Price:

Ahmet Kirk unveils post quantum Lightning network

Oct 2, 2026Summary from 1 podcast.
  • Developer Ahmet Kirk built a post-quantum Lightning prototype to protect off-chain transactions from future decryption.
  • The architecture maintains existing onion packet sizes but increases node gossip bandwidth up to tenfold.
  • Bitcoin Core launched community testing for version 32.0, replacing its legacy HTTP server.

Quantum computers do not need to crack the Bitcoin blockchain to break Lightning privacy.

Adversaries only need to store encrypted off-chain traffic today and decrypt it once quantum hardware arrives. On October 1, 2026, Bitcoin Optech detailed the Post-Quantum Lightning Network (PQLN), an 11,000-line Rust prototype built by researcher Ahmet Kirk and co-author Abdullah. The implementation secures transport, gossip, and onion routing without forcing a base-layer hard fork on Bitcoin Core.

"The quantum threat to Bitcoin is closer off-chain than on-chain."

- Ahmet Kirk, Bitcoin Optech

Kirk's architecture tackles the physical limits of Lightning routing by preserving the protocol's fixed 1,300-byte onion packet size. Instead of stuffing heavy post-quantum ciphertexts into the onion itself, PQLN routes per-hop secrets alongside payment messages across 20 fixed update slots. Transport security relies on BIP 8 to run classical and post-quantum keys side by side, while Bolt 11 invoices split larger signatures across four distinct tag fields to pass through Rust Lightning's 639-byte message ceiling.

That backward compatibility comes at a steep network cost. Running NIST-standardized MLDSA-44 signatures multiplies node gossip bandwidth tenfold, though switching to non-standardized Falcon signatures drops the overhead to four times standard traffic. Yet Kirk proved off-chain quantum mitigation works today with minimal signing latency, adding just 0.33 milliseconds of signing overhead across 100 benchmark tests.

While Kirk focuses on future cryptographic threats, Bitcoin Core contributor Jan B opened community testing for version 32.0 ahead of its fall launch. The upcoming release completely strips out libevent in favor of a strict custom HTTP server, enforcing tighter RFC rules for RPC and REST calls that could break legacy downstream software.

"Automated software tests cannot replicate a node running in someone's closet."

- Jan B, Bitcoin Optech

Core 32.0 also shifts default behavior to PSBT version 2 and adds parallel coin fetching to speed up node synchronizations. Downstream teams face immediate work to ensure third-party block explorers and hardware wallets handle the stricter RPC formatting before full deployment.

These protocol shifts arrive alongside urgent security maintenance across the Lightning ecosystem. Core Lightning developers released version 26.06.8 to fix a bug where malicious peers could trick nodes into skipping penalty transactions on revoked channels by sending fake shutdown requests.

Additional patches in Core Lightning PR 9507 capped fee rates at 4,000 satoshis per vbyte to stop database overflow crashes during channel splices. Meanwhile, LND updated its Atomic Multipath Payments to prevent whole-invoice cancellations on single-path failures, illustrating the constant state-machine maintenance required while long-term post-quantum defenses take shape.

Source Intelligence

- Deep dive into what was said in the episodes

Bitcoin Optech: Newsletter #424 Recap • Oct 1

  • Ahmet Kirk argues that even if Bitcoin receives an on-chain post-quantum upgrade, Lightning's off-chain components like gossip and onion routing remain vulnerable. Decoupled upgrades are necessary because attackers could record current traffic to decrypt it later.
  • Ahmet Kirk's proposal distributes post-quantum node identities via gossip, upgrading two of three gossip messages while leaving channel announcements classical. The transport layer relies on BIP 8 to integrate post-quantum primitives next to classical ones.
  • Ahmet Kirk states that Bolt 11 post-quantum signatures fit within QR code limits using MLDSA-44 signatures. Because Rust Lightning has a 639-byte message limit, PQLN splits the signature across four tag fields.
  • To keep onion packets under the 1,300-byte limit, Ahmet Kirk's design avoids sending 1,088-byte MLKEM ciphertexts inside the onion. Instead, per-hop secrets are made hybrid and travel alongside the onion in a fixed-size list of 20 slots.
  • Ahmet Kirk reports that PQLN adds 11,000 lines of Rust code and 100 tests. MLDSS signing adds a negligible 0.33 milliseconds of overhead, but gossip bandwidth increases tenfold with MLDSA-44 or fourfold with Falcon.
  • Core Lightning 26.06.8 acts as a security release that temporarily withholds certain tests to prevent attackers from finding vulnerabilities. PR 9507 caps peer-proposed fee rates at 4,000 sats per vB to prevent overflow bugs that crash restarting nodes.
  • Core Lightning fixed vulnerabilities where peers could trick nodes into ignoring force-closed revoked commitments by sending a decoy shutdown message. Other fixes address nodes losing splice signature memory across restarts and limit peers to three concurrent negotiations.
  • LND updated its Atomic Multipath Payments (AMP) logic to prevent whole-invoice cancellations when a single path fails. Additionally, LND introduced validation logic ensuring returned Bolt 12 invoices are signed by the actual receiver.
Also discussed on this episode: (7)

Protocol (4)

  • Jan explains that Bitcoin Core 32.0 release candidate 2 is feature-complete ahead of its October 10th target. The associated testing guide covers 10 tests across four groups on Regtest, focusing on new RPCs and the HTTP server rewrite.
  • Jan highlights key Core 32.0 features, including getopenrpcinfo for machine-readable RPC diffs, PSBT version 2 by default, and exportwatchonlywallet for phone tracking. The HTTP server is rewritten from scratch to remove libevent and enforce stricter RFC compliance.
  • A Stack Exchange contributor explains that Taproot commits to every individual input amount rather than just the sum. Committing only to the total allows a malicious machine to shuffle amounts between inputs to steal funds in a coinjoin.
  • Bitcoin Knots nodes that split off during the failed BIP 110 activation in August do not need a full re-sync. Because the minority chain quickly stalled, pruned nodes still hold the last common block and can reorg automatically.

Lightning (3)

  • Core Lightning PRs 9510 and 9511 mitigate crash risks by capping JSON nesting to 256 levels and rejecting oversized DNS hostnames. PR 9513 now validates that Bolt 12 fetched invoice amounts do not exceed requested or offered parameters.
  • LDK 0.3 release candidate 2 introduces RBF fee bumping for stuck splices, defaults to negotiating anchor channels, and invalidates older Bolt 11 invoices. The LDK project has also migrated its repository off GitHub to a self-hosted mirror.
  • LND restored Bolt 1 compliance by ensuring it replies to all valid ping messages. This fix preserves the inbound rate-limiting and bucket protections against ping-based denial of service attacks introduced in a previous release.