Safety

Responsible quantum cryptanalysis

Potomac is developing the algorithms and software needed to use quantum computers for practical cryptanalysis. Our long-term objective includes recovering inaccessible Bitcoin and returning assets through a credible claims and governance process. This is a technical ambition with consequences well beyond a research benchmark.


The question

Capability and authority

The same capability that might support recovery could enable theft, forged signatures, and attacks on systems that depend on public-key cryptography. The question is therefore not only whether quantum key recovery can be achieved. It is also who can use it, under what authority, and with what accountability.

Our position is that this work should develop inside institutions prepared to confront those questions before the capability becomes practical. Good intentions alone do not protect an asset owner or a vulnerable system. Research needs authorization, evidence, independent challenge, and clear limits on consequential actions.


The long-term risk

What is at risk

Digital signatures authorize transactions and establish trust in software, identities, and records. A sufficiently capable quantum computer could undermine widely deployed signature systems based on mathematical problems that quantum algorithms can solve more efficiently. Some forms of public-key encryption and key exchange face a related threat to confidentiality.

These effects are different. Compromising a signing key can enable unauthorized instructions. Recovering a decryption or key-agreement secret can expose information. Bitcoin uses signatures to authorize spending; describing its risk as decrypting Bitcoin obscures the actual problem.

Signatures
A compromised signing key can authorize instructions the owner never gave: a payment, a software release, a record.
Secrets
A recovered decryption or key-agreement secret can expose information, including data collected long before the capability existed.

The threat extends beyond digital assets. Software distribution, financial infrastructure, government systems, and long-lived confidential information depend on cryptographic mechanisms that must evolve. Some sensitive data can be collected before an adversary has the capability to decrypt it. Signature migration raises its own problems of deployment, authority, and continuity.

No reliable date follows from a single hardware milestone or resource estimate. A long development horizon is nevertheless a reason to prepare early. Cryptographic migration requires software changes, coordination, testing, and decisions about systems that cannot be upgraded easily. Potomac’s research should help make those decisions better informed. It should not become a reason to delay migration.

Source: NIST: What Is Post-Quantum Cryptography?


Responsible leadership

Capability with safeguards before adversarial use

We want useful cryptanalytic capabilities to develop with safeguards before they are deployed by adversaries. That ambition does not create permission to take shortcuts with other people’s assets. Being earlier than an attacker would not by itself make an intervention legitimate or its consequences acceptable.

Responsible leadership means building both the technical competence and the institutional discipline to use a capability carefully. It includes publishing results that challenge our own assumptions, inviting criticism from people who do not benefit from our success, and being willing to stop an experiment or postpone a release.

There are real tensions here. Openness allows science to be checked, while unrestricted release can reduce the cost of misuse. A commercial company needs a durable business, while a recovery program may have duties to people who are not its customers. Secrecy can protect a sensitive finding, but it can also prevent scrutiny. Our framework should make these tensions visible and establish how decisions are challenged.

We do not assume that every difficult question has a technical answer. Network communities, affected owners, independent specialists, and appropriate public institutions have roles that a research company cannot claim for itself.


Research authorization

Research authorization

General mathematical research, controlled hardware experiments, target-specific key recovery, and asset transfers are different activities. They require different levels of authorization and review.

Our proposed operating boundary is to begin with synthetic keys, controlled challenges, and explicitly authorized experiments. Access to a quantum computer is permission to use that provider’s resources under its terms. It is not permission to recover a third party’s key.

Before any target-specific recovery, the program must establish who can authorize the work, what evidence supports that authority, which operations are permitted, and when work must stop. The scope must also cover data handling and any proposed disposition of recovered secrets or assets. An authorization to investigate must not silently become an authorization to transfer funds.

Public visibility does not resolve these questions. A key or balance being visible on a blockchain does not make it available for unrestricted experimentation. A successful recovery would demonstrate technical control, not prior ownership.

General research
Mathematics, circuits, and synthetic keys. Reviewed as research; published under the disclosure framework.
Controlled experiments
Hardware runs under a provider’s terms on authorized workloads and challenges.
Target-specific recovery
Requires documented authority, defined scope, stop conditions, and handling rules before work begins.
Asset transfer
Requires a separate decision under the recovery-and-return governance, never implied by an authorization to investigate.

Adopted and proposed

What is practised now and what is still proposed

Adopted practices

  • Research on synthetic keys, public challenges, and explicitly authorized experiments only.
  • Reports that separate measured results, simulations, and estimates and state their assumptions.
  • Public, dated, sourced evidence for every claimed contribution.

Proposed safeguards

  • A coordinated-disclosure process with artifact-specific publication decisions.
  • Recovery-and-return governance covering claims, authority, custody, network rules, and financial conflicts.
  • Capability review, access controls for AI systems and hardware, independent challenge, and incident handling.

Unresolved

  • Who authorizes target-specific recovery and how that authority is evidenced.
  • Custody, holding periods, fees, disputes, and the disposition of unclaimed assets.
  • The remit and appointment of any formal review body.