A cryptography advisory board convened by Coinbase has laid out Bitcoin’s quantum problem in blunt terms: the hard part is not replacing signatures, but deciding what to do with old coins that may never move. On that point, the group refused to take a side and said the choice belongs to the Bitcoin community.
The report includes Scott Aaronson of the University of Texas at Austin, Dan Boneh of Stanford, and Justin Drake of the Ethereum Foundation. Its premise is clear. Quantum computers are not a present-day threat to blockchains, and no one can say when they will become one, but that uncertainty is not a reason to delay the debate.
Bitcoin carries the largest visible exposure
The board says the risk is concentrated in Bitcoin. Around 1.7 million BTC sit in roughly 20,000 early pay-to-public-key addresses, a format that reveals the owner’s public key on-chain and leaves those coins more vulnerable to a future quantum attacker.
Many of those holdings are believed to belong to Bitcoin’s pseudonymous creator Satoshi Nakamoto and to other users who lost their keys long ago, meaning the funds cannot be moved into safer formats. Research group Project11 also estimates that another 5 million BTC are exposed through address reuse, though most of that amount is thought to be active exchange wallet holdings.
The dispute centers on coins that cannot migrate
Switching Bitcoin to quantum-resistant signatures is described as the easier task. The real divide is over unmoved coins. One side wants a hard cutoff date: after that point, the signature schemes Bitcoin uses today, ECDSA and Schnorr, would no longer be accepted, and any coins that failed to migrate would become unspendable.
Supporters of that approach argue that leaving vulnerable coins live could hand a future attacker a stockpile large enough to hit the market and damage Bitcoin’s legitimacy. The report cites the possibility of a sanctioned state such as North Korea. The opposing camp calls such a cutoff confiscation, saying it violates the strong property-rights principle Bitcoin was built around and could create a precedent for freezing coins later under government pressure.
Several proposals aim for middle ground
The report notes that a number of proposals now sit between those poles. Hourglass would limit how many vulnerable coins can be spent in each block, reducing the chance of a sudden supply shock. BIP-361, proposed by developer Jameson Lopp and others, would let migrated holders prove ownership after a cutoff using a quantum-resistant proof without exposing any key material. PACTs, proposed by Paradigm’s Dan Robinson, would let owners timestamp a private claim now and move funds later without revealing anything on-chain today.
The Coinbase board says these ideas are not mutually exclusive and could be adopted together. Even so, it would not endorse one answer to the abandoned-coins question. The report states that there is no single correct solution and that the decision has to come from the Bitcoin community itself.
Two recommendations were explicit
The council did make two points without hesitation. First, technical planning for post-quantum migration should start now, because the engineering work is separate from the governance fight over abandoned coins. Second, users need clearer communication so the issue does not linger as unresolved uncertainty.
In its words, the council takes no position on the abandoned-coins debate, but it is direct about starting the engineering work now. It also says users need to know the problem is being treated seriously, because uncertainty carries its own risk. As more proposals emerge and more prominent names enter the discussion, one instruction is shared across the spectrum: move early. The report notes that Bitcoin still has not acted, while Ethereum has spent years preparing for related questions.

