Skip to content
  • BIP-361 proposes freezing quantum-vulnerable Bitcoin addresses unless users migrate funds within the transition period.
  • A zero-knowledge recovery method supports modern HD wallets but excludes many pre-2012 Bitcoin addresses.
  • Legacy wallets, including those linked to Satoshi Nakamoto, would remain locked under the proposed recovery framework.

Bitcoin developers have advanced the debate around quantum security after introducing BIP-361, a proposal that would gradually disable vulnerable addresses while exploring a recovery option for eligible wallet owners. According to the proposal and Project Eleven, the recovery method relies on zero-knowledge proofs, although it does not extend to older wallets, including those linked to Satoshi Nakamoto.

Recovery Plan Targets Modern Bitcoin Wallets

According to BIP-361, developers plan to block new transfers to quantum-vulnerable Bitcoin addresses after three years. They also propose freezing remaining balances after five years if users fail to migrate their funds.

The proposal addresses a future scenario known as Q-Day. At that point, a quantum computer could derive private keys from exposed public keys. Developers said attackers could then create valid signatures indistinguishable from legitimate owners. 

Consequently, BIP-361 seeks to prevent unauthorized spending before that becomes possible. Project Eleven introduced a prototype recovery method using zero-knowledge proofs. The system lets wallet owners prove control without revealing sensitive key material.

Older Wallets Face Different Challenge

However, the recovery method depends on hierarchical deterministic wallets introduced through BIP-32 in 2012. Those wallets generate addresses from a parent key using hardened derivation.

EliteFXLabs Banner

That requirement excludes many early Bitcoin wallets. Notably, wallets created before 2012 lack the derivation structure needed for the proof. The limitation also affects roughly 1.1 million BTC widely attributed to Satoshi Nakamoto. 

Those coins sit in early pay-to-public-key outputs that expose public keys directly onchain. According to Project Eleven, the prototype currently supports three Bitcoin address types instead of Taproot. It also remains unaudited and does not recover funds on any live blockchain.

Proposal Shifts Governance Debate

Project Eleven reported that the prototype generates proofs in 243 milliseconds on an M5 MacBook Air. Verification takes about 40 milliseconds using CPU processing alone.

Developers said the prototype completes the full process in roughly 910 milliseconds without requiring a GPU. They also reported memory usage of about two gigabytes.

Meanwhile, the proposal changes the governance discussion surrounding BIP-361. According to the developers, modern seed-based wallets could eventually recover frozen coins, while many legacy wallets would remain outside that recovery path.

Share this article

© 2026 Cryptofrontnews. All rights reserved.