BitMEX Research has proposed a "quantum canary" security mechanism for Bitcoin: a publicly known bounty address containing enough BTC to tempt a quantum attacker. If the address is cracked and funds moved, the protocol would automatically freeze all wallets still using quantum-vulnerable legacy formats. This "wait-and-react" strategy stands in contrast to the mandatory freeze timeline of BIP-361.
The Bounty Trap: A Lure for Quantum Attacks
The canary address uses the P2PK format, exposing the public key on-chain and making it a prime target. A predetermined amount of BTC is deposited—sufficient to motivate an attacker to test their capabilities. If the funds are spent, it serves as a public declaration that quantum cracking is viable. The protocol then triggers a freeze on all legacy wallets. BitMEX Research describes this as a "wait-and-react" approach, unlike BIP-361's "forced regardless of attack" design.
Safety Window: One-Year Buffer for Migration
Alongside the canary, BitMEX Research proposes a "safety window." While the canary remains untouched, users can move assets from legacy addresses, but the recipient cannot spend them for approximately one year. The cooling-off period allows the protocol to retroactively freeze recently migrated funds if the canary is triggered during that window, preventing last-minute escapes before a quantum attack. CoinDesk's Margaux Nijkerk notes the core assumption: quantum threats won't go from zero to full-scale instantly; there will be a transitional period of probing, which the canary is designed to detect.
The Flaw: Why Would an Attacker Touch the Bounty?
Critics quickly targeted the scheme's central assumption. A rational attacker with quantum capability would avoid a conspicuous trap and instead silently target high-value cold wallets. The 2016 DAO incident serves as a precedent: the attacker didn't test publicly but drained 3.6 million ETH in one go. If a Bitcoin quantum attack follows a similar pattern, the canary system would fail to provide any warning. Additionally, setting the bounty amount is tricky—too small and it won't attract state-level actors; too large and it creates a massive incentive for attack.
The Other Side: BIP-361 and Its Costs
The canary proposal aims to replace BIP-361, authored by Jameson Lopp and others. BIP-361 has two enforcement phases: Phase A bans sending new BTC to quantum-vulnerable legacy addresses; Phase B invalidates all legacy signatures after two years, permanently freezing unmigrated coins. Critics call it "authoritarian and confiscatory." On-chain data shows about 25% of Bitcoin still resides in P2PK legacy addresses, including early miner coins and suspected Satoshi wallets. Enforcement would freeze those funds permanently.
Quantum Threat Timeline: Decade-Long Window or False Alarm?
The underlying tension stems from divergent assessments of quantum risk. Google's latest paper lowered resource estimates for a quantum attack, leading some researchers to believe a real risk window may open within ten years. Others argue current quantum computers are still orders of magnitude away from breaking 256-bit elliptic curve cryptography. Solana's founder warned Bitcoin could collapse if it doesn't achieve quantum resistance by 2030; StarkWare researchers proposed an alternative QSB scheme. The only consensus: regardless of the approach, the time for the Bitcoin community to reach consensus is shorter than most realize.
The quantum canary offers a moderate path for those who prefer to wait and see—no forced action now, but an automatic line of defense built in. The catch: if the canary never sings, it may not mean the threat is absent, but that the attacker simply chose not to trigger it. In that case, the entire defense could be useless at the critical moment.

