Bitcoin Quantum Threat: Why the New Protection Cannot Save Satoshi’s Coins
Quantum computers are still considered a technology of the future, but Bitcoin developers are already preparing for the moment when they could become a real threat to the cryptocurrency. Research firm Project Eleven has unveiled a prototype tool that could one day help Bitcoin holders prove ownership of their coins even after quantum computers become powerful enough to break today’s cryptography. At the same time, it does not solve one of the most debated issues in the Bitcoin ecosystem protecting the oldest coins, including those commonly associated with Satoshi Nakamoto.
Today, Bitcoin’s security relies on public-key cryptography. As long as conventional computers cannot derive a private key from a public key, the system remains secure. However, this could theoretically change after the arrival of the so-called Q-Day the point at which sufficiently powerful quantum computers become capable of performing such calculations using Shor’s algorithm. If that happens, the greatest risk would affect addresses whose public keys have already been exposed on the blockchain. In that scenario, an attacker could potentially recover the corresponding private key, sign transactions, and impersonate the legitimate owner. A digital signature would no longer be reliable proof of ownership because both the rightful owner and an attacker would be able to produce it. It is precisely this scenario that the proposed BIP-361, introduced earlier this year, aims to address. The proposal outlines a phased protection mechanism: three years after activation, vulnerable addresses would no longer be able to receive new deposits, and two years later, any remaining coins stored on those addresses would be frozen. According to the proposal’s authors, this could potentially affect more than one-third of all existing bitcoins. The proposal immediately sparked intense debate within the Bitcoin community. Critics argued that freezing coins contradicts one of Bitcoin’s core principles the permanence of ownership. If a person can no longer access their funds despite possessing all the necessary information, it raises fundamental questions about the very idea of a decentralized currency.
Project Eleven is attempting to offer a compromise between protecting the network and preserving users’ ownership rights. The company says it has developed a prototype zero-knowledge proof a technology that allows someone to prove ownership without revealing the secret key itself. The concept is relatively straightforward. A modern wallet owner can prove that they know the master key from which the entire wallet structure was derived, without exposing that key to anyone else. If digital signatures become unreliable after Q-Day, this proof could potentially be used to authorize the migration of bitcoins into a new quantum-resistant wallet.
According to the developers, the technology is already fast enough for practical use. On a MacBook Air equipped with Apple’s M5 processor, generating a proof takes approximately 243 milliseconds, while verification requires around 40 milliseconds. The system also operates without a graphics processor and does not require a trusted setup. However, this is also where the technology’s biggest limitation becomes clear. The prototype only works with modern hierarchical deterministic wallets built under the BIP-32 standard introduced in 2012. These wallets generate all addresses from a single master secret commonly known as a seed phrase creating a mathematical relationship between every address in the wallet. That relationship is exactly what makes the zero-knowledge proof possible. The earliest Bitcoin wallets were built very differently. Before BIP-32, every private key was generated independently, without a seed phrase or a hierarchical key tree. As a result, there is simply no parent key that can be used to prove ownership through this new method. This is why the technology cannot recover or protect the oldest bitcoins, including the coins widely believed to belong to Satoshi Nakamoto. Those early holdings have long been at the center of discussions about Bitcoin’s future quantum security. Project Eleven also acknowledges that the prototype remains an early-stage technology. It has not yet undergone an independent security audit, currently supports only a limited number of Bitcoin address types, does not yet work with Taproot, and has not been deployed on the live Bitcoin network. Even so, the existence of this proof changes the nature of the debate surrounding BIP-361.
Until now, freezing quantum-vulnerable coins was often viewed as effectively destroying access to them. If legitimate owners can instead prove ownership through another cryptographic method and move their assets into secure wallets, freezing becomes less of a permanent confiscation and more of a temporary protective measure. The problem of the oldest Bitcoin addresses, however, remains unresolved. Wallets created before the introduction of modern hierarchical architecture simply lack the cryptographic structure required for this type of proof. As a result, the future of roughly 1.1 million bitcoins commonly attributed to Satoshi Nakamoto remains one of the most challenging unresolved questions in the broader discussion about Bitcoin’s quantum security.













