BIP-361 has pushed Bitcoin developers into a sharp argument over how to handle a possible quantum threat. The proposal, submitted by Jameson Lopp and five other security researchers, calls for freezing all Bitcoin addresses considered vulnerable to quantum attacks before such machines become capable of stealing funds. That list would include Satoshi Nakamoto’s long-dormant holdings, estimated in the source at $81.9 billion.
The backlash came quickly. Developer and researcher Mark Erhardt described the proposal as “authoritarian and confiscatory”, while Metaplanet business development head Phil Geiger framed it as taking people’s money to stop it from being stolen later. The dispute is not only about security. It is also about whether Bitcoin should intervene in ownership before an actual attack exists.
Back says the threat is distant, but preparation should start now
Speaking at Paris Blockchain Week, Blockstream CEO Adam Back laid out a different approach. He said quantum computing remains an area with many open questions and argued that current systems are still experimental in nature. Back said he has followed the field for more than 25 years and has seen progress move gradually rather than through sudden breakthroughs.
In comments cited from an earlier Bloomberg interview, Back said today’s quantum computers are still slower than classical computers and that the largest calculation achieved was “factoring 21 into 7×3.” His estimate is that quantum machines capable of posing a real threat to Bitcoin may still be 20 to 40 years away.
He is not arguing for inaction. Back’s position is that Bitcoin should prepare before the threat becomes urgent. In his view, a controlled upgrade path is safer than trying to redesign critical parts of the network during a crisis.
Optional migration instead of forced freezes
Back said the better route is to build optional upgrade mechanisms that let users move voluntarily to quantum-resistant cryptography if and when needed. That is a very different model from freezing coins at the protocol level. One path emphasizes user choice; the other prioritizes preventive restrictions in exchange for a stricter security posture.
He did not explicitly endorse or reject BIP-361, but his language around optionality and controlled deployment puts distance between his view and any blanket freeze of existing holdings.
Blockstream has already tested post-quantum signatures on Liquid
Back also said Blockstream has a dedicated internal quantum research team tracking possible attack vectors for Bitcoin. He pointed to one concrete result: the company has already implemented hash-based signatures on Liquid Network, Blockstream’s Bitcoin layer-2 network. Hash-based signatures are one of the main directions in post-quantum cryptography.
He added that Taproot, activated in 2021, already includes architecture that can support alternative signature schemes. According to Back, that means Bitcoin has room to introduce quantum-resistant options without disrupting current users.
Google research has intensified the timeline debate
The timing question became more urgent after research published last month by Google and the California Institute of Technology. The researchers said functional quantum computers may arrive earlier than many had expected, and that the computing resources needed to break encryption may be far lower than previous mainstream estimates. Google also said a quantum computer could potentially break Bitcoin’s cryptography in nine minutes, enabling what it described as an “on-spend attack.”
Asked what happens if the threat arrives sooner than expected, Back said Bitcoin developers can move quickly when necessary. He pointed to past incidents where vulnerabilities were fixed within hours, arguing that urgency tends to focus attention and speed up consensus inside the development community.
The clash around BIP-361 has turned a technical question into a broader argument about Bitcoin’s rules. The issue is no longer just whether to prepare for quantum attacks, but whether that preparation should begin with freezing coins or with building a migration path that users can choose.

