Last updated:
Table of Contents
ToggleIn April 2026, a researcher managed to break a 15-bit cryptographic key on a real quantum computer. Although Bitcoin’s keys are 256-bit and the network does not face an immediate danger, this breakthrough reactivated a latent debate about its future security.
Anticipating this scenario, the developer community integrated BIP-360 in February of that same year as the first official proposal to prepare the protocol against the quantum threat.

What is truly at stake is the integrity of almost 7 million BTC, 30% of the total in circulation, whose public key data has been exposed on the blockchain. With the development of Shor’s algorithm, a sufficiently powerful quantum computer could decipher the private keys associated with these old addresses and empty their funds, which represents a systemic risk for the ecosystem.
To avoid this, developers propose the adoption of address schemes resistant to quantum attacks (BIP-360) and a progressive migration framework (BIP-361) so that users transfer their funds to these new secure structures. The central objective is to protect future addresses and give a wide margin to update existing ones before quantum hardware represents a real threat.
The debate becomes uncomfortable when deciding what to do with inactive Bitcoin that are not migrated in time. Establishing deadlines or freezing vulnerable addresses to prevent them from being stolen would solve the technical problem, but would clash head-on with the principles of immutability and non-confiscation that underpin Bitcoin’s philosophy.

During the celebration of the Q-Day Prize of Project Eleven, a researcher deciphered a cryptographic key on a real quantum computer. Although the test was only 15 bits, it confirmed in practice that this type of attack is technically viable.
This vulnerability affects ECDSA (secp256k1) signatures. Once the public key is exposed on-chain, a sufficiently powerful quantum computer could apply Shor’s algorithm to deduce the private key and sign unauthorized transactions. Satoshi Nakamoto himself already foresaw this situation in 2010, suggesting migrating the protocol by consensus if current cryptography weakened.
Concern intensified after a Google study published in March 2026. According to its estimates, breaking ECC-256 would take just 10 minutes with fewer than 1,200 logical qubits and 500,000 physical qubits. While Google projects its post-quantum transition for 2029 and NIST places it around 2035, Bitcoin developers responded by designing BIP-361 (Post-Quantum Migration). Unlike historical improvements focused on scalability or privacy, this proposal establishes a preventive calendar with defined deadlines to retire support for old signatures.
The attack vector is concentrated exclusively on addresses whose public key is already visible on the network. While a key remains hidden behind its hash, the quantum computer cannot compute it; but it becomes exposed when making a transaction. This directly affects two groups: the original Pay-to-Public-Key (P2PK) addresses and any P2PKH or SegWit address from which funds have been spent at least once.
According to Project Eleven estimates, this exposed group encompasses 6.9 million BTC, including about 1.7 million BTC attributed to Satoshi Nakamoto. A massive theft of these dormant or inactive coins would not only affect their owners, but would also deal a devastating blow to the value and economic confidence of the entire ecosystem.
To contain this structural threat, technical responses are divided into two fronts: preventive protection of future transactions through standards like P2MR (BIP-360) and drastic transition measures on existing balances contemplated by BIP-361, which range from migration deadlines to permanent freezing or fund recovery via hard fork.
Given the advance of quantum computing, Bitcoin’s development strategy seeks to establish a clear transition framework toward a maximum-security environment. This approach combines preventive protection for the future with a migration mechanism to address existing vulnerable balances.

The two main proposals that make up this comprehensive defense are BIP-360 (focused on infrastructure and new addresses) and BIP-361 (focused on the transition plan for old funds).
|
Feature |
BIP-360 (P2MR) |
BIP-361 (Migration / Freezing) |
| Main objective | Protect addresses created from its implementation onward (future use). | Migrate or freeze the 6.9 million existing vulnerable BTC. |
| Security approach | Preventive: Eliminates public key exposure when spending funds. | Corrective / Transfer: Gradually deactivates old addresses. |
| Technical mechanism | Introduces the Pay-to-Merkle-Root (P2MR) standard with no internal key. | Structured phase transition with deadlines. |
| User impact | Transparent. Does not modify existing addresses. | Requires active user action to move funds to new addresses. |
| Risk / Controversy | Low. It is a clean structural foundation for future updates. | High. Permanent freezing of inactive or keyless BTC. |
The debate around post-quantum preparation places Bitcoin at a crossroads where collective security and the inviolability of private property collide.
|
Position |
Main Argument |
Associated Risk |
| Mandatory Migration (BIP-361) | Protect the network by nullifying exposed addresses, preventing quantum attacks from destabilizing the market with dormant coins. | Compromises immutability by intervening on inactive funds or lost keys. |
| Voluntary Approach (Consensus Preservation) | Maintain user sovereignty without altering the rules of the game or forcing confiscation/freezing of BTC. | Exposes the network to a confidence shock if a quantum computer breaches old signatures. |
While BIP-360 lays the technical groundwork for the future by creating resistant addresses (P2MR), the BIP-361 proposal forces the community to decide whether the system can alter its principles to protect its economic viability.

That said, although no proposal has been approved, Bitcoin holders do not need to wait for social consensus to mitigate risks: