Lopp's Map of the Choice
Jameson Lopp, 17 Sep 2026. If quantum computers break today's signatures, he argues one property Bitcoin treats as inviolable breaks either way: owners keep the right to spend, or exposed keys stay safe from theft.
HIS FIGURES
About 1.7 million BTC sits in old pay-to-public-key outputs. He counts at least 2.6 million BTC, about 13% of supply, as still exposed even if every active user migrates.
BOTH SIDES
A freeze stops vulnerable spends, and can look like confiscation to an owner who still has the key. Doing nothing leaves long-exposed keys to whoever can run Shor's algorithm first.
HIS OPTIONS
Freeze; do nothing; stop new vulnerable outputs; temporary locks instead of burns; rate limits, such as Hourglass's 1 BTC per block from pay-to-public-key; commit-delay-reveal rescues; and zero-knowledge proofs that you know the seed behind an exposed key.
WHERE THESE FIT
SHRINCS is a candidate signature for the outputs people would move to. The exposure draft says which coins are at risk. PQLN covers Lightning's messages. DropKick is a commit-delay-reveal rescue. QSAVE pairs a seed proof with custody.
SHRINCS, Specified
26 Aug 2026: Conduition with Ethan Heilman, Mikhail Kudinov, Oleksandr Kurbatov, Jonas Nick, and remix7531. A hash-based post-quantum signature that assumes only SHA256. A cryptographic draft, not yet a pull request in the BIPs repository.
SIZES
Public key 48 bytes. A key's first stateful signature is 548 bytes, growing to at most 4,619 as the key keeps signing; earlier write-ups said 324. A 5,777-byte stateless fallback covers up to 240 signatures. Schnorr is 64 bytes. Key plus smallest signature is about 13 times smaller than SLH-DSA-128s, and 6 times smaller than ML-DSA-44.
STATE
Reusing a counter value under one key lets anyone who saw both signatures forge a new one. Lost state, a restored backup, or two devices on one seed can do that, so a wallet unsure of its counter must refuse stateful signing. April's SHRIMPS is the multi-device variant, at about 2.5 KB.
NOT AN OUTPUT
Like BIP340, it defines keys and signing, not consensus. It cannot be deployed safely without a new output type, and it has no structure for BIP32 xpubs or MuSig. Wuille, in Optech #421: bundling cross-input aggregation into P2TRv2 saves at most about 28% weight, and wallet support, not fees, is the bottleneck.
FEES AND PROOFS
Antoine Riard: the fallback is about 90 times a Schnorr signature in Lightning or vault fee-bump reserves. Conduition: a 2-in, 2-out spend is 840 WU with Schnorr and 12,426 WU with the fallback, about 14.8 times. Still missing: test vectors and a proof for the full scheme. remix7531's libshrincs has machine-checked proofs for WOTS+C, its one-time piece.
Which Outputs Are Exposed
duncan0k's informational draft, BIPs pull request #2294, now at v0.6.0 (24 Sep). It classifies outputs; it changes no consensus or policy rule.
AT REST
EXPOSED_AT_REST: the public key is already on chain, as with pay-to-public-key, or a reused address that has been spent and still holds a balance.
ON SPEND
EXPOSED_ON_SPEND: the key appears when the coin is spent. A P2MR leaf that requires a signature publishes a secp256k1 key, so P2MR sits here until post-quantum leaves exist. Outputs sharing a script count together: once a confirmed spend publishes the key, the rest are at rest.
FAIL CLOSED
NOT_EXPOSED has no member today. Unrecognised types are UNDETERMINED, not safe. When the data cannot distinguish two levels, the draft assigns the more exposed one.
CORRECTION
Earlier versions listed P2MR as NOT_EXPOSED. v0.5.0 moved it to EXPOSED_ON_SPEND after Murch pointed to BIP 360's own terms. A wallet using the old rule would show P2MR as hidden when a leaf spend is not.
PQLN on Lightning
Ahmet Kurt, Delving 16 Sep. A hybrid post-quantum layer for Lightning messages, implemented in a rust-lightning fork. Funding, commitment, and penalty keys stay classical, because those need a consensus change.
WHAT MOVES
BOLTs 4, 7, 8, 11, and 12. Gossip carries ML-DSA and ML-KEM keys and pins them on first sight. The Noise handshake adds two ML-KEM encapsulations on a separate port, with no in-band negotiation, so a quantum adversary cannot rewrite a downgrade.
HIS MEASUREMENTS
ML-DSA signing at 0.33 ms. On a 50 ms, 10 Mbit/s link, a payment is 19–53 ms slower per hop, mostly from a 21.8 kB ciphertext list. A new node on a 33,000-channel network downloads about 270 MB of gossip instead of 26 MB, about 10×, because channel_announcement stays classical.
ROASBEEF
29 Sep reply. He wants hybrid schemes, questions BOLT 11's size limits, and says ML-KEM ciphertexts sitting in fixed slots beside the onion can reveal a hop's position and are not re-randomised the way Sphinx packets are. Trust-on-first-use only helps nodes that met before a quantum computer exists.
OPEN
TLV types and feature bits are unassigned. No interoperability run against CLN, LND, or Eclair yet. PQ gossip does not relay through vanilla rust-lightning nodes while MAX_EXCESS_BYTES_FOR_RELAY stays at 1024 bytes.
DropKick
Conduition, Brink-funded write-up dated 1 Aug 2026, then discussed on bitcoindev. A commit-delay-reveal rescue for coins whose owners do not migrate before a quantum computer can spend them.
TWO STEPS
Commit to a hidden value in a block, for example in an OP_RETURN or a Taproot tweak. After a long delay, 1,440 blocks (about 10 days) in his example, reveal the witness, a post-quantum signature, and a proof in the style of SPV or OpenTimestamps that the commitment is old enough.
VS LIFEBOAT
Tadge Dryja's Lifeboat needs each user to hold a post-quantum-secure output, and validators to index every commitment. DropKick lets untrusted aggregators merkle-commit many users under one root, with no index. Optech #421: the cost is more miner-censorship risk on the reveal.
WHAT IT CAN COVER
Optech's summary: a non-confiscatory soft fork if it only encumbers outputs where validators can see, from the output alone, that hidden data exists. Covering undecidable cases such as BIP32 derivation would rescue more coins and could confiscate some. Pay-to-public-key cannot be covered.
CENSORSHIP
His minimum fee ratio is 1/(1 + delay): about 100 blocks of delay works if users pay 1% of the coin to honest miners, assuming censors will not reorg the commitment out. Those are his parameters, not a deployed rule.
QSAVE
James Tagg, bitcoindev, 22 Sep 2026. Five draft BIPs, hosted on qsave.org. He presents it as a no-burn alternative to BIP 361 and Hourglass for coins that do not migrate.
SECOND FACTOR
After an enforcement height, a spend still needs the existing signature plus a second factor: a zero-knowledge proof linking the seed to a post-quantum authority, or a watermark committed before the cutoff. He says a quantum-derived key alone is not enough.
IF IT IS MISSING
The coin is not burned. It goes to recovery outputs held by a set of custodians, with a backup custodian and a veto controller. He says held funds can earn 0.5% for charity, and is explicit that recovery without on-chain proof involves people and is no longer permissionless.
THE FIVE DRAFTS
Conditional spending, watermarks, a seed-derivation factor, protective recovery, and a zk-STARK spend leaf for BIP 360 P2MR. He also describes a path with no consensus change, in which "white-hat" quantum spends move coins to custody. None of these has a BIP number.
CONTEXT
qsave.org is titled QSAVE Staking, and the GitHub organisation is the QSAVE Wealth Fund. His August 2025 version proposed a fund targeting 3–5% returns. Replying then, Conduition wrote that KYC cannot be the answer, and Javier Mateos objected to writing a group of claim arbiters into the code.