A proposal to shield Bitcoin from quantum computers would render roughly a third of all coins permanently unspendable.
A proposal to shield Bitcoin from quantum computers would render roughly a third of all coins permanently unspendable.

Roughly 6.7 million Bitcoin, a third of total supply, sit in addresses vulnerable to quantum attack, and the proposed fix would freeze them permanently.
The proposal, BIP-361, was authored by a group including Jameson Lopp, co-founder of custody firm Casa and a veteran security researcher, and was assigned its number on 11 February 2026. It remains in draft status, with no activation and no fixed date.
A Google-commissioned study puts the exposed supply at approximately 6.7 million BTC, worth about $425 billion at current prices near $63,400. Within that total, roughly 1.7 million coins sit in Bitcoin's oldest address format from 2009 and 2010, widely believed to include Satoshi Nakamoto's holdings. They have never moved, and if the keys are lost, no migration is possible.
The proposal sets a deadline: coins not moved to a new quantum-safe address type by a fixed date would become unspendable. No machine capable of breaking Bitcoin's cryptography exists today, but McKinsey research places the arrival of a cryptographically relevant quantum computer as early as 2027 to 2030, and expert surveys put the probability of arrival before the late 2030s above 50 percent.
The mechanism works in two steps. BIP-360 creates a new address type a quantum computer could not break, adding an option without removing anything. BIP-361, formally titled "Post Quantum Migration and Legacy Signature Sunset," then sets the deadline. The second cannot function until the first is activated, so the clock only begins once a safe destination exists.
The vulnerability turns on a single question: has a public key ever been revealed on the blockchain? For most modern addresses it has not, since the key only becomes visible at the moment of spending. But Bitcoin's oldest address format published the raw public key directly on the chain, and any address reused after spending permanently exposes its key. An attacker who broke a key would not need to spend immediately; the proposal's authors describe a scenario in which funds are drained gradually over weeks or months to avoid detection.
The migration has three phases
BIP-361 sets out three phases. In Phase A, funds can no longer be sent to old vulnerable addresses, though existing coins remain spendable, running 160,000 blocks, roughly three years, after activation. In Phase B, signatures from the old system stop being valid, so coins that have not migrated can no longer be spent at all, two years after Phase A. Phase C, the least developed, proposes a recovery route for frozen coins using a cryptographic proof that the holder owns the original wallet recovery phrase, without revealing it. If Phase C works, the freeze becomes a strong inconvenience rather than a permanent loss; if it does not, Phase B is final.
The proposal specifies that miner signalling would not begin before 1 January 2027 and would require 90 percent support, a deliberately high bar. For comparison, the BIP-110 proposal that reached its signalling window this August has attracted under 2 percent miner support.
Why the fix is more contested than the threat
The proposal collides with Bitcoin's central promise. The phrase "not your keys, not your coins" holds that possession of the private key is absolute and no authority can interfere with funds. Critics argue BIP-361 is confiscation in effect if not in form, and that the precedent is more dangerous than the threat it addresses. If the network can render one category of output unspendable for a good reason, the mechanism exists to do so again for a worse one.
Supporters frame the choice as between two bad outcomes. Doing nothing does not preserve the vulnerable coins; it hands them to whoever reaches quantum capability first. The proposal describes three possible approaches: allow anyone to take vulnerable coins, allow them to be taken gradually, or allow nobody to take them. There is no fourth option in which the coins simply remain safe.
The debate has shifted from cryptography to governance. Bitcoin has no chief executive and no foundation empowered to ship a consensus change; the last one, Taproot, activated in November 2021. TRON's Justin Sun has announced plans to deploy post-quantum signatures on that network's mainnet, and Ethereum co-founder Vitalik Buterin has warned publicly about the risk, but neither Bitcoin nor Ethereum has published a formal post-quantum upgrade roadmap.
For holders, nothing is required today. BIP-361 is a draft, depends on a prerequisite that has not been activated, and signalling could not begin before 2027 under its own terms. Coins in modern address formats that have never been spent from are not currently exposed, and avoiding address reuse remains a reasonable habit regardless of quantum considerations. The more consequential point is long term: any Bitcoin intended to sit untouched for a decade or more, including inheritance arrangements and corporate treasury positions, now carries a migration requirement that did not exist two years ago. Three markers will indicate whether this moves from debate to implementation: BIP-360 progress, Phase C research, and whether miner support approaches the 90 percent threshold in the January 2027 signalling window.
This article is for informational purposes only and does not constitute investment advice.