A proposed Bitcoin recovery protocol would shield the network from quantum computers but would leave Satoshi Nakamoto's 1.1 million coins frozen in unmigratable legacy addresses.
Bitcoin's elliptic-curve cryptography faces a structural threat from quantum computers executing Shor's algorithm, with Google's Quantum AI team publishing research in March 2026 showing that ECDSA could be broken with as few as 1,200 to 1,450 logical qubits — a fraction of earlier estimates that ran into the tens of millions of physical qubits, according to the paper cited by CoinDesk. Google's own Willow chip currently operates at roughly 105 qubits, and a company spokesperson said "the Willow chip is incapable of breaking modern cryptography," per Cryptopolitan. Google has set 2029 as its internal deadline for migrating authentication services to post-quantum cryptography.
"The practical threat is 20 to 40 years away," Adam Back, chief executive of Blockstream, said, pushing back against what he called premature alarm. A Google-commissioned study estimated that roughly 6.9 million BTC currently sit in address types that would be vulnerable if a cryptographically relevant quantum computer existed today, according to Autheo data.
The governance response has split the Bitcoin community. BIP-361, authored by Jameson Lopp and others, proposes a three-phase plan to retire ECDSA and Schnorr signatures in favor of quantum-resistant alternatives. Its later phase would freeze coins remaining in unmigrated address types — an estimated 170,000 BTC in older P2PK-style addresses, including the 1.1 million BTC widely attributed to Satoshi. Critics argue the plan effectively confiscates coins that cannot migrate because their owners are unreachable. A separate proposal, BIP-360, has already been merged and introduces a new quantum-resistant address type (bc1z) without any freeze mechanism.
Why Satoshi's coins cannot be saved
The 1.1 million BTC attributed to Bitcoin's pseudonymous creator sit in P2PK addresses from the network's earliest days. Those wallets cannot sign transactions under a new signature scheme because their private keys — assuming they exist — are unreachable. Under BIP-361's Phase B, those coins would be frozen permanently. Bitcoin Magazine's editor rejected the proposal outright, with one widely shared comment calling it "highly authoritarian and confiscatory." Strategy executive chairman Michael Saylor has dismissed the near-term threat as overblown and launched a separate Bitcoin Security Program to coordinate industry research, framing quantum risk as an engineering challenge rather than an emergency, The Block reported.
What comes next for Bitcoin holders
BIP-361 can only take effect if it wins broad consensus among developers, miners and node operators — a process that has historically taken years for far less contentious changes. Bernstein analysts characterized the situation as a standard upgrade cycle rather than an existential threat, according to The Block. For most holders, the practical risk remains distant: IBM targets 200 logical qubits by 2029 with its Starling system, while no existing quantum computer approaches the scale needed to break Bitcoin's cryptography. BIP-360 already gives users a voluntary path to quantum-resistant addresses, and the network's decentralized governance means any forced migration faces steep political hurdles.
This article is for informational purposes only and does not constitute investment advice.