Paradigm’s PACTs Proposal Offers Dormant Bitcoin a Private Hedge Against Quantum Risk

Paradigm’s PACTs Proposal Offers Dormant Bitcoin a Private Hedge Against Quantum Risk

N
News Editor 01
2026-07-08 20:50:12
Paradigm researcher Dan Robinson has proposed PACTs, a privacy-preserving method that could let dormant bitcoin holders prove address control before quantum threats emerge, without moving coins or publicly revealing ownership.
BitcoinQuantum ComputingParadigmPACTsCrypto Security

Paradigm researcher and general partner Dan Robinson has introduced a proposal called Provable Address-Control Timestamps, or PACTs, aimed at giving dormant bitcoin holders a private way to prepare for a future quantum computing threat. Published on May 1, the idea is designed to help holders of older, potentially vulnerable bitcoin addresses establish proof of control ahead of time without moving funds, broadcasting any public signal, or revealing their identity onchain.

The proposal speaks directly to a long-running concern in Bitcoin: if cryptographically relevant quantum computers ever become capable of attacking exposed public keys before the network adopts a defense, some legacy coins could become stealable. At the same time, any emergency protocol change that forces coins to migrate could expose dormant holders who have intentionally remained silent for years. PACTs is presented as a possible middle path.

Why quantum risk matters for old bitcoin addresses

Robinson frames the issue around addresses whose public keys are already exposed. In a world where powerful enough quantum machines exist, those addresses may be more vulnerable than modern outputs that still hide public keys until spending. If Bitcoin were to respond with a “sunset” style soft fork that disables or restricts quantum-vulnerable coins after a cutoff date, users with old addresses could be forced into a public migration process.

That creates a unique dilemma for dormant wallets, especially the ones widely believed to be associated with Satoshi Nakamoto. According to the figures cited in the report, wallets linked to Satoshi are estimated to hold about 1.1 million BTC, worth more than $75 billion at current prices. Any forced movement from those addresses would not just be a technical event. It would also become a major signal to the market, potentially indicating whether the keys are still controlled and whether the owner is active.

PACTs tries to reduce that pressure by letting someone prepare evidence of control now while staying silent in public. In other words, if a quantum emergency ever arrives and the protocol later supports a recovery mechanism, a dormant holder may already have the cryptographic receipts needed to prove prior control.

How the PACTs process works

The proposal outlines a three-step construction using tools that already exist in the Bitcoin ecosystem. First, the holder creates a 256-bit secret salt. Second, they use a BIP-322 full message signature to prove control over a vulnerable scriptPubKey. Third, they take the resulting commitment hash and timestamp it through OpenTimestamps, a system that batches hashes into a Merkle tree and anchors the root into Bitcoin using an OP_RETURN output.

What makes the design notable is what it does not require. There is no onchain fund movement, no need to reveal the address owner publicly, and no immediate protocol change. The user simply stores three things privately: the secret salt, the BIP-322 control proof, and the OpenTimestamps proof file. If no quantum crisis ever materializes, nothing further may be needed. If one does, the holder may already have a time-anchored record proving they controlled the address before a predefined cutoff date.

Robinson describes OpenTimestamps as a free and trustless Bitcoin-based timestamping service. He ties the idea back to Bitcoin’s original architecture, noting that Satoshi Nakamoto described the network in the 2008 white paper as a distributed timestamp server. In that sense, PACTs attempts to repurpose an existing Bitcoin-native concept for a possible future security emergency.

A rescue path that depends on future upgrades

PACTs does not solve the quantum problem by itself. It is more accurately described as a preparedness layer. For the proposal to become actionable in a real recovery scenario, Bitcoin would still need broader social and technical coordination. Robinson notes that if the network eventually adopted some form of sunset soft fork, a PACT holder could present a STARK-based zero-knowledge proof showing that they knew both the secret salt and the control proof before a date set prior to quantum capability becoming practical.

Under that vision, the holder could unlock a rescue transaction without revealing the original keys or the salt itself. The transaction would also need to be bound in a way that prevents replay. This is where the proposal moves from present-day tooling into future protocol design: Bitcoin does not currently have this full recovery path activated, and any such system would need review, implementation work, and eventual consensus from the wider community.

Robinson explicitly says that PACTs requires no Bitcoin fork today, but it would depend in the future on support for STARK verification and on community agreement to include such a rescue mechanism. That means the proposal is not a finalized roadmap. It is an early framework intended to stimulate discussion and provide optionality before time pressure sets in.

Relationship to existing Bitcoin quantum discussions

The proposal builds on broader debates already underway in the Bitcoin ecosystem. It references draft BIP-361, which addresses legacy addresses exposed to quantum attacks, and also points to earlier forum discussions by Jeremy Rubin on related ideas. In parallel, other Bitcoin developers have been publicly discussing the possibility that progress in quantum computing may be accelerating faster than many expected.

Following publication, developers and quantum-focused commentators responded quickly on X. Much of the discussion centered on practical issues: how realistic STARK integration would be, how difficult it would be to add zero-knowledge proof verification through a soft fork, and whether the privacy guarantees described in the proposal would hold under real-world scrutiny. Those responses underscore that the concept has attracted attention, but also that it remains at an early and highly debated stage.

Important limitations and caveats

Robinson is careful not to oversell the proposal. He notes that Bitcoin may never adopt a quantum sunset mechanism at all. Even if it does, there is no guarantee that this specific recovery path would be included. For that reason, he says holders should not rely solely on PACTs unless and until a standardized rescue protocol is actually accepted by the community.

There are also scope limitations. The current design does not extend cleanly to multisig wallets, complex scripts, or custodial accounts. Each of those use cases would require additional standardization and likely more intricate proof systems. That means PACTs, at least in its present form, is best understood as a proposal focused on simpler classes of vulnerable outputs rather than a universal solution for all bitcoin custody structures.

Even so, Robinson argues that the cost of creating a PACT could be low enough to justify action once a standard format is agreed. From his perspective, the main advantage of adopting such a standard early is time. Long-term holders would have a chance to prepare quietly before any emergency governance process begins, rather than scrambling in the middle of a crisis.

Why the proposal matters now

The practical value of PACTs today lies less in immediate deployment and more in strategic preparation. Bitcoin’s quantum debate has often been framed as a binary choice between doing nothing and forcing visible migrations later. PACTs introduces a third idea: private precommitment. If accepted in some form, it could give dormant holders a way to preserve optionality without changing their public footprint.

That matters for ordinary users who still control old exposed addresses, but it matters even more for historically significant holdings. Any system that can reduce the need for public proof of life from dormant whale wallets would likely attract intense interest across the Bitcoin ecosystem. In this way, the proposal is not just about cryptography. It is also about privacy, market signaling, and how Bitcoin might manage a security transition without unnecessarily exposing its oldest holders.

For now, PACTs remains a proposal in need of review by cryptographers, Bitcoin developers, and the broader community. Robinson acknowledged as much and credited contributors including Eli Ben-Sasson, Jameson Lopp, Neha Narula, Nic Carter, and others. Whether or not the design is eventually adopted, it has already sharpened an increasingly important conversation: how Bitcoin should prepare for quantum risk before that risk becomes urgent.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.