NewsCryptoBitcoin's Quantum Threat Debate Shifts to Governance Battle Over BIP-361

Bitcoin's Quantum Threat Debate Shifts to Governance Battle Over BIP-361

Author: CryptoNewsNet·

Key Takeaways

  • •BIP-361 proposes a phased migration away from Bitcoin's quantum-vulnerable signature schemes, with Stage A restricting transfers to legacy addresses and Stage B eventually rendering unmigrated coins unspendable.
  • •Cardano co-founder Charles Hoskinson contended that Bitcoin's decentralized governance model, which lacks on-chain voting, may be the network's greatest obstacle to addressing quantum threats in time.
  • •As of March 1, 2026, more than 34% of all Bitcoin had exposed a public key onchain, making those coins theoretically vulnerable to theft if sufficiently powerful quantum computers are developed.
  • •Recovery mechanisms using zero-knowledge proofs and Paradigm's PACTs concept are under exploration, but these solutions do not cover all wallet formats, including approximately 1.1 million BTC attributed to Satoshi Nakamoto.
  • •Author Jameson Lopp emphasized that BIP-361 remains a rough contingency plan requiring further research, not a finalized specification proposed for activation.
Bitcoin's Quantum Threat Debate Shifts to Governance Battle Over BIP-361

Bitcoin's Quantum Threat Debate Shifts to Governance Battle Over BIP-361

A draft proposal designed to shield Bitcoin from future quantum computing breakthroughs has reframed the conversation. The debate has moved beyond cryptography to focus on governance: can a system engineered to resist change reach consensus on a critical upgrade before the threat becomes urgent?

The issue gained fresh attention this week when Cardano co-founder Charles Hoskinson argued that Bitcoin's greatest challenge is not quantum computing itself, but the network's capacity to coordinate a response before the danger materializes.

Hoskinson: Bitcoin May Struggle to Coordinate

Speaking on The Starting Block on Friday, Hoskinson warned that quantum computing could threaten Bitcoin's standing as the world's leading digital currency—currently valued at approximately $1.3 trillion—if the network cannot agree on an upgrade.

"The issue with Bitcoin is it's frozen in time. It's very difficult to change anything," he said, according to The Block.

Hoskinson contrasted Bitcoin's rigidity with Cardano's governance framework. "If there needs to be a migration, we can have a vote, and then there could be an onchain function to do that," he said.

Cardano has already demonstrated this process in practice. In June, elected delegates rejected a Cardano Foundation Summit funding proposal after it failed to secure the required two-thirds majority. Bitcoin has no comparable on-chain voting mechanism, and the divergence between the two networks' governance models has become a central point of discussion.

Bitcoin's governance model relies on rough consensus among developers, miners, exchanges, and users—a process that has successfully delivered major upgrades before, including SegWit in 2017 and Taproot in 2021, though both required years of debate and in SegWit's case triggered the creation of Bitcoin Cash.

BIP-361 Proposes a Staged Migration

At the center of the conversation is BIP-361, titled "Post Quantum Migration and Legacy Signature Sunset." The proposal was authored by Jameson Lopp, a founding member of Casa, along with five co-authors, who outlined a framework for transitioning away from Bitcoin's current signature schemes—ECDSA and Schnorr.

Both schemes rely on elliptic curve cryptography, which a sufficiently powerful quantum computer running Shor's algorithm could theoretically break. While no such machine exists today, the National Institute of Standards and Technology published its first post-quantum cryptography standards in August 2024, signaling that governments and industries are already preparing for the transition.

According to the proposal, as of March 1, 2026, more than 34% of all Bitcoin had exposed a public key onchain, making those coins theoretically vulnerable to theft if sufficiently powerful quantum computers are developed.

The migration would unfold in phases. Stage A, beginning roughly three years after implementation, would prohibit transfers to vulnerable legacy addresses. Stage B, starting two years after Stage A, would render unmigrated coins unspendable. While users would technically retain custody, those coins would no longer be usable.

Freeze Mechanism Draws Backlash

Stage B proved the most contentious element of the proposal. Critics on developer forums and X labeled the plan "authoritarian and confiscatory," while others called it "predatory," as reported by Yahoo Finance.

Lopp has been clear that BIP-361 is not a finished product. "It isn't a spec, nor is it proposed for activation. It's a rough idea for a contingency plan that needs more R&D," he said in April, as reported by BigGo Finance, emphasizing that he preferred investigating the problem to ignoring it.

Recovery Paths Remain Early and Incomplete

Developers have begun exploring ways to reduce the proposal's impact. A prototype from the Project Eleven security team and Jim Posen of Binius employs zero-knowledge proofs, enabling owners of modern seed-based wallets to prove ownership and recover frozen funds. This approach addresses one of the chief concerns: that the proposal could permanently lock users out of their coins.

However, this technique applies only to wallets conforming to the BIP-32 standard introduced in 2012. It does not cover older formats such as pay-to-pub-key outputs—including the approximately 1.1 million BTC believed to belong to Satoshi Nakamoto, valued at roughly $84 billion.

A separate proposal from Paradigm, known as PACTs, offers a potential workaround, provided key holders act proactively before the migration deadline.

As Cryptopolitan previously reported, Bitcoin's developers have largely moved past the question of whether post-quantum security is necessary. With BIP-360 and its Pay-to-Merkle-Root output type now merged, attention has shifted toward implementation. The open question is whether miners, exchanges, custodians, and users can coordinate their migration before quantum computing forces the issue.

What Comes Next for Post-Quantum Bitcoin?

Paradigm General Partner Dan Robinson has proposed "Provable Address-Control Timestamps" (PACTs), a research concept that would allow Bitcoin holders to privately timestamp proof of wallet ownership before quantum computers become practical.

If Bitcoin eventually adopts a quantum migration plan such as BIP-361, users who had created a PACT could potentially recover frozen coins using quantum-resistant STARK zero-knowledge proofs. The concept, however, would require additional protocol changes and broad community consensus before implementation.

Some researchers and developers have proposed alternative recovery mechanisms, including zero-knowledge proof techniques and other cryptographic methods, though none are currently part of BIP-361. Any recovery mechanism would need its own proposal and widespread community support.

Because BIP-361 remains a draft, its migration rules, timelines, and treatment of legacy coins could all evolve before any future implementation. The broader question it raises—whether Bitcoin's decentralized coordination model can respond to a predictable but distant threat faster than the threat itself arrives—may ultimately prove more consequential than any single proposal.