← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] BIP-361: Three Plans for Bitcoin's 20B Quantum Risk

Zephyra|April 17, 2026|BPF
EXECUTIVE SUMMARY

On April 14, 2026, six Bitcoin developers including Jameson Lopp submitted BIP-361 — "Post-Quantum Migration and Legacy Signature Sunset" — proposing a mandatory five-year phase-out of ECDSA and Schnorr signatures and the permanent freezing of all wallets that fail to migrate to quantum-resistant...

"At the moment, I don't believe any of this is necessary. But if there is any credible evidence that anyone has the capability to recover lost coins with a quantum computer, you should expect massive market panic immediately." — Jameson Lopp, Co-founder, Casa

Executive Summary

On April 14, 2026, six Bitcoin developers including Jameson Lopp submitted BIP-361 — "Post-Quantum Migration and Legacy Signature Sunset" — proposing a mandatory five-year phase-out of ECDSA and Schnorr signatures and the permanent freezing of all wallets that fail to migrate to quantum-resistant addresses. The proposal targets approximately 5.6 million BTC ($420 billion at current prices) that has not moved in over a decade, including an estimated 1.1 million BTC attributed to Satoshi Nakamoto.

Within 48 hours, the Bitcoin community fractured into three camps. Blockstream CEO Adam Back countered with an optional, voluntary migration framework. BitMEX Research proposed a reactive "quantum canary" bounty system that would trigger restrictions only after a quantum attack is publicly demonstrated. Cardano founder Charles Hoskinson argued from outside the Bitcoin ecosystem that any solution amounts to a hard fork in disguise.

The debate exposes a core tension in Bitcoin's design: whether the network's immutability guarantee extends to coins that may never move again, and whether preemptive action to protect network integrity violates the property rights the protocol was built to secure. A January 2026 Citi Institute report estimates the probability of quantum computers breaking public-key encryption at 19–34% by 2034, framing the discussion as a near-term risk rather than a theoretical exercise.

Table of Contents

  1. The Quantum Threat: Current State of Risk
  2. BIP-361: The Mandatory Freeze Proposal
  3. Adam Back's Counter: Optional Migration
  4. BitMEX Research: The Canary Approach
  5. Hoskinson's External Critique
  6. Comparative Framework: Three Proposals Side by Side
  7. Economic Implications
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Quantum Threat: Current State of Risk

The debate is grounded in measurable exposure. According to the BIP-361 proposal document, over 34% of all bitcoins have had their public keys exposed on-chain as of March 1, 2026. Once exposed, these keys are vulnerable to Shor's algorithm, which can derive private keys from public keys given a sufficiently powerful quantum computer.

The vulnerable supply breaks down as follows:

| Category | Estimated BTC | Status | |----------|--------------|--------| | P2PK addresses (Satoshi-era) | ~1.7 million | Non-migratable (no BIP-39 seed) | | Reused/P2TR addresses | ~5.2 million | Migratable if holders act | | Other reused categories | ~200,000 | Migratable | | Total exposed | ~7.1 million | ~34% of supply |

Hardware requirements for an attack are falling. In March 2026, research from Google Quantum AI and Oratomic demonstrated that breaking ECDSA could require fewer than 500,000 qubits using advanced architectures — down from earlier estimates of millions. Google's current Willow chip operates at 105 qubits, but the trajectory is accelerating. The Citi Institute estimates a 19–34% probability of cryptographically relevant quantum computers by 2034, rising to 60–82% by 2044.

Bitcoin's proof-of-work mining remains comparatively secure. Grover's algorithm offers only a quadratic speedup for hash preimage attacks, which can be neutralized by adjusting mining difficulty parameters.

BIP-361: The Mandatory Freeze Proposal

BIP-361 introduces a three-phase sunset of legacy signature schemes:

Phase A (~3 years post-activation, ~160,000 blocks): Prohibits new sends to quantum-vulnerable address types. All new transactions must use post-quantum output types. Legacy addresses can still spend, but cannot receive.

Phase B (5 years post-activation, flag day): Renders all ECDSA and Schnorr spends invalid. Nodes reject any transaction relying on legacy signature schemes. Funds in non-migrated addresses become permanently inaccessible.

Phase C (TBD): Proposes a recovery mechanism for frozen UTXOs via zero-knowledge proof of possession of a BIP-39 seed phrase. Timeline and technical specifications remain undefined pending further research.

The proposal's logic is adversarial. Lopp told CoinDesk: "Quantum miners don't trade anything. They are vampires feeding upon the system." The argument is that a sudden quantum attack on $420 billion in dormant coins would trigger systemic market panic regardless of whether the coins are sold, simply because the attack demonstrates that Bitcoin's cryptographic foundation has been compromised.

Leo Fan, founder of Cysic and formerly of Algorand, identified the philosophical shift: "Ownership becomes conditional. Having keys no longer guarantees you can spend."

The proposal was submitted by six contributors. No Bitcoin Core maintainers have publicly endorsed it. No activation timeline has been proposed for consensus deployment.

Adam Back's Counter: Optional Migration

On April 16, Blockstream CEO Adam Back presented an alternative framework at Paris Blockchain Week. His core argument: quantum computers remain "essentially lab experiments" with progress that has been "incremental" over 25 years, and Bitcoin's existing upgrade infrastructure can accommodate quantum resistance without mandatory freezes.

Back's proposal centers on three elements:

  1. Taproot flexibility: The 2021 Taproot upgrade was designed to accept new signature methods without disrupting existing users. Post-quantum signature schemes can be deployed as optional Taproot leaf scripts.

  2. Liquid testing: Blockstream is already testing quantum-resistant transaction signatures on Liquid, its federated sidechain. Results could inform mainnet deployment.

  3. Decade-long migration window: Users would have approximately ten years to voluntarily migrate keys to quantum-resistant formats, with no forced freezes.

Back's position rests on a bet that Bitcoin's developer community can coordinate rapidly if quantum threats materialize: "Making changes in a controlled way is far safer than reacting in a crisis," he told conference attendees. This contrasts directly with Lopp's bet that developers cannot coordinate quickly enough under pressure.

The key vulnerability in Back's framework: it relies on voluntary action. Any dormant wallets — including Satoshi's — would remain unprotected indefinitely, leaving the network exposed to the same $420 billion attack vector BIP-361 aims to eliminate.

BitMEX Research: The Canary Approach

BitMEX Research published a third alternative on April 16, proposing a reactive system rather than a preemptive one.

The mechanism works as follows:

  1. Canary address creation: A special Bitcoin address is generated using a "Nothing-Up-My-Sleeve Number" — a cryptographic construct where the private key is provably unknown. The address is valid but unspendable by conventional means.

  2. Bounty accumulation: Anyone can deposit bitcoin into the canary address. Contributors retain withdrawal rights. The accumulating bounty incentivizes a quantum-capable entity to demonstrate its capability publicly rather than silently draining wallets.

  3. Tripwire activation: If the canary address is ever spent, it constitutes public proof that quantum capability exists. This triggers an automatic network-wide freeze on all quantum-vulnerable UTXOs.

  4. Safety window: Vulnerable coins can still move in the interim, but recipients cannot spend received funds for an extended period (approximately one year). If the canary triggers during this window, those transactions freeze retroactively.

The proposal's critical assumption is that the first quantum attacker will claim a relatively small bounty rather than quietly stealing billions. As CoinDesk noted, this "cuts against the kind of worst-case scenario Bitcoin's design has always tried to prevent." A rational attacker with quantum capability would likely bypass the canary entirely and target the largest unprotected wallets directly.

Hoskinson's External Critique

Cardano founder Charles Hoskinson weighed in on April 16, arguing that BIP-361 is "a hard fork in disguise" that Bitcoin's anti-hard-fork governance culture cannot accommodate.

His technical critique focuses on Phase C's recovery mechanism. The zero-knowledge proof scheme assumes wallet holders possess BIP-39 seed phrases. However, approximately 1.7 million BTC in P2PK addresses — including Satoshi's coins — were generated before BIP-39's 2013 introduction using a different key derivation method based on local key pools. No seed phrase exists for these wallets. Phase C cannot recover them.

Hoskinson contends that BIP-361, if adopted as written, would permanently freeze those 1.7 million BTC by design, not as a side effect. He frames this as evidence that "Bitcoin's lack of formal on-chain governance leaves it ill-equipped to handle such contentious upgrades." He projected that 34% of Bitcoin's supply could be stolen by quantum computers "in the 2030s" without mitigation.

Comparative Framework: Three Proposals Side by Side

| Dimension | BIP-361 (Lopp) | Optional Migration (Back) | Canary System (BitMEX) | |-----------|---------------|--------------------------|----------------------| | Trigger | Pre-scheduled flag day | Voluntary adoption | Proven quantum attack | | Timeline | 5 years fixed | ~10 years flexible | Reactive (no fixed date) | | Dormant coin treatment | Frozen at Phase B | Unprotected indefinitely | Frozen only after canary spend | | Satoshi's coins (~1.1M BTC) | Permanently frozen | Vulnerable | Frozen only after attack | | Migration mechanism | Mandatory | Voluntary | Voluntary until trigger | | Recovery option | Phase C (ZK proof, BIP-39 only) | None specified | None specified | | Governance model | Soft fork (disputed) | Soft fork via Taproot | Soft fork | | Core risk | Property rights violation | Inaction under pressure | Attacker bypasses canary | | Current status | BIP submitted, no endorsements | Conceptual, Liquid testing | Research paper |

Economic Implications

The $420 billion in dormant BTC represents a latent supply shock. Under current conditions, these coins function as permanently removed from circulation, contributing to Bitcoin's scarcity premium. Any proposal that changes the status of these coins — whether by freezing, recovering, or leaving them vulnerable to theft — carries second-order economic effects.

Scenario 1 — BIP-361 adopted: The 5.6 million dormant BTC are formally removed from circulating supply. Bitcoin's effective supply cap drops from 21 million to approximately 15.4 million. This could increase scarcity-driven price pressure but also sets a precedent that the network can retroactively modify property rights.

Scenario 2 — No action taken, quantum attack succeeds: A sudden influx of 5.6 million previously dormant BTC — 26.7% of total supply — entering circulation would constitute the largest supply shock in Bitcoin's history. At current prices, even partial liquidation would overwhelm order book depth on every exchange.

Scenario 3 — Canary triggers, reactive freeze: Market confidence would be tested by the confirmation that quantum capability exists. Even with a freeze mechanism in place, the demonstrated vulnerability of Bitcoin's signature scheme would likely trigger repricing across all ECDSA-dependent assets.

Mati Greenspan, founder of Quantum Economics, summarized the dilemma: "The path to quantum resistance is relatively clear. The real question is how the Bitcoin community chooses to handle vulnerable coins along the way." He added that "freezing dormant bitcoin accounts would mark a significant departure from Bitcoin's core principles."

Key Takeaways

  • BIP-361 proposes freezing ~5.6 million BTC ($420B) that has not moved in over a decade, including Satoshi's estimated 1.1 million BTC, via a mandatory five-year phase-out of legacy signatures.

  • Three competing frameworks have emerged in 48 hours: mandatory freeze (Lopp/BIP-361), optional voluntary migration (Back/Blockstream), and reactive canary trigger (BitMEX Research). None has achieved consensus.

  • 34% of Bitcoin's supply has exposed public keys vulnerable to Shor's algorithm. Citi estimates a 19–34% probability of cryptographically relevant quantum computers by 2034.

  • 1.7 million BTC in P2PK addresses cannot be recovered under BIP-361's Phase C mechanism because they predate BIP-39 seed phrases, making their freeze permanent by design.

  • No Bitcoin Core maintainers have publicly endorsed BIP-361. The proposal remains at the discussion stage with no activation timeline.

  • The economic stakes are asymmetric: doing nothing risks a $420 billion supply shock; acting preemptively risks undermining Bitcoin's immutability guarantee — the property that distinguishes it from centrally managed monetary systems.

Conclusion

BIP-361 forces a question Bitcoin was designed never to face: who decides what happens to coins that cannot defend themselves. The three proposals represent fundamentally different risk tolerances — preemptive action, voluntary preparation, and reactive defense — but all three acknowledge the same underlying reality. Quantum computing's threat to ECDSA is no longer a matter of "if" but "when," with timelines ranging from 2029 to 2044 depending on the source.

The absence of any Core maintainer endorsement suggests BIP-361 is unlikely to advance in its current form. But the debate it triggered is already reshaping how the Bitcoin community thinks about property, governance, and the limits of immutability. The 5.6 million dormant BTC will remain a latent vulnerability until the network reaches consensus — or until a quantum computer makes the decision for it.

Sources & References

  1. Bitcoin developer says 5.6 million 'lost' tokens may need freezing to stop hackers — CoinDesk, April 15, 2026
  2. Bitcoin's quantum debate splits as Adam Back pushes optional upgrades over forced freeze — CoinDesk, April 16, 2026
  3. Bitcoin devs float 'quantum tripwire' that triggers coin freeze only if attack is proven — CoinDesk, April 16, 2026
  4. Cardano's Charles Hoskinson says Bitcoin's quantum fix is a hard fork that can't save Satoshi's coins — CoinDesk, April 16, 2026
  5. BIP-361: Post Quantum Migration and Legacy Signature Sunset — Official BIP-361 specification
  6. BIP 361 on GitHub — Bitcoin Improvement Proposals repository
  7. Citi Institute: Quantum Threat — The Trillion-Dollar Security Race Is On — Citi Institute, January 2026
  8. Bitcoin's $1.3 trillion security race: Key initiatives aimed at quantum-proofing the world's largest blockchain — CoinDesk, April 4, 2026
  9. Satoshi's $76 Billion Bitcoin Stash Faces Quantum Threat as Community Debates Solutions — CoinAlert News, April 7, 2026
  10. BIP-361 Proposal Sparks Debate Over Freezing Early Bitcoin Wallets to Counter Quantum Threat — KuCoin News, April 15, 2026