BitcoinAdvanced16 min read2026-10-09
R

QuanChain Research

Research Division

P2TR and Taproot: Bitcoin's Quantum Migration Challenge

TL;DR: Taproot (P2TR), activated in November 2021, introduced Schnorr signatures to Bitcoin — but also made quantum security worse for addresses that use it. Unlike P2WPKH (where unspent addresses hide the public key behind a hash), P2TR exposes the full Schnorr public key in the UTXO set from the moment of creation. BIP-360 proposes a post-quantum output type (P2QRH), but has no activation timeline. Lightning Network is also affected. Bitcoin faces a harder quantum migration challenge than any other major blockchain.

Bitcoin's Cryptographic Architecture: A Brief Foundation

To understand Taproot's quantum security implications, it is necessary to understand how Bitcoin's transaction output types have evolved and what each reveals about the associated public key.

Bitcoin uses the secp256k1 elliptic curve for all signature operations. A Bitcoin private key is a 256-bit integer; the corresponding public key is a point on the secp256k1 curve. The relationship between private key and public key is one-way under classical computation — deriving the private key from the public key requires solving the elliptic curve discrete logarithm problem, which is computationally intractable classically but tractable with Shor's algorithm on a sufficiently powerful quantum computer.

The critical quantum security variable for Bitcoin addresses is whether the full public key is visible on-chain. If the public key is hidden (for example, behind a cryptographic hash), a quantum attacker must first obtain the public key before running Shor's algorithm. This gives some protection to unspent outputs — the attacker cannot target them without the public key. Once an address signs a transaction, the public key becomes visible, and that protection ends.

P2PKH and P2WPKH: Hash-Protected Public Keys

Legacy Bitcoin address formats (P2PKH — Pay to Public Key Hash, used in base58 "1" addresses) and SegWit v0 addresses (P2WPKH — Pay to Witness Public Key Hash, used in bech32 "bc1q" addresses) share a key quantum security property: the scriptPubKey commits to the hash of the public key, not the public key itself.

For a P2WPKH address that has never sent a transaction, the blockchain contains only the HASH160 of the public key (SHA256 followed by RIPEMD-160, producing a 160-bit value). A quantum attacker cannot run Shor's algorithm against a hash — Shor's algorithm targets the elliptic curve discrete logarithm, not hash preimage computation. Hash preimage computation is addressed by Grover's algorithm, which provides only a quadratic speedup — HASH160 at 160 bits provides roughly 80-bit quantum security, which is marginally below ideal but much better than an exposed public key.

The critical caveat: this protection applies ONLY to addresses that have never sent a transaction. The moment a P2WPKH address signs and broadcasts a transaction, the full public key is included in the witness data. From that point forward, the public key is permanently on-chain and the address is a full quantum target. Reusing P2WPKH addresses (sending to the same address multiple times and then spending from it again) is a common user mistake that exposes the public key for the life of any remaining balance.

Taproot (P2TR): The Quantum Downgrade

Taproot was activated at Bitcoin block 709,632 on November 14, 2021, implementing BIPs 340, 341, and 342. It introduced Schnorr signatures (BIP-340), a new output type called P2TR (Pay to Taproot), and the MAST (Merkelized Abstract Syntax Tree) structure for complex scripts.

Schnorr signatures offer significant advantages over ECDSA: they are mathematically simpler, support key aggregation (allowing multiple signers to produce a single signature indistinguishable from a single-key signature), and enable more efficient script structures. For these reasons, Taproot adoption has grown steadily since activation.

However, P2TR has a critical structural difference from P2WPKH with respect to public key exposure. In a P2TR output, the scriptPubKey directly encodes the tweaked Schnorr public key. The format is OP_1 {32-byte tweaked public key}. This means the full public key is embedded in the transaction output from the moment the output is created — before any spending transaction is broadcast.

The implications are significant. For P2WPKH, a never-spent address hides the public key behind a hash. For P2TR, the public key is visible in the UTXO set from the moment of the first deposit transaction. Even if the address has never signed a spending transaction, the public key is exposed and can be used as input to Shor's algorithm.

This is a direct quantum security downgrade compared to P2WPKH for the use case of long-term cold storage. An address holding funds for years without spending — a common pattern for HODLers — has zero public key exposure with P2WPKH and full public key exposure with P2TR.

The Schnorr Signature Scheme and Shor's Algorithm

Schnorr signatures, like ECDSA, rely on the hardness of the elliptic curve discrete logarithm problem over secp256k1. Both are vulnerable to Shor's algorithm. The specific mathematical structure differs between Schnorr and ECDSA, but the quantum attack vector is the same: given a public key (a point on the secp256k1 curve), derive the private key (the integer k such that k * G equals the public key point, where G is the curve's generator point).

Shor's algorithm can solve this problem in polynomial time — specifically O((log n)^3) gate operations with O(log n) qubits, where n is the order of the curve group (approximately 2^256 for secp256k1). In practice, running Shor's against secp256k1 requires several thousand logical qubits with high fidelity — a capability beyond current quantum hardware but within the plausible capability range of hardware expected in the 2030-2040 window.

There is no quantum security difference between P2TR Schnorr and P2PKH ECDSA once the public key is exposed. Both are fully broken by the same quantum attack. The quantum downgrade in P2TR is entirely in the earlier exposure of the public key, not in any weakness specific to Schnorr over ECDSA.

Bitcoin Address Types: Quantum Exposure Summary

Address Type Format PubKey in scriptPubKey? Unspent Address Exposure Post-Spend Exposure
P2PK (legacy) N/A (output script) Yes — raw pubkey Full quantum exposure Full quantum exposure
P2PKH 1... (base58) No — HASH160 of pubkey Partial (80-bit hash security) Full quantum exposure
P2SH 3... (base58) No — HASH160 of script Partial (80-bit hash security) Full quantum exposure
P2WPKH (SegWit v0) bc1q... (bech32) No — HASH160 of pubkey Partial (80-bit hash security) Full quantum exposure
P2WSH (SegWit v0) bc1q... (bech32) No — SHA256 of script Better (256-bit hash security) Full quantum exposure
P2TR (Taproot) bc1p... (bech32m) YES — 32-byte Schnorr pubkey Full quantum exposure Full quantum exposure

BIP-360: The P2QRH Proposal

BIP-360, proposed by Hunter Beast in 2024 under the title "Pay to Quantum Resistant Hash (P2QRH)," represents the Bitcoin community's primary formal attempt to define a post-quantum output type. The proposal would introduce a SegWit version 3 output type that uses ML-DSA (CRYSTALS-Dilithium, now NIST FIPS 204) signatures instead of Schnorr.

The BIP-360 proposal faces significant technical challenges that explain its Draft status and lack of activation timeline as of 2026.

Signature size is the most fundamental challenge. Schnorr signatures are 64 bytes. An ML-DSA-44 signature is 2,420 bytes. ML-DSA-65 is 3,309 bytes. ML-DSA-87 (the highest security level, matching QuanChain's approach) is 4,627 bytes. For comparison, a typical Bitcoin transaction with one input and two outputs is roughly 250 bytes. A P2QRH transaction with ML-DSA-87 signatures would be approximately 4,900 bytes — nearly 20 times larger. This has profound implications for block space consumption, fee markets, and throughput.

SLH-DSA (SPHINCS+, NIST FIPS 205) is even larger: signatures range from 7,856 bytes (SLH-DSA-SHAKE-128s) to 49,856 bytes (SLH-DSA-SHAKE-256f). Hash-based signatures are quantum-secure under more conservative assumptions than lattice-based signatures (they rely only on the security of the hash function, not on any algebraic structure), but their size makes direct use in Bitcoin transactions impractical without significant protocol engineering.

BIP-360's current draft discusses hybrid schemes — combining classical Schnorr with post-quantum signatures for a transition period. The "hash then sign" approach (committing to a hash of the transaction using the post-quantum scheme) reduces what is being signed, but the signature itself remains large.

The Lightning Network Complication

Lightning Network (LN) payment channels add additional quantum complexity to Bitcoin's migration challenge. Lightning channels are built on P2WSH (SegWit v0) funding transactions and use a combination of P2WPKH and P2TR outputs for channel management. Channel state is managed through HTLC (Hash Time Locked Contract) scripts that use secp256k1 keys.

Lightning's security model has different quantum properties than on-chain Bitcoin. A Lightning channel between Alice and Bob requires Alice and Bob's channel keys to remain secret for the duration of the channel's open period. If a quantum attacker derives Alice's channel key, they can forge commitment transactions that steal Bob's channel balance — and the attack can happen while the channel is open, without waiting for an on-chain close.

More problematically, Lightning Network gossip broadcasts each node's public key to the entire network as part of the peer discovery and routing protocol. Every Lightning node's public key is permanently and publicly broadcast — providing quantum attackers with a comprehensive directory of targets whose keys can be harvested for later decryption.

Migrating Lightning to post-quantum cryptography requires not just a new output type (P2QRH) but a complete overhaul of the BOLT specifications governing channel lifecycle, HTLC construction, and onion routing. The engineering complexity significantly exceeds the on-chain P2QRH problem alone.

Why Bitcoin's Quantum Migration Is Harder Than Other Chains

Bitcoin faces a uniquely difficult quantum migration challenge for several structural reasons.

First, immutable UTXO set: Bitcoin's UTXO set contains millions of outputs created with various address formats, many of which belong to lost wallets, exchanges that have closed, and holders who cannot be reached for migration. A quantum migration that "burns" old address formats would disenfranchise unknown numbers of legitimate holders — a politically contentious decision that Bitcoin's governance model is not well-suited to make quickly.

Second, conservative development culture: Bitcoin Core's development philosophy prioritizes stability and security review over rapid feature deployment. A change as significant as a new post-quantum address type requires extensive review, multiple implementations, and broad consensus — a process that typically takes years even for uncontroversial changes.

Third, no soft-fork path: unlike SegWit (which was deployable as a soft fork by making new output types "anyone can spend" to old nodes), a genuine post-quantum output type likely requires new validation logic that old nodes must implement. This pushes toward a hard fork — the most contentious type of Bitcoin protocol change.

Fourth, the Satoshi coins problem: approximately 1 million BTC in early P2PK outputs (directly encoding public keys, with no hash protection) are associated with Satoshi Nakamoto and other early miners. These coins have the weakest quantum security posture of any Bitcoin outputs — the public keys are already on-chain and exposed. If quantum hardware matures before Bitcoin has a migration path, these coins become immediately vulnerable, raising the politically charged question of whether the community would invalidate them to prevent quantum theft.

QuanChain's Contrast: Quantum-Resistant from Block Zero

The contrast with QuanChain's architecture is stark. QuanChain uses ML-DSA-87 + SLH-DSA composite signatures at the protocol layer from genesis — there are no legacy address types, no UTXO set migration problem, no Satoshi coins issue, and no need for consensus on a contentious protocol change.

QuanChain's composite signature approach combines the algebraic security of ML-DSA-87 (lattice-based, NIST FIPS 204) with the hash-based security of SLH-DSA (NIST FIPS 205) in a single signature. The composite approach means that breaking the signature requires simultaneously breaking both an algebraic problem (lattice reduction) AND a hash function preimage problem — providing security against adversaries who might find a vulnerability in one algorithm class but not both. This defense-in-depth approach reflects the uncertainty inherent in novel cryptographic systems: even NIST-standardized post-quantum algorithms may have weaknesses not yet discovered, and the composite design hedges against that risk.

For Bitcoin users and developers who understand the P2TR quantum downgrade, QuanChain offers a blockchain where the concerns described in this guide simply do not apply. There is no address type that exposes public keys before spending. There is no UTXO set migration challenge. There are no Schnorr signatures waiting for a quantum computer. The post-quantum security is a property of the chain's genesis block, not a future upgrade waiting for consensus.

For a complete picture of Bitcoin's quantum vulnerability, read our guide on whether Bitcoin is quantum safe and our detailed Bitcoin quantum vulnerability explainer. For the broader harvest now, decrypt later context, see our threat guide.