null

Author: Claude, Deep Tide TechFlow

Deep Tide Guide: Bitcoin developers Jameson Lopp and others officially submitted the BIP-361 proposal on April 14, planning to phase out ECDSA and Schnorr signatures in three stages, ultimately freezing all early wallets that have not migrated to quantum-resistant addresses.

The proposal involves approximately 1.7 million BTC in P2PK addresses (including about 1.1 million held by Satoshi Nakamoto, valued at approximately 74 billion dollars), with around 34% of Bitcoin in the network facing quantum attack risks due to exposed public keys. The proposal was met with fierce criticism from the community, with detractors labeling it as 'authoritarian confiscation', but Lopp responded that he would rather freeze 5.6 million dormant BTC than let them fall into the hands of quantum hackers.

Renowned cryptopunk and Casa CTO Jameson Lopp, along with five researchers, submitted a draft named BIP-361 to GitHub's bitcoin/bips repository on April 14, titled "Post Quantum Migration and Legacy Signature Sunset." The core assertion of this proposal is straightforward: before quantum computers can break existing cryptographic algorithms, the network should proactively freeze all Bitcoin wallets relying on old signature schemes.

According to CoinDesk, Lopp stated in an interview that he currently does not believe there is an immediate need for these measures, but emphasized that he is engaging in "counterfactual thinking about potential future threats." He further admitted on the X platform: "I know people don't like this proposal. I don't like it either. But I wrote it because I dislike another outcome even more."

Three-phase "Sunset Plan": from restrictions to freezes

BIP-361 builds on BIP-360, released in February this year. BIP-360 proposed a new address format called P2MR (pay-to-Merkle-root), similar to existing Taproot addresses but removing key paths vulnerable to quantum attacks, providing forward protection for new coins. The issue BIP-361 aims to address is the existing problem: as of March 1, 2026, over 34% of Bitcoin on the network has exposed public keys on-chain, a figure directly sourced from the BIP-361 document itself.

The proposal outlines three progressive phases:

Phase A will take effect about three years after activation, at which point the network will prohibit sending new BTC to old-style addresses, and all users should have migrated to quantum-resistant address types. Phase B will take effect five years after activation, at which point old-style ECDSA and Schnorr signatures will be completely abolished, and any Bitcoin still left in vulnerable addresses will be effectively frozen. Phase C is an unfinished relief mechanism, envisioned to allow legitimate owners holding mnemonic phrases to recover frozen funds through zero-knowledge proofs.

According to Live Bitcoin News, GitHub reviewer Conduition believes that Phase C is "the most critical component of any proposal involving confiscatory freezes" and argues that without this mechanism, BIP-361 is incomplete.

The proposal's authors describe the freeze mechanism as a "private incentive for upgrades": lost or frozen coins will only slightly increase the value of others' coins, while coins recovered from quantum attacks will devalue everyone's holdings.

5.6 million dormant BTC and $74 billion of Satoshi's holdings

The reason this debate strikes a nerve is due to the enormous scale involved.

According to Lopp's estimates, about 5.6 million Bitcoins (28% of the total supply) have not moved in over ten years, and he and other analysts believe these coins are likely lost. At current prices, the value of these dormant tokens is approximately $420 billion.

Among the most symbolic is Satoshi's holdings. According to Cointelegraph, about 1.7 million BTC is locked in early P2PK addresses, including approximately 1.1 million of Satoshi's holdings, currently valued at around $74 billion. The public keys of these addresses have long been exposed on-chain, and once quantum computing capabilities reach a critical point, attackers can reverse-engineer private keys from public keys using Shor's algorithm, directly controlling the funds.

Lopp warned in an interview with CoinDesk that even without a need for massive sell-offs, "as long as there is any credible evidence that someone has the ability to recover lost or vulnerable coins with quantum computers, the market will immediately panic on a large scale."

The odds on Polymarket for "Will Satoshi move any Bitcoin in 2026" are currently around 9.3%, an increase from 4.5% at the beginning of the year, but the market's reaction to the release of BIP-361 has been mild, suggesting it is still viewed as a governance discussion rather than an urgent catalyst.

The community reacted strongly: "Stealing money to prevent being stolen"

BIP-361 touches on the deepest philosophical tenets of Bitcoin: ownership should not come with conditions. Immediately upon its release, criticism surged.

Bitcoin Magazine editor Brian Trollz directly rejected the proposal; TFTC founder Marty Bent called it "ridiculous"; Metaplanet's business development head Phil Geiger sarcastically remarked: "We must steal people's money to prevent their money from being stolen."

A comment by X platform user Cato the Elder has been widely circulated: "This quantum proposal is highly authoritarian and confiscatory... There is no reasonable justification for forcing upgrades and rendering old spending paths obsolete. Upgrades should be 100% voluntary."

Leo Fan, founder of Cysic and former quantum resistance lead at Algorand, pointed out from a technical governance perspective: "Ownership has become conditional. Holding keys no longer guarantees you can spend. This undermines Bitcoin's promise of being 'unstoppable money.'" However, Fan also acknowledged that removing millions of Bitcoins from circulation could tighten supply and thus push up coin prices.

Discussions in the Reddit community r/cryptocurrency are equally intense (the post received 631 likes and 311 comments), with the top comment stating: "If you fork frozen wallets to hedge investment risks, BTC is no longer BTC." Another user took a completely opposite stance: "Let them be hacked, let the price crash for a month. We will still buy the dip, just like last time during the survival crisis."