Anchorage Digital, a regulated crypto bank, has introduced a strategy aimed at preparing institutional assets for the post-quantum era. The organization also announced the implementation of hybrid protection for its internal TLS connections.
The primary risk for cryptocurrencies stems not from mining or hashing but rather from digital signatures. Shor's algorithm theoretically enables the computation of a private key from an exposed public key.
“Quantum computing is not a moment, but a migration. At Anchorage Digital, we have been building the infrastructure for this migration from day one,” stated Nathan McCauley, co-founder and CEO of the crypto bank.
According to Anchorage, client bitcoins are in a more secure position by utilizing addresses based on the hash of the public key. This approach keeps the key hidden until a transaction is sent, and the company adheres to the practice of minimizing address reuse.
Regarding TLS connections, the organization mentioned that employee-managed devices running ChromeOS are already using post-quantum key encapsulation — a key agreement mechanism designed to withstand future quantum attacks.
An additional component of the strategy includes hardware security modules where cryptographic keys are stored and processed. Anchorage has indicated that it is deploying post-quantum cryptography within its production infrastructure and is testing the performance of various algorithms.
Beyond internal measures, Anchorage has proposed a mechanism known as Post-Quantum Turnstile to transition legacy accounts to post-quantum keys. This mechanism utilizes STARK — a type of zero-knowledge proof that allows verification of knowledge of a secret without revealing it and does not require a trusted setup.
This concept addresses one of the challenges associated with the future migration of Bitcoin. If the network were to ever disable classical signatures, some funds on addresses with undisclosed public keys would remain secure from quantum attacks but could become inaccessible to their owners. The Turnstile mechanism offers a way to transfer signing rights to a post-quantum key without disclosing the old private or public key.
Anchorage estimates that this approach could be applicable to roughly two-thirds of the circulating coins.
The crypto bank has also released the source code for sqisign-rs, an implementation of the SQIsign digital signature scheme in Rust. Representatives claim that SQIsign produces signatures approximately seven times smaller than those generated by Falcon.
Previously, analysts from Glassnode estimated that around 6 million BTC on addresses with exposed public keys could be at risk from quantum attacks.
It is worth noting that in May, developers from Quantus pointed out the crypto market's unpreparedness for a transition to post-quantum cryptography.
