Source
Mailing listPQC - What is our Goal, Even?
Added to the wiki July 15, 2026 at 09:28 PM UTC · full text archived July 15, 2026 at 09:28 PM UTC
A bitcoin-dev mailing list thread in which Matt Corallo argues the post-quantum debate keeps talking past itself because participants hold different unstated goals. His proposed goal: maximize the number of coins reasonably likely to be secured by the time a CRQC exists — equivalently, minimize the coins a future community might feel forced to freeze or burn. That, he argues, means designing for the wallets least likely to migrate (mainstream app-store wallets that reuse a single static address), not for advanced users, who will protect themselves under any design. He names two explicit non-goals: giving advanced setups the best possible post-quantum security, and settling today on the signature scheme bitcoin would use long-term.
The replies surface the fault lines that shaped the following months' debate. Erik Aronesty objects that maximizing sovereignty, not secured-coin counts, is the point of a decentralized protocol. conduition pushes back on optimizing a single metric and on Corallo's preference for a Taproot-shaped output type ("P2TRv2") over BIP-360's P2MR, arguing for a migration path that stays secure without depending on follow-up soft forks; Corallo counters that P2MR's at-rest protection means little while address reuse remains the norm. Antoine Poinsot broadly aligns with Corallo's framing.
The thread produced no resolution — it is cited here because later proposals explicitly position themselves against the goals it laid out.