Bitcoin’s BIP-360 Proposal Formally Sets Out Quantum-Resistance Roadmap
Bitcoin, with a market capitalization of about $1.3 trillion, relies on elliptic-curve cryptography to secure transactions. If large-scale quantum computers become viable, exposed public keys could potentially be used to derive private keys. Bitcoin developers have therefore proposed BIP-360, adding a quantum-resistant migration to the network’s long-term technical roadmap to reduce the potential risk to existing assets.
Proposed in 2025, BIP-360 introduces Pay-to-Merkle-Root (P2MR), which removes Taproot’s public-key spending path and instead locks scripts with a Merkle root, allowing keys to remain hidden until funds are spent. The proposal remains a draft, with no mainnet activation date, and does not yet introduce a complete post-quantum signature scheme. It nevertheless establishes a foundation for future upgrades.
All Coverage
3 original reportsThe Backstory
The history behind this eventBlockstream Publishes SHRINCS Proposal for Quantum-Secure Bitcoin
A sufficiently powerful quantum computer could eventually break the elliptic-curve signatures protecting Bitcoin, putting coins at risk once their public keys are exposed. That prospect has pushed developers to seek an upgrade well before such machines become practical. Blockstream’s SHRINCS design uses post-quantum signatures while seeking to prevent their much larger data footprint from displacing ordinary transactions, a central obstacle facing earlier proposals.
Blockstream published the SHRINCS Bitcoin Improvement Proposal in August 2026 after testing the mechanism on its Liquid sidechain. The proposal separates bulky post-quantum signature data in a way intended to preserve Bitcoin’s regular transaction capacity. The trade-off is higher data and verification overhead, along with added implementation complexity. SHRINCS must still undergo technical review and win broad developer and community support before any activation path can be considered.
New Proof Offers Bitcoin a Post-Quantum Recovery Path
Bitcoin relies on elliptic-curve cryptography to authenticate wallet transactions. A sufficiently powerful quantum computer could derive private keys from exposed public keys, allowing an attacker to forge signatures and seize funds. The risk is not immediate, but migration is complex because blockchains must distinguish legitimate owners from attackers after conventional signatures fail. Coinbase’s quantum advisory council said in June 2026 that about 7 million bitcoin could eventually be exposed if holders do not move assets to quantum-safe addresses.
On July 15, 2026, Project Eleven unveiled a post-quantum zero-knowledge proof developed with Jim Posen, lead maintainer of the open-source Binius proof system. The method uses BIP-32 wallet derivation to prove control of key material above an address without revealing it, potentially authorizing recovery into a quantum-safe wallet. On an M5 MacBook Air, the prototype generated a proof in 243 milliseconds using four cores and verified it in 40 milliseconds, with 2.1 GB of peak proving memory. It supports P2PKH, P2WPKH and P2SH-P2WPKH addresses, but remains unaudited and requires protocol-level integration.
Bitcoin’s BIP-361 Proposal to Freeze Satoshi’s Coins Sparks Quantum-Defense Debate
Bitcoin developers have proposed BIP-361 to address the risk that future quantum computers capable of breaking elliptic-curve cryptography could steal dormant assets from early addresses whose public keys have already been exposed. The affected holdings include an estimated 1.1 million BTC attributed to Satoshi Nakamoto, putting cybersecurity defenses in direct conflict with the decentralized principle that assets should be immune from confiscation.
Proposed in 2025, BIP-361 sets out a three-stage migration process. It would first encourage transfers to quantum-resistant addresses, then restrict spending from quantum-vulnerable addresses and ultimately freeze assets that have not been migrated. Market estimates suggest about 5.6 million dormant BTC could be affected. Blockstream CEO Adam Back has urged early preparation, while Cardano founder Charles Hoskinson argues that the measure is effectively a hard fork and could permanently lock Satoshi’s 1.1 million BTC.
New Bitcoin PACTs Proposal Seeks to Counter Quantum Computing Threat
If quantum computers were to break Bitcoin's ECDSA signatures, funds held at older addresses whose public keys have been exposed could be stolen. These include addresses attributed to Satoshi Nakamoto, who is estimated to hold about 1.1 million BTC. The dispute centers on whether the community should preemptively freeze vulnerable legacy coins: doing so could prevent theft but might also permanently deprive their original owners of access.
Paradigm partner Dan Robinson unveiled PACTs on May 1, 2026. The proposal would let holders use BIP-322 signatures and OpenTimestamps to create private, timestamped proof of control without moving their BTC. If Bitcoin later freezes vulnerable addresses through a soft fork, holders could recover their assets using quantum-resistant STARK proofs. The proof must be created before a quantum attack or freeze, however, and the proposal has not yet been implemented.
Adam Back Urges Bitcoin to Prepare for Quantum Computing Threat
Bitcoin currently relies on ECDSA and Schnorr signatures to secure asset ownership. A sufficiently powerful quantum computer could eventually use Shor’s algorithm to derive private keys from exposed public keys. Although the threat remains confined to laboratory experiments, migrating the network’s wallets, software and users would take considerable time, making early development of quantum-resistant safeguards critical to asset security.
Speaking at Paris Blockchain Week on April 16, 2026, Blockstream CEO Adam Back advocated introducing an optional upgrade first and giving users 10 years to move funds to quantum-resistant addresses. He estimated that a real threat remains at least 20 years away. Blockstream’s research division proposed a hash-based signature scheme in December 2025. The migration could also clarify whether the roughly 500,000 to 1 million Bitcoin attributed to Satoshi Nakamoto can still be moved.
StarkWare Researcher Proposes Quantum-Safe Bitcoin Without a Soft Fork
Bitcoin transactions rely on elliptic-curve digital signatures. A sufficiently powerful quantum computer running Shor’s algorithm could derive private keys from exposed public keys and steal assets. Replacing the signature mechanism would require network-wide consensus and asset migration, drawing attention to StarkWare’s upgrade-free approach as a fallback until longer-term changes such as BIP-360 are completed.
On April 9, 2026, StarkWare Chief Product Officer and BIP-360 co-author Avihu Levy published the QSB paper and open-source code. The system uses Bitcoin’s existing Script constraints and hash-based proofs to create quantum-resistant transactions without a soft fork or miner activation. Each transaction requires substantial offline GPU computation at an estimated cost of $75–$200, and the tool is currently intended for emergency recovery.
Bitcoin Gets First Working Prototype of Quantum-Resistant Wallet Rescue Tool
Most Bitcoin wallets currently rely on elliptic-curve cryptography. If large-scale quantum computers become capable of breaking signatures, funds tied to exposed public keys could be stolen, while an emergency upgrade could freeze assets that have not been migrated. A tool developed by Lightning Labs Chief Technology Officer Olaoluwa Osuntokun addresses a critical gap by allowing ordinary users to securely prove ownership and recover their funds.
As of July 20, 2026, Osuntokun had completed Bitcoin’s first working prototype of a quantum-resistant wallet rescue tool. The system allows users to submit proof of ownership without revealing their private-key seed and recover frozen funds once the network activates an emergency quantum-defense upgrade. The tool remains a prototype, and Lightning Labs has not announced a formal launch date or any amount of funds involved.
Samson Mow Warns Rushed Bitcoin Quantum Fix Could Create Security Risks
Bitcoin relies primarily on elliptic-curve digital signatures to protect assets. If a practical quantum computer emerges, it could theoretically break addresses whose public keys have been exposed. A transition to quantum resistance is therefore a long-term concern, but protocol changes would require compatibility across nodes, wallets and exchanges worldwide. A flawed upgrade could also directly jeopardize network security.
Jan3 founder Samson Mow opposed accelerating the deployment of a quantum-resistant fix in a recent report. He warned that new signatures could become significantly larger, increasing the burden on block space, bandwidth and verification while creating compatibility vulnerabilities. Mow argued that Bitcoin should not sacrifice its defenses against current attacks before the quantum threat becomes imminent. The report provided no specific launch date or figures for the potential increase.
Bitcoin’s Quantum-Proof Upgrade Faces Governance Challenge
Quantum computers could threaten Bitcoin private keys and onchain assets if they become capable of breaking today’s elliptic-curve cryptography. BOLT Technologies founder Yoon Auh said adopting post-quantum cryptography would require more than a protocol overhaul. Large numbers of wallets, exchanges and holders worldwide would also need to migrate in coordination, testing the efficiency of decentralized governance.
The latest report focuses on whether Bitcoin governance can move quickly enough to address quantum risks, comparing the upgrade capacity of decentralized networks such as Ethereum with that of centralized systems. It gives no value for the assets at risk, potential date of a quantum attack or upgrade timetable. However, it stresses that assets held at legacy addresses could remain exposed if some wallets fail to migrate, even after the core protocol is updated.
ARK Invest White Paper Examines Bitcoin’s Quantum-Attack Resilience
Bitcoin relies on elliptic-curve digital signatures to secure asset ownership, but powerful quantum computers could eventually derive private keys from public keys that have already been exposed. ARK Invest and Bitcoin financial services provider Unchained therefore studied advances in quantum technology and potential paths for Bitcoin to adopt quantum-resistant cryptography, an issue with implications for long-term asset security and consensus on network upgrades.
On March 11, 2026, ARK Invest and Unchained published the “Bitcoin and Quantum Computing” white paper, estimating that 34.6%, or about 6.9 million BTC, is theoretically at risk. That includes about 1.7 million BTC believed to be lost and roughly 5.2 million BTC that could be moved to more secure addresses. The report said the threat would emerge in stages and was not urgent in the near term, leaving the community time to deploy quantum-resistant solutions.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →