Key Takeaways:
- BIP-361 would freeze coins in quantum-vulnerable addresses over three stages
- Glassnode estimates 30.2% of Bitcoin's supply — 6.04M BTC — is exposed
- Satoshi's 1.1M BTC from 2009-2010 cannot be recovered under the proposal
Key Takeaways:

Bitcoin's BIP-361 proposal would freeze coins in quantum-vulnerable addresses, affecting 30.2% of supply as the US government pours $2 billion into quantum computing development.
"Quantum computers can extract a private key from a public key. They cannot reverse the hashing that produced it," Project Eleven stated in its recent proof-of-concept for a post-quantum recovery tool. Glassnode estimated in May that 6.04 million BTC — roughly $388 billion at current prices — carry publicly visible keys, making them the most exposed to a quantum attack.
The proposal unfolds in three stages. First, sending funds to quantum-vulnerable addresses would be disallowed. Second, ECDSA and Schnorr spends would be invalidated in a change triggered by a flag day five years after activation. Third, a still-unknown method of recovering legacy UTXOs would be developed. Google published research in March showing a sufficiently powerful quantum computer could hijack a Bitcoin transaction within nine minutes in 41% of cases. A researcher in April cracked a 15-bit elliptic curve cryptography key on a publicly accessible quantum computer, demonstrating the feasibility of deriving private keys from public ones.
The clock is accelerating. The Trump administration's $2 billion quantum investment has put the threat on the map for policymakers, and Google's research this year cut the hardware needed for such attacks by 20 times. US agencies face post-quantum cryptography deadlines by 2031. Project Eleven's recovery tool — running 16 times faster than prior prototypes at 243 milliseconds on a laptop — offers a path back for coins in modern wallets using BIP-32 seed phrases. But it cannot save Satoshi Nakamoto's 1.1 million BTC, mined across roughly 22,000 addresses in 2009 and 2010 before seed phrases existed, with public keys already exposed on-chain.
Project Eleven's tool covers three older address types but remains unaudited, and no blockchain accepts it yet. The proof works like a receipt — it shows ownership of the master key behind an address without revealing it. A quantum computer may crack the private key of an exposed address, but it cannot climb up to the master key because the math there only runs one way. Academics Or Sattath and Shai Wyborski first floated the concept, called signature lifting, in 2023. Lightning Labs CTO Olaoluwa Osuntokun built the first prototype.
The governance question now hanging over Bitcoin: if a freeze comes, which coins ever come back? Casa co-founder Jameson Lopp co-authored BIP-361, and Binance co-founder Changpeng Zhao suggested in June the community could freeze Satoshi's coins after a quantum breakthrough, a proposal critics called confiscation. Under BIP-361's design, coins that never move — including Satoshi's — would freeze forever. The fight will not be over whether coins get frozen, but over which coins ever come back.
This article is for informational purposes only and does not constitute investment advice.