TLDR
- BIP-361 is a draft Bitcoin proposal to freeze and migrate wallets with exposed public keys that quantum computers could exploit
- Over 34% of all Bitcoin had exposed public keys on-chain as of March 1, 2026
- The plan is phased, with a roughly three-year delay before restrictions kick in
- Project Eleven built a zero-knowledge proof recovery tool that runs in 243 milliseconds on a laptop
- Satoshi Nakamoto’s estimated 1.1 million BTC cannot be recovered using this method due to pre-2012 wallet architecture
Bitcoin faces a growing debate over how to protect hundreds of billions of dollars worth of coins from a future quantum computing attack. A draft proposal called BIP-361 lays out a plan to freeze and migrate at-risk wallets before that threat becomes real.
🚨NEW: Bitcoin developers have introduced BIP-361, a proposal designed to safeguard wallets against future quantum-computing risks.
The proposal would:
– Block new BTC transfers to addresses considered vulnerable to quantum attacks.
– Phase out legacy signature schemes over a… pic.twitter.com/Cv3fARUBGR
— Coin Bureau (@coinbureau) July 20, 2026
The proposal was assigned on February 11, 2026, written by Jameson Lopp and five co-authors. Its full title is “Post Quantum Migration and Legacy Signature Sunset.”
What Makes a Wallet Vulnerable
Bitcoin wallets become vulnerable when their public keys are exposed on the blockchain. A powerful enough quantum computer could use that public key to work out the private key, and then spend the coins.
This is not a current threat. The concern is a “harvest now, decrypt later” scenario, where attackers collect exposed keys today and crack them once quantum hardware catches up.
More than 34% of all Bitcoin had already exposed public keys on-chain as of March 1, 2026. That is a large share of the total supply sitting at potential future risk.
Bitcoin uses elliptic curve cryptography, which is a one-way mathematical system. A quantum algorithm called Shor’s algorithm, published in 1994, can reverse that process, turning a public key back into a private key.
How BIP-361 Would Work
The proposal sets out two main phases. Phase A would stop new transactions being sent to vulnerable addresses. This phase has a 160,000-block delay after activation, roughly three years.
Phase B would go further. It would invalidate legacy signatures entirely at a set date five years after activation, sunsetting the older cryptographic methods.
A third phase, Phase C, is still undecided. It would offer a recovery path using zero-knowledge proofs tied to a BIP-39 seed phrase.
Lopp himself has said he does not like the proposal. He wrote it because he found the alternative worse. He has been clear it is not ready for activation and needs more research.
Project Eleven’s Recovery Tool
Separately, crypto research firm Project Eleven has built a working zero-knowledge proof system designed to help users recover frozen coins.
The tool lets a wallet owner prove they hold the key material above their address in a derivation tree, without revealing any of that key material. It runs in 243 milliseconds on a standard laptop with no GPU required.
This matters because it turns a permanent freeze into a recoverable lock for anyone who still holds their seed phrase.
However, it does not help everyone. Satoshi Nakamoto’s estimated 1.1 million Bitcoin, mined in 2009 and 2010, were generated before the BIP-32 wallet standard existed in 2012. Those coins have no derivation tree above them. The recovery tool has nothing to work with.
Bitcoin was trading at around $64,492 at the time of reporting, with the crypto Fear and Greed Index sitting at 28, in “Fear” territory.







