Samson Mow Warns Against Rushing Bitcoin Post-Quantum Cryptography Migration

Editorial illustration for: Samson Mow Warns Against Rushing Bitcoin's Post-Quantum Cryptography Migration

In brief

  • Samson Mow warns rushing post-quantum migration exposes Bitcoin to immediate classical computing risks
  • Anthropic AI discovered new attacks against weakened cryptographic algorithms
  • Hash-based schemes offer better security margins than lattice-based alternatives like HAWK
  • Crypto-agility enables algorithm swaps without requiring full system redesign

The Case for Conservative Migration

Mow argued that replacing Bitcoin's ECDSA and Schnorr signature schemes with post-quantum alternatives too early could inadvertently weaken the network against conventional computers. Bitcoin should only migrate to post-quantum signatures once quantum computers actually pose a practical threat, he stated. Slow, conservative development is the right approach.

His timing matters. Anthropic published research showing that its AI model, Mythos Preview, discovered new attacks against weakened cryptographic algorithms. The model found a substantially faster attack against a reduced-round version of the Advanced Encryption Standard (AES), and researchers reported improvements to a known private-key recovery attack targeting HAWK, a lattice-based post-quantum scheme.

Neither discovery poses an immediate threat, according to Anthropic. But the findings underscore Mow's core concern: rushing cryptographic transitions introduces unforeseen vulnerabilities.

Hash-Based Schemes and Crypto-Agility

Mow praised ongoing research by Blockstream cryptographers, noting that hash-based schemes have a smaller mathematical attack surface than lattice-based alternatives like HAWK. This distinction matters for Bitcoin's long-term security posture.

Ledger Chief Technology Officer Charles Guillemet said the research shows how rapidly artificial intelligence is changing cybersecurity. He noted that Anthropic's paper specifically affects HAWK's newer security assumptions rather than lattice cryptography as a whole. Guillemet argued that the findings reinforce the need for crypto-agility, the ability to replace cryptographic algorithms without redesigning an entire system.

That flexibility is Bitcoin's real hedge against both quantum and AI-driven cryptographic breakthroughs. Migration on a timeline driven by threat evidence, not speculation, keeps the network secure today while preparing for tomorrow.

Frequently asked questions

Why should Bitcoin wait before adopting post-quantum cryptography?

Mow argues that premature migration from ECDSA and Schnorr to post-quantum schemes could expose Bitcoin to conventional computing attacks today. Bitcoin should migrate only when quantum computers pose a practical threat, not before. This conservative approach prioritizes immediate security over speculative future risks.

What did Anthropic's AI discover about cryptographic algorithms?

Anthropic's AI model, Mythos Preview, discovered a substantially faster attack against a reduced-round version of AES and improvements to a known private-key recovery attack targeting HAWK. However, neither discovery poses an immediate threat to deployed systems.

What is crypto-agility and why does it matter?

Crypto-agility is the ability to replace cryptographic algorithms without redesigning an entire system. Guillemet argued that this flexibility is critical because it allows networks like Bitcoin to swap algorithms if new vulnerabilities emerge, whether from quantum computers or AI research.