• Home
  • Industry Blog
  • Bitcoin's Quantum Debate: What Happens to the Coins That Can't Migrate?

Bitcoin's Quantum Debate: What Happens to the Coins That Can't Migrate?

Picture2wolfgang.png
Wolfgang Amadeus VitaleCrypto Protocol Expert
13 Aug 202610 Min

The quantum threat to Bitcoin's ECC is by now a matter of public record. The timeline for cryptographically relevant quantum computers (CRQCs) continues to compress. The core mechanics of a post-quantum cryptography migration are technically understood, if not yet politically resolved. Other blockchain ecosystems have published roadmaps and begun implementation.  

What has been less settled is how Bitcoin's own community is navigating the response and that conversation has shifted considerably over the past year, as quantum computing has moved from a theoretical risk to an active area of Bitcoin protocol development.

How has Bitcoin's quantum debate evolved?

For most of the past year, the loudest quantum-Bitcoin debate was focused on urgency and effort. One camp initially argued the threat was imminent and developers were ignoring it. The other called those warnings commercially motivated noise built on speculative timelines.  

For instance, Nic Carter, partner at Castle Island Ventures, was very vocal about Bitcoin developers not being concerned enough about quantum risk. He clearly helped spread awareness of the quantum risk. But his view on developer attention changed in the last few months, as he started perceiving the main bottleneck as the absence of an organization that could coordinate effort and provide funding. Galaxy’s Bitcoin Quantum Readiness Initiative and the new Bitcoin Security Consortium are promising initiatives to fulfill that role.  

On the other side, Adam Back, co-founder of Blockstream, appeared to be more dismissive about the migration urgency, even though Blockstream was already working on post-quantum signatures. His public stance also changed. While he still leans towards relatively long timelines, citing expert estimates that place CRQCs decades away, he believes preparation should begin regardless, as he told me on our podcast, where he advocated for deploying a conservative signature scheme now and upgrading it later.  

I believe there is ample evidence that Bitcoin developers were already paying attention and putting in effort to design post-quantum solutions as early as mid-2025. But I also think that necessity increased over time and eventually became undeniable.

What happens to quantum-vulnerable Bitcoin? 

The quantum debate now mainly concerns another question: how to organize the migration? Deploying new post-quantum signature schemes does not automatically, retroactively upgrade all coins. To ensure an orderly migration, all BTC holders must have enough time and incentives to move their coins to post-quantum addresses.  

At the core of this debate there is an unavoidable and controversial question: what happens to quantum-vulnerable lost coins, for which nobody owns the private key? It touches the core beliefs about Bitcoin’s value proposition and affects a meaningful amount of BTC.  

More than a third of all Bitcoin in circulation sits in addresses with exposed public keys, which would be vulnerable to Shor's algorithm once a sufficiently powerful quantum computer exists. A significant portion have not transacted in over a decade, including one million BTC attributed to Satoshi Nakamoto. It is reasonable to estimate that 2-3 million BTC are stuck in wallets whose keys have been lost.  

There is no way to migrate vulnerable lost coins to post-quantum addresses. What happens to them is where the debate now sits, and three broad positions have emerged.

Should Bitcoin freeze quantum-vulnerable coins? 

BIP-361, authored by Jameson Lopp and five co-authors, proposes a plan that would eventually disallow spending coins relying on ECC signatures for transaction authorization. This is an example of all migration strategies that propose to disable ECC, either at a predefined block height, or depending on conditions like proof of CRQC existence. Coins in addresses that fail to migrate would become unspendable: either permanently burned, or temporarily frozen.  

The rationale is clear: if ECC signatures can be forged, vulnerable coins become a bounty for the first entity to build a capable quantum computer. Allowing that could redistribute a substantial share of Bitcoin's supply to whoever wins the quantum computing race — quite possibly a nation-state with no particular obligation to the network. 

The trade-off is equally direct. Disabling ECC while some coins still rely on it for spendability could establish the precedent that the network can agree on making a portion of existing holdings inaccessible, a tension with Bitcoin's identity as bearer money that the community has not had to confront before. 

The good news is that some coins can be frozen rather than burned. Bitcoin developers are proposing and improving so-called rescue protocols, allowing holders of frozen coins to spend them by proving their ownership in other ways than using their private key, which would be meaningless in presence of CRQCs. Unfortunately, this is not possible for all types of addresses: unrecoverable lost coins are either made permanently unspendable, or left vulnerable to CRQCs.

Should Bitcoin do nothing at the protocol level? 

Some developers and a part of the broader community argue that the priority should be to preserve Bitcoin as unconfiscatable, censorship-resistant money. If quantum computers eventually enable someone to produce a valid signature for another person's coins, that may constitute theft, but it becomes a question for courts and law enforcement, not for the consensus rules to adjudicate. This camp thus proposes to never disable ECC.  

The trade-off is economic. If quantum computers can break Bitcoin's ECC, even a small fraction of vulnerable coins moving within a few blocks would be enough to trigger a price collapse that undermines confidence in the network itself. Non-action is itself a choice, and one that penalizes holders who took every available precaution, only to see the network's credibility collapse around them. 

As a counterpoint, some proponents of this approach note how Bitcoin’s 'unconfiscatability' should be protected not just for ideological reasons, but very practically because this is Bitcoin’s main value proposition. Destroying this property might prevent market supply shock, but it might also cause even worse consequences for Bitcoin’s long-term value. 

It should also be clear that doing nothing at protocol level doesn’t necessarily mean that most vulnerable BTC will end up being sold into the market. For instance, Nic Carter envisioned a government-administered trust model: a sovereign actor recovers the coins and holds them in escrow for original owners to claim within a defined window.

Is there a middle ground? 

A third family of proposals attempts to find a compromise: spending ECC-protected coins would not be disabled outright, but rate-limited. This would simultaneously avoid confiscation and mitigate worst case quantum theft scenarios.  

For instance, Hourglass V2 proposes to eventually limit vulnerable coin spending to a maximum of 1 BTC per block, meaning that moving all coins would take at least 32 years, dramatically reducing quantum-theft market risks. Specifically, Hourglass V2 scope is limited to P2PK addresses, the ones most likely to be lost. 

The drawback is complexity. Properly navigating tradeoffs on design parameters requires assumptions about the identity and intent of the entities acquiring access to CRQCs first. This is also an important point for other migration strategies, but still, I believe agreeing on the rate limit and its scope may prove harder to encode in consensus rules than a clean freeze.

Where This Leaves Us

The progress on post-quantum transactions is a positive development. The funding is committed and developer attention is no longer questioned.  

What to do about coins that cannot or will not migrate is where the next phase of this debate will play out. It touches Bitcoin's monetary properties, its governance model, and the practical interests of holders, custodians, and institutions who now have material exposure to the outcome. The positions are forming, but we are nowhere near a resolution.

Related Articles

  • Quantum Research

    Beyond Bitcoin: How Other Blockchains Are Preparing for Quantum Computing

    Ethereum, Solana, Ripple and Cardano have published quantum resistant cryptography plans. Why the migration paths diverge, and where Bitcoin stands.

    31 Jul 20267 Min
  • Quantum Research

    Migration Is the Hard Part

    A sufficiently powerful quantum computer running Shor's algorithm could derive private keys from exposed public keys, breaking the elliptic curve cryptography (ECC) that Bitcoin depends on for digital signatures. The preparation window is measured in years, not decades, and the clock is already running.

    16 Jul 20269 Min
  • Quantum Research

    How Close Are We? The Quantum Timeline

    When you hold Bitcoin, what you actually own is knowledge of a private key. Elliptic-curve cryptography (ECC) lets you prove you know it without ever revealing it, using a digital signature and a corresponding public key.

    30 Jun 20269 Min

Personal Support, Every Step

Our team of native experts are here to provide you with the tools, insights and support you need.

Opening hours

24/7 online

Monday to Friday: 7am to 7pm

contact@bitcoinsuisse.com

0800 800 008

Call us toll-free from Switzerland

+41 41 660 00 00

Call us from abroad