Bitcoin’s quantum problem may hit governance before quantum hardware arrives

Bitcoin’s quantum problem may hit governance before quantum hardware arrives

N
News Editor
2026-07-22 02:16:19
A new zero-knowledge recovery tool from Project Eleven offers a possible escape route for some Bitcoin holders before practical quantum attacks become a reality, but it does not solve the hardest part of the problem. The tool works only for HD wallets created after 2012, leaving older coins in early pay-to-public-key, or P2PK, addresses outside its reach. That includes roughly 1.1 million BTC widely associated with Satoshi Nakamoto, spread across about 22,000 addresses. According to the article, the real debate is no longer just about when quantum computers will become capable of breaking elliptic-curve signatures. It is about what the Bitcoin community should do with legacy coins that cannot be migrated through modern cryptographic methods. Several paths are on the table, including doing nothing, freezing vulnerable coins under proposals such as BIP-361, throttling spending from old addresses, or even redistributing dormant coins through a hard fork. Each option cuts against a different part of Bitcoin’s value proposition, from property rights to immutability. The report also says markets are starting to price in this governance risk. It cites Jefferies’ decision in January 2026 to remove a 10% Bitcoin allocation from its pension model portfolio, not because a quantum breakthrough had already happened, but because of uncertainty over how Bitcoin would handle early vulnerable coins.
BitcoinQuantum ComputingProject ElevenBIP-361Satoshi NakamotoZero-Knowledge ProofsGovernance Risk

Project Eleven has released a zero-knowledge recovery tool that could help some Bitcoin holders move funds before quantum attacks become practical. But the mechanism stops at a hard boundary: it works only for HD wallets created after 2012, leaving a large set of early coins with no comparable path to safety.

That turns the central question away from when quantum computers will arrive and toward a more immediate governance problem: what to do with legacy Bitcoin, including roughly 1.1 million BTC linked in the article to Satoshi Nakamoto.

What Project Eleven’s tool can and cannot do

The MarsBit article says the tool lets modern wallet holders prove control of upstream key material and migrate funds to quantum-resistant addresses without revealing a master private key or mnemonic. In benchmark testing on an M5 MacBook Air, proof generation took 243 milliseconds, verification took 40 milliseconds, and peak memory use reached 2.1 GB.

The design relies on what the report calls “signature uplift,” a concept proposed in 2023 by researchers Or Sattath and Shai Wyborski. The logic is straightforward. Shor’s algorithm can break elliptic-curve signatures, but it does not break hash functions. In HD wallets, child private keys are derived from a master key through HMAC-SHA512, so recovering one child key with a quantum computer would not let an attacker climb back up the derivation tree and reconstruct the parent key.

That is why a zero-knowledge proof can work here. A wallet holder proves control over the parent key material in the derivation path, binds that proof to a quantum-resistant destination address, and moves the funds on-chain without exposing the root secret.

The 2012 cutoff leaves early P2PK coins exposed

The problem is that early Bitcoin did not use that tree structure. Before 2012, wallet addresses were typically generated at random and existed independently of one another. There was no parent-child hierarchy, no master seed, and no BIP-39 mnemonic to anchor a derivation path. In cryptographic terms, the article argues, these coins sit in a dead end.

That matters most for coins in early pay-to-public-key addresses. The report says about 1.1 million BTC mined by Satoshi during 2009 and 2010 are spread across roughly 22,000 P2PK addresses, with around 50 BTC per address. For these outputs, Project Eleven’s approach does not work at all.

The article groups Bitcoin by how much of its public-key data is exposed on-chain:

  • The safest category is unused hash-protected addresses, where the public key remains hidden behind a hash. The report puts that group at more than 65% of circulating supply.
  • The middle category consists of modern addresses with exposed public keys, whether because of address reuse or Taproot design. The estimate given is about 4.5 million to 5.2 million BTC.
  • The highest-risk category is early P2PK addresses, where the public key appears directly in the script. The article places that bucket at roughly 1.7 million to 1.9 million BTC.

The middle group may still be recoverable through Project Eleven’s tool. The oldest P2PK coins are not. In the framing of the article, a technical line drawn around 2012 now decides who can still self-rescue and who cannot.

Four possible responses, none without damage

The report says the issue has moved out of pure cryptography and into politics. It lays out four broad paths for the Bitcoin community, each carrying a different cost.

1. Do nothing and let quantum thieves take what they can

The first option is strict non-intervention: keep the principle that possession of the private key decides ownership, and let whoever gets quantum capability first claim the coins. The article calls this the purest answer and also the most expensive one.

If about 1.7 million BTC now treated by the market as permanently lost were to re-enter secondary markets, that would amount to an extra 8% to 9% of circulating supply, according to the report. It argues that Bitcoin’s “digital gold” narrative would be shaken because the underlying property rights would have changed hands in practice.

2. Freeze vulnerable coins by rule change

The second option is compulsory freezing. Under the BIP-361 proposal cited in the article, new deposits to vulnerable addresses would be barred in the third year after activation, and traditional signature-based spending would lose validity entirely in the fifth year. Coins not migrated in time would become permanently locked.

Economically, the article says, that would amount to deliberately destroying roughly 1.7 million BTC and creating a permanent deflationary shock. The political objection is more direct: in trying to stop future theft, the protocol would first confiscate user funds.

The report notes that protocol developer Mark Erhardt shared the proposal on social media and faced an angry response in the comments.

3. Throttle old-coin outflows through an “hourglass” design

A third path comes from developer Hunter Beast. This approach accepts that old P2PK coins may eventually be stolen but limits how quickly they can move.

The suggested rule is one P2PK spend per block, capped at 1 BTC per transaction. Even if all 1.1 million BTC associated with Satoshi were controlled by a quantum attacker, liquidation would stretch across more than a century. Any attacker trying to cash out would have to compete aggressively in the fee market, and those fees would ultimately flow to miners as a long-term security subsidy.

4. Hard-fork redistribution

The most aggressive option is to hard fork the chain, move ownerless legacy coins into a kind of treasury, and redistribute them pro rata to active holders who have migrated to quantum-resistant addresses.

The article says total supply would still remain at 21 million BTC, but the ledger’s promises would be overridden directly. In that scenario, the likely result would be community fracture, multiple chains each claiming legitimacy, and severe valuation splits.

Cardano founder Charles Hoskinson is cited criticizing BIP-361 in blunt terms, arguing that the proposal is not a soft fork but a hard fork. The article also says BIP-361 co-author Jameson Lopp has described the proposal as closer to an emergency backup sketch than a final answer.

In the article’s view, all four approaches aim to protect Bitcoin’s value while damaging the very principle they are trying to defend. Non-intervention weakens store-of-value claims. Freezing weakens property rights. Throttling concedes that stolen coins can still circulate. Redistribution cuts against ledger immutability.

Markets are already reacting to governance uncertainty

The report argues that many investors still frame quantum risk as a distant hardware issue, but markets have started pricing the governance side of the problem already.

It points to Jefferies, which in January 2026 removed a 10% Bitcoin allocation from its pension model portfolio. The article says the firm’s strategists were explicit: the move was not driven by the arrival of quantum computers, but by uncertainty over how the Bitcoin community would handle early vulnerable coins.

That distinction matters for institutional capital. The piece argues that if Satoshi’s coins can be frozen by consensus-level code, then any coins could in principle be exposed to the same kind of deprivation later. For investors seeking legal and property-right certainty, that possibility alone changes the risk profile.

The article also flags a “harvest now, decrypt later” threat. Because the Bitcoin ledger is public, an attacker can download and store the full chain today. Once practical quantum machines exist, they would not need to interact with the live network to target old wallets with exposed public keys. They could break them offline. In the report’s framing, that delayed attack model makes the governance debate more urgent, not less.

How much Bitcoin is actually exposed

The estimates vary depending on methodology, and the article highlights those differences:

  • BIP-361 puts the share of publicly exposed supply above 34%.
  • Citi estimates the range at 25% to 37%.
  • Glassnode puts it at about 30%.
  • Talos, using a full-ledger scan, arrives at 34.5%.

Whichever figure is used, the article says at least one quarter of Bitcoin remains under long-term quantum threat.

It also cautions that Project Eleven’s tool is still an unaudited early prototype and currently supports only three wallet types. Before it could reach mainnet use, the report says, it would still require contentious consensus-rule changes. Treating it as a ready-made emergency exit would be premature.

The article ends at the same unresolved point where the debate begins: how Bitcoin can clear a historical technological break without abandoning its own property-rights principles. No settled answer exists yet. Practical quantum computers have not arrived, but the crisis of confidence around how Bitcoin would respond is already here.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.