The answer to this question lies not in cryptography, but in politics.
By: Clow
A zero-knowledge proof tool can help your Bitcoin escape quantum attacks in just 243 milliseconds. But Satoshi's 1.1 million coins? No hope.
It’s not that quantum computers are not powerful enough; it’s that they haven’t arrived yet, and the Bitcoin community is already fighting among themselves.
Project Eleven has just released a zero-knowledge proof recovery tool that can allow modern wallet holders to safely migrate their assets before quantum attacks arrive. In a benchmark test on an M5 chip MacBook Air, it generated a proof in 243 milliseconds, verified in 40 milliseconds, with peak memory usage of 2.1 GB. Fast, light, and elegant.
However, this solution has a major flaw: it only works for HD wallets created after 2012.
Old coins created before 2012, including about 1.1 million Bitcoins mined by Satoshi, are scattered across approximately 22,000 P2PK addresses, each holding about 50 BTC. These addresses lack parent keys, mnemonics, or any derivation paths to construct zero-knowledge proofs. Cryptographically, they are dead ends.
So the real question has never been "when will quantum computers arrive," but "what to do with these 1.1 million old coins?"
The answer to this question lies not in cryptography, but in politics.
01 Who Can Save Themselves, Who is Sentenced to Death
To understand this crisis, you must first clarify one thing: not all Bitcoins are equally vulnerable.
On-chain assets can roughly be divided into three tiers based on their public key exposure.
The safest are unused addresses protected by hashes, where the public key is hidden behind a hash, and quantum computers cannot do anything about them, representing over 65% of the total supply.
The middle tier consists of modern addresses where public keys are exposed due to address reuse or Taproot design, with about 4.5 to 5.2 million BTC.
The most dangerous are early P2PK addresses, where the public key is directly written in the transaction script, numbering around 1.7 to 1.9 million.
The middle tier can be saved. Project Eleven's tools are precisely designed for them.
The principle is called "signature uplift," proposed by researchers Or Sattath and Shai Wyborski in 2023. The Shor algorithm breaks elliptic curve signatures but is powerless against hash functions.
The private keys of subaddresses in modern HD wallets are derived from the master key via HMAC-SHA512 hashing. Even if a quantum computer manages to produce the private key of a certain subaddress, it cannot backtrack past the hash barrier to derive upwards.
Wallet holders only need to prove they possess the parent key upstream in the derivation path, generate a zero-knowledge proof, bind it to a quantum-resistant address, and complete the migration. No exposure of the main private key, no exposure of the mnemonic, and verifiable on-chain.
However, old coins before 2012 lack this "key tree." During Satoshi’s active years from 2009 to 2010, every time a Bitcoin wallet generated an address, it was completely random and independent.
No parent-child hierarchy, no master key, and no BIP-39 mnemonics. Logically, Project Eleven's solution fails completely for them.
1.7 million Bitcoins are barred from the self-rescue path by a technological dividing line drawn in 2012.
02 Four Solutions, Four Ways to Die
Problems that technology cannot solve must be left to politics. The community faces four paths, each leading to a form of disaster.
The first: inaction, allowing liquidation. Strictly adhering to "private keys equal justice," whoever has a quantum computer first takes the coins. This sounds the purest but has the highest cost.
The 1.7 million Bitcoins that the market treats as "permanently lost" would suddenly flood the secondary market, equivalent to an artificial increase of 8% to 9% in circulating supply. The narrative of "digital gold" would be shaken by the actual change in underlying ownership.
The second: forced freezing. The BIP-361 proposal plans to prohibit depositing new funds to vulnerable addresses three years after its implementation and to completely abolish the spending efficacy of traditional signatures after five years. Unmigrated coins would be permanently locked.
Economically, this is equivalent to actively destroying 1.7 million Bitcoins, creating a permanent deflation. But the community's response was very direct: to prevent the theft of assets, you're choosing to confiscate users' money first?
Protocol developer Mark Erhardt faced a backlash in the comments when sharing this proposal on social media.
The third: "hourglass" throttling. Developer Hunter Beast proposed a compromise, acknowledging the fact that old coins might be stolen, but setting very low thresholds for spending P2PK addresses.
Each block can confirm at most one P2PK spend, with a single transaction limit of 1 BTC. Even if Satoshi's 1.1 million coins were all controlled by quantum hackers, the sell-off would have to stretch over decades.
Attackers wanting to cash out must compete fiercely in the fee market, and this money will ultimately flow to miners, becoming a long-term subsidy for network security.
The fourth: forced redistribution. The most radical option. By hard forking, "unowned" old coins would be nationalized and proportionally distributed to active holders who have migrated to quantum-resistant addresses.
The total supply remains 21 million, but the bookkeeping commitments would be directly overturned. The outcome is almost predictable: community division, multiple "orthodox chains" existing in parallel, and catastrophic valuation divergence.
Cardano founder Charles Hoskinson's criticism of BIP-361 was spot on: this is not a soft fork, but a hard fork.
Any attempt to forcibly freeze early assets by setting a deadline is a violation of Bitcoin's property principles. BIP-361 co-author Jameson Lopp also acknowledged this proposal is more like an "emergency backup plan draft," not the final answer.
Ironically, all four solutions aim to protect the value of Bitcoin, but each is undermining what it seeks to protect. Allowing theft destroys value storage, forced freezing undermines property commitments, throttling acknowledges the legitimacy of theft, and redistribution destroys the immutability of the ledger.
This is not a technical question but a political one with no correct answer.
03 The Market Has Started Voting
Most investors still regard the quantum threat as a long-term issue of "when will the hardware meet the standards."
But the market has already begun to price it in.
In January 2026, Jefferies announced it would liquidate 10% of its Bitcoin holdings in pension model portfolios.
The strategist was very clear: the reason for liquidation was not that quantum computers have already emerged, but that the Bitcoin community exhibits governance uncertainty in "how to handle early vulnerable coins."
This is the real expectation gap. Physicists are still in the lab battling error-correcting logic, while Wall Street is already discounting governance risks.
For institutional capital seeking legal certainty, the logic is simple: if Satoshi's coins can be forcibly frozen by code, then any future coins can be consensually stripped away.
There’s also the significant latent risk of "current harvesting, future decryption." The blockchain ledger is public, and attackers are currently downloading and storing the entire Bitcoin ledger.
Once practical quantum computers emerge, they won't need to connect to the network; they can crack those old wallets that have exposed their public keys offline. This delayed attack makes the governance game more urgent.
The discrepancies in how institutions count vulnerable Bitcoins are also worth noting. The BIP-361 proposal claims over 34% of the supply exposes public keys, Citibank's figure is 25% to 37%, Glassnode estimates about 30%, and Talos’ full ledger scan shows 34.5%. Regardless of which number is taken, it means at least a quarter of Bitcoin is under long-term quantum threat.
Furthermore, Project Eleven's tool is currently just an early prototype that hasn't been security audited, supporting only three types of wallets, and needs controversially high consensus rule changes before main net launch. Treating it as an always-available emergency channel is premature.
Back to that fundamental question: how can Bitcoin settle a historical technological transition without undermining its own property principles?
No one has the answer. Quantum computers have not yet arrived, but a crisis of faith has already begun.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。