Project Eleven proposes Bitcoin Q-Day recovery method to verify wallet ownership after quantum attacks

Project Eleven proposes Bitcoin Q-Day recovery method to verify wallet ownership after quantum attacks

N
News Editor
2026-07-16 19:00:32
Project Eleven has introduced a proposed Bitcoin recovery mechanism for a post-quantum scenario in which digital signatures can no longer reliably prove wallet ownership. The security firm argues that the real problem after “Q-Day” is not only that quantum computers may derive private keys from public keys, but that both attackers and legitimate holders could then produce equally valid signatures. Its answer is a derivation-based proof tied to a wallet’s key derivation path, allowing a user to prove control of the parent key used to generate a wallet’s private key without revealing that parent key itself. According to CEO Alex Pruden, that distinction would remain meaningful even if the address private key had already been compromised. The proposal was developed with Binius lead maintainer Jim Posen and builds on a method called “signature lifting,” first proposed by Alon Sattath and Robert Wyborski. The company frames the mechanism as a fallback for users who miss a future migration to quantum-safe addresses, at a time when work on Bitcoin’s post-quantum preparedness is moving ahead through BIP-360, BTQ Technologies’ testnet work, and warnings from Coinbase’s quantum advisory council.
BitcoinQuantum ComputingProject ElevenWallet SecurityZero-Knowledge ProofsBIP-360Coinbase

Security firm Project Eleven on Thursday unveiled a cryptographic proposal aimed at one of Bitcoin’s hardest post-quantum questions: how a user could still prove wallet ownership once a quantum computer can derive private keys and generate valid signatures.

Project Eleven proposes Bitcoin Q-Day recovery method to verify wallet ownership after quantum attacks 2

In a thread posted on X on Wednesday, Project Eleven CEO Alex Pruden said the main issue is not simply defending wallets from quantum attacks. The deeper problem, he wrote, is establishing ownership after those attacks become possible.

“How do you prove you still own a wallet after a quantum computer can forge its signatures?” Pruden wrote. “After Q-Day, once a quantum computer can derive an ECC private key from its public key, a valid signature no longer proves ownership. Both the quantum adversary and the legitimate owner are able to produce identical signatures.”

What Q-Day means for Bitcoin wallets

“Q-Day” is the point at which a quantum computer can break the elliptic curve cryptography that protects Bitcoin transactions. The concern across the industry is that an attacker could derive a private key from a public key, which would make digital signatures unreliable as proof that a wallet belongs to a specific owner.

In practical terms, that would let an attacker target vulnerable wallets, forge digital signatures, and move Bitcoin without the owner’s permission.

A derivation-based proof instead of a signature-based one

Project Eleven’s proposal uses a wallet’s key derivation path. The idea is to let a user prove control of the parent key that generated the wallet’s private key, without disclosing that parent key.

The company says a quantum computer cannot reconstruct that parent key. On that basis, it argues the method can still separate a legitimate owner from an attacker even after the wallet’s private key has been compromised.

“So even after Q-Day, an attacker who’s broken your address’s private key does not hold, and can’t compute, the seed phrase it was derived from,” Pruden wrote. “Proving you know that parent key, without revealing it, is something only the real owner can do.”

Built with Binius and based on “signature lifting”

Pruden said the work was developed with Jim Posen, lead maintainer of the open-source Binius zero-knowledge proof system. The proposal builds on a technique called “signature lifting,” first proposed by researchers Alon Sattath and Robert Wyborski.

Project Eleven funded Posen to implement the approach with Binius, an open-source proof system designed to speed up hash-heavy cryptographic operations.

The firm said the recovery mechanism is meant for users who miss a future migration to quantum-safe addresses. It is being pitched as a fallback rather than a replacement for migration, and it arrives as Bitcoin-related work on post-quantum readiness picks up pace.

Broader post-quantum work is already moving forward

In February, Bitcoin developers moved BIP-360 into the formal review process, creating a basis for future quantum-resistant upgrades. In March, BTQ Technologies released the first working implementation on its Bitcoin Quantum testnet, giving developers a way to test the proposal while also showing how difficult it may be to build consensus for a network-wide upgrade.

In June, Coinbase’s quantum advisory council urged blockchain developers to start planning post-quantum migrations. The group warned that about 7 million Bitcoin could eventually be exposed to quantum attacks if owners do not move funds to quantum-safe addresses.

Later that month, President Donald Trump signed executive orders to speed the federal government’s transition to post-quantum cryptography, adding momentum to preparations for Q-Day more broadly.

A fallback for wallets that miss the migration window

“As much as I’d love for the entire world to take a quantum migration plan seriously, the reality is that some digital asset wallets will miss the window,” Pruden wrote. “This gives them a fallback: prove ownership through derivation, not signature, even after that window closes.”

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.