Charles Hoskinson has taken direct aim at Bitcoin’s proposed quantum defense, arguing that BIP 361 is being presented as a soft fork even though, in his view, the plan would only work as a hard fork. In comments made during a livestream this week, the Cardano founder said the proposal could leave about 1.7 million BTC beyond recovery, including coins widely believed to belong to Satoshi Nakamoto.
Hoskinson points to exposed public keys onchain
According to Hoskinson, data as of March 1, 2026 shows that more than 34% of Bitcoin’s circulating supply has an exposed public key onchain, making those holdings vulnerable if a sufficiently capable quantum computer emerges. He put that total at roughly 8 million BTC. BIP 361, authored by Jameson Lopp, Christian Papathanasiou, Ian Smith, Joe Ross, Steve Vaile, and Pierre-Luc Dallaire-Demers, proposes freezing quantum-vulnerable funds and moving users to post-quantum addresses.
The dispute centers on how the proposal is classified
His main objection is not only about the size of the risk. He says the proposal mislabels the kind of protocol change it would require. In Hoskinson’s telling, the mechanics described in BIP 361 go beyond what a soft fork can do and amount to a hard fork instead. For Bitcoin, that is a major distinction, because the network has never carried out a hard fork.
The proposal also includes a zero-knowledge proof recovery path intended to let users reclaim frozen funds if they still control HD wallet seed phrases. Hoskinson argues that this breaks down for older wallets created before the BIP 32 and BIP 39 standards became widely used. In those cases, he said, a seed-phrase-based ZK recovery system cannot restore access.
He says older wallets leave 1.7 million BTC outside the recovery path
Hoskinson estimates that about 1.7 million BTC fall into that category. He included in that figure roughly 1.1 million BTC believed to be Satoshi’s holdings. His claim is blunt: for coins stored under those older structures, there is no workable zero-knowledge proof that can be built around a seed phrase to recover them.
That leads to a governance argument. Hoskinson says Bitcoin lacks the onchain governance needed to resolve a protocol-level decision of this scale in a clean way. In his view, if the network remains unwilling to hard fork, Bitcoin could face two options in the 2030s: allow a quantum-capable attacker to drain vulnerable addresses and dump a large block of supply onto the open market, or force through a hard fork that leaves 1.7 million BTC permanently unspendable.
Institutional ownership is part of his warning
He also tied the issue to large institutional holders. Hoskinson said Blackrock and Strategy have built major Bitcoin positions, and he added that the U.S. government could also emerge as a strategic reserve holder. His view is that such actors may eventually pressure Bitcoin developers to act, regardless of ideological objections inside the community.
Hoskinson acknowledged that he holds no authority within the Bitcoin ecosystem and described himself as an observer who has warned about the problem for years. He added that Cardano, Ethereum, and Solana are all pursuing post-quantum work on their own tracks, while governance systems such as Cardano’s provide a formal route for collective protocol decisions. He closed with a message to Bitcoin developers: if a hard fork becomes unavoidable, treat it as a full protocol upgrade and execute it properly.

