Bitcoin's cryptographic foundation faces a narrowing timeline. In April 2026, a researcher broke a 15-bit elliptic curve key on publicly accessible quantum hardware, a 512x improvement over the previous demonstration seven months earlier. Google's Quantum AI team published estimates in March 2026...
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them." — Alex Pruden, CEO, Project Eleven
Bitcoin's cryptographic foundation faces a narrowing timeline. In April 2026, a researcher broke a 15-bit elliptic curve key on publicly accessible quantum hardware, a 512x improvement over the previous demonstration seven months earlier. Google's Quantum AI team published estimates in March 2026 reducing the hardware threshold for a full 256-bit ECDSA attack to under 500,000 physical qubits, a 20x reduction from prior models. A subsequent Caltech-Oratomic paper pushed the estimate as low as 10,000 qubits in neutral-atom architectures.
The response from Bitcoin's developer community has been fast and fractured. Two competing Bitcoin Improvement Proposals, BIP-360 and BIP-361, now define a policy split: build optional quantum-resistant address types and let users migrate voluntarily, or enforce a hard timeline that freezes unmigrated coins. A third proposal from Paradigm, called PACTs, offers dormant holders a way to timestamp proof of ownership before quantum threats arrive. Approximately 6.9 million BTC, roughly one-third of total supply and valued at over $440 billion, sits in addresses with exposed public keys.
The debate is no longer theoretical. U.S. federal agencies faced an April 2026 deadline under NSM-10 to submit post-quantum cryptography transition plans. NIST guidance (IR 8547) targets phasing out quantum-vulnerable algorithms after 2030 and disallowing them after 2035. Bitcoin's governance model, which requires rough consensus for protocol changes, must now resolve a question that intersects cryptography, property rights, and the fate of Satoshi Nakamoto's estimated 1.1 million BTC.
Bitcoin's transaction signing relies on the Elliptic Curve Digital Signature Algorithm (ECDSA) over the secp256k1 curve. Shor's algorithm, run on a sufficiently powerful quantum computer, can derive a private key from a public key in polynomial time. The vulnerability is specific: mining (SHA-256) remains resistant, but any address whose public key has been exposed on the blockchain is a potential target.
Project Eleven estimates 6.9 million BTC sits in such addresses. An Ark Invest/Unchained report from March 2026 breaks down the exposure: approximately 1.7 million BTC in early Pay-to-Public-Key (P2PK) addresses where the full public key is embedded in the locking script, and roughly 5.2 million BTC in reused or P2TR addresses where the key has been revealed through prior transactions.
On April 24, 2026, Project Eleven awarded its Q-Day Prize — one bitcoin — to researcher Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible quantum hardware using a variant of Shor's algorithm. The result covered a search space of 32,767 values and represented a 512x improvement over Steve Tippeconnic's 6-bit demonstration in September 2025.
The gap between 15-bit and 256-bit remains enormous. But the trajectory matters. Google Quantum AI's March 2026 whitepaper estimated fewer than 500,000 physical qubits would be needed to attack secp256k1, down from earlier estimates of 4 million or more. A subsequent paper from Caltech and Oratomic modeled the attack at as few as 10,000 qubits using neutral-atom architectures. Current hardware stands at approximately 1,500 qubits. According to Google, quantum computers could crack vulnerable Bitcoin addresses in as little as 9 minutes by 2029.
BIP-360, published on February 11, 2026, and merged into Bitcoin's official BIP repository, introduces Pay-to-Merkle-Root (P2MR), a new output type designated as SegWit version 2 with bc1z address encoding. P2MR retains Taproot's scripting flexibility but eliminates the key-path spend mechanism that exposes public keys.
The technical implementation commits directly to the Merkle root of a script tree rather than relying on an internal key or tweak. Five Dilithium post-quantum signature opcodes are enabled within the P2MR tapscript context, using NIST-standardized ML-DSA (formerly CRYSTALS-Dilithium) for signature verification.
BTQ Technologies deployed the first working BIP-360 implementation on Bitcoin Quantum testnet v0.3.0 in March 2026. The testnet has attracted over 50 miners, processed more than 100,000 blocks, and assembled an open-source contributor community of more than 100 cryptographers and developers. The implementation includes full P2MR consensus verification, Merkle root commitment validation, control block verification, and end-to-end CLI wallet tooling for creating, funding, signing, and spending P2MR transactions.
BIP-360 is designed as a soft fork, meaning it does not require all nodes to upgrade simultaneously. The proposal does not address what happens to coins that remain in legacy address types.
BIP-361, published on April 15, 2026, addresses the legacy question directly. Co-authored by Casa CTO Jameson Lopp and five other developers, it proposes a three-phase soft fork with a fixed five-year activation timeline.
Phase A begins approximately three years after BIP-360 (or a comparable quantum-resistant address standard) is activated. During Phase A, wallets are blocked from sending funds to legacy address types, pushing users toward P2MR or equivalent quantum-safe formats.
Phase B activates two years after Phase A. All legacy ECDSA and Schnorr signatures become invalid at the consensus layer. Coins that have not migrated are frozen — they cannot be moved.
Phase C, still under research, would allow holders of frozen coins to prove ownership through a zero-knowledge proof tied to a BIP-39 seed phrase and recover their funds.
According to BanklessTimes, the proposal would affect approximately $74 billion in BTC currently held in quantum-vulnerable addresses that are classified as potentially unrecoverable — coins whose owners may have lost access or cannot migrate.
On May 1, 2026, Paradigm researcher Dan Robinson proposed PACTs (Provable Address-Control Timestamps) as a third option. PACTs allow holders to timestamp proof of address control without moving coins, creating an unforgeable record that they had access before quantum threats materialized.
The mechanism works as follows: a holder generates a random salt, produces a BIP-322 proof of ownership (a standard for signing messages from a Bitcoin address without spending), bundles the salt and proof into an on-chain commitment, and timestamps it through OpenTimestamps. The salt, proof, and timestamp files remain private and off-chain.
The proposal targets dormant wallets — particularly the estimated 1.1 million BTC attributed to Satoshi Nakamoto across roughly 22,000 P2PK addresses. If BIP-361's freeze were activated, PACTs could serve as evidence of legitimate ownership during Phase C recovery.
Robinson noted that PACTs require Bitcoin to eventually adopt a STARK verification protocol, which would itself require a separate soft fork. The proposal also does not extend cleanly to multisig wallets, complex scripts, or custodial accounts.
Satoshi's estimated 1.1 million BTC, worth approximately $76 billion at current prices, represents the most concentrated quantum-vulnerable position on the network. The coins sit in early P2PK addresses that have never transacted since mining, meaning the public keys are permanently visible on-chain.
The governance implications are significant. Freezing Satoshi's coins under BIP-361 would effectively transfer control of $76 billion in value from an absent holder to the protocol itself. According to CoinDesk, some developers have warned this could trigger a hard fork, with one chain preserving the freeze and another rejecting it.
The community faces three paths for these specific coins: burn or freeze them to prevent future quantum theft, deliberately slow their release by rate-limiting spending from P2PK addresses, or do nothing and accept the risk that a future quantum-capable actor could claim them.
Lopp published a separate blog post, "Against Quantum Recovery of Bitcoin," arguing that allowing frozen coins to be recovered through ZK proofs creates perverse incentives and does not meaningfully improve network security.
The debate has crystallized into two camps. BIP-361's proponents argue that a pre-scheduled migration is safer than emergency coordination. The proposal gives holders five years to migrate — a longer runway than most software deprecation cycles.
Blockstream CEO Adam Back opposes the forced timeline. "Preparation is key. Making changes in a controlled way is far safer than reacting in a crisis," Back stated, but added that Bitcoin's governance has demonstrated the ability to respond quickly: "Bugs have been identified and fixed within hours. When something becomes urgent, it focuses attention and drives consensus."
Back advocates for optional quantum-safe spend paths that activate only when needed, pointing to Blockstream's work on hash-based signature schemes as a conservative approach. He has warned against rushing untested cryptography that could itself introduce vulnerabilities.
The debate mirrors prior Bitcoin governance conflicts — the block size war, SegWit activation, and the Taproot upgrade — where competing visions of the protocol's future required extended consensus-building before resolution.
Bitcoin's quantum timeline intersects with a broader federal cryptographic transition. Under National Security Memorandum 10 (NSM-10), signed May 4, 2022, and reinforced by OMB Memorandum M-23-02, every U.S. federal agency faced an April 2026 deadline to submit comprehensive post-quantum cryptography transition plans.
These plans must inventory all cryptographic systems, prioritize assets by sensitivity and risk, identify migration pathways, and establish completion timelines. Annual progress reviews are tied to funding decisions.
NIST finalized three post-quantum cryptographic standards in August 2024: ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for digital signatures, and SLH-DSA (FIPS 205) as a backup signature scheme. HQC was added as a fourth standard in March 2025.
NIST guidance document IR 8547 recommends phasing out quantum-vulnerable algorithms after 2030 and disallowing them entirely after 2035. BIP-360's adoption of ML-DSA for its post-quantum signatures aligns with these federal standards.
The convergence is notable: the same algorithms that U.S. federal agencies are mandated to adopt are being proposed for Bitcoin's protocol layer. Whether Bitcoin's decentralized governance can match the federal government's 2035 target timeline remains an open question.
Bitcoin's quantum defense effort has moved from academic speculation to active protocol development in under six months. The technical components — BIP-360's P2MR addresses, ML-DSA signatures, and a functioning testnet — demonstrate that quantum-resistant Bitcoin transactions are feasible. The unresolved question is political, not technical: whether to force migration and freeze non-compliant coins, or to deploy optional defenses and rely on market incentives and emergency coordination.
The stakes are denominated in hundreds of billions of dollars. The 6.9 million BTC in exposed addresses, the $76 billion attributed to Satoshi, and the philosophical commitment to "your keys, your coins" all converge on a governance decision that no previous Bitcoin upgrade has required. The federal PQC transition timeline creates an external clock: if government systems are migrating by 2030, the argument for Bitcoin remaining on deprecated cryptography weakens considerably.
The next inflection point is BIP-360's activation proposal on mainnet. If it passes, the five-year clock proposed by BIP-361 starts ticking. If it stalls, the network bets that quantum hardware development will remain slow enough to allow reactive measures. Both paths carry risk. The data suggests the window for low-cost preparation is measured in years, not decades.