The Bitcoin community expected unity when quantum computing threats finally became real enough to discuss seriously. Instead, April 2026 finds developers, miners, and holders locked in a fundamental disagreement about protecting the network’s most vulnerable addresses.
Adam Back, CEO of Blockstream and one of the few cryptographers cited in Satoshi’s whitepaper, threw a wrench into the emerging consensus yesterday. His proposal? Let Bitcoin holders decide for themselves when to upgrade to quantum-resistant addresses, rather than imposing a network-wide deadline that would freeze millions of coins.
The quantum threat takes shape
Quantum computers pose a specific danger to Bitcoin’s cryptography. While they can’t break the SHA-256 mining algorithm (that would require impossible amounts of energy even with quantum advantages), they could theoretically derive private keys from exposed public keys using Shor’s algorithm.
This vulnerability affects different Bitcoin addresses unequally. Pay-to-public-key (P2PK) addresses, common in Bitcoin’s early years, expose the public key directly on the blockchain. Pay-to-public-key-hash (P2PKH) addresses, which became standard later, only reveal the public key when spending. The newest formats like P2WPKH and P2TR provide similar protection through hashing.
According to blockchain analytics firm Glassnode, approximately 4.5 million BTC sits in P2PK addresses, with another 2.3 million in reused P2PKH addresses where public keys are already exposed. That’s nearly $420 billion at current prices, all theoretically vulnerable once quantum computers achieve sufficient power.

Back’s optional upgrade proposal
Back outlined his thinking in a detailed post to the Bitcoin-dev mailing list. Rather than setting a flag day where all vulnerable coins must move or be frozen, he advocates for gradual, voluntary migration.
“Bitcoin has always been about individual sovereignty,” Back wrote. “Forcing users to act by a certain date or lose their coins forever contradicts this principle.”
His proposal includes several key elements:
- New address types using post-quantum cryptography (likely SPHINCS+ or a similar hash-based signature scheme)
- Wallet software that automatically generates quantum-resistant addresses for new transactions
- Clear warnings for users about the risks of keeping funds in older address types
- No automatic freezing of vulnerable coins
The technical implementation would use a soft fork, maintaining backward compatibility. Users could continue using existing addresses indefinitely, accepting the quantum risk themselves.
The case for forced migration
Bitcoin Core developer Peter Todd leads the opposition to Back’s approach. Todd and others argue that leaving vulnerable coins unprotected creates systemic risks for the entire network.
Their primary concern: if quantum computers suddenly achieve a breakthrough, billions in Bitcoin could be stolen before users have time to react. This mass theft would crater Bitcoin’s price and potentially destroy confidence in all cryptocurrencies.
“It’s not just about protecting individual users,” Todd explained in a competing blog post. “If even 10% of Bitcoin’s supply gets stolen via quantum attacks, the entire ecosystem collapses. We have a responsibility to prevent that scenario.”
The forced migration camp proposes:
- A two-year warning period starting when the soft fork activates
- Automatic freezing of coins in quantum-vulnerable addresses after the deadline
- A secondary process allowing legitimate owners to reclaim frozen coins using zero-knowledge proofs
- Emergency unfreezing mechanisms if quantum threats don’t materialize as expected
This approach has precedent. Ethereum successfully pushed users to upgrade during its transition to proof-of-stake, though that involved active validators rather than dormant addresses.
Technical challenges multiply
Both proposals face significant implementation hurdles. Post-quantum signature schemes produce much larger signatures than Bitcoin’s current ECDSA system. SPHINCS+ signatures can be 8-40 times larger, depending on the security parameters chosen.
Larger signatures mean:
- Higher transaction fees (potentially 5-10x current rates for complex transactions)
- Reduced block capacity (fewer transactions per block)
- Increased blockchain size (faster growth of storage requirements)
- Longer validation times (more computational work per transaction)
Some developers suggest hybrid approaches. Luke Dashjr proposes using aggregated signatures that combine multiple quantum-resistant signatures into one, reducing the size penalty. Others explore commit-reveal schemes where the quantum-resistant signature only appears on-chain if challenged.
Mining pools have their own concerns. F2Pool’s administrator notes that any significant change to transaction processing could require hardware upgrades across their entire operation. “We’re talking about millions in infrastructure costs,” they said, requesting anonymity.

Satoshi’s coins hang in the balance
The elephant in every quantum discussion: Satoshi Nakamoto’s estimated 1 million BTC, mostly held in vulnerable P2PK addresses. These coins haven’t moved since Bitcoin’s earliest days, and many assume they never will.
Under Back’s proposal, Satoshi’s coins remain at risk indefinitely. Under forced migration, they’d be frozen after the deadline, effectively removed from circulation.
This creates philosophical divides. Bitcoin maximalists argue that freezing Satoshi’s coins violates Bitcoin’s core promise that nobody can confiscate your funds. Pragmatists counter that leaving a million BTC as a honeypot for quantum hackers endangers everyone.
“If those coins move because someone cracked them with a quantum computer, Bitcoin is finished,” argues Samson Mow, CEO of JAN3. “Better to freeze them preventively than watch the entire system burn.”
Others see opportunity in crisis. If Satoshi’s coins are provably frozen or destroyed, it reduces Bitcoin’s effective supply, potentially driving up prices for remaining coins.
Timeline pressures mount
The debate’s urgency stems from recent quantum computing advances. IBM’s latest 5,000-qubit processor achieved quantum advantage in specific optimization problems last month. While still far from breaking Bitcoin’s cryptography, the trajectory worries security experts.
Academic modelling cited in the debate estimates roughly a 15% chance of quantum computers threatening Bitcoin within 10 years, rising to around 60% within 20 years, assuming continued exponential improvement in qubit stability and error correction.
Chinese researchers recently demonstrated a new error correction technique that dramatically improves qubit coherence times. The paper, published in Nature, suggests practical quantum computers could arrive years earlier than expected.
These developments put pressure on Bitcoin’s traditionally conservative development process. Major protocol changes typically take 2-3 years from proposal to activation. If quantum threats materialize faster than expected, the network might not have time for its usual deliberative approach.
Back acknowledges this tension but maintains that rushed decisions create more problems than they solve. “Ethereum rushed their PoS transition and faced multiple critical bugs. Bitcoin can’t afford those mistakes.”
The Bitcoin Improvement Proposal (BIP) process will ultimately decide between these competing visions. Draft BIPs from both camps are expected by May 15, with community discussion periods extending through summer 2026.




