Crypto Mining

This “quantum-safe” Bitcoin idea eliminates Taproot’s key path and intentionally increases fees.

Bitcoin developer contributors have just cleared a documentation hurdle that Crypto Twitter had been treating like an emergency quantum patch. It wasn’t like that.

On February 11, a proposal for a new output type, Pay-to-Merkle-Root (BIP-0360), was merged into the official Bitcoin Improvement Proposals repository. No nodes have been upgraded. There is no activation timeline.

The BIP repository itself warns that publication does not mean consensus or adoption, nor does it mean the idea is even good. What actually happened was that the draft specification met the threshold to be within range of officially documented status.

But framing P2MR reveals something more interesting than the merger itself. The Bitcoin developer community is grappling with migration problems that can’t be solved with clever cryptography alone.

The real story is that Bitcoin’s upgrade path is slow, difficult to adjust, and preparing for low-probability, high-consequence risks requires starting years before anyone agrees that the threat is real.

Current Differences Between Taproot and P2MR
Diagram comparing Taproot’s two spending options and P2MR’s single script path option, which eliminates quantum vulnerable key path spending.

Taproot without key path door

It is easy to understand P2MR if you think of it as Taproot with one piece removed.

The current Taproot output (P2TR) commits the adjusted public key. When spending from Taproot output, users have two options: use a key path (a simple signature that looks like any other Bitcoin signature) or a script path (reveal one script in the Merkle tree of possible scripts and prove that it is part of the promise).

Most Taproot spends use the key path because it is smaller and cheaper, and it does not indicate anything about whether other spend conditions existed.

P2MR completely removes the key path. Output is committed directly to the script tree Merkle root without any internal keys or key spending options.

All expenditures must disclose the script and provide Merkle proof. This makes P2MR more expensive (at least 103 bytes vs. 66 bytes for Taproot key path supervision).

The balance is intentional. P2MR eliminates the always-on attack surface that public keys create.

P2TR key spendingP2TR key spending
A chart showing Taproot key path spending, which accounts for approximately 60-80% of all P2TR transactions, sees spikes in script path usage during certain periods.

Long Exposure vs. short exposure

This distinction is important because BIP-0360 frames quantum risk through two attack models, and their defenses are different.

Long-term exposure attacks target data that is already visible on the chain, such as public keys from unused output that have been exposed for months or years. An attacker using a future quantum computer could decrypt that key offline, without time pressure.

You don’t have to win a mempool competition, but you do have to build a quantum system that can recover the private key from the public key.

However, exposure attacks have become more stringent. An attacker must recover the private key while the transaction remains unconfirmed (usually within minutes or seconds).

BIP-0360 asserts that short-exposure attacks require more advanced quantum systems and post-quantum signature frames as defenses against such windows.

P2MR does not resolve short exposures, but eliminates long exposure surfaces for Taproot-style functionality.

Migration lead time is a real constraint.

If quantum computers capable of breaking elliptic curve cryptography are still years or decades away, why submit this proposal now?

The answer has more to do with Bitcoin’s upgrade rate than its quantum timeline. Even if the risks are uncertain, a safe transition path requires several sequential steps: specification, implementation, review, activation discussions, wallet and exchange support, user training, and gradual migration.

Each step takes months or years. Starting early gives you options. Because waiting for certainty means starting too late.

BIP-0360’s tone is “I’m not afraid, I’m prepared.”

This proposal does not claim that quantum computers will break Bitcoin in 2027 or 2030. The proposal argues that Bitcoin should adopt the low-risk TabScript default output type to avoid extended exposure before post-quantum signatures are ready.

The logic is future-oriented. Taproot and tapscript are modern scripting languages ​​for the advanced Bitcoin protocol.

If you think these tools are important to your Lightning, commitments, or other smart contract use cases, having a version of that functionality without the risk of long-term exposure is a useful component.

The timing also reflects a shift in the way quantum risk is discussed in Bitcoin circles.

BIP-0360 explicitly addresses criticism that Bitcoin developers are not taking quantum threats seriously.

The addition of Isabel Foxen Duke as a co-author indicates someone’s focus on making the proposal understandable for a general audience, not just core developers, and an intention to make quantum preparations readable and accessible.

Recent academic research has also discussed quantum risks in more detail. The paper on benchmarking hybrid post-quantum signatures and elliptic curve cryptanalysis in quantum systems provides quantitative resource estimates rather than vague warnings.

Science is advancing, although the timeline is uncertain.

Opt-in migration, not auto-protection

If P2MR is activated, this is an important “if” considering that activation requires widespread consensus and a successful soft fork deployment, and changes are optional, not mandatory.

The wallet adds support for new address types starting with bc1z, corresponding to SegWit version 2. Users who wish to reduce their risk of long-term exposure can create a P2MR address and send funds to that address.

CryptoSlate Daily Summary

Daily signal, no noise.

Read the market-moving headlines and context in one go every morning.