Paper 2025/1307
The Post-Quantum Security of Bitcoin's Taproot as a Commitment Scheme
Abstract
As of November 2021, Bitcoin supports “Taproot” spending policies whose on-chain format is a single elliptic curve point. A transaction spending the funds associated with a Taproot policy can be authorized by interpreting the curve point either (a) as a public key of the Schnorr signature scheme and providing a suitable signature, or (b) as a commitment to alternative spending conditions and satisfying those. Since a sufficiently powerful quantum adversary would be able to forge Schnorr signatures, an upgrade to Bitcoin may, at some point in the future, disable the ability to spend existing funds via Schnorr signatures in order to prevent the havoc created by leaving a large fraction of the currency supply prone to theft. However, to avoid irrevocably losing all funds not migrated in time to (yet to be added) post-quantum signature schemes, it will be desirable for an upgrade disabling Schnorr signatures to retain the ability to spend funds by interpreting the curve point in a Taproot policy as a commitment to alternative spending conditions. This paper justifies such an upgrade strategy by demonstrating the post-quantum security of Taproot as a commitment scheme. Specifically, it provides concrete upper bounds on the probability that a quantum adversary making some number of queries to a quantum random oracle can break the binding or hiding property. Since the bounds follow from powerful existing results, which enable reasoning as if dealing with a classical adversary, the proofs are accessible without a background in quantum computing.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- BitcoinTaprootpost-quantum cryptographycommitment schemesquantum random oracle model
- Contact author(s)
- me @ real-or-random org
- History
- 2025-07-19: approved
- 2025-07-17: received
- See all versions
- Short URL
- https://ia.cr/2025/1307
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1307,
author = {Tim Ruffing},
title = {The Post-Quantum Security of Bitcoin's Taproot as a Commitment Scheme},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1307},
year = {2025},
url = {https://eprint.iacr.org/2025/1307}
}