Bitcoin’s quantum debate turns into a governance fight over BIP-361

- BIP-361, drafted by Casa founding member Jameson Lopp and five co-authors, would restrict spending from legacy addresses roughly three years after activation and render unmigrated coins permanently unspendable two years after that.
- More than 34% of all Bitcoin had revealed a public key on-chain as of March 1, 2026, leaving it theoretically exposed if sufficiently powerful quantum computers arrive.
- The leading recovery prototype only reaches wallets built on the BIP-32 standard, which excludes the roughly 1.1 million BTC believed to belong to Satoshi Nakamoto.
A draft plan developed to protect Bitcoin against future quantum computing advancements has turned the debate in a different direction. The discussion is no longer related to cryptography, but governance. Is a system that was set up to resist changes capable of agreeing on an important upgrade before it is imperative?
This week, the issue got renewed attention when Cardano co-founder Charles Hoskinson claimed that the biggest problem for Bitcoin is not quantum computing in itself but the ability to organize a response ahead of time before the threat is confirmed.
Hoskinson says Bitcoin may struggle to coordinate
During a conversation on The Starting Block on Friday, Hoskinson pointed out that quantum computing could pose a threat to Bitcoin’s position as the world’s top digital currency, currently valued at about $1.3 trillion, should the network be unable to come to an agreement on an upgrade.
“The issue with Bitcoin is it’s frozen in time. It’s very difficult to change anything,” he said, according to The Block.
According to Hoskinson, Cardano’s governance model stands in stark contrast to that of Bitcoin. “If there needs to be a migration, we can have a vote, and then there could be an onchain function to do that,” he said.
The process has been previously illustrated by Cardano. In June, elected delegates turned down a Summit funding plan from the Cardano Foundation on account of it not obtaining the needed two-thirds majority. Bitcoin lacks any systems of voting of that sort, which means that the discrepancies between the currencies are causing discussions on the matter now.
BIP-361 would force a staged migration
The proposal that the conversation is based on is BIP-361 titled, “Post Quantum Migration and Legacy Signature Sunset”. The proposal was formulated by Jameson Lopp, a founding member of Casa, and five co-authors who created a plan for transitioning from Bitcoin’s signature methods, currently being ECDSA and Schnorr.
As per the proposal, as of March 1, 2026, over 34% of all Bitcoin had revealed a public key on-chain and, thus, they are theoretically at risk to be stolen, should the sufficiently powerful quantum computers emerge.
The migration will take place in several stages. Stage A will begin approximately three years after the start of the implementation, prohibiting users from transferring money to legacy addresses that are in danger. Stage B will come two years after stage A and will prevent users from using coins that have not been migrated. Nevertheless, the coins will still be held by users in their safes but will no longer be usable.
The freeze proposal triggers backlash
The last step became the most controversial part of the proposal.
IG reports that critics on developer forums and X called the plan “authoritarian and confiscatory,” while others dubbed it “predatory,” according to Yahoo Finance.
Lopp did not take the opportunity to say that BIP-361 is currently a final product. “It isn’t a spec, nor is it proposed for activation. It’s a rough idea for a contingency plan that needs more R&D,” Lopp stated in April as reported by BigGo Finance, emphasizing that he was more interested in investigating the subject than in turning a blind eye to the problem.
Recovery paths remain early and incomplete
Developers have initiated the search for methods to minimize the effects of the proposal.
The prototype created by Project Eleven security group and Jim Posen of Binius uses a special technique called zero-knowledge proofs that allows the owners of modern wallets based on seeds to prove ownership and retrieve frozen funds. This solution responds to one of the major concerns about the proposal, that it will leave people without access to their affected coins forever.
Yet, this technique can be applied only to wallets complying with the BIP-32 standard that was introduced in 2012 and does not include older technologies like pay-to-pub-key outputs, which would cover the approximately 1.1 million BTC believed to belong to Satoshi Nakamoto, equivalent to about $84 billion. Another proposal by Paradigm called PACTs has a potential solution as long as the people who have the keys are proactive enough before the migration deadline.
As reported earlier by Cryptopolitan, Bitcoin’s developers have already largely moved past the debate about the necessity of post-quantum security. With BIP-360 and its Pay-to-Merkle-Root output type merged, the focus has now switched to its implementation. The question that remains is whether miners, exchanges, custodians and users can come together and coordinate their migration before the advent of quantum computing makes it necessary.
What’s next post-quantum?
Paradigm General Partner Dan Robinson has proposed “Provable Address-Control Timestamps” (PACTs), a research proposal that would let Bitcoin holders privately timestamp proof of wallet ownership before quantum computers become practical.
If Bitcoin later adopts a quantum migration such as BIP-361, users who created a PACT could potentially recover frozen coins using quantum-resistant STARK zero-knowledge proofs, although the proposal would require additional protocol changes and broad community consensus before it could be implemented.
Some researchers and developers have suggested alternative recovery mechanisms, including zero-knowledge proof approaches and other cryptographic techniques, but none of these are part of BIP-361 today. Any recovery mechanism would require its own proposal and broad community consensus.
Because BIP-361 is still a draft, its migration rules, timelines, and treatment of legacy coins could all change before any future implementation.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
What is BIP-361?
It is a draft Bitcoin Improvement Proposal titled "Post Quantum Migration and Legacy Signature Sunset," authored by Jameson Lopp and five co-authors, that would phase out quantum-vulnerable ECDSA and Schnorr signatures and eventually freeze coins that fail to migrate. It remains a draft with no activation timeline.
Would BIP-361 freeze Satoshi Nakamoto's coins?
Likely yes. The roughly 1.1 million BTC attributed to Satoshi sit in pre-2012 pay-to-public-key addresses that lack the BIP-32 derivation structure the proposed zero-knowledge recovery method needs, so those coins could not be reclaimed through that path.
Why does Charles Hoskinson say Bitcoin could lose its top spot?
Hoskinson argues Bitcoin is "frozen in time" and hard to change, so if its governance cannot coordinate a quantum migration, it may fail to respond in time, unlike Cardano's on-chain voting system that can authorize an upgrade directly.
When would Phase A activate?
Phase A would not activate immediately. Under the current BIP-361 draft, it would begin 160,000 Bitcoin blocks after the proposal itself is activated through Bitcoin's consensus process. BIP-361 has not yet been approved or activated. It remains a draft Bitcoin Improvement Proposal, meaning there is currently no activation date or block height for Phase A.
Can frozen coins ever be recovered?
Under the current BIP-361 draft, the answer is generally no for coins that remain in legacy quantum-vulnerable outputs after the migration window closes.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Micah Abiodun
Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.
















