BTQ Docs
Concepts

Security Model

Threat analysis and defense layers in the BTQ protocol

Security Model

BTQ's security model builds on Bitcoin's proven foundations while adding a new cryptographic layer to defend against quantum attacks. This page provides a comprehensive analysis of the threats BTQ addresses, the threats it inherits from Bitcoin, and the defense mechanisms at each layer.

Threat Categories

Security threats to a blockchain fall into three broad categories:

1. Cryptographic Attacks

These target the mathematical foundations of the system: signature schemes, hash functions, and key derivation.

  • Classical cryptographic attacks: Attempts to forge signatures or find hash collisions using conventional computers
  • Quantum cryptographic attacks: Using quantum algorithms (Shor's, Grover's) to break cryptographic primitives

2. Network Attacks

These target the peer-to-peer network and consensus mechanism:

  • 51% attacks: An entity controlling majority hash power can rewrite recent history
  • Eclipse attacks: Isolating a node from honest peers
  • Sybil attacks: Creating many fake identities to influence the network
  • Selfish mining: Withholding blocks to gain a disproportionate share of rewards

3. Application-Level Attacks

These target individual users rather than the protocol:

  • Double spending: Sending the same coins to two recipients
  • Key theft: Stealing private keys through malware, phishing, or physical access
  • Address reuse exploitation: Attacking addresses whose public keys have been revealed

What BTQ Protects Against

Shor's Algorithm (Signature Forgery)

This is the primary threat BTQ was built to address. Shor's algorithm, running on a sufficiently powerful quantum computer, can derive a private key from a public key in polynomial time. This completely breaks ECDSA, the signature scheme used by Bitcoin.

BTQ's defense: Dilithium2 signatures are based on the Module Learning with Errors (MLWE) problem, a lattice problem for which no efficient quantum algorithm is known. Dilithium provides 128 bits of quantum security, meaning even a quantum computer would need an infeasible amount of computation to forge a signature.

Harvest Now, Decrypt Later

Adversaries are already recording blockchain data today with the expectation of decrypting it when quantum computers become available. Every Bitcoin transaction that reveals a public key creates a permanent record that a future quantum computer could exploit.

BTQ's defense: Dilithium addresses never expose a quantum-vulnerable public key. The public key committed to the blockchain (as a hash in the UTXO) cannot be reversed, and the full public key revealed during spending is quantum-resistant. Funds moved to Dilithium addresses are protected both now and in the future.

This protection only applies to Dilithium addresses. ECDSA addresses on BTQ carry the same quantum risk as Bitcoin addresses. Users should migrate funds to Dilithium addresses to benefit from quantum resistance.

Public Key Exposure

In Bitcoin, spending from an address reveals the full public key on the blockchain. For ECDSA addresses, this means a quantum computer could compute the private key and steal any remaining funds sent to that address.

BTQ's defense: When spending from a Dilithium address, the revealed public key is quantum-resistant. Even with full knowledge of the public key, a quantum adversary cannot derive the private key.

What BTQ Does NOT Change

BTQ inherits Bitcoin's security model for threats unrelated to signature cryptography. These are well-understood and remain unchanged:

51% Attack Resistance

An attacker with more than 50% of the network's hash power can:

  • Reverse their own recent transactions (double spending)
  • Prevent specific transactions from being confirmed
  • Prevent other miners from finding valid blocks

An attacker with majority hash power cannot:

  • Steal coins from other users (private keys are still required)
  • Create coins out of thin air (invalid blocks are rejected by all nodes)
  • Change old, deeply-buried transactions (cost grows exponentially with depth)

BTQ's 51% attack resistance is proportional to the total hash power securing the network, just like Bitcoin.

Double-Spend Protection

Protection against double spending comes from confirmation depth:

ConfirmationsTime (~1-min blocks)Security Level
0 (mempool)0 minutesUnconfirmed, vulnerable
1~1 minuteInitial inclusion
3~3 minutesSuitable for small values
6~6 minutesStandard security
60+~1 hourHigh-value transactions

With 1-minute blocks, BTQ achieves the same confirmation security as Bitcoin in one-tenth the wall-clock time.

Transaction Finality

Like Bitcoin, BTQ has probabilistic finality. Transactions become exponentially harder to reverse as more blocks are built on top of them. There is no absolute finality point, but after 6 confirmations the probability of reversal is negligible for all practical purposes.

Quantum Impact on Mining

Grover's Algorithm and SHA-256

Grover's algorithm provides a quadratic speedup for searching unstructured data. Applied to SHA-256 mining, it would effectively halve the security level:

PropertyClassicalPost-Quantum
SHA-256 security256 bits128 bits
Brute-force difficulty2^256 operations2^128 operations
Practical impactSecureStill secure

128-bit security remains far beyond any feasible attack. For context, 2^128 operations would require more energy than the sun produces in its entire lifetime.

Why This Is Less Urgent Than Signatures

FactorSignature AttackMining Attack
ImpactFunds stolen directlyEconomic advantage in mining
VictimIndividual usersNetwork fairness
ReversibilityPermanent lossDifficulty adjustment compensates
UrgencyMust fix before quantum arrivesCan address later if needed
HardwareSoftware-only attackRequires quantum mining hardware (doesn't exist)

The signature threat is existential: someone can steal your money. The mining threat is economic: someone can mine more efficiently. BTQ prioritizes the existential threat.

If quantum mining ever becomes practical, the proof-of-work algorithm can be upgraded through a hard fork. The hash function is a network parameter, not a fundamental architectural choice.

Defense in Depth

BTQ's security is not a single mechanism but multiple independent layers:

Layer 1: Cryptographic

  • Dilithium2 signatures: 128-bit quantum security for transaction authorization
  • SHA-256 hashing: 128-bit post-quantum security for proof of work and address derivation
  • RIPEMD-160: Additional hashing layer in address derivation hides the public key until spending

Layer 2: Economic

  • Mining cost: Attacking the network requires sustained expenditure exceeding the potential gain
  • Fee market: Transaction fees create ongoing incentive for miners to behave honestly
  • Block rewards: New coin issuance funds network security during the bootstrap period

Layer 3: Network

  • Decentralized validation: Every full node independently verifies every transaction and block
  • Peer-to-peer propagation: No single point of failure for transaction or block distribution
  • Peer scoring: Nodes that relay invalid data are penalized and eventually disconnected

Layer 4: Protocol

  • Confirmation depth: Security increases exponentially with each additional block
  • Coinbase maturity: 100-block waiting period prevents miners from spending rewards that might be invalidated by a reorganization
  • Difficulty adjustment: Maintains consistent block timing regardless of changes in hash power

NIST Standardization

Dilithium was standardized by NIST as FIPS 204 in 2024 after a seven-year evaluation process involving hundreds of researchers worldwide. This standardization provides:

  • Confidence: The algorithm has been scrutinized by the global cryptographic community
  • Longevity: NIST standards are typically maintained for 20+ years
  • Regulatory acceptance: Government and enterprise use cases require NIST-approved cryptography
  • Interoperability: A standard specification ensures consistent implementations

BTQ uses the exact parameters specified in the Dilithium2 (ML-DSA-44) standard, with no custom modifications to the core algorithm.

Comparison with Other Post-Quantum Approaches

ApproachSecurity BasisMaturityBTQ Status
Dilithium/ML-DSA (lattice)MLWE hardnessNIST standardized (2024)Active
Falcon (lattice)NTRU latticesNIST standardized (2024)Future consideration
SPHINCS+ (hash-based)Hash function securityNIST standardized (2024)Future consideration
Hybrid ECDSA+DilithiumBoth classical and quantumResearch phaseRoadmap item

BTQ's architecture is designed to be cryptographically agile: if a weakness is discovered in Dilithium, the protocol can adopt alternative post-quantum schemes through a coordinated upgrade.

Migration Security

The transition from ECDSA to Dilithium addresses is a critical security operation:

Safe Migration Steps

  1. Generate a Dilithium address on the BTQ network
  2. Transfer funds from ECDSA addresses to the new Dilithium address
  3. Verify the transfer is confirmed with adequate depth
  4. Stop using the ECDSA address for receiving new funds

Migration Risks

  • Incomplete migration: Funds left in ECDSA addresses remain quantum-vulnerable
  • Address reuse: Reusing an ECDSA address after spending from it exposes the public key
  • Lost access: If wallet access is lost, funds in ECDSA addresses cannot be migrated

The migration window is not infinite. Once quantum computers can break ECDSA, any funds remaining in ECDSA addresses with exposed public keys are at risk. The time to migrate is before quantum computers arrive, not after.

Known Limitations

LimitationStatusMitigation
No HD wallet derivation for DilithiumStandalone keys onlyFuture protocol upgrade planned
ECDSA addresses still supportedQuantum-vulnerable if usedMigration path available; auto-detection supports both
Larger transaction sizesHigher bandwidth requirements8 MB blocks, witness discount, 1-minute block times
No quantum-resistant proof of workSHA-256 uses classical PoW128-bit post-quantum security sufficient; upgradeable later

Learn More

On this page