Security firm Project Eleven on Thursday unveiled a cryptographic proposal aimed at one of Bitcoin’s hardest post-quantum questions: how a user could still prove wallet ownership once a quantum computer can derive private keys and generate valid signatures.

In a thread posted on X on Wednesday, Project Eleven CEO Alex Pruden said the main issue is not simply defending wallets from quantum attacks. The deeper problem, he wrote, is establishing ownership after those attacks become possible.
“How do you prove you still own a wallet after a quantum computer can forge its signatures?” Pruden wrote. “After Q-Day, once a quantum computer can derive an ECC private key from its public key, a valid signature no longer proves ownership. Both the quantum adversary and the legitimate owner are able to produce identical signatures.”
What Q-Day means for Bitcoin wallets
“Q-Day” is the point at which a quantum computer can break the elliptic curve cryptography that protects Bitcoin transactions. The concern across the industry is that an attacker could derive a private key from a public key, which would make digital signatures unreliable as proof that a wallet belongs to a specific owner.
In practical terms, that would let an attacker target vulnerable wallets, forge digital signatures, and move Bitcoin without the owner’s permission.
A derivation-based proof instead of a signature-based one
Project Eleven’s proposal uses a wallet’s key derivation path. The idea is to let a user prove control of the parent key that generated the wallet’s private key, without disclosing that parent key.
The company says a quantum computer cannot reconstruct that parent key. On that basis, it argues the method can still separate a legitimate owner from an attacker even after the wallet’s private key has been compromised.
“So even after Q-Day, an attacker who’s broken your address’s private key does not hold, and can’t compute, the seed phrase it was derived from,” Pruden wrote. “Proving you know that parent key, without revealing it, is something only the real owner can do.”
Built with Binius and based on “signature lifting”
Pruden said the work was developed with Jim Posen, lead maintainer of the open-source Binius zero-knowledge proof system. The proposal builds on a technique called “signature lifting,” first proposed by researchers Alon Sattath and Robert Wyborski.
Project Eleven funded Posen to implement the approach with Binius, an open-source proof system designed to speed up hash-heavy cryptographic operations.
The firm said the recovery mechanism is meant for users who miss a future migration to quantum-safe addresses. It is being pitched as a fallback rather than a replacement for migration, and it arrives as Bitcoin-related work on post-quantum readiness picks up pace.
Broader post-quantum work is already moving forward
In February, Bitcoin developers moved BIP-360 into the formal review process, creating a basis for future quantum-resistant upgrades. In March, BTQ Technologies released the first working implementation on its Bitcoin Quantum testnet, giving developers a way to test the proposal while also showing how difficult it may be to build consensus for a network-wide upgrade.
In June, Coinbase’s quantum advisory council urged blockchain developers to start planning post-quantum migrations. The group warned that about 7 million Bitcoin could eventually be exposed to quantum attacks if owners do not move funds to quantum-safe addresses.
Later that month, President Donald Trump signed executive orders to speed the federal government’s transition to post-quantum cryptography, adding momentum to preparations for Q-Day more broadly.
A fallback for wallets that miss the migration window
“As much as I’d love for the entire world to take a quantum migration plan seriously, the reality is that some digital asset wallets will miss the window,” Pruden wrote. “This gives them a fallback: prove ownership through derivation, not signature, even after that window closes.”

