Paper 2025/1307

The Post-Quantum Security of Bitcoin's Taproot as a Commitment Scheme

Tim Ruffing, Blockstream Research
Abstract

As of November 2021, Bitcoin supports “Taproot” spending policies whose on-chain format is a single elliptic curve point. A transaction spending the funds associated with a Taproot policy can be authorized by interpreting the curve point either (a) as a public key of the Schnorr signature scheme and providing a suitable signature, or (b) as a commitment to alternative spending conditions and satisfying those. Since a sufficiently powerful quantum adversary would be able to forge Schnorr signatures, an upgrade to Bitcoin may, at some point in the future, disable the ability to spend existing funds via Schnorr signatures in order to prevent the havoc created by leaving a large fraction of the currency supply prone to theft. However, to avoid irrevocably losing all funds not migrated in time to (yet to be added) post-quantum signature schemes, it will be desirable for an upgrade disabling Schnorr signatures to retain the ability to spend funds by interpreting the curve point in a Taproot policy as a commitment to alternative spending conditions. This paper justifies such an upgrade strategy by demonstrating the post-quantum security of Taproot as a commitment scheme. Specifically, it provides concrete upper bounds on the probability that a quantum adversary making some number of queries to a quantum random oracle can break the binding or hiding property. Since the bounds follow from powerful existing results, which enable reasoning as if dealing with a classical adversary, the proofs are accessible without a background in quantum computing.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
BitcoinTaprootpost-quantum cryptographycommitment schemesquantum random oracle model
Contact author(s)
me @ real-or-random org
History
2025-07-19: approved
2025-07-17: received
See all versions
Short URL
https://ia.cr/2025/1307
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1307,
      author = {Tim Ruffing},
      title = {The Post-Quantum Security of Bitcoin's Taproot as a Commitment Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1307},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1307}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.