1.1M BTC from early addresses face quantum threat as Bitcoin community divides

iconTechFlow
Share
AI summary iconSummary
Bitcoin news: A new zero-knowledge tool from Project Eleven aims to help BTC holders prepare for quantum threats, but 1.1 million BTC in early P2PK addresses remain vulnerable. These coins, linked to Satoshi’s mining, lack the key structure required for migration. BTC update: The community is debating four solutions, each risking Bitcoin’s core values. Market participants are responding, with Jefferies reducing its 2026 BTC exposure amid governance concerns.

Written by: Clow

A zero-knowledge proof tool can help your Bitcoin evade quantum attacks in just 243 milliseconds. But Satoshi’s 1.1 million? No saving them.

It's not that quantum computers aren't powerful enough—it's that the Bitcoin community started fighting before they even arrived.

Project Eleven has just launched a zero-knowledge proof recovery tool that enables modern wallet holders to securely migrate assets before quantum attacks arrive. A benchmark test on a MacBook Air with an M5 chip showed proof generation in 243 milliseconds, verification in 40 milliseconds, and peak memory usage of 2.1 GB. Fast, lightweight, and elegant.

However, this solution has a critical flaw: it only works for HD wallets created after 2012.

Old coins from before 2012, including approximately 1.1 million bitcoins mined by Satoshi Nakamoto, are dispersed across about 22,000 P2PK addresses, with roughly 50 BTC per address. These addresses have no parent key, no mnemonic phrase, and no derivation path that could be used to construct a zero-knowledge proof. Cryptographically, they are dead ends.

So the real question has never been “When will quantum computers arrive?” but rather “What do we do with these 1.1 million old coins?”

The answer to this question is not in cryptography; it's in politics.

01 Who can save themselves, who has been sentenced to death

To understand this crisis, first understand one thing: not all bitcoins are equally vulnerable.

On-chain assets are roughly categorized into three tiers based on the extent of public key exposure.

The safest are hash-protected unused addresses, where the public key is hidden behind the hash—quantum computers cannot access them—and they account for over 65% of the circulating supply.

The intermediate tier consists of modern addresses with exposed public keys due to address reuse or Taproot design, where public keys are permanently recorded on the blockchain, totaling approximately 4.5 to 5.2 million BTC.

The most dangerous are early P2PK addresses, where the public key is directly embedded in the transaction script, totaling approximately 1.7 to 1.9 million coins.

The middle tier is salvageable. Project Eleven’s tools are specifically designed for them.

The principle is called "signature enhancement," proposed by researchers Or Sattath and Shai Wyborski in 2023, noting that Shor's algorithm can break elliptic curve signatures but is ineffective against hash functions.

The private keys for subaddresses in modern HD wallets are derived from the master key using HMAC-SHA512 hashing. Even if a quantum computer were to uncover the private key of a subaddress, it could not reverse-engineer past the hashing barrier to derive the master key.

Wallet holders only need to prove ownership of the parent key upstream in the derivation path, generate a zero-knowledge proof bound to a quantum-resistant address, and complete the migration. No exposure of the master private key or mnemonic phrase—verifiable on-chain.

However, coins created before 2012 do not have this "key tree." During Bitcoin's early years, from 2009 to 2010, when Satoshi Nakamoto was active, each address generated by a Bitcoin wallet was completely random and independent of the others.

No parent-child hierarchy, no master key, no BIP-39 mnemonic. Cryptographically, Project Eleven’s approach renders them completely ineffective.

1.7 million bitcoins are blocked from recovery paths by a technical boundary drawn in 2012.

02 Four plans, four ways to die

Problems that technology cannot solve must be left to politics. The community faces four paths, each leading to some form of disaster.

Rule One: Inaction, allowing liquidation. Strictly adhere to "private key equals justice"—whoever gets a quantum computer first takes it all. This approach sounds the purest but carries the highest cost.

1.7 million bitcoins, long considered "permanently lost" by the market, have suddenly reentered the secondary market, effectively increasing the circulating supply by 8% to 9%. The "digital gold" narrative may be undermined by the actual transfer of underlying ownership.

Article 2: Mandatory Freeze. The BIP-361 proposal plans to prohibit new deposits to vulnerable addresses in the third year after launch, and completely invalidate traditional signature-based spending in the fifth year. Coins not migrated will be permanently locked.

Economically equivalent to actively destroying 1.7 million bitcoins, creating a permanent deflationary effect. But the community’s reaction was direct: To prevent assets from being stolen, you’ve decided to confiscate users’ funds first?

When protocol developer Mark Erhardt shared this proposal on social media, the comments section was flooded with criticism.

Article 3: "Hourglass" rate limiting. Developer Hunter Beast proposes a compromise, acknowledging that old coins may have been stolen, but sets a very low threshold for spending from P2PK addresses.

Each block can confirm at most one P2PK transaction, with a limit of 1 BTC per transaction. Even if all 1.1 million coins owned by Satoshi were controlled by quantum hackers, selling them would take over a century.

Attackers seeking to cash out must bid aggressively in the fee market, with these funds ultimately flowing to miners as long-term subsidies for network security.

Article 4: Mandatory Reallocation. The most aggressive option. Through a hard fork, orphaned old coins are "nationalized" and distributed proportionally to active holders who have migrated to quantum-resistant addresses.

The total supply remains 21 million, but the ledger commitment was directly overturned. The outcome was almost inevitable: a fractured community, multiple competing "legitimate chains" running in parallel, and a catastrophic divergence in valuations.

Cardano founder Charles Hoskinson sharply criticized BIP-361: this is not a soft fork, it's a hard fork.

Any attempt to forcibly freeze early assets by setting a deadline is a violation of Bitcoin’s property rights principles. Jameson Lopp, a co-author of BIP-361, also acknowledges that this proposal is more like a “draft emergency contingency plan” than a final solution.

Ironically, all four proposals aim to protect Bitcoin’s value, yet each undermines what it seeks to protect: allowing theft undermines its role as a store of value, forced freezes violate the promise of property rights, rate limiting acknowledges the legitimacy of theft, and reallocation compromises the immutability of the ledger.

This is not a technical question; it's a political question with no correct answer.

Market has already started voting.

Most investors still view the quantum threat as a distant issue of "when hardware will be ready."

But the market has already priced it in.

In January 2026, Jefferies announced it had fully exited its 10% Bitcoin allocation in its pension model portfolio.

The strategist put it clearly: the reason to liquidate isn't that quantum computers have already been developed, but rather the governance uncertainty within the Bitcoin community regarding how to handle early, vulnerable coins.

This is the real expectation gap. Physicists are still struggling with error-corrected logical qubits in the lab, while Wall Street is already discounting governance risk.

For institutional capital seeking legal certainty, the logic is straightforward: if Satoshi’s coins can be forcibly frozen by code, then any coin in the future can be stripped away by consensus.

Another significant risk is the hidden threat of “harvest now, decrypt later.” Blockchain ledgers are public, and attackers are currently downloading and storing the entire Bitcoin ledger.

Once practical quantum computers become available, they can offline-crack old wallets that have exposed their public keys without needing network access. This delayed attack makes the governance stakes even more urgent.

It is also worth noting the differences in statistical methodologies among institutions. The BIP-361 proposal states that over 34% of the supply has exposed public keys; Citibank’s figure ranges from 25% to 37%; Glassnode reports approximately 30%; and Talos’s full-chain scan yields 34.5%. Regardless of which figure is used, it means at least a quarter of all bitcoins are exposed to long-term quantum threats.

Moreover, Project Eleven’s tools are currently only an un-audited early prototype, supporting just three types of wallets, and require highly contentious consensus rule changes before mainnet deployment. It is too early to treat it as a ready-to-use emergency channel.

Returning to that fundamental question: How can Bitcoin accomplish a historic technological reckoning without compromising its own property principles?

No one has an answer. The quantum computer hasn’t arrived yet, but the crisis of faith already has.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.