Bitcoin Developers Weigh BIP-361 to Freeze Unmigrated Legacy Coins Over Quantum Risk

Bitcoin Developers Weigh BIP-361 to Freeze Unmigrated Legacy Coins Over Quantum Risk

N
News Editor 01
2026-07-23 18:00:15
A draft proposal called BIP-361 would phase out vulnerable legacy Bitcoin outputs and eventually freeze coins that are not moved, citing the long-term threat posed by quantum computing.
BitcoinQuantum ComputingBIP-361Blockchain SecurityLegacy Addresses

A draft proposal known as BIP-361 is drawing attention across the Bitcoin developer community by outlining a path that could eventually freeze coins left in vulnerable legacy outputs. The proposal is framed as a defensive response to quantum computing. Bitcoin today relies on elliptic curve cryptography, specifically ECDSA and Schnorr signatures, which remain secure against conventional computers. The concern is what happens if quantum machines capable of running Shor’s algorithm become practical enough to reconstruct private keys from public keys already exposed onchain.

That risk is not spread evenly across the network. Older address formats such as P2PK, along with reused addresses, reveal public keys on the blockchain. Estimates cited in the proposal say more than one-third of bitcoin in circulation is held in these categories, including a meaningful share believed to be associated with Satoshi Nakamoto. In a scenario where quantum attacks become viable, those coins would sit in one of the most exposed positions.

A multi-year migration path with tighter rules at each step

BIP-361 sets out a three-stage migration framework that could play out over several years. The first phase would begin about three years after activation. At that point, the network would stop allowing new transactions to the legacy address types considered compromised. Users would still be able to move funds out of those addresses, creating a transition window for holders and service providers to shift to quantum-resistant formats.

Roughly two years later, the second phase would move the restriction into the consensus layer. Once that happens, any transaction that depends on legacy signature schemes would be invalid under Bitcoin’s rules, and any coins that remain unmigrated would be frozen permanently. A third phase is still being researched. Under that idea, users could try to recover frozen coins through zero-knowledge proofs by showing control of their seed phrases without exposing private keys directly. The proposal does not present that recovery path as settled; both the technical design and real-world practicality remain open questions.

Supply effects and trust concerns sit at the center of the debate

The authors describe the freeze mechanism as a necessary way to reduce systemic attack surface before quantum computing becomes practically relevant to Bitcoin. They also point to a possible economic consequence: if some coins become permanently inaccessible through the migration process, Bitcoin’s effective supply would shrink, which could alter parts of the asset’s long-term economic profile.

One of the proposal’s authors, Jameson Lopp, is widely known for work on Bitcoin security and protocol resilience. In the proposal summary, the authors warn that even if Bitcoin is not the first major target of a cryptographically relevant quantum computer, public confirmation that such a machine exists and can break Bitcoin’s cryptography would damage confidence in the network. For now, BIP-361 remains in draft form. There is no activation timeline, and discussion across Bitcoin Core developers and the broader community is expected to focus on both implementation details and the economic consequences of freezing legacy coins.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.