Goldman Sats's avatar
Goldman Sats 9 months ago
Also, dumb question: is there a way to make the current UTXO set quantum resistant, with no need to migrate to quantum resistant addresses?

Replies (2)

It seems to me that you could prove a hardened derivation or a BIP-39 derivation. Unfortunately this reveals your secret key, so you need to either use a (quantum resistant!) ZKP, or a two-stage reveal: hash of the proof, what outputs you will spend, and an indication of what address you want to transfer the coins to, then after that is mined, you do the spend at put the derivation in the annex (or, for non-taproot, in an OP_RETURN).