4 ms·
Second time I read this. How so? The address has been used to receive coins, surely a private key must exist?
by brainburn 13y ago
Second time I read this. How so? The address has been used to receive coins, surely a private key must exist?
- gibybo 13y agoA private key is not strictly necessary to receive coins, only to spend them. So while there is still probably a private key with that address (since he intended to actually be able to use those bitcoins), the public key is not revealed unless coins are spent from that address.
- sliverstorm 13y agoBut the public key must be linked to the address, or else you could not confirm the public key belongs to that address. Right?
- gibybo 13y agoYes, but this information is not published to the blockchain until you spend it. The address is literally RIPEMD-160(SHA-256(public key)), plus a 4 byte checksum. To receive coins to that address, the sender publishes the amount they are sending and that address, they never see the public key. When the owner of the address wants to send bitcoins from it, only then do they publish the public key, along with a transaction signed by their private key.
- sliverstorm 13y agoOk, so I'm not a cryptography specialist, but I don't see how "address = RIPEMD-160(SHA-256(public key))" makes it impossible to derive the public key from the address if you have a quantum computer. Or is SHA-256 not vulnerable to quantum computing the way public/private keypairs are?
- gibybo 13y agoYes that is correct. SHA256 is not known to be vulnerable to quantum computers[^], ECDSA (Bitcoin's public/private key algorithm) is. [^] There is a known quantum attack against SHA256 that reduces the brute force search space from 2^256 to 2^128, but that wouldn't really break the Bitcoin protocol. The ECDSA quantum vulnerability, however, would make ECDSA essentially useless.