Bitcoin Developers Push BIP 360 and P2MR to Reduce Quantum Attack Exposure

Bitcoin Developers Push BIP 360 and P2MR to Reduce Quantum Attack Exposure

N
News Editor 01
2026-07-24 10:05:18
BIP 360 proposes a new P2MR output model for Bitcoin, removing key-path spending and aiming to limit public-key exposure on-chain as a defense against future quantum threats.

Bitcoin developers are advancing BIP 360, a proposal centered on a new output type called Pay-to-Merkle-Root (P2MR). The design is built to support quantum-resistant script trees while remaining compatible with Bitcoin’s existing Tapscript framework. Its main change is simple but significant: P2MR removes key-path spending and allows funds to be spent only through the script path, which developers say cuts down possible attack surfaces.

The proposal addresses a long-term concern in Bitcoin security. If quantum computers become powerful enough, public keys revealed on-chain could in theory be used to derive private keys, exposing digital assets to unauthorized transfers. The article identifies Taproot addresses, Pay-to-Public-Key (P2PK) outputs, and reused addresses as notable areas of concern because public-key data is visible in those cases.

Why P2MR focuses on eliminating public-key exposure

P2MR is structurally similar to Taproot, but it drops the key-path option entirely. That design choice is meant to keep public keys from appearing on the blockchain wherever possible. In the view of the developers behind the proposal, that creates an extra defensive layer for Bitcoin if quantum computing capabilities advance faster than expected over the next several years.

The team also presents BIP 360 as groundwork for later protocol changes, not only as a security patch for current conditions. According to the proposal, future soft forks could introduce post-quantum signature schemes such as ML-DSA (Dilithium) and SLH-DSA (SPHINCS+).

Authors describe the proposal as the start of a transition

Hunter Beast, one of the principal authors of BIP 360 and a protocol engineer, described the change as the beginning of a transition period. He said the team is also working on supplementary measures aimed at protecting dormant assets, which may be especially exposed as security threats evolve.

Contributor Isabel Foxen Duke, who works in technical communication, said the documentation was written in everyday language and presented transparently so that it could be understood not only by software developers but also by the broader public. That choice reflects the sensitivity of the subject and the need for wider scrutiny.

Post-quantum migration is already a broader policy issue

The source notes that governments and major technology companies are increasing investment in post-quantum cryptography. The U.S. National Security Agency wants quantum-safe systems to become commonplace by 2030, while the National Institute of Standards and Technology plans to phase out elliptic curve cryptography during the 2030s as part of a broader shift toward quantum-resistant standards.

Supporters of the proposal argue that BIP 360 keeps Bitcoin aligned with that direction. The immediate goal is protocol preparation: reduce the exposure created by on-chain public keys now, and leave room for post-quantum signature systems that may be introduced later.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.