Bitcoin's Quantum Threat Debate Shifts to Governance Amid BIP-361 Controversy
Key Takeaways
- •BIP-361 proposes a phased post-quantum migration that would eventually render unmigrated Bitcoin unspendable, a provision critics have described as authoritarian and confiscatory.
- •Over 34% of all Bitcoin had exposed public keys on-chain as of March 1, 2026, making those funds theoretically vulnerable to theft by sufficiently powerful quantum computers.
- •Cardano co-founder Charles Hoskinson argued that Bitcoin's rigid governance and lack of on-chain voting could hinder its ability to coordinate a proactive response to quantum threats.
- •Recovery prototypes using zero-knowledge proofs exist but only cover BIP-32-compliant wallets, leaving older output types including Satoshi Nakamoto's approximately 1.1 million BTC unprotected.
- •Paradigm's Dan Robinson proposed PACTs, a concept allowing users to privately timestamp proof of wallet ownership before quantum computers become practical, potentially enabling future recovery of frozen coins.

A draft proposal designed to safeguard Bitcoin against future quantum computing breakthroughs has sparked a debate that extends well beyond cryptography into the realm of governance. The central question now facing the Bitcoin community is whether a system deliberately designed to resist change can reach consensus on a critical upgrade before the threat becomes imminent.
Quantum computers running Shor's algorithm could theoretically break the elliptic curve cryptography underlying Bitcoin's ECDSA and Schnorr signature schemes, which are fundamental to how the network authorizes transactions. While no quantum computer today is powerful enough to execute such an attack, researchers across academia and government have been racing to prepare. The U.S. National Institute of Standards and Technology has been running a post-quantum cryptography standardization process since 2016, and has already selected several quantum-resistant algorithms for formal standardization, underscoring that the broader technology industry treats this as a when, not if, problem.
This week, the discussion gained renewed traction when Cardano co-founder Charles Hoskinson argued that Bitcoin's greatest challenge is not quantum computing itself, but rather the network's ability to coordinate a proactive response before the threat materializes.
Hoskinson: Bitcoin May Struggle to Coordinate a Response
Speaking on The Starting Block on Friday, Hoskinson warned that quantum computing could threaten Bitcoin's standing as the world's leading digital currency — currently valued at approximately $1.3 trillion — if the network cannot agree on an upgrade path.
"The issue with Bitcoin is it's frozen in time. It's very difficult to change anything," he said, as reported by The Block.
Hoskinson contrasted Bitcoin's governance challenges with Cardano's model. "If there needs to be a migration, we can have a vote, and then there could be an onchain function to do that," he explained.
Cardano's governance process has already been demonstrated in practice. In June, elected delegates rejected a Summit funding proposal from the Cardano Foundation after it failed to secure the required two-thirds majority. Bitcoin, by contrast, has no comparable on-chain voting mechanism, and this structural divergence has intensified discussions about how the network would handle a coordinated migration.
Bitcoin's history of contentious upgrades reinforces this concern. The years-long block size debate, which culminated in the 2017 activation of SegWit and the subsequent chain splits, demonstrated how difficult protocol changes can be even when the technical merits are widely understood.
BIP-361 Outlines a Staged Migration
At the center of the conversation is BIP-361, titled "Post Quantum Migration and Legacy Signature Sunset." The proposal was authored by Jameson Lopp, a founding member of Casa, alongside five co-authors, who laid out a plan for transitioning away from Bitcoin's current signature schemes — ECDSA and Schnorr.
According to the proposal, as of March 1, 2026, over 34% of all Bitcoin had revealed a public key on-chain, making those funds theoretically vulnerable to theft if sufficiently powerful quantum computers were to emerge. The vulnerability stems from the fact that once a public key is exposed through a transaction, a sufficiently powerful quantum computer could derive the private key and authorize unauthorized transfers.
The migration would unfold in phases. Stage A would begin approximately three years after implementation begins, prohibiting users from sending funds to vulnerable legacy addresses. Stage B would follow two years later, rendering unmigrated coins unspendable. Under this framework, users would still technically retain custody of their coins, but those coins would lose functionality.
Freeze Proposal Draws Sharp Criticism
The final stage of the proposal has proven the most contentious. Critics on developer forums and X described the plan as "authoritarian and confiscatory," while others labeled it "predatory," according to Yahoo Finance.
Lopp has emphasized that BIP-361 is far from finalized. "It isn't a spec, nor is it proposed for activation. It's a rough idea for a contingency plan that needs more R&D," Lopp said in April, as reported by BigGo Finance. He stressed that he was more interested in exploring the issue thoroughly than in ignoring the problem altogether.
Recovery Paths Remain Early and Incomplete
Developers have begun exploring ways to mitigate the proposal's harshest effects. A prototype created by the Project Eleven security team and Jim Posen of Binius leverages zero-knowledge proofs, enabling owners of modern seed-based wallets to prove ownership and recover frozen funds. This approach addresses one of the primary concerns surrounding the proposal — that affected users could permanently lose access to their coins.
However, this technique applies only to wallets compliant with the BIP-32 standard introduced in 2012. It does not cover older output types such as pay-to-pub-key, which includes the approximately 1.1 million BTC — roughly $84 billion — believed to belong to Satoshi Nakamoto.
A separate proposal from Paradigm, known as PACTs, offers a potential recovery path for users who act proactively before the migration deadline.
As previously reported by Cryptopolitan, Bitcoin's developers have largely moved beyond the question of whether post-quantum security is necessary. With BIP-360 and its Pay-to-Merkle-Root output type now merged, attention has shifted toward implementation logistics. The open question is whether miners, exchanges, custodians, and users can align on a coordinated migration before quantum computing advances force the issue.
What Comes Next for Post-Quantum Bitcoin?
Paradigm General Partner Dan Robinson has proposed "Provable Address-Control Timestamps" (PACTs), a research concept that would allow Bitcoin holders to privately timestamp proof of wallet ownership before quantum computers become practical.
If Bitcoin eventually adopts a quantum migration framework such as BIP-361, users who had created a PACT could potentially recover frozen coins using quantum-resistant STARK zero-knowledge proofs. However, this would require additional protocol changes and broad community consensus before implementation.
Several researchers and developers have suggested alternative recovery mechanisms, including zero-knowledge proof techniques and other cryptographic approaches, though none of these are currently part of BIP-361. Any recovery mechanism would need its own proposal and widespread community support.
Because BIP-361 remains a draft, its migration rules, timelines, and treatment of legacy coins could all change substantially before any potential implementation.