Thanks for the reply; after three months, I had given up hope of hearing back from anyone ![]()
In principle I agree with you, but on the point that a PQ L2 is useless, no. Actually, the more I think about it, the more the argument turns against itself.
Because the L2 doesn’t add the vulnerability, it inherits it. If a quantum computer can derive the private key from an L1 public key, it can steal those funds directly on-chain, with or without an L2. A peg-in with a classical signature isn’t a flaw of the layer, it’s the cost of spending a UTXO on Bitcoin, full stop. So an L2 like this is as secure as the L1 against the quantum threat: if your reasoning made the L2 useless, it would make Bitcoin itself useless too. Immaterial for fund security, as you say, but fund security isn’t the only thing a payment system has to offer.
Then there’s the role. If the L2 were created to replace the L1, then yes, it would be useless, and on that I agree with you. But the role of a layer like this is to make Bitcoin easier to use for payments (the reason Bitcoin was created), and there the post-quantum properties matter a lot. Privacy, for example: the L1 doesn’t offer it at all. An adversary who intercepts and stores encrypted traffic today will decrypt it tomorrow, once a quantum computer exists. PQ signatures and encryption off-chain protect today’s payments from tomorrow’s attack, and that value doesn’t depend in any way on whether the L1 is PQ.
On custody you’re right, and in my case even more than you say: a custodial channel concentrates many users’ funds under a few keys, a bigger target than average. That’s exactly why the peg-out is designed as a commitment-based claim, with the classical signature reduced to a single moment, the final one. Minimizing the number and the window of exposure is the only engineering answer possible as long as the L1 stays as it is. It doesn’t make it perfect, it makes it as little exposed as possible.
About preparing. When the L1 adopts something like P2QRH (BIP-360), QuBit or Lamport signatures in Script, an off-chain layer that is already PQ can migrate the peg the same day without redesigning anything and without unlocking user’s founds. Today’s work is the prerequisite for tomorrow’s migration.
In the end, the point of my original post was exactly this: what does “post-quantum” actually mean for an L2 when settlement happens on a non-PQ L1? I don’t think the answer is definitive, it depends on the phase we’re in. Right now Bitcoin’s L1 is not yet post-quantum, so a post-quantum L2 has the function, beyond the one it was created for, of reducing as much as possible the sensitive information that can be collected today and decrypted tomorrow. If one day Bitcoin itself becomes PQ resistant, then a PQ L2 will take on a different definition. I don’t claim it’s already perfect, but the fact that it already exists means someone is thinking and acting to face this challenge, instead of doing everything at the last second.
What do you think? Have you worked hands-on on anything in this space, or is this a concern you’ve looked at from the outside?