Charles Hoskinson has attacked Bitcoin’s proposed quantum-defense upgrade BIP-361, arguing that the plan is not a soft fork in any practical sense and would instead function as a hard fork. He also said the proposal’s zero-knowledge recovery path fails for a large class of early coins created before 2013, affecting roughly 1.7 million BTC, including more than 1.1 million BTC widely believed to belong to Satoshi Nakamoto.
BIP-361 aims to address quantum risks to Bitcoin signatures
The proposal, formally titled “Post Quantum Migration and Legacy Signature Sunset,” was drafted by Bitcoin developers including Jameson Lopp. Its purpose is to prepare for a scenario in which quantum computing could break the elliptic-curve signature schemes used today. Supporting material cited in the discussion says that as of March 2026, more than 34% of Bitcoin’s supply had exposed public keys and could face quantum-related risk.
Under the draft, transfers to legacy addresses would be blocked after three years, and old digital signatures would stop working entirely after five years. The estimated impact is about 8 million BTC. To let users migrate funds, the proposal includes a zero-knowledge recovery mechanism built around BIP-39 mnemonic phrases, allowing holders to prove control and unlock coins through a new process.
Hoskinson says the recovery path breaks down for pre-2013 wallets
His main objection is that BIP-39 did not exist until 2013. Before that point, early Bitcoin wallets generally relied on local key pools rather than deterministic seeds, which means many of those holders never had mnemonic phrases in the first place. In Hoskinson’s view, that makes the recovery design unusable for a large set of older coins.
He argued that if access restoration depends on a cryptographic proof derived from an assumption that does not hold for early wallets, then those coins cannot be recovered through the mechanism at all. Based on his estimate, around 1.7 million BTC fall into that category, including the 1.1 million BTC he said are tied to Satoshi. If the proposal were adopted in its current form, those funds could end up permanently frozen.
Dispute over whether the proposal is really a soft fork
Hoskinson also challenged the way the proposal has been described. BIP-361’s authors framed it as a soft fork, but he rejected that classification. His argument is that a soft fork tightens existing rules while old software can still operate on the network, whereas a hard fork changes compatibility so deeply that non-upgraded software no longer fits the system cleanly.
Because BIP-361 would invalidate signature methods that current users still depend on, he said the change crosses that line. That is why he called the “soft fork” label a lie in his video remarks.
Lopp says he does not want the plan to be used
Jameson Lopp, one of the co-authors, said on X this week that he does not like the proposal and hopes it never needs to be deployed. He described it as a rough emergency concept rather than a final specification.
Lopp’s position is based on trade-offs. If quantum attacks ever become real, freezing an estimated 5.6 million BTC in dormant coins may be preferable to letting a future attacker recover those assets and sell them. Hoskinson extended the criticism beyond cryptography and argued that Bitcoin still lacks a formal on-chain governance framework for handling highly contentious upgrades, leaving disputes to developer mailing lists and public pressure.

