Bitcoin Improvement Proposal 361, titled "Post Quantum Migration and Legacy Signature Sunset," was updated in Bitcoin's official proposal repository on April 15, 2026. The proposal, co-authored by Casa CTO Jameson Lopp, outlines a three-phase plan to invalidate legacy cryptographic signatures and...
Bitcoin Improvement Proposal 361, titled "Post Quantum Migration and Legacy Signature Sunset," was updated in Bitcoin's official proposal repository on April 15, 2026. The proposal, co-authored by Casa CTO Jameson Lopp, outlines a three-phase plan to invalidate legacy cryptographic signatures and freeze coins in quantum-vulnerable addresses. An estimated 6.7 million to 6.9 million BTC — roughly 33% of the circulating supply, valued at approximately $500 billion at current prices — sits in address types exposed to future quantum attack.
The proposal arrives amid accelerating quantum research. Three papers published between May 2025 and March 2026 reduced the estimated qubit count needed to break elliptic curve cryptography from 9 million to fewer than 500,000. Google Quantum AI's March 2026 whitepaper, co-authored with Ethereum Foundation researcher Justin Drake and Stanford cryptographer Dan Boneh, demonstrated that a sufficiently capable quantum computer could derive a Bitcoin private key in approximately nine minutes — within the network's ten-minute block confirmation window.
BIP-361 does not have a deployment timeline. It remains a draft proposal requiring broad community consensus before activation. The debate it has triggered, however, is immediate: whether Bitcoin's immutability guarantee can coexist with proactive defense against a credible cryptographic threat.
Three research papers published in rapid succession between May 2025 and March 2026 compressed the estimated quantum threat timeline significantly.
Paper 1 — Gidney (May 2025): Craig Gidney of Google Quantum AI demonstrated that RSA-2048 factoring could be achieved with fewer than 1 million physical qubits, down from his own 2019 estimate of 20 million qubits. The improvement came from advances in approximate residue arithmetic and magic state cultivation.
Paper 2 — Iceberg Quantum (February 2026): Sydney-based startup Iceberg Quantum published its Pinnacle architecture, showing RSA-2048 could potentially fall to fewer than 100,000 physical qubits using quantum low-density parity-check (QLDPC) codes. The result has not been validated on hardware and assumes qubit connectivity beyond current nearest-neighbor grids.
Paper 3 — Google Quantum AI (March 2026): Targeting 256-bit elliptic curve discrete logarithm problems (ECDLP) — the specific cryptography protecting Bitcoin — Google showed that fewer than 500,000 physical qubits could derive a private key in approximately nine minutes. The previous best estimate, from Litinski in 2023, required roughly 9 million qubits. This represents a 20-fold reduction.
Current quantum hardware has crossed the 1,500 physical qubit threshold. Roughly 1,000 physical qubits are required to produce one stable logical qubit. The gap between present capability and the attack threshold remains large, but the trajectory of reduction — from 20 million to under 500,000 in six years — has shifted the conversation from "if" to "when."
Adam Back, Blockstream CEO and inventor of Hashcash, stated on April 8 that "the prudent thing to do is to prepare Bitcoin and give people the option to migrate their keys to a quantum ready format, and to have, let's say, a decade in which to do that." He cited Blockstream's Liquid network as an early proving ground for quantum-resistant cryptography.
Google has set an internal 2029 deadline for its own post-quantum cryptography migration. NIST requires all new National Security Systems to be quantum-safe by January 2027.
BIP-361, building on the technical framework established in BIP-360 (published February 2026), outlines a phased deprecation of legacy Bitcoin signature schemes. The timeline begins only after a quantum-resistant output type is live on the Bitcoin network.
Phase A (3 years post-activation): New transactions sending BTC to quantum-vulnerable address types — primarily P2PK (pay-to-public-key) and any output with an exposed public key — are blocked. Spending from these addresses remains permitted. This creates a migration window.
Phase B (5 years post-activation): Legacy signatures using ECDSA and Schnorr become invalid. Bitcoin remaining in vulnerable addresses is effectively frozen. Holders who have not migrated lose the ability to transact.
Phase C (timeline under research): A potential recovery mechanism using zero-knowledge proofs. Holders who missed the Phase B deadline but still possess their seed phrase could reclaim frozen funds by proving ownership without exposing their private key.
The BIP-361 authors wrote in the proposal's GitHub repository: "This is not an offensive attack, rather, it is defensive: our thesis is that the Bitcoin ecosystem wishes to defend itself."
Lopp framed his position: "At the moment, I don't believe any of this is necessary. We believe it will be necessary to incentivize the ecosystem to upgrade because humans tend to be procrastinators."
According to CryptoQuant founder Ki Young Ju, approximately 6.89 million BTC are held in quantum-vulnerable addresses. The breakdown:
| Category | Estimated BTC | Notes | |----------|--------------|-------| | Directly exposed public keys (P2PK) | 1.91 million | Public key visible on-chain without any transaction | | Public keys revealed via past transactions | 4.98 million | Address reuse or spending history exposed the key | | Satoshi-attributed coins | ~1.1 million | Spread across ~22,000 addresses at ~50 BTC each | | Dormant over 10 years | ~3.4 million | Subset of above categories |
Google Quantum AI's March 2026 whitepaper identified 100,000 Bitcoin addresses exposed to "at-rest" attacks — where a quantum computer could derive private keys without the owner initiating any transaction. The 1.7 million BTC in early P2PK addresses, including Satoshi's holdings, falls squarely into this category.
At Bitcoin's price of approximately $75,050 on April 15, 2026, the 6.89 million vulnerable BTC represents roughly $517 billion in exposed value. The Satoshi-attributed portion alone accounts for approximately $82.5 billion.
Approximately 28% of all bitcoin — about 5.6 million tokens — has not moved in over a decade, according to Lopp.
BIP-361's phased sunset depends on BIP-360, which introduces a new transaction output type: pay-to-Merkle-root (P2MR). The design mirrors Bitcoin's existing Taproot (P2TR) framework but removes the key-path spend — the component exposed to quantum attack.
P2MR outputs commit directly to the script tree's Merkle root without relying on an internal key or tweak. This preserves Taproot's scripting capabilities while eliminating the cryptographic vulnerability.
In March 2026, BTQ Technologies deployed the first working implementation of BIP-360 on its Bitcoin Quantum testnet v0.3.0. The implementation includes full P2MR consensus with SegWit version 2 outputs, five Dilithium post-quantum signature opcodes enabled in tapscript context, and end-to-end CLI wallet tooling for creating and spending quantum-resistant transactions.
Dilithium (formally ML-DSA) is one of NIST's finalized post-quantum signature standards, published in August 2024. Its inclusion in the testnet signals that Bitcoin's quantum resistance path aligns with federally standardized cryptography rather than experimental schemes.
Despite the testnet progress, a May 2025 analysis from Chaincode Labs noted that Bitcoin post-quantum initiatives remained at "an early and exploratory stage." Bitcoin's governance culture has historically made protocol upgrades slow to advance from concept to activation — the Taproot upgrade itself took approximately four years from initial proposal to deployment.
The proposal has generated sharp division.
In favor: Proponents argue that inaction creates a binary outcome — either quantum-vulnerable coins are migrated by their rightful owners or seized by a quantum-capable attacker. Mati Greenspan, founder of Quantum Economics, said: "The path to quantum resistance is relatively clear. The real question is how the Bitcoin community chooses to handle vulnerable coins along the way."
Lopp warned of systemic consequences: "If there is any credible evidence that anyone has the capability to recover lost or vulnerable coins with a quantum computer, you should expect a massive market panic immediately."
Against: Critics frame BIP-361 as an existential threat to Bitcoin's core value proposition. Leo Fan, founder of Cysic and former lead on quantum resilience at Algorand, stated: "Ownership becomes conditional. Having keys no longer guarantees you can spend. That weakens Bitcoin's 'unstoppable money' promise."
On social media, opponents labeled the proposal "highly authoritarian and confiscatory." The argument: if a network can freeze coins today for quantum defense, it can freeze coins tomorrow for other reasons. The precedent itself is the threat.
Greenspan acknowledged both sides: "Freezing dormant or exposed coins could remove a major tail-risk and protect market confidence. On the other, it introduces a precedent of intervention that many would argue is more dangerous than the threat itself."
The economic calculus centers on supply dynamics. If 6.89 million BTC — 33% of circulating supply — were permanently frozen via Phase B, Bitcoin's effective liquid supply would contract substantially. Coins that are currently categorized as "lost" but theoretically recoverable would become definitively unspendable.
This has two competing effects. Reduced circulating supply is mechanically price-supportive. But the precedent of protocol-level confiscation introduces governance risk that institutional allocators would need to price. Bernstein analysts, referenced in an April 2026 report alongside Adam Back, characterized the quantum threat as "not existential" for Bitcoin, suggesting that preparedness measures would be sufficient.
The quantum-resistant token market has already reacted. According to CoinDesk, tokens associated with post-quantum cryptography projects rose approximately 50% in the week following Google's March 2026 whitepaper release.
For Satoshi's coins specifically, the question carries philosophical weight. If the coins are frozen and their owner never surfaces, they transition from "probably lost" to "definitively locked." If a quantum attacker claims them first, the market impact of 1.1 million BTC entering circulation — equivalent to approximately 5.2% of supply — could be severe.
BIP-361 forces a question that Bitcoin's design was built to avoid: under what conditions can the network override individual property rights for collective security. The quantum threat provides a technically defensible rationale. The research trajectory — three papers compressing the attack threshold by 20x in under a year — lends urgency to the proposal.
But the proposal's critics are not arguing that quantum computing is harmless. They are arguing that the cure — conditional ownership, protocol-level freezing, time-limited access to one's own assets — violates the property that makes Bitcoin worth defending in the first place.
The proposal has no deployment date. It may never activate. But its existence in Bitcoin's official proposal repository, backed by a recognized core developer, signals that the community has begun pricing quantum risk into its governance framework. The debate over BIP-361 is, in practical terms, a debate over what Bitcoin is.