Bitcoin Quantum Freeze Proposal Gains Recovery Path, Satoshi Coins Excluded

BTC-0.15%

A Bitcoin quantum security proposal published in April by Jameson Lopp and five co-authors has gained a potential recovery mechanism through zero-knowledge proof technology. BIP-361 proposes freezing bitcoin held in quantum-vulnerable addresses after a multi-year timeline, targeting more than 34% of bitcoin's supply where public keys have been exposed onchain, including approximately 1.1 million BTC attributed to Satoshi Nakamoto. Project Eleven developed a prototype recovery method that allows modern wallet users to prove ownership without exposing private keys, addressing concerns that a freeze would mean permanent loss. The development shifts the debate from whether vulnerable coins should be frozen to which holders can safely recover frozen assets after a future quantum threat materializes.

BIP-361 addresses a theoretical moment known as Q-Day, when a quantum computer becomes capable of deriving a private key from a public key. The proposal suggests blocking new deposits to vulnerable bitcoin addresses after 3 years and freezing whatever remains after 5 years. If Q-Day occurs, any address with an exposed public key could be spent by an attacker, and the blockchain would not distinguish the attacker from the real owner because both could produce a valid signature.

Project Eleven Builds Zero-Knowledge Recovery Prototype

Project Eleven built a prototype recovery method based on zero-knowledge proofs, a cryptographic technique that lets a user prove they know something without revealing the underlying information. The recovery path focuses on modern wallets built around hierarchical deterministic key trees, where keys are derived from higher-level key material.

The prototype, developed with Jim Posen, lead developer of the Binius proof system, uses a structural gap in wallet architecture. A hardened derivation step uses a one-way function, HMAC-SHA512, to produce child keys from parent key material. An attacker who breaks a single exposed address after Q-Day would obtain that specific key, but not the higher-level wallet material used to derive it.

A user proves they know the key material above the address in the wallet's derivation tree, proves that it derives the address in question, and binds the proof to a specific message that can authorize migration. The private key material itself is not disclosed. This approach changes the recovery argument by allowing holders using modern seed-based wallets to unlock frozen coins by proving valid upstream ownership without exposing the secret data that protects the rest of their wallet.

Prototype Achieves 243-Millisecond Proof Generation on Consumer Hardware

Project Eleven reports its prototype generates a proof in 243 milliseconds on an M5 MacBook Air using 4 cores, verifies it in 40 milliseconds, and uses about 2 gigabytes of memory without a GPU. The full run, including circuit construction, proof generation, and self-checking, takes 910 milliseconds on CPU alone. The team describes that as 16 times faster on the full run and about 60 times faster when excluding one-time setup work that a real prover could reuse.

The performance figures suggest recovery proofs could be generated by ordinary users on consumer hardware. This matters for bitcoin, where any large-scale migration path must be usable by holders across jurisdictions, custody types, and technical skill levels.

The prototype has clear limits. It is unaudited, supports 3 Bitcoin address types rather than Taproot, roots the proof at the coin-type key rather than the seed, and does not recover coins on any live blockchain. Those caveats keep it far from a deployable fix, but it gives BIP-361 a clearer technical route for reversible freezing.

Pre-2012 Wallets Lack Derivation Structure for Recovery

The recovery method depends on a wallet having a derivation tree above the address. Hierarchical deterministic wallets arrived with BIP-32, which was assigned on Feb. 11, 2012. Before that, Bitcoin wallets generated keys independently and at random. There was no seed phrase, no derivation path, and no parent key sitting above older addresses.

Satoshi mined through 2009 and 2010 and disappeared from public activity by 2011. The coins attributed to Satoshi sit in old pay-to-public-key outputs where the public key is written directly onchain. Those outputs were generated before seed-based wallet structures became standard. There is no upstream wallet material to prove knowledge of because the tree structure did not exist.

The same problem applies to many other pre-2012 wallets, especially dormant coins from Bitcoin's earliest years. These are precisely the coins most exposed to a future quantum attack and among the hardest to recover under the proposed proof method. A working proof could turn a freeze into a recoverable lock for seed-based wallets, but it does not solve the oldest bitcoin balances, including coins attributed to Satoshi.

Recovery Path Creates Wallet Generation Divide in Governance Debate

Freezing quantum-vulnerable coins would be one of the most controversial changes ever proposed because it would alter the treatment of existing balances, including dormant holdings that may belong to lost, inactive, or deceased owners. A credible recovery path reduces the force of one objection: that BIP-361 would permanently destroy ownership rights for affected holders.

The recovery path creates a dividing line between wallet generations. Modern users with seed phrases may have a way out. Early bitcoin holders may not. That split leaves bitcoin with a policy question: whether protecting the network from quantum theft justifies freezing coins that cannot be recovered by the same method.

The prototype changes the terms of the argument. Bitcoin's quantum risk is no longer only about whether vulnerable coins can be frozen. It is about who gets a key to reopen them, and who never had one in the first place.

FAQ

What does BIP-361 propose for quantum-vulnerable bitcoin addresses?

BIP-361, published in April by Jameson Lopp and five co-authors, proposes blocking new deposits to vulnerable bitcoin addresses after 3 years and freezing whatever remains after 5 years. The plan targets coins in addresses where public keys have already been exposed onchain, accounting for more than 34% of bitcoin's supply, including approximately 1.1 million BTC attributed to Satoshi Nakamoto.

How does the zero-knowledge recovery method work?

Project Eleven built a prototype recovery method that uses zero-knowledge proofs to let users prove they know the key material above an address in a hierarchical deterministic wallet's derivation tree. The user proves this upstream knowledge and that it derives the address in question, binding the proof to a message that can authorize migration, without disclosing the private key material itself. The prototype generates a proof in 243 milliseconds on an M5 MacBook Air using 4 cores.

Why cannot Satoshi's coins be recovered through this method?

The recovery method depends on a wallet having a derivation tree structure, which arrived with BIP-32 assigned on Feb. 11, 2012. Satoshi mined through 2009 and 2010 using wallets that generated keys independently and at random, before seed-based wallet structures became standard. There is no upstream wallet material to prove knowledge of because the tree structure did not exist for pre-2012 wallets.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments