Problem
Bitcoin's ECDSA (secp256k1) and Schnorr signatures are vulnerable to a cryptographically relevant quantum computer via Shor's algorithm. Per BIP-361, migration requires experimenting with post-quantum output types.
Proposal
Add an additive, self-contained experimental toolset under contrib/
(e.g. contrib/pq-shield) that:
- generates ML-DSA-65 (FIPS 204, NIST level 3) keypairs,
- signs and verifies messages as a CLI,
- ships a small audit utility validating key sizes and file permissions,
- is covered by unit tests and is not wired into the main build.
Scope is strictly limited to contrib/; no consensus, validation, or
networking changes are proposed. The goal is to give developers and
wallet authors a reference implementation to evaluate PQ signature sizes,
performance, and integration surfaces before any consensus-level BIP
discussion.
Open questions
- Should such tooling live in-tree or as a separate depends-style submodule?
- Is
liboqsan acceptable external dependency for contrib tools?
Feedback welcome before any PR is opened.