Bitcoin quantum security and mass adoption: ZK STARKs is the best solution?
StarkWare co-founder Eli Ben-Sasson believes that ZK STARKs is the best way to solve Bitcoin\'s quantum security issues while achieving large-scale adoption. He also claimed that Blockstream founder Adam Back agreed with this view.
Ben-Sasson made the news this week when he made a controversial proposal on social platforms to increase Bitcoin\'s annual inflation rate to 4%. Relevant analysis shows that the proposal \"did not receive clear support.\"
But as a co-inventor of STARKs, a hash-based zero-knowledge proof of quantum security, his stance is more solid and is supported by some leading Bitcoin researchers. Ben-Sasson\'s own project, Starknet, also announced last week its three-phase plan to achieve quantum security.
Large-volume post-quantum signature problem on Bitcoin
Adding zero-knowledge proof to Bitcoin does not in itself make the blockchain quantum secure. The ZK proof is a way to solve the problems caused by introducing a larger post-quantum signature scheme into Bitcoin.
The post-quantum signature scheme currently approved by the National Institute of Standards and Technology is 10 to 100 times larger than Bitcoin\'s existing ECDSA and Schnorr signature schemes. Some believe this could slow down blockchain processing to less than 1 transaction per second. But all large-volume transaction signatures in a block can be compressed into a tiny ZK STARK proof. Because the proof is even much smaller than just containing existing signatures, the blockchain may eventually run faster.
Ben-Sasson said: \"If they didn\'t allow ZK STARK aggregation, it would be a very unfortunate move because it doesn\'t really solve the problem... the question is \'Can everyone actually use Bitcoin?\' To do this, you need huge scale expansion. And to do that, you need something like signature aggregation, and just increasing the block size is not enough.\"
Quantum Alternative: Increase Bitcoin Block Size
Marin Ivezic, author of PostQuantum.com and founder of Applied Quantum, told the media that Bitcoin\'s SegWit solution reduces the impact of large signatures by 75%. But when he modeled NIST\'s ML-DSA-44 scheme (2420 bytes per signature), he found that \"the block capacity would drop to approximately 500 to 700 transactions, compared to 2500 to 3000 currently.\" This is where the block size debate comes from.\"
Increasing the size of the Bitcoin block is a real alternative, but the community was divided in 2017 over a proposal to double the block size. Many of the reasons for opposition at the time still apply today because it was a crude repair that required each node to carry, store and verify more data. It costs more and requires more equipment, which critics say will decentralize the network.
Blockstream Research has been trying to compress the volume of a hash-based post-quantum signature scheme in recent months for use on Bitcoin. They have proposed promising SHRINCS and SHRIMPS solutions, whose daily signature volume is about 5 times the current signature size of Bitcoin, but if you lose your wallet and need to be restored, the signature volume can be as high as 40 times. Although SHRINCS has been used to sign real transactions on Liquid sidechains, its development is still in its early stages and suffers from flaws in complexity and usability. Unless the block size is increased, these much larger signatures will also slow down the blockchain.
Marin Ivezic said of increasing block size: \"Increasing capacity locally is the simple engineering answer, but it is also the most difficult governance answer. We don\'t have time for those debates anymore.\"
ZK proves that polymerization has advantages
ZK proves that aggregation does increase capacity, but it can be said that it improves Bitcoin efficiency while more effectively maintaining decentralization. Simply put, ZK proof is a mathematical method of proof that can prove the existence of something without revealing all the details. For example, a ZK certificate can prove that you know the password to the safe without having to tell the other party what the password is.
Technically, it only takes to generate ZK certificates for a single block once (although it is safer to generate additional copies for redundant backups), and the equipment cost required appears to be much lower than commercial mining equipment. Lean Ethereum\'s specifications prove that the equipment costs less than $100,000 (it can run in an average home). Verification of ZK certification can be done on almost any device, including the Raspberry Pi.
Ben-Sasson said that early Bitcoin developers Greg Maxwell and Mike Hearn were \"very optimistic about ZK STARKs because it has post-quantum security and requires no trusted settings,\" and he believes Bitcoin Core developer Luke Dashjr and Blockstream founder Adam Back are also embracing the idea. \"I heard them say this with my own ears. They are optimistic about things related to ZK STARKs and taking advantage of them. I think each of them has expressed support in private and even in public. Adam Back and Luke Dashjr don\'t always agree, but on this, I think they agree that this is a great technology that can be applied to Bitcoin under the right conditions.\" Adam Back was contacted by media seeking comment but was not returned.
Ethereum researcher Justin Drake has publicly stated that he hopes Bitcoin will adopt Lean Ethereum\'s ZK proof aggregation technology to make it an industry standard. But this may not be feasible for political reasons.
Bitcoin exclusive ZK proposal
Given Bitcoin\'s conservative culture, from the most politically pragmatic perspective, the most likely way to add ZK functionality to Bitcoin is to re-enable OP_CAT, which is nine lines of code written by Satoshi Nakamoto. Ben-Sasson said: \"He introduced it and removed it. If you add it, you can achieve STARK proof, aggregation, and post-quantum security. I think this is the best and safest solution that will really restart the journey Satoshi Nakamoto really started and hopes to achieve.\" Although interest in OP_CAT surged about 12 to 24 months ago, it seems to have lost momentum recently.
There are also some more exploratory proposals, including OP_STARK_VERIFY, which will add opcodes specifically designed to more efficiently verify STARKs on Bitcoin. Ethan Heilman, co-author of BIP-360, proposed aggregating Bitcoin\'s signature and public key into a STARK certificate called BitZip. Heilman told reporters earlier this year that there are two main ways to achieve the desired results: \"Either add a bunch of universal opcodes to Bitcoin and then build something similar to ZK Rollup on Bitcoin, or support STARKs in Bitcoin\'s consensus layer.\" Alternatively, other weaker aggregation solutions, such as CISA, may also help.\"
What are the chances ofbeing implemented?
Ivezic said the crux lies in Bitcoin\'s governance, not technical capabilities. \"Eli\'s cryptography is rock-solid: a pure hash assumption, no trusted settings, thousands of signatures compressed into a small proof. The problem lies in everything other than cryptography. Bitcoin scripts currently cannot verify STARK, and a production-level verifier is a huge consensus surface compared to a narrow hash signature opcode. Given that a small opcode like OP_CAT has been debated for years, the STARK validator at the foundation level will realistically not be discussed until the 2030s.\"
Meanwhile, Ethereum aims to transition to the post-quantum era by 2029, and Solana has also been experimenting with adding post-quantum signatures. StarkNet\'s three-phase transition will benefit from account abstraction, which allows the underlying cryptography to be upgraded without having to manually migrate to a new account. As a result, Ben-Sasson said the post-quantum roadmap for Solana and Ethereum will be \"extremely difficult.\" \"At Starknet, we have a huge advantage because we already have native account abstractions and smart wallets, which means nothing is fixed, so it\'s very easy to upgrade wallets and infrastructure for post-quantization.\"

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH
SOL