Why Does Bitcoin’s Quantum Risk Matter?
A proposal to freeze bitcoin held in quantum-vulnerable addresses has moved from a hard-loss debate toward a more complex question: which holders can prove ownership safely after a future quantum threat, and which cannot.
BIP-361, published in April by Jameson Lopp and five co-authors, proposes blocking new deposits to vulnerable bitcoin addresses after 3 years and freezing whatever remains after 5. The plan targets coins in addresses where public keys have already been exposed onchain, a category that accounts for more than 34% of bitcoin’s supply. That includes about 1.1 million BTC widely attributed to Bitcoin’s pseudonymous creator, Satoshi Nakamoto.
The concern centers on a theoretical moment known as Q-Day, when a quantum computer becomes capable of deriving a private key from a public key. If that happens, any address with an exposed public key could be spent by an attacker. The blockchain would not be able to distinguish the attacker from the real owner because both could produce a valid signature.
That is the core problem BIP-361 tries to address. If signatures no longer prove ownership for exposed keys, then leaving those coins spendable creates a race between rightful owners and attackers. Freezing them before that point would stop the race, but it also challenges one of bitcoin’s most important assumptions: that coins remain under the owner’s control as long as the private key is held.
How Would Zero-Knowledge Recovery Work?
Project Eleven says it has built a prototype recovery method based on zero-knowledge proofs, a cryptographic technique that lets a user prove they know something without revealing the underlying information.
The recovery path focuses on modern wallets built around hierarchical deterministic key trees. In those wallets, keys are derived from higher-level key material. A hardened derivation step uses a one-way function, HMAC-SHA512, to produce child keys from parent key material. That structure matters because an attacker who breaks a single exposed address after Q-Day would obtain that specific key, but not the higher-level wallet material used to derive it.
The proof built by Project Eleven and Jim Posen, lead developer of the Binius proof system, uses that gap. A user proves they know the key material above the address in the wallet’s derivation tree, proves that it derives the address in question, and binds the proof to a specific message that can authorize migration. The private key material itself is not disclosed.
In practical terms, that changes the recovery argument. A freeze would not automatically mean permanent loss for everyone. Holders using modern seed-based wallets could, in theory, unlock frozen coins by proving valid upstream ownership without exposing the secret data that protects the rest of their wallet.
Investor Takeaway
The quantum debate is shifting from whether vulnerable coins should be frozen to whether bitcoin can create a recovery process that protects rightful owners without reopening the door to quantum attackers.
Why Are The Benchmarks Important?
The technical case for zero-knowledge recovery depends heavily on performance. A recovery method that works only in theory, or requires specialized hardware, would struggle to become a credible part of bitcoin’s long-term defense plan.
Project Eleven says its prototype generates a proof in 243 milliseconds on an M5 MacBook Air using 4 cores, verifies it in 40 milliseconds, and uses about 2 gigabytes of memory without a GPU. The full run, including circuit construction, proof generation, and self-checking, takes 910 milliseconds on CPU alone. The team describes that as 16 times faster on the full run and about 60 times faster when excluding one-time setup work that a real prover could reuse.
The figures make the proposal more serious because they suggest recovery proofs could be generated by ordinary users on consumer hardware. That matters for bitcoin, where any large-scale migration path must be usable by holders across jurisdictions, custody types, and technical skill levels.
The prototype still has clear limits. It is unaudited, supports 3 Bitcoin address types rather than Taproot, roots the proof at the coin-type key rather than the seed, and does not recover coins on any live blockchain today. Those caveats keep it far from a deployable fix. Still, it gives BIP-361 something it previously lacked: a clearer technical route for reversible freezing.
Why Would Satoshi’s Coins Still Be Locked Out?
The recovery method depends on a wallet having a derivation tree above the address. That is where the Satoshi problem begins.
Hierarchical deterministic wallets arrived with BIP-32, which was assigned on Feb. 11, 2012. Before that, Bitcoin wallets generated keys independently and at random. There was no seed phrase, no derivation path, and no parent key sitting above older addresses.
Satoshi mined through 2009 and 2010 and disappeared from public activity by 2011. The coins attributed to Satoshi sit in old pay-to-public-key outputs where the public key is written directly onchain. Those outputs were generated before seed-based wallet structures became standard. There is no upstream wallet material to prove knowledge of because the tree structure did not exist.
The same problem applies to many other pre-2012 wallets, especially dormant coins from Bitcoin’s earliest years. These are precisely the coins most exposed to a future quantum attack and among the hardest to recover under the proposed proof method.
Investor Takeaway
A working proof could turn a freeze into a recoverable lock for seed-based wallets. It does not solve the oldest bitcoin balances, including coins attributed to Satoshi, because those wallets lack the derivation structure needed for proof-based recovery.
What Does This Mean For Bitcoin Governance?
The debate now moves deeper into bitcoin’s governance layer. Freezing quantum-vulnerable coins would be one of the most controversial changes ever proposed because it would alter the treatment of existing balances, including dormant holdings that may belong to lost, inactive, or deceased owners.
A credible recovery path reduces the force of one objection: that BIP-361 would permanently destroy ownership rights for affected holders. If users can later prove control through zero-knowledge methods, the freeze becomes less like a burn and more like a security lock.
But the recovery path also creates a dividing line between wallet generations. Modern users with seed phrases may have a way out. Early bitcoin holders may not. That split leaves bitcoin with a difficult policy question: whether protecting the network from quantum theft justifies freezing coins that cannot be recovered by the same method.
The prototype does not settle that question. It does, however, changes the terms of the argument. Bitcoin’s quantum risk is no longer only about whether vulnerable coins can be frozen. It is about who gets a key to reopen them, and who never had one in the first place.







