance profoundly affects how engineers assess threat models, choose signature schemes, and design state transitions.

Quantum resistance concerns the hardness of specific mathematical problems faced by both classical and quantum computers. Traditional public-key cryptography, including Bitcoin’s secp256k1 elliptic curve cryptography (ECDSA) and SHA-256/Keccak-256 hashing, relies on problems like prime factorization and discrete logarithms. However, Peter Shor’s algorithm can solve these problems efficiently on a fault-tolerant quantum computer, rendering ECDSA-based signatures vulnerable.

To achieve quantum resistance, cryptographers replace discrete logarithms with mathematical structures believed to be resistant to quantum algorithms. The National Institute of Standards and Technology (NIST) has standardized several families of such primitives:

- Lattice-based cryptography, exemplified by ML-DSA (formerly Dilithium), relies on the hardness of the learning with errors (LWE) problem and vector reduction in high-dimensional lattices.

- Hash-based signatures, such as SPHINCS+ and SLH-DSA, depend entirely on the collision and preimage resistance of underlying hash functions.

- Code-based cryptography, like McEliece, depends on the difficulty of decoding general linear codes.

A cryptographic primitive is deemed quantum-resistant when its security parameter provides a concrete margin of both classical and quantum bit-security, as classified by NIST.

Quantum safety, however, is a broader, end-to-end property. A protocol is considered quantum-safe only when every layer—key generation, protocol logic, operational lifecycle, and state transitions—remains secure against quantum attacks. Even if a blockchain protocol adopts a quantum-resistant signature scheme, it may fail to be quantum-safe if it exposes vulnerabilities in its internal workings. For UTXO-based blockchains, this includes:

1. Exposed public keys versus hashed address reuse: In Bitcoin, Pay-to-Public-Key-Hash (P2PKH) addresses reveal only the hash of a public key. While a quantum attacker cannot invert the hash function to reveal the public key from the address, once a transaction spends funds from a P2PKH address, the full public key becomes public. This reveals the private key if an attacker can intercept the transaction or exploit address reuse.

2. Hierarchical Deterministic (HD) key derivation: BIP32/BIP44 HD wallets derive child keys from a master key using elliptic curve scalar multiplication. Even if the signature scheme on-chain is replaced with a post-quantum algorithm, unhardened HD derivation paths can expose master public keys if a single compromised child key releases the whole key chain.

Transitioning a UTXO protocol to post-quantum signatures introduces substantial engineering tradeoffs. Signature and key sizes expand dramatically: NIST ML-DSA (Dilithium) keys are 1,312 to 2,592 bytes, and signatures are 2,420 to 4,627 bytes—40 to 70 times larger than ECDSA signatures. This size increase dramatically impacts transaction weight, block space consumption, network propagation latency, and resource requirements for full node validation.

Additionally, integrating larger signatures requires extending transaction formats and employing extensions like Protocol Standardized Broadcast Transactions (PSBT) to accommodate the increased data sizes.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

Anyone can start building verified knowledge with Stack Internal

Stack Internal transforms your daily work into a living memory that’s shared with the rest of your team. Now anyone can create and share their knowledge in a Stack Internal workspace for free by…

  • Stack Internal platform enables building verified knowledge with AI agents
  • Free Starter workspace available for anyone from September 30
  • Trust score evaluates knowledge based on provenance, recency, expertise

More from Wednesday 30 September →