Overview
- Developers published the BIP-361 draft this week as a blueprint for a multi-year migration that would stop new quantum-vulnerable outputs and later require proof to spend unmigrated coins.
- The proposal maps three phases: a 160,000-block delay before restricting new legacy outputs, a later sunset of legacy signatures roughly five years after activation, and an undecided Phase C for recovery methods.
- Authors estimate that about 34% of Bitcoin had exposed public keys on-chain as of March 1, 2026, creating a large pool of coins that could be targeted in a ‘harvest now, decrypt later’ scenario.
- Independent teams are building zero-knowledge recovery tools to let legitimate owners prove control without revealing private keys, with Project Eleven reporting a working proof that runs in about 243 milliseconds on a laptop.
- Key decisions remain unresolved: no post-quantum signature standard has been selected, no code is merged into Bitcoin Core, and early P2PK coins including roughly 1.1 million BTC tied to Satoshi-era addresses would not be recoverable under the proposed methods.