Price:

Ahmet Kirk builds post quantum Bitcoin Lightning tool

Oct 3, 2026Summary from 1 podcast.
  • Developers built a post-quantum Lightning prototype using MLDSA-44 signatures to protect off-chain payments.
  • Standardized MLDSA-44 signatures increase node gossip bandwidth tenfold, while Falcon signatures reduce overhead to fourfold.
  • AI optimization models cut post-quantum Bitcoin transaction generation costs from $320 to $67.

Quantum decryption threatens off-chain Bitcoin long before base-layer transactions.

On September 28, 2026, Bitcoin And | Bitcoin & Economic News highlighted how AI models like Anthropic's Opus 5 and OpenAI's GPT-6 Astra slashed the GPU cost of building post-quantum Bitcoin transactions from $320 down to $67 in one week. Host David Bennett noted these GPU-heavy computations prove research progress without altering base-layer consensus rules, though transactions currently require direct routing to cooperative miners.

"The math got fast."

- David Bennett, Bitcoin And | Bitcoin & Economic News

While base-layer upgrades remain a distant debate, off-chain networks face immediate risks. Adversaries can record encrypted network traffic today and decrypt it once quantum hardware arrives. On October 1, 2026, Bitcoin Optech detailed researcher Ahmet Kirk and co-author Abdullah's Post-Quantum Lightning Network prototype, built to secure off-chain surfaces without requiring a base-layer hard fork.

"The quantum threat to Bitcoin is closer off-chain than on-chain."

- Bitcoin Optech

Kirk's design preserves classical 1,300-byte onion packets by routing post-quantum secrets alongside HTLC messages in fixed 20-slot updates. To stay within QR code limits, Bolt 11 post-quantum signatures use MLDSA-44 split across four tag fields. The implementation adds 11,000 lines of Rust code and 100 tests, proving off-chain defenses are viable today.

Backward compatibility carries heavy trade-offs. Nodes using NIST-standardized MLDSA-44 signatures face a tenfold increase in gossip bandwidth, though switching to non-standardized Falcon signatures reduces overhead to fourfold. MLDSS signing adds just 0.33 milliseconds of computation, but the network footprint highlights the real-world friction of off-chain post-quantum migration.

Off-chain security extends beyond future quantum risks to current operational vulnerabilities. Bitcoin Optech reported emergency security updates for Core Lightning, fixing flaws where malicious peers could trick nodes into ignoring force-closed revoked commitments. Developers also capped peer-proposed fee rates at 4,000 satoshis per vByte to eliminate database overflow crash loops upon node restart.

Downstream testing for Bitcoin Core 32.0 further reflects off-chain complexity. Contributor Jan B emphasized that unit test suites cannot replace real-world validation on hardware wallets and Lightning daemons, particularly after replacing the legacy libevent library with a strict custom HTTP server enforcing rigid RPC formatting.

Hardening Bitcoin for the quantum era requires securing every layer against current bugs and future physics.

Source Intelligence

- Deep dive into what was said in the episodes

Bitcoin Optech: Newsletter #424 Recap • Oct 1

  • Ahmet Kirk argues that even if Bitcoin receives an on-chain post-quantum upgrade, Lightning's off-chain components like gossip and onion routing remain vulnerable. Decoupled upgrades are necessary because attackers could record current traffic to decrypt it later.
  • Ahmet Kirk's proposal distributes post-quantum node identities via gossip, upgrading two of three gossip messages while leaving channel announcements classical. The transport layer relies on BIP 8 to integrate post-quantum primitives next to classical ones.
  • Ahmet Kirk states that Bolt 11 post-quantum signatures fit within QR code limits using MLDSA-44 signatures. Because Rust Lightning has a 639-byte message limit, PQLN splits the signature across four tag fields.
  • To keep onion packets under the 1,300-byte limit, Ahmet Kirk's design avoids sending 1,088-byte MLKEM ciphertexts inside the onion. Instead, per-hop secrets are made hybrid and travel alongside the onion in a fixed-size list of 20 slots.
  • Ahmet Kirk reports that PQLN adds 11,000 lines of Rust code and 100 tests. MLDSS signing adds a negligible 0.33 milliseconds of overhead, but gossip bandwidth increases tenfold with MLDSA-44 or fourfold with Falcon.
  • Core Lightning 26.06.8 acts as a security release that temporarily withholds certain tests to prevent attackers from finding vulnerabilities. PR 9507 caps peer-proposed fee rates at 4,000 sats per vB to prevent overflow bugs that crash restarting nodes.
  • Core Lightning fixed vulnerabilities where peers could trick nodes into ignoring force-closed revoked commitments by sending a decoy shutdown message. Other fixes address nodes losing splice signature memory across restarts and limit peers to three concurrent negotiations.
  • Core Lightning PRs 9510 and 9511 mitigate crash risks by capping JSON nesting to 256 levels and rejecting oversized DNS hostnames. PR 9513 now validates that Bolt 12 fetched invoice amounts do not exceed requested or offered parameters.
Also discussed on this episode: (7)

Protocol (4)

  • Jan explains that Bitcoin Core 32.0 release candidate 2 is feature-complete ahead of its October 10th target. The associated testing guide covers 10 tests across four groups on Regtest, focusing on new RPCs and the HTTP server rewrite.
  • Jan highlights key Core 32.0 features, including getopenrpcinfo for machine-readable RPC diffs, PSBT version 2 by default, and exportwatchonlywallet for phone tracking. The HTTP server is rewritten from scratch to remove libevent and enforce stricter RFC compliance.
  • A Stack Exchange contributor explains that Taproot commits to every individual input amount rather than just the sum. Committing only to the total allows a malicious machine to shuffle amounts between inputs to steal funds in a coinjoin.
  • Bitcoin Knots nodes that split off during the failed BIP 110 activation in August do not need a full re-sync. Because the minority chain quickly stalled, pruned nodes still hold the last common block and can reorg automatically.

Lightning (3)

  • LDK 0.3 release candidate 2 introduces RBF fee bumping for stuck splices, defaults to negotiating anchor channels, and invalidates older Bolt 11 invoices. The LDK project has also migrated its repository off GitHub to a self-hosted mirror.
  • LND updated its Atomic Multipath Payments (AMP) logic to prevent whole-invoice cancellations when a single path fails. Additionally, LND introduced validation logic ensuring returned Bolt 12 invoices are signed by the actual receiver.
  • LND restored Bolt 1 compliance by ensuring it replies to all valid ping messages. This fix preserves the inbound rate-limiting and bucket protections against ping-based denial of service attacks introduced in a previous release.