From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Sun, 12 Jul 2026 12:13:56 -0700 Received: from mail-oa1-f60.google.com ([209.85.160.60]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1wizch-0007jO-18 for bitcoindev@gnusha.org; Sun, 12 Jul 2026 12:13:55 -0700 Received: by mail-oa1-f60.google.com with SMTP id 586e51a60fabf-455cf15f8b5sf48845fac.0 for ; Sun, 12 Jul 2026 12:13:54 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1783883629; cv=pass; d=google.com; s=arc-20260327; b=VeoBgXiOrUbfZg0VETKVanY/+lidRJok1cFrASPSMoIsjNmsWLzLTViqMbunopsedZ s8VI2v5xoRj4Rk4OS1y1czuLPX9zuMLtKULnFPPsSX2HLlLQBZ8JP89QbdDxWO1qgI4C MgOrqz8noW71dywt7o2FuZUBr2BwRzg7wYCCoGP8r7LNjlHquMiomMHla2y4Y9Jopevr TQWU5SzrdVbx9q+zQmZKPa/MQX8wM0pGpDeAux4SO+PjqMn4rjDnL9UiB088kvKQ4EqR JT3St9qezX2dYwU5QpqCKH+lS2/kSEKuQmw2edIE34go+/YiBbk427l0qpDk1eas2Lss b2zg== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:cc:to:subject:message-id:date:from :mime-version:sender:dkim-signature:dkim-signature; bh=kLkvBq2sozRFy3rG2iDBE4VvMPV09XrlGLAFKK1FyUY=; fh=99YureRnC0HiSn1dOcHSrBZrGX7sF7hTn2wa7/HiQDY=; b=pVY/HrHPdSK8gZGJseN4piOWzvZ3UNHOMAdMtmp8DbXfMS+1l6OV5fqvcQETVF8qvh H5k7msWtOC7gVDHTlLK/Q44VsM+/Mdmwxmh5tIaTwAP1LPdEVKz9KnHdUSSHF6XhwDlK BW4Da9lKrO9dbKXQ83RdR5gtygSmDrpE2hQnsxQTJpe75iSTB6y+Lfc5zZZZHYENYrGX 55/Fjesrn2gnFGQILljOFquRyi7vCao730TsoJRNoYeDG8T1dSyG3dZjDkO5nLWbE8TG wv6yvTIANxaPRYedqkY5mAuBFny/9Nl2qaPcu41losMdn/klHpiCbNUru34MpRqAzv3s JS1w==; darn=gnusha.org ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=YsjXkDMF; arc=pass (i=1); spf=pass (google.com: domain of antoine.riard@gmail.com designates 2607:f8b0:4864:20::62c as permitted sender) smtp.mailfrom=antoine.riard@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1783883629; x=1784488429; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:content-type:cc:to:subject:message-id:date:from :mime-version:sender:from:to:cc:subject:date:message-id:reply-to :content-type; bh=kLkvBq2sozRFy3rG2iDBE4VvMPV09XrlGLAFKK1FyUY=; b=vIzOcooSxnChVqZQWEKqFg3i8j/ROG4Wrw2TW2pE9UZ5lGIjW8Iy7r9/wDg+VBIUKx kHoYnZMUhpZ5h4me8I+LavU4tBDgFah+RzUC+x7qPtcoBamIe49OIcRmyq8gAP2EGlw/ BlGyKqhq0d96gJNC2zveU7ZLdQyBcMuyrjd3pb30nsOegkljbKju78YiHv02I2lHH/EC iLJXOu1w0FusnkJyXz/HBq+UWpg+VdmohfU9+aUuwPzeXTwff3hN7ADUoommkQmIamQR 13efje447DR5hqFSJ1uhCShyULwWJJZJaJCLR/T4oOGRY00sMdWaWWNFotgQfs//BOvM Bgzw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783883629; x=1784488429; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:content-type:cc:to:subject:message-id:date:from :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=kLkvBq2sozRFy3rG2iDBE4VvMPV09XrlGLAFKK1FyUY=; b=FTfrQpI3efGwXyTCoG6Ff62doERxqh1xm/pV8n441VxMlUPuzUiLrs2dtndCR2lLy7 y+KGWm7TeW9zNwzS8mGhnsUacru5KAtEKDJqaLx3yk6owOUvgmrGfU5x4u/cjzQ71rKS FaaasgSKqlPrhSl0lMoEyNCmOil7o5TSI7uMppQbobGCYNWKNKxGDFvaenvKNJrRU/tP ZWZ3yxEQKW0Nc3TYJqLPyCsCgG4P2RTMa7FJG3Zzbc39s5MLA4zbUlTiT/Dc87v4DwQH pTwckPMvTOi/V8MwbVKyBSbuRuqOOlY2WE97zXorkympLwctNukN0jK3UyWRz0ZwCGLd DEFg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783883629; x=1784488429; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:content-type:cc:to:subject:message-id:date:from :mime-version:x-gm-gg:x-beenthere:x-gm-message-state:sender:from:to :cc:subject:date:message-id:reply-to:content-type; bh=kLkvBq2sozRFy3rG2iDBE4VvMPV09XrlGLAFKK1FyUY=; b=CLYimZe2WU2nyBVEkt+bqAD0n8CY3IJIMpC/aMz8SHeY8LHAzm57yuNJ8PV8b80Vmq NLG0s5QpVAYpDNxtS/jk+gkQLdmEljPYKFtgW0Cg3gvwd86+hmtSr7FEVMuQiRjINV7i WsmJpCHkW02KrZYVS0UqIM1Paq8cX/Q2dZ9MsQMJr1geJTUoxv/LYxKh+O35/vVBK01K /y870w/veEb0L769f5INyPG9ZfflILKVsttWkJHf8nzF4NpP9pHFXwV/L9YWvA1DMHgn NBXwzk/i0hS5EUzmDlMVm7sHZUjaHaEvUfj4IM/3g3O+/slzEbsCrdXGF3QDxnuqipPL w/5g== Sender: bitcoindev@googlegroups.com X-Forwarded-Encrypted: i=3; AFNElJ9wLi5CrR3A6YRejvn4RNDSt3u+zDos4ejsKza+uqOYlVkJ2/K00cUZ2MIViEcENt8MtvS1Rel+dRql@gnusha.org X-Gm-Message-State: AOJu0YyD8npWiAq91Ed2EYIwdcbIsD6GW3JZHGU/it+scQzCWnbspx/j BcnJrkpBc3atOXj0Q3S8BqyL//M4zz76V/AM6FlOF9CaoPl1MGmDP68B X-Received: by 2002:a05:6870:16ea:b0:448:d83b:edaf with SMTP id 586e51a60fabf-451bb27cc71mr5406544fac.25.1783883628736; Sun, 12 Jul 2026 12:13:48 -0700 (PDT) X-BeenThere: bitcoindev@googlegroups.com; h="AX0PUUe9R3/h2kvVWzGDLjTasNKG4BZmOdZtz0TUS1iEmTNwBQ==" Received: by 2002:a05:6870:d40f:b0:447:4c66:fcb6 with SMTP id 586e51a60fabf-45189aac4f6ls1049584fac.2.-pod-prod-00-us-canary; Sun, 12 Jul 2026 12:13:44 -0700 (PDT) X-Received: by 2002:a05:6808:2f13:b0:492:7ecb:94ef with SMTP id 5614622812f47-4a42d0d0e5dmr3696702b6e.18.1783883624043; Sun, 12 Jul 2026 12:13:44 -0700 (PDT) Received: by 2002:a05:6808:7dd:b0:495:f457:d35e with SMTP id 5614622812f47-4a410d02d43msb6e; Sun, 12 Jul 2026 11:34:53 -0700 (PDT) X-Received: by 2002:a05:6820:4df2:b0:6a3:127a:bf27 with SMTP id 006d021491bc7-6a39bc515ebmr3202703eaf.11.1783881293329; Sun, 12 Jul 2026 11:34:53 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1783881293; cv=pass; d=google.com; s=arc-20260327; b=LAKKl9zmamDJ+RXTw6597KdBTEgIaRhdmKaw7MncoiXzc81LvqHA/dHqTiv4eAoPQ3 ou3ZEf5sLETshWiuEs3aFWwTlfX9B+c/EROiNijHNdm2bZRiSA8NwJJuSPIOslViL9cT eJG9pyrxnht3Umqo85OCgWMPsrRuJMl86HwLqCLkdlYEXrcyqF2EqlAurSjNWDyo6SMY VlWyUl6dSTQ8M+qcXb5SiDRlqXLLUeGhEle/9+Dv0I2ffCWog66IVmcybXc0CjZYD06s tbT6dlzd7SnLf7grbZYSRanGfWXQE7BMCAucuYy25vfnxWLI+T0iUw/sZO8A8we4gnus kbew== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:mime-version:dkim-signature; bh=zNZtHk2VD/R3FnKSCco7yGGOIshK5anvIuhUz+ZUc+U=; fh=rkm3bHbFkkqaOCEhDYIrUdh+uNF0aEpt1sjHeEyiFh0=; b=bVENQ3MRcS/LyGBTReyjOzM4I/Zkfe8S+PoOjOIHU6SEJjSe3ur21irSe3LcJKh9al LTBWDpKmXD3nne4GQHWdRaAu0NcClkWA1Qyy3CmVly2+AgvTWIMoRYxwSbI1yTSFl1UY EN/HCrtx1Gjk05QKSBJLeIvBvNKB2epWKfel22vza3Q724GwGwfXIHMqi0QV4peRmbGF cHjP7OqrvxPA6wAv49JDx8ZdZqZ/x0TDm17uMHwa7RM+Zx6Fwc2wt2LFMD7dLWTcQ6PN PIY48uOR2rvijQR6a6/G/SvEP42Ajdk5rtsqK0GFC3iAc5ZPCm3aZFBr1ptykGw+MvWg 4oRQ==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=YsjXkDMF; arc=pass (i=1); spf=pass (google.com: domain of antoine.riard@gmail.com designates 2607:f8b0:4864:20::62c as permitted sender) smtp.mailfrom=antoine.riard@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com Received: from mail-pl1-x62c.google.com (mail-pl1-x62c.google.com. [2607:f8b0:4864:20::62c]) by gmr-mx.google.com with ESMTPS id 46e09a7af769-7ebcae3d1a8si561346a34.1.2026.07.12.11.34.53 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 12 Jul 2026 11:34:53 -0700 (PDT) Received-SPF: pass (google.com: domain of antoine.riard@gmail.com designates 2607:f8b0:4864:20::62c as permitted sender) client-ip=2607:f8b0:4864:20::62c; Received: by mail-pl1-x62c.google.com with SMTP id d9443c01a7336-2cc61541f8cso40303995ad.0 for ; Sun, 12 Jul 2026 11:34:53 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1783881292; cv=none; d=google.com; s=arc-20260327; b=GduMewVDF6UU8ZWeQ+MTq076zUBWIVHi15oKWPGuT+Q56ocQmVjMW91zWAQMmW8eXX Mx99g5SFRpIY/ulXMEmFYmZdo4IkwMihyfx/BMzrvT/xEZI0j5K3VN3LxKMnSmybcoWC EtYEMYsWIHoD77fM6nq1Wkm7bAZdKus6f77v7reEMHPuF//PaOgPpmBIVmXDmx0MI+kN 8zL9JVrcvQgtExeqGNNgoQOr3ui8FK4MInJGHzX7q3npYIjQ3ACxvp2QHqLH1nO9+GpF G6sOI33C8NE/6lCk0mnLTVabCTf0oXDUcfsNAYTRBtRfqw2saM2MeM0ou2PSuKeSh+fX xFeg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:mime-version:dkim-signature; bh=zNZtHk2VD/R3FnKSCco7yGGOIshK5anvIuhUz+ZUc+U=; fh=rkm3bHbFkkqaOCEhDYIrUdh+uNF0aEpt1sjHeEyiFh0=; b=rD9w3o9+bjeuU5KoWl5UI8PMlkR5zYGS5/nym+ykRf+swULiSCoqCpIpFTA4TVVL22 fAlRjuZfEU1kj10GJo2hWuaOLcUcs7v04Cw0LyYGOoVrfdjVjko8oslIG/CDQbM6LcXH yZcqYtpj/U7TX0GPTSDQXgwB4Hn9VeFSCKeT1+8DegRt5PmOzwYEDIXu85mPj5yCbfb/ GVNLcPoHgHWxSmW8dPpRkMOXdaG6bPGPLKsd36ymd3XkZjGjlDKC064uTTzTE5fdlWiI u3p9cH83zf4oioKVAe9D2ALVqIQAZjGL5rfv8obrkbRZJU+KNEEl2jfupp3VR57zv+up 5ing==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; arc=none X-Gm-Gg: AfdE7cm9PcqF9jZzWOVsIV7FPFJarTOTehirGVLAg68trEI3JnVBQWumxvlk84qlJ9C v1wCdHLENn7pJ7JIV/P7DJ7SHkD0ivXYlqRdZaTDiwIq6U65nbyQk/12x29xHDO9biY3ui0hCTN AtMWtzjOwqP6LgI3t6RR3Qz1VF7pCW2ie3KsBsy12s2eRc3Mt4jLP6tjDrOOjFPCnXdvQuLdPIb jjfGGoLEjFHDCuKN0O0IvzfXyxsAg4VAEnrFKANyP4C2Uam6KDuiVkzSgqy5gqmax6mZc6lIg== X-Received: by 2002:a17:903:1b6b:b0:2ca:5023:f983 with SMTP id d9443c01a7336-2ce8298a455mr109943325ad.29.1783881292062; Sun, 12 Jul 2026 11:34:52 -0700 (PDT) MIME-Version: 1.0 From: Antoine Riard Date: Sun, 12 Jul 2026 19:34:40 +0100 X-Gm-Features: AVVi8CetGcH3Hp-Qsh6PpOuRMWSckDYy4gtI54qaIJuOIOhjMFOnFe8GiFI2ZZs Message-ID: Subject: [bitcoindev] The game-theory problems of PQ sunsetting modes To: Bitcoin Development Mailing List Cc: btc@ariard.me Content-Type: multipart/alternative; boundary="000000000000bc247a06566e3a0a" X-Original-Sender: antoine.riard@gmail.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@gmail.com header.s=20251104 header.b=YsjXkDMF; arc=pass (i=1); spf=pass (google.com: domain of antoine.riard@gmail.com designates 2607:f8b0:4864:20::62c as permitted sender) smtp.mailfrom=antoine.riard@gmail.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com; dara=pass header.i=@googlegroups.com Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: -0.5 (/) --000000000000bc247a06566e3a0a Content-Type: text/plain; charset="UTF-8" Hi list, In this post, I'm extending on the game-theory problems underscored for my answer to [ ] to other post-quantum sunsetting scenarios previously mentioned on this list. Firstly, let's remember the "tripwire" idea [0]. With the "tripwire", if I understand it correctly we introduce a consensus level proof of quantum computers e.g with a NUMS puzzle. This NUMS is committed in a honeypot UTXO let's say with some non-null bitcoin reward to unlock it. When the NUMS point is solved by a QC entity, it automatically triggers a "freeze" of all the "legacy" coins starting at some block height-defined window in the future. While it appears feasible engineering-wise, the problem is more on the game-theory plane of analysis. As it was previously noted by another commentator than me [1], why an economically-rational CRQC entity would go to trigger such an evident "honeypot" UTXO depriving it from further (covert) extractions of the legacy coins to a safe wallet owned by this entity. A more sophisticated scenario, that I was laying out more recently, a 51% majority coalition of miners could coordinate with a CRQC entity to censor the transaction inclusion of any PQ proof, even an inclusion attempt of a PQ proof generated by an honest PQ entity [2]. Exposing again the economic analysis, a year of mining income is evaluated at around $20B. The number of legacy P2Pk coins is evaluated to be around 1.7 M of coins or as of today $107B. If we go to account the numbers of "coin loss", the estimated number can be more around 3-4 M, so let's say $215B worth of target coins (a coin lost to you is not a coin lost to a CRQC entity...). That's something like ~10 years of potential income, that an economically rational miner might not refuse if a miner has a credible odd of capturing a share of this magic income to the prorata of their hashrate capabilities [3]. If we assume a PQ coin extraction game with 2 CQRC entities availing roughly the same capabilities, they might compete for the majority hashrate of the miners, those miners solely driven by economic incentives. The focal point of equilibrium between the two strategies is likely going to be the marginal energy cost to run a CQRC, assuming that in a fee race a CQRC entity can offer to the majority of miners to burn more of a coin value as reorg fee. Secondly, for the second approach of sunsetting, the one very roughly described in BIP361 and based on pure "flag-day" activation, the security analysis can extend to this approach too. Even assuming a week-long period for a BIP9-like activation mechanism, a coalition of miners might stil go to reorg in depth the chain before the activation of said soft-fork. Such an approach is only theoretically increasing the coordination cost (and one would observe the asymmetry of information is selecting a time horizon period, as a CRQC might appear at any time during this period). One can observe that the 2 sunsetting approach, be it "tripwire" or "flag-day" approaches are introducing a "choke point" to the chain finality, as in the lack of it a CQRC entity might covertly exfiltrate "legacy" coins, with no knowledge of the miners, or even without coordination with them. After the "choke point", a CQRC entity might alter its strategy of going overt and start to offer fee bounties to reorg the chain as it's advantage to the majority of miners (to not loss an exploitation advantage to another CQRC entity). Finally, in this analysis we're only underscoring the risk of "legacy" coins, i.e coins that would have not upgraded to a PQ safe format, after some time horizon. However, in the Bitcoin blockchain world, time is relative, or rather only thermodynamically convergent. If a CQRC entity is able to build a coalition with a 51% majority of miners, the "upgraded PQ safe" coins might be also at risk [4]. Indeed, such malicious coalition could just roll-back the chain state back to the migration height of said coin, solve the DL for this coin and unroll back forward the chain. I do not believe that the old chain history would be safe from deep reorgs attacks by CQRC capable entities, as soft-fork deployments are "height-based" burnt and not "hash-based" burnt (BIP90). Checkpoints have been removed from the latest bitcoind versions. Maybe user-activated checkpoints or other similar mechanisms might be a more robust defense against CQRC entities attacking the chain finality. Current bitcoin mining process and the chain finality is assumed to be reasonably secure under the Gambler's Ruin Problem and some other assumptions (e.g a reliable network to relay the blocks). It might be considered that the introduction of CQRC computers might not be only a risk for the "legacy" coins, though far more concerning for the chain finality itself. Independently of being philosophically "pro" or "contra" in freezing legacy coins, I do believe the irruption of one or more CQRC entities and the potential of disruptions on the Bitcoin network stability is a subject deserving a bit more research and more work from the development community [5]. Cheers, Antoine OTS hash: 496d9c26c6f3d805dae88f487600f46990572fc84c4ca907fb85b5441c235cf3 [0] https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m/8nr6I5NIAwAJ [1] https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m/7uu4dZNgAwAJ [2] One might consider the following realistic scenario, it might that even if a CRQC become relevant, at first it will be only operated by big companies let's say in the US or China and they will prefer to keep the existence of such capabilities hidden for a while for non-economical reasons. Suddenly, one of the actor starts to use those post-quantum capabilities and the social equilibrium does not hold anymore with impactful second-order implications for the Bitcoin ecosystem. [3] On the low time incentive miner hypothesis, one can empirically observe (as of June '26) than it has limits given how fast are ready mainstream mining companies to reallocate their data centers and sources of energies to more generic high-performance computations rather than SHA256 hashing. [4] For the degree of scientificity of "game-theory" in itself, I can only forward the reader to the "Formulation of the Economic Problem" chapter in the "Theory of Games and Economic Behavior" book from Von Neumann & Morgenstern, 1944 [5] As quantum raises a number of skeptical eyebrows in the community, the first elaboration of quantum physics have been as old as the 30's, and so far no one has got a Nobel Prize, or any other major scientific prize to prove the physical impossibility of a large-scale quantum computer -- You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/CALZpt%2BFOUJF3E7YDk5xh-Cv9kxduGiuOPVK5x171%3D25C3ryJPQ%40mail.gmail.com. --000000000000bc247a06566e3a0a Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable

Hi list,

In this post, I= 9;m extending on the game-theory problems
underscored for my answer to [= ] to other post-quantum
sunsetting scenarios previously mentioned on th= is list.

Firstly, let's remember the "tripwire" idea [= 0]. With the
"tripwire", if I understand it correctly we intro= duce a
consensus level proof of quantum computers e.g with a NUMS
puz= zle.

This NUMS is committed in a honeypot UTXO let's say withsome non-null bitcoin reward to unlock it. When the NUMS
point is solve= d by a QC entity, it automatically triggers
a "freeze" of all = the "legacy" coins starting at some block
height-defined windo= w in the future.

While it appears feasible engineering-wise, the pro= blem
is more on the game-theory plane of analysis. As it was
previous= ly noted by another commentator than me [1], why
an economically-rationa= l CRQC entity would go to trigger
such an evident "honeypot" U= TXO depriving it from further
(covert) extractions of the legacy coins t= o a safe wallet
owned by this entity.

A more sophisticated scenar= io, that I was laying out more
recently, a 51% majority coalition of min= ers could coordinate
with a CRQC entity to censor the transaction inclus= ion of any
PQ proof, even an inclusion attempt of a PQ proof generated b= y
an honest PQ entity [2].

Exposing again the economic analysis, = a year of mining income
is evaluated at around $20B. The number of legac= y P2Pk coins
is evaluated to be around 1.7 M of coins or as of today $10= 7B.
If we go to account the numbers of "coin loss", the estima= ted
number can be more around 3-4 M, so let's say $215B worth of
= target coins (a coin lost to you is not a coin lost to a CRQC
entity...)= .

That's something like ~10 years of potential income, that aneconomically rational miner might not refuse if a miner has
a credible= odd of capturing a share of this magic income to
the prorata of their h= ashrate capabilities [3].

If we assume a PQ coin extraction game wit= h 2 CQRC entities
availing roughly the same capabilities, they might com= pete for
the majority hashrate of the miners, those miners solely driven=
by economic incentives. The focal point of equilibrium between
the t= wo strategies is likely going to be the marginal energy cost
to run a CQ= RC, assuming that in a fee race a CQRC entity can
=C2=A0offer to the maj= ority of miners to burn more of a coin value
as reorg fee.

Second= ly, for the second approach of sunsetting, the one very roughly
describe= d in BIP361 and based on pure "flag-day" activation, the
secur= ity analysis can extend to this approach too. Even assuming
a week-long = period for a BIP9-like activation mechanism, a coalition
of miners might= stil go to reorg in depth the chain before the
activation of said soft-= fork.

Such an approach is only theoretically increasing the coordina= tion cost
(and one would observe the asymmetry of information is selecti= ng a time
horizon period, as a CRQC might appear at any time during this= period).

One can observe that the 2 sunsetting approach, be it &quo= t;tripwire" or
"flag-day" approaches are introducing a &q= uot;choke point" to the chain finality,
as in the lack of it a CQRC= entity might covertly exfiltrate "legacy" coins,
with no know= ledge of the miners, or even without coordination with them.

After t= he "choke point", a CQRC entity might alter its strategy of going=
overt and start to offer fee bounties to reorg the chain as it's ad= vantage
to the majority of miners (to not loss an exploitation advantage= to another
CQRC entity).

Finally, in this analysis we're onl= y underscoring the risk of "legacy"
coins, i.e coins that woul= d have not upgraded to a PQ safe format, after
some time horizon. Howeve= r, in the Bitcoin blockchain world, time is
relative, or rather only th= ermodynamically convergent. If a CQRC entity
is able to build a coalitio= n with a 51% majority of miners, the "upgraded
PQ safe" coins = might be also at risk [4]. Indeed, such malicious coalition
could just r= oll-back the chain state back to the migration height of
said coin, solv= e the DL for this coin and unroll back forward the chain.

I do not b= elieve that the old chain history would be safe from deep
reorgs attacks= by CQRC capable entities, as soft-fork deployments are
"height-bas= ed" burnt and not "hash-based" burnt (BIP90). Checkpointshave been removed from the latest bitcoind versions. Maybe user-activated<= br>checkpoints or other similar mechanisms might be a more robust defenseagainst CQRC entities attacking the chain finality.

Current bitcoi= n mining process and the chain finality is assumed to be
reasonably secu= re under the Gambler's Ruin Problem and some other assumptions
(e.g = a reliable network to relay the blocks). It might be considered that
the= introduction of CQRC computers might not be only a risk for the "lega= cy"
coins, though far more concerning for the chain finality itself= .

Independently of being philosophically "pro" or "c= ontra" in freezing
legacy coins, I do believe the irruption of one = or more CQRC entities
and the potential of disruptions on the Bitcoin ne= twork stability is
a subject deserving a bit more research and more work= from the development
community [5].

Cheers,
Antoine
OTS h= ash: 496d9c26c6f3d805dae88f487600f46990572fc84c4ca907fb85b5441c235cf3
[0] https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m/8nr6I5NIA= wAJ
[1] https://groups.google.com/g/bitcoindev/c/8O857bRSVV8/m= /7uu4dZNgAwAJ
[2] One might consider the following realistic scenari= o, it
might that even if a CRQC become relevant, at first it will
be = only operated by big companies let's say in the US or China
and they= will prefer to keep the existence of such capabilities
hidden for a whi= le for non-economical reasons.
Suddenly, one of the actor starts to use = those post-quantum
capabilities and the social equilibrium does not hold= anymore
with impactful second-order implications for the Bitcoin ecosys= tem.
[3] On the low time incentive miner hypothesis, one can empirically=
observe (as of June '26) than it has limits given how fast are read= y
mainstream =C2=A0mining companies to reallocate their data centers and=
sources of energies to more generic high-performance computations
ra= ther than SHA256 hashing.
[4] For the degree of scientificity of "g= ame-theory" in itself, I can
only forward the reader to the "F= ormulation of the Economic Problem"
chapter in the "Theory of = Games and Economic Behavior" book from Von
Neumann & Morgenster= n, 1944
[5] As quantum raises a number of skeptical eyebrows in the comm= unity,
the first elaboration of quantum physics have been as old as the = 30's,
and so far no one has got a Nobel Prize, or any other major sc= ientific
prize to prove the physical impossibility of a large-scale quan= tum computer

--
You received this message because you are subscribed to the Google Groups &= quot;Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoind= ev+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/= d/msgid/bitcoindev/CALZpt%2BFOUJF3E7YDk5xh-Cv9kxduGiuOPVK5x171%3D25C3ryJPQ%= 40mail.gmail.com.
--000000000000bc247a06566e3a0a--