Welcome back to the show. Today's topic sounds like science fiction, but it is sitting in Bitcoin's official proposal repository right now. Quantum computers, and Bitcoin's plan to survive them.
番組へようこそ。今日のテーマはサイエンスフィクションのように聞こえますが、いままさにビットコインの公式提案リポジトリに置かれている話です。量子コンピュータと、それを生き延びるためのビットコインの計画です。
Straight to the scary stuff, I see. Should I be selling everything? Is my Bitcoin about to evaporate?
いきなり怖い話ですね。全部売ったほうがいいですか? 僕のビットコイン、蒸発しちゃうんですか?
No. The theme of this episode is: don't panic, but do pay attention. Quick quiz. Bitcoin runs on two pieces of cryptography. Hash functions, and digital signatures. Which one does a quantum computer break?
いいえ。今回のテーマはこれです。慌てないで、でも目は離さないで。まずクイズから。ビットコインは二つの暗号技術で動いています。ハッシュ関数と、デジタル署名。量子コンピュータが壊すのはどちらでしょう?
Um. Both? Everything? The entire internet?
えっと……両方? 全部? インターネットまるごと?
Just the signatures. The hashes are basically fine. And that one fact explains everything else we are going to talk about today.
署名だけです。ハッシュは基本的に無事です。そしてこの一つの事実が、今日話すことすべての説明になります。
Okay, I need that unpacked. What is a signature protecting, exactly?
ちゃんと解説してください。署名って、何を守っているんですか?
Your wallet has two keys. A private key, your secret, and a public key, which anyone may see. Making the public one from the private one takes an instant. Going backwards is impossible for a normal computer. That one-way street is the entire security model.
あなたのウォレットには鍵が二つあります。秘密鍵、これはあなただけの秘密。そして公開鍵、こちらは誰が見てもかまいません。秘密鍵から公開鍵を作るのは一瞬です。逆をたどるのは、普通のコンピュータには不可能です。この一方通行が、セキュリティモデルのすべてです。
And a quantum computer just... walks back the wrong way down the street?
それで量子コンピュータは……その一方通行を、平気で逆走してくるわけですか?
With something called Shor's algorithm, yes. If your public key is visible, a large enough quantum computer could compute your private key from it. And whoever has the private key can spend the coins.
ショアのアルゴリズムと呼ばれるもので、そうなります。公開鍵が見えていれば、十分に大きな量子コンピュータはそこから秘密鍵を計算できてしまう。そして秘密鍵を持つ者は、そのコインを使えます。
So the whole game becomes: never let anyone see your public key.
つまり勝負はこう変わるんですね。公開鍵を、誰にも絶対に見せないこと。
Exactly. So, when is it visible? Older address types only contain a fingerprint of your key. A hash. The key stays hidden until you spend. But the newest standard, Taproot, with addresses starting with b-c-one-p, writes the public key directly into the output. Receive coins there, and the key is visible immediately. Even if you never spend.
そのとおり。では、いつ見えるのか。古いタイプのアドレスに入っているのは、鍵の指紋、つまりハッシュだけです。鍵そのものは、支払う瞬間まで隠れています。ところが最新の標準、タップルート、ビー・シー・ワン・ピーで始まるアドレスは、公開鍵をそのまま出力に書き込みます。そこでコインを受け取ると、鍵は即座に見える。一度も支払わなくても、です。
Hold on. The newest one is the exposed one? That feels completely backwards.
待ってください。一番新しいやつが、一番むき出しなんですか? 完全に逆じゃないですか。
Back in twenty twenty-one, nobody was grading address designs on quantum resistance. But here is the number that makes this real. As of March first, twenty twenty-six, more than thirty-four percent of all bitcoin has a public key already visible on the chain. That figure comes from one of the proposals themselves.
2021年当時、量子耐性でアドレス設計を採点する人は誰もいませんでした。でも、この話を現実にする数字があります。2026年3月1日の時点で、全ビットコインの34パーセント超が、すでにチェーン上に公開鍵を晒しています。この数字は、これから話す提案そのものに書かれているものです。
A third of everything. Including, what, coins nobody can even touch?
全体の3分の1。それって、誰も触れないコインも含めて、ですか?
Including coins whose owners lost their keys fifteen years ago. Those can never be moved to safety. They just sit there, visible, waiting.
15年前に鍵を失くした持ち主のコインも含めて、です。あれらは二度と安全な場所に動かせません。ただそこに、見えたまま、置かれています。
Okay, that is genuinely unsettling. So how would an attack actually play out?
それは、本気でぞっとしますね。実際の攻撃はどう進むんですか?
Two ways. The first targets coins sitting still. If a key is exposed, an attacker quietly derives the private key and takes the funds. The second targets the moment you spend. Spending reveals your public key no matter what address you use, and there is a window of roughly ten minutes before your transaction confirms. A fast enough attacker derives your key inside that window and outbids your fee with a rival payment to themselves.
二通りです。一つめは、置いてあるコインを狙う。鍵が露出していれば、攻撃者は静かに秘密鍵を割り出して資金を持っていきます。二つめは、支払う瞬間を狙う。支払いはどのアドレスでも公開鍵を晒し、承認までにおよそ10分の窓があります。十分に速い攻撃者は、その窓の中で鍵を割り出し、自分宛ての対抗取引で、あなたの手数料を上回ってきます。
A ten-minute race to crack a key. How close is anyone to actually doing that?
鍵を割る10分間レース。実際、どのくらい近づいているんですか?
Honest reality check. In April twenty twenty-six, a competition called the Q-Day Prize was won by breaking a fifteen-bit key on real quantum hardware. Bitcoin's keys are two hundred fifty-six bits. An enormous gap. But one year earlier, the record was six bits.
正直な現在地を。2026年4月、キューデイ・プライズというコンペで、本物の量子ハードウェアを使って15ビットの鍵が破られました。ビットコインの鍵は256ビット。途方もない差です。ただし、その1年前の記録は6ビットでした。
So the threat is distant, but it is moving. And the exposure already exists today.
脅威は遠い。でも動いている。そして露出は、今日すでに存在している。
That is the exact tension. And it is why two proposals now exist. Let's take them one at a time.
それがまさに、この問題の緊張関係です。そして、いま二つの提案が存在する理由です。一つずつ見ていきましょう。
Proposal number one.
では、提案その1。
Bitcoin Improvement Proposal number three sixty. People just say BIP three sixty. It defines a new address type, and my favorite way to picture it is a house with two entrances. Today's Taproot address has an easy door that opens with a single key. Very convenient. But having that easy door is exactly why your public key has to be written on the front of the house.
ビットコイン・インプルーブメント・プロポーザル、番号360。ふだんはビップ360と呼ばれます。新しいアドレスタイプを定義するもので、私のお気に入りのたとえは、入口が二つある家です。いまのタップルートのアドレスには、鍵一本で開く、かんたんな入口があります。とても便利。でも、そのかんたんな入口があるせいで、家の正面に公開鍵を書いておかなければならないのです。
And the new house?
それで、新しい家は?
Bricks up the easy door entirely. What is written outside is now just a hash. Nothing readable, nothing to attack. The technical name is Pay to Merkle Root, and the new addresses would start with b-c-one-z.
かんたんな入口を、完全に塞ぎます。外に書かれているのは、もうただのハッシュだけ。読めるものはなく、攻撃するものもない。技術的な名前はペイ・トゥ・マークルルート。新しいアドレスはビー・シー・ワン・ゼットで始まることになります。
A house with no easy door sounds annoying to live in. What does it cost me?
かんたんな入口のない家って、住みにくそうですけど。僕は何を払うことになるんですか?
The address is exactly the same length, and payments carry slightly more data, so fees rise a little. In exchange you get a privacy bonus. You register several spending rules in advance, like spend with my signature alone, or spend when two family members sign. When you pay, you reveal exactly one rule. The others stay secret forever.
アドレスの長さはまったく同じ。支払いのデータが少し増えるぶん、手数料は少し上がります。代わりにプライバシーのおまけがつく。支払いルールを前もって複数登録できるんです。自分の署名だけで使う、家族二人の署名がそろえば使う、など。支払うときに見せるのはちょうど一つだけ。残りは永遠に秘密のままです。
Okay, so problem solved, right? Everyone moves into the hash house, quantum computers stare at a wall, the end.
じゃあ解決ですよね? 全員がハッシュの家に引っ越して、量子コンピュータは壁を眺めて、おしまい。
Here is the catch. This is only half a defense. Think of a two-stage rocket where only stage one exists. The new address protects coins while they sit still. The moment you spend, you reveal your public key, exactly like today. Stage two would be a signature that quantum computers cannot break. Nobody has written that specification. It does not exist.
ここに落とし穴があります。これは防御の半分でしかない。1段目しか存在しない2段ロケットです。新しいアドレスが守るのは、コインが置いてあるあいだ。支払う瞬間には、今とまったく同じく公開鍵を晒します。2段目は、量子コンピュータに破れない署名になるはずのもの。その仕様は誰も書いていません。存在しないんです。
So we should not call this a quantum-proof address.
つまりこれを、量子耐性アドレスと呼んではいけない。
The proposal itself refuses to call it that, which I respect. And note: it was merged into the official repository this February, meaning the document was accepted. Not that the feature exists on the network. It is still a draft.
提案自身が、そう呼ぶことを拒んでいます。そこには敬意を持ちたい。補足を一つ。今年2月に公式リポジトリへマージされましたが、それは文書が受理されたという意味で、機能がネットワークに存在するという意味ではありません。まだ草案です。
Understood. But even if the new address were live tomorrow, moving is voluntary. My grandmother is not migrating her wallet because a repository said so.
わかりました。でも、仮に新しいアドレスが明日使えるようになっても、引っ越しは任意ですよね。リポジトリが言ったからって、うちの祖母はウォレットを移行しませんよ。
That is the problem the second proposal tackles. BIP three sixty-one. It proposes two deadlines. The first arrives roughly three years after the rules take effect. Past it, old vulnerable addresses can no longer receive. You can still send, and that is the nudge to move. The second comes about two years later. Past it, spending from an old address requires proving you are the rightful owner.
それこそが二つめの提案、ビップ361が取り組む問題です。二つの期限を提案しています。一つめは、ルールが有効になってからおよそ3年後。過ぎると、古い脆弱なアドレスは受け取れなくなります。送ることはまだできる。それが引っ越しの合図です。二つめはその約2年後。過ぎると、古いアドレスからの支払いには、正当な持ち主だという証明が必要になります。
Proving? Hang on, this is the freeze thing I read about. Coins locked away forever.
証明? ちょっと待って、それ、僕が読んだ凍結の話ですよね。コインが永遠にロックされるっていう。
I am glad you brought that up, because this is the most misreported part of the story. The version published in April twenty twenty-six really did stop those payments outright. It was criticized, hard, and rewritten. The current version is not a freeze. The rightful owner can still spend, by proving ownership. And if you have already moved, nothing ever restricts your funds. At any point.
その話をしてくれて助かります。ここが、この物語でいちばん誤って報じられている部分だからです。2026年4月の公開版は、たしかに支払いを完全に止める内容でした。激しく批判され、書き直されました。現行版は凍結ではありません。正当な持ち主は、所有を証明すれば今までどおり使えます。そして引っ越しを済ませていれば、資金が制限されることは、どの時点でも一切ありません。
But how can I prove I am the owner when the attacker literally holds my private key? We just said they can compute it.
でも、攻撃者が文字どおり僕の秘密鍵を握っているのに、どうやって持ち主だと証明するんですか? さっき、計算できるって言いましたよね。
Beautiful question. Your wallet does not invent keys at random. It derives them from a seed, that recovery phrase you wrote on paper, going down a staircase made of hashing. And remember our opening quiz. Quantum computers do not break hashes. The attacker can compute the key at the bottom of the staircase, but can never climb back up to the seed. You can prove this key came from a seed you know, without ever revealing it. The attacker has no seed, so no proof, so no spending.
いい質問です。ウォレットは鍵をでたらめに作ってはいません。タネから導いています。紙に書き留めた、あのリカバリーフレーズです。タネから鍵までは、ハッシュでできた階段を降りていく。そして冒頭のクイズを思い出してください。量子コンピュータはハッシュを壊せません。攻撃者は階段の一番下の鍵なら計算できる。でもタネまで登り返すことは絶対にできない。あなたは、この鍵が自分の知るタネから来たことを、タネを見せずに証明できます。攻撃者にはタネがない。だから証明がない。だから支払えない。
That is... actually elegant. Wait, you said there was a catch earlier. Is there a catch here too?
それは、たしかにエレガントですね。あれ、さっき落とし穴があるって言いましたよね。ここにも落とし穴、あるんですか?
An honest exception. The very oldest coins, from before twenty twelve, predate this seed system. For those, even the true owner could not produce the proof. And most coins attributed to Satoshi Nakamoto, around one million, sit in that oldest format.
正直な例外が一つ。いちばん古いコイン、2012年より前のものは、このタネの仕組みより先に生まれています。あれらについては、本物の持ち主でも証明を作れません。そして、サトシ・ナカモトのものとされるコインの大半、およそ100万枚が、その最古の形式に置かれています。
So under this proposal, Satoshi's stash effectively stops moving. I feel like that is where the shouting starts.
じゃあこの提案のもとでは、サトシの保有分は事実上動かなくなる。ここから怒鳴り合いが始まる予感がします。
It is exactly where the shouting starts. Exposed coins face three roads. Road one, do nothing. Whoever builds the machine first takes everything. Road two, slow the theft down. A bidding war over fees, miners profit from stolen coins, and the money leaves anyway, just slower. Road three, require proof. Nobody can steal.
まさにそこから始まります。露出したコインの前には、三つの道があります。道その1、何もしない。マシンを最初に作った者が全部持っていく。道その2、盗みの速度を落とす。手数料の競り合いが起き、マイナーが盗まれたコインで儲かり、それでもお金は出ていく。ただ、ゆっくりと。道その3、証明を求める。誰も盗めない。
Road three sounds obviously best. Why is anyone shouting?
道その3が明らかに一番よさそうですけど。何をそんなに怒鳴り合うんですか?
Because road three is the only one where the community actively decides about other people's coins. Opponents say that breaks Bitcoin's deepest promise. Whoever holds the key can spend, no conditions, no committees. It sets a precedent, and it drags politics into a system built to avoid politics. Supporters answer that theft here is irreversible, so acting after the damage is not an option, and that doing nothing is also a choice, with a winner you did not pick.
道その3だけが、コミュニティが他人のコインについて能動的に決める道だからです。反対派は、ビットコインの最も深い約束を破ると言います。鍵を持つ者が使える。条件なし、委員会なし。前例を作り、政治を避けるために作られたシステムに政治を持ち込むことになる。賛成派はこう答えます。ここでの盗難は取り返しがつかず、被害の後に動く選択肢はない。そして何もしないこともまた選択であり、自分で選んでいない勝者が生まれるのだと。
What would Satoshi say? People always ask that.
サトシならどう言うでしょうね。みんな、それを聞きたがりますよ。
Both sides already quote him. In twenty ten, Satoshi wrote, and I am paraphrasing, lost coins just make everyone else's coins worth a little more. Think of it as a donation to everyone. The deadline proposal flips that sentence. Coins taken by a quantum computer make everyone else's coins worth less. Think of it as theft from everyone. Same sentence, two mirror readings.
どちらの側も、すでにサトシを引用しています。2010年、サトシはこう書きました。意訳ですが、失われたコインは、みんなのコインの価値を少しだけ上げる。みんなへの寄付だと思えばいい。期限の提案はこの文をひっくり返します。量子コンピュータに奪われたコインは、みんなのコインの価値を下げる。みんなからの盗みだと思えばいい。同じ一文の、鏡写しの二つの読み方です。
Even the authors must feel the weight of that.
著者たち自身も、その重さは感じているでしょうね。
One of them, Jameson Lopp, has said, in effect, I do not like this proposal either. I just dislike the alternatives more. When even the author is not celebrating, you know it is a genuine dilemma. So I will not hand you a verdict today, and I mean that.
その一人、ジェイムソン・ロップは、趣旨としてはこう言っています。自分もこの提案が好きなわけではない。ただ他の選択肢のほうがもっと嫌いなだけだ。著者本人すら喜んでいないなら、それは本物のジレンマです。だから今日は、私から結論はお渡ししません。本気です。
Fine, then hand me the sober summary instead. Where does all of this actually stand right now?
わかりました。じゃあ代わりに、冷静なまとめをください。これ全部、いま実際どこまで進んでいるんですか?
Four steps are needed, and exactly one is done. Step one, design the address that hides the key. Done, still a draft. Step two, write the quantum-resistant signature specification. It does not exist. Step three, set the moving deadline. Drafted, but waiting on step two. Step four, activate it on the real network. Not planned. Nothing scheduled at all.
必要なステップは四つ、できているのはちょうど一つ。ステップ1、鍵を隠すアドレスの設計。完了、ただしまだ草案。ステップ2、量子耐性の署名仕様。存在しません。ステップ3、引っ越し期限。草案はあるがステップ2待ち。ステップ4、実ネットワークでの有効化。予定なし。日程は何もありません。
So when a headline says Bitcoin has adopted quantum protection...
つまり、見出しが、ビットコインが量子対策を採用、と言っていたら……
Step one, and only step one. My favorite detail: the new address changed its name twice. It started as Pay to Quantum Resistant Hash, then the team admitted it only protects coins sitting still, and it ended up as plain Pay to Merkle Root. The name got more honest as the design did.
ステップ1の、ステップ1だけの話です。お気に入りの豆知識を一つ。この新アドレスは名前が2回変わっています。最初はペイ・トゥ・クオンタム・レジスタント・ハッシュ。その後チームは、守れるのは置いてあるコインだけだと認め、最後はただのペイ・トゥ・マークルルートに落ち着きました。設計が正直になるにつれ、名前も正直になったんです。
Okay, takeaways. Give them to me.
よし、持ち帰りポイントをください。
Four. One, quantum computers break signatures, not hashes. Two, the new address hides your key while coins sit still, and that is all it does. Three, the deadline proposal is a proof requirement, not a freeze. Four, nothing is decided. Both are drafts, and the piece everything depends on has not been written.
四つです。一つ、量子コンピュータが壊すのは署名で、ハッシュではない。二つ、新しいアドレスは、コインが置いてあるあいだ鍵を隠す。できるのはそれだけ。三つ、期限の提案は証明の要求であって、凍結ではない。四つ、何も決まっていない。どちらも草案で、すべてが依存するあの一片は、まだ書かれていない。
And for listeners who want to poke at this themselves instead of trusting two voices on the radio?
ラジオの二人の声を信じる代わりに、自分でつついてみたいリスナーには?
There is an interactive website that goes with this episode, in five languages, where every diagram from today can be touched and played with. Every claim is sourced to the master versions in the official Bitcoin proposal repository, linked right in the footer. Play with it, read the sources, and make up your own mind.
この回とセットの、触って遊べるウェブサイトがあります。5つの言語で動き、今日の図はぜんぶ自分で動かせます。すべての主張は、公式のビットコイン提案リポジトリのマスター版を出典にしていて、フッターからそのままリンクしています。触って、出典を読んで、自分で決めてください。
My homework is a website. I can live with that. As long as my coins can too.
宿題はウェブサイトですか。まあ、いいでしょう。僕のコインも生き延びてくれるなら。
Move along with the network when the time comes, and they will. That is the show. Thanks for listening, and we will see you next time.
時が来たらネットワークと一緒に引っ越せば、生き延びますよ。今日はここまで。お聞きいただきありがとうございました。また次回お会いしましょう。
Production Notes
- 総語数: 約1821語(A/B発話部分)/ 155〜175 words per minute で約10〜12分。さらに短くしたい場合はBの相槌行から削るのが安全です
- 固有名詞の読み: Shor's = ショアズ / Lopp = ロップ / Merkle = マークル(いずれも一般的な英語読みでTTSは自然に処理します)
- 内容はサイト本体と同じ正確性基準で作成: 「quantum-proof address と呼ばない」「freeze ではない(現行版)」「マージ≠採用」「サトシ引用・Lopp発言は paraphrase と明示」「両論併記で結論を出さない」