Bitcoin Quantum Plan Excludes Satoshi's 1.1M BTC

Bitcoin Quantum Recovery Proposal Excludes Satoshi’s Estimated 1.1 Million BTC

Last Updated:
Bitcoin Quantum Plan Excludes Satoshi's 1.1M BTC
  • BIP-361 recovery could protect many Bitcoin wallets, but excludes Satoshi’s estimated 1.1M BTC.
  • Zero-knowledge proofs let eligible users migrate funds without exposing private keys.
  • The prototype remains unaudited and still requires future Bitcoin consensus changes.

Bitcoin’s ongoing preparations for future quantum computing risks have entered a new phase with the introduction of a recovery mechanism built to work alongside the proposed BIP-361 framework. The new system aims to enable eligible Bitcoin holders to move vulnerable funds to quantum-resistant addresses without exposing their private keys.

While the approach addresses a major concern surrounding the proposal by offering a path to recover many at-risk coins, it does not extend to every wallet. Most notably, the estimated 1.1 million BTC attributed to Bitcoin creator Satoshi Nakamoto would remain outside its scope because of the way those early wallets were originally created.

Recovery Method Targets Modern Wallets

Quantum security startup Project Eleven introduced a zero-knowledge proof system intended to complement BIP-361, a proposal that would gradually restrict the use of quantum-vulnerable Bitcoin addresses. Under the draft plan, affected addresses would stop accepting deposits after 3 years, and any remaining coins would be frozen after 5 years.

According to the proposal, more than 34% of Bitcoin’s circulating supply falls into the category of quantum-vulnerable addresses. The new recovery method is designed to let legitimate owners transfer those funds to quantum-safe addresses without revealing sensitive wallet credentials.

The approach relies on a distinction within Bitcoin’s cryptography. Although a sufficiently advanced quantum computer could compromise elliptic curve signatures, the one-way hash functions used in modern hierarchical deterministic (HD) wallets remain protected. Instead of signing a transaction, users would prove they possess secret key material further up the wallet’s derivation tree.

Early Bitcoin Wallets Remain Outside the Framework

The proposed recovery process applies only to BIP-32 hierarchical deterministic wallets, which were introduced in 2012. Satoshi’s wallets predate that standard and generated each private key independently, without using a shared seed phrase or derivation tree.

Because the proof system depends on that derivation structure, no higher-level key material is available for verification in those early wallets. The same limitation also affects many of Bitcoin’s oldest dormant addresses.

Project Eleven stated that its prototype has not yet undergone an audit, currently supports only a limited range of Bitcoin address types, and would still require future consensus changes before it could be implemented on the Bitcoin network.

Related: Bitcoin Security Faces Fresh Test From Quantum Computing Progress

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.