
Is blockchain up with PQC?
A major concern in PQC is that many who need it are not taking it seriously or truly understanding the urgency. For some this is a lack of forethought but for others, perhaps most, its because they are already overrun with attacks that affect them now and simply lack the bandwidth for quantum computers decrypting their secrets ten years hence. Yes, I am aware that many think that Q-day is earlier and perhaps even already happened but I’m following the mainstream, most common view.
One field in particular which needs to take PQC seriously is blockchain, especially cryptocurrencies. The reason is simple, conventional blockchain uses public key encryption to protect its contents and that will be all but transparent when cryptographically relevant quantum computers become available. Secure hash algorithms used to connect the chain are also theoretically weakened by Grover’s algorithm but there are practical issues which can wait for another blog and even the theoretical worst case is easily offset.
Getting back to blockchain’s use of public key encryption, the information I receive appears to be mixed. Almost everyone in the PQC space that I’ve spoken to believes that only a rare few cryptocurrencies are taking the quantum threat seriously and yet I have also been assured of the opposite, with one person I take seriously declaring that all the serious cryptocurrencies have PQC in place or will very soon, and a developer at a cryptocurrency meetup I went to recently assuring me that all developers in the field are aware of the quantum threat and are taking it seriously. Then again, a cryptocurrency CEO at this same meetup, I'm not naming names, was of the view that if quantum hacking happened then the community could spot where the anomalies started and rewind the communal ledger back to that point, easy! (Spoiler alert: no they can’t)
Where it gets puzzling is that I myself know of only two cryptocurrencies which are quantum resistant, krown and quranium , and they each claim to be the only one!
A Gemini enquiry tells me of Quantum Resistant Ledger and Algorand which use NIST-approved XLSS and Falcon, respectively, as digital signatures to secure their histories. The same is true of Mochimo. Some other ledgers are working towards post-quantum encryption but are not there yet.
It would therefore seem that quranium and krown are not the only two quantum-resistant blockchains. I welcome any informed feedback on this topic, preferably with supporting URLs. If your favourite blockchain/crypto is quantum resistant and I haven’t mentioned them or you can enlighten us on the relative security of each then I want to hear from you.
I expect to attend a BitCoin meetup on Wednesday, its at Molly Malone’s Irish Tavern in Surrey Hills if you live in Sydney, where I shall be raising this, so there might be more after this….
Addendum: So BitCoin meeting Wednesday was very enlightening. I had no idea that BitCoin enthusiasts were so political, its a real freedom movement! But more to the point, I was told that BitCoin is not using post-quantum encryption yet but has a plan to introduce it before quantum computers become capable of hacking it, which is something. Not sure what they're waiting for, and remember harvest now, decrypt later.....