Paper 2026/2173
Switch Commitments by Coincidence: Confidential Transactions Were Quantum-Upgradable All Along
Abstract
Upgrading cryptocurrencies to post-quantum security is inherently difficult, because their on-chain state associates users' holdings with public keys: users who fail to transfer their funds to (yet to be added) post-quantum signature schemes remain exposed to theft. In networks with Confidential Transactions (CT) such as Liquid, Monero, and Grin, which hide monetary amounts inside homomorphic Pedersen commitments, the situation is worse still: an adversary who computes a single discrete logarithm can inflate the currency as a whole, rather than merely steal individual funds. The contentious remedy is to expire all funds not transferred by a deadline, destroying the funds of everyone who fails to act. Switch commitments (Ruffing and Malavolta 2017) were proposed to avoid exactly this expiration, but only Grin has deployed them deliberately—and the security theorem later stated for its scheme does not hold, as we show. In this paper, we show that Liquid and Monero already deploy a switch commitment scheme by coincidence: the ciphertext a sender stores on-chain to convey the hidden amount to the recipient can be re-interpreted, together with the Pedersen commitment, as a switch commitment. We conceptualize this construction as coincidental switch commitments and prove it secure in the quantum random oracle model. Additionally, we save the construction that Grin deploys: it is computationally switch binding, with practical bounds in the algebraic group model. The real-world implication of our results is that these networks can be upgraded to post-quantum CT schemes without expiring any user funds.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Switch CommitmentsConfidential TransactionsConfidential AssetsLiquidMoneroGrinPost-Quantum
- Contact author(s)
-
yhrubiian @ blockstream com
mredko @ blockstream com
me @ real-or-random org - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2173
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2173,
author = {Yevhen Hrubiian and Mykyta Redko and Tim Ruffing},
title = {Switch Commitments by Coincidence: Confidential Transactions Were Quantum-Upgradable All Along},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2173},
year = {2026},
url = {https://eprint.iacr.org/2026/2173}
}