Paradigm’s Dan Robinson just gave the crypto world a potential answer to one of its longest-running technical puzzles: how do you protect Satoshi Nakamoto’s $84 billion bitcoin stash from quantum computers without forcing the pseudonymous creator to reveal themselves?
The proposal, published Friday, introduces Provable Address-Control Timestamps, or PACTs, a system that would let holders of vulnerable Bitcoin addresses privately prove they control their keys today and use that proof later if the network ever freezes legacy wallets. It’s an elegant workaround to a problem that has plagued quantum defense proposals for years. But it comes with a significant asterisk that no cryptography can solve.
The Quantum Clock Is Ticking for Legacy Addresses
Bitcoin’s vulnerability to quantum computing isn’t theoretical hand-wringing. Addresses with exposed public keys, which includes most pre-2012 wallets and any address that has ever sent a transaction, could be cracked by sufficiently powerful quantum hardware. The private key derivation that would take classical computers billions of years might take a quantum machine hours or days.
The roughly 1.1 million BTC attributed to Satoshi Nakamoto fall squarely in this category. Those coins haven’t moved since 2010, and their public keys are visible on the blockchain. At current prices near $76,000 per coin, that’s approximately $84 billion sitting in what will eventually become a honey pot for quantum attackers.
Our quantum computing guide breaks down the technical threat in detail, but the short version is this: Bitcoin has time, probably a decade or more, but not infinite time. And the solutions being debated now will determine whether dormant holders like Satoshi lose everything or get a path forward.
In mid-April, prominent developer Jameson Lopp and five other developers proposed BIP-361, a quantum defense mechanism that would phase out vulnerable address types over five years and freeze any coins that fail to migrate. The logic is sound: force everyone into quantum-safe formats before attackers can exploit the weakness. But it creates an obvious problem for anyone who can’t or won’t come forward publicly.
How PACTs Work Without Revealing Anything
Robinson’s proposal attacks the problem from a different angle. Instead of requiring holders to move coins now, PACTs let them timestamp proof of ownership secretly and reveal nothing until they actually need to spend.
The mechanism involves three components working together. First, a holder generates a random salt, which is just a piece of secret data that makes a cryptographic commitment unique and impossible to guess. Then they use BIP-322, a standard for signing messages from a Bitcoin address without spending from it, to produce a proof of ownership. The salt and proof get bundled into an onchain commitment.

The timestamp itself comes from OpenTimestamps, a free service that anchors data onto the Bitcoin blockchain through a single batched transaction. This creates an immutable record proving the commitment existed at a specific date. Critically, the salt, proof, and timestamp files all stay private. The blockchain only sees a hash, not the underlying data.
If Bitcoin later activates a soft fork freezing quantum-vulnerable coins, the protocol could include a rescue path accepting STARK proofs. These are a type of zero-knowledge proof that remains secure against quantum computers. A holder would submit their STARK proof when they want to spend, demonstrating they created the commitment before quantum hardware existed. The network releases the coins, and the redemption reveals nothing about which address, which amount, or even when the original timestamp was created.
That last detail matters more than it might seem. Even the timing of a commitment could leak information about the holder’s identity. PACTs preserve privacy at every step.
The BIP-32 Gap and Pre-2012 Wallets
One technical subtlety in Robinson’s proposal addresses a specific limitation in BIP-361. The Lopp proposal includes a rescue path for wallets derived through BIP-32, the deterministic key generation standard that became widespread after 2012. This standard lets users derive multiple addresses from a single seed phrase in a predictable way.
But pre-2012 wallets, which includes most of Satoshi’s known addresses, don’t use BIP-32. They were created before the standard existed. BIP-361’s rescue mechanism simply doesn’t apply to them.
PACTs fill this gap by providing a universal rescue path that works regardless of how the original keys were generated. A holder with a 2009-era wallet could create a commitment today using the exact same process as someone with a modern BIP-32 wallet. The proof-of-ownership mechanism through BIP-322 message signing works for any address type.
This is where the proposal gets genuinely interesting for the Satoshi question. The creator’s coins have always been the elephant in every quantum defense discussion. Any freeze proposal that doesn’t address them is implicitly taking a position on whether those coins should be protected or abandoned. PACTs at least offer a technically neutral path forward.
What Bitcoin Would Need to Adopt
The catch, and it’s a significant one, is that PACTs require infrastructure Bitcoin doesn’t currently have. STARK proof verification would need to be added through a separate soft fork with broad community consensus. Robinson himself describes this as “substantial new plumbing.”
We’re talking about multisig wallet support, complex script modifications, and hardware wallet standardization that would all need careful development and testing. The derivatives market already tracks Bitcoin futures pricing for various scenarios, but a soft fork of this magnitude would likely create sustained volatility during the debate period.
The verification infrastructure could take years to build properly. Robinson’s proposal doesn’t try to shortcut this reality. It’s more of a roadmap than a ready-to-deploy solution. But having the roadmap matters because it shapes what the community prioritizes and when.
One comparison worth noting: Ethereum’s transition to proof-of-stake took roughly two years from serious commitment to execution, and that was for infrastructure the team had been planning since the network’s inception. Bitcoin’s development culture moves more slowly and deliberately. A STARK verification soft fork could easily take three to five years from initial proposal to activation.
The Constraint No Cryptography Can Solve
Here’s the part Robinson’s proposal acknowledges openly: PACTs only work if the holder acts. The protocol cannot protect Satoshi if Satoshi is genuinely gone.
If whoever controls those 1.1 million BTC doesn’t create a commitment before quantum computers arrive or before the community imposes a freeze, no retroactive rescue is possible. The coins remain exposed to whichever scenario plays out first. Quantum theft would mean someone else gets them. A community freeze would mean nobody does.
This constraint isn’t a flaw in the proposal. It’s just the reality of cryptographic proof. You cannot prove you control keys without actually controlling them at some point. Robinson’s contribution is making that proof possible without requiring a public transaction that would reveal the holder’s continued presence.
The philosophical question underneath all of this is whether Bitcoin should even try to protect coins from holders who won’t or can’t respond. The network has always operated on the principle that coins belong to whoever controls the keys. PACTs preserve that principle while acknowledging the quantum threat creates a deadline that wasn’t originally contemplated.
MARA’s recent commitment to quantum computing research through its new foundation suggests at least some major miners are taking the long-term threat seriously. The infrastructure conversation is happening across multiple fronts.
What Happens to the $84 Billion Question
PACTs make the BIP-361 debate less binary. Without a rescue path, the community faces an ugly choice: either protect against quantum theft by freezing dormant coins, or respect dormant property rights by leaving the network vulnerable. Robinson’s proposal creates a middle ground where holders can prove legitimacy without revealing identity.
Whether Satoshi will use it remains the question no proposal can answer. The creator hasn’t moved coins or signed messages since 2010. Sixteen years of silence doesn’t necessarily mean death, but it doesn’t suggest active monitoring of Bitcoin development discussions either.
If Satoshi is watching, PACTs offer a way to secure those coins without ending the mystery. A private commitment today, revealed only if needed later, would preserve both the bitcoin and the pseudonymity. If Satoshi isn’t watching, or isn’t alive, those 1.1 million coins are on borrowed time.
The market cap dashboard shows Bitcoin’s total valuation hovering near $1.5 trillion. Satoshi’s stake represents roughly 5% of all bitcoin in existence. What happens to that stake matters for network security, for the precedent it sets about property rights, and for the billions of dollars at stake.
Robinson published his proposal Friday. The BIP-361 discussion has been active since mid-April. The quantum computing timeline, while uncertain, is measured in years rather than decades according to most researchers tracking the field. The window for dormant holders to act is open now. It won’t stay open forever.
Related Reading
- Seed phrase security, start to finish
- Hardware wallet showdown: Ledger vs Trezor
- Bitcoin news
- More on Bitcoin
- More on Quantum Computing




