Particle.news

BIP-361 Draft Proposes Phased Migration to Protect Bitcoin From Future Quantum Attacks

Planning now gives the network years to design a migration, test zero-knowledge recovery tools, limit the risk of mined public keys being harvested, and avoid rushed changes to protocol

Overview

  • Developers published the BIP-361 draft this week as a blueprint for a multi-year migration that would stop new quantum-vulnerable outputs and later require proof to spend unmigrated coins.
  • The proposal maps three phases: a 160,000-block delay before restricting new legacy outputs, a later sunset of legacy signatures roughly five years after activation, and an undecided Phase C for recovery methods.
  • Authors estimate that about 34% of Bitcoin had exposed public keys on-chain as of March 1, 2026, creating a large pool of coins that could be targeted in a ‘harvest now, decrypt later’ scenario.
  • Independent teams are building zero-knowledge recovery tools to let legitimate owners prove control without revealing private keys, with Project Eleven reporting a working proof that runs in about 243 milliseconds on a laptop.
  • Key decisions remain unresolved: no post-quantum signature standard has been selected, no code is merged into Bitcoin Core, and early P2PK coins including roughly 1.1 million BTC tied to Satoshi-era addresses would not be recoverable under the proposed methods.