Whatever happens with quantum computers and whatever happens with bitcoin, most bitcoin addresses (IIUC both legacy P2PKH and segwit) publish the public key only upon spending the utxo (funds), thus the time of exposure is very limited, i.e. not vulnerable in rest. It's because those transactions include hashes instead of public keys.
Hashes are not inherently more vulnerable. In those cases, public key is only made known when the spending transaction is formed and submitted thus when the funds are moved. (But only if you didn't reuse P2PKH keys as is generally advised.)
Don't take my word for it. Read up on it yourself to be sure. Tell me if I'm wrong.
I'd love to know if there is an additional risk involving SHA256.
Ostry
npub10q8s...4qv3
Well, this could've been a goal.
View quoted note →