Bitcoin's 1.1M Satoshi Coins Become a Problem Before Quantum Computers Arrive

btc
Zero Knowledge ProofQuantum ComputingSatoshi NakamotogovernancesecurityBitcoinBIP-361
1 hours agoSource: blockweeks.com
Bitcoin's 1.1M Satoshi Coins Become a Problem Before Quantum Computers Arrive

Author: Clow

A zero-knowledge proof tool can help your Bitcoin escape quantum attacks in 243 milliseconds. But Satoshi's 1.1 million coins? No hope.

It's not that quantum computers aren't powerful enough; it's that before they arrive, the Bitcoin community is already fighting.

Project Eleven has just released a zero-knowledge proof recovery tool that allows modern wallet holders to safely migrate assets before a quantum attack. A benchmark test on a MacBook Air with an M5 chip generated a proof in 243 milliseconds, verified it in 40 milliseconds, with a peak memory of 2.1 GB. Fast, lightweight, and elegant.

But this solution has a flaw: it only works for HD wallets created after 2012.

Old coins before 2012, including the approximately 1.1 million Bitcoins mined by Satoshi, are scattered across about 22,000 P2PK addresses, each holding about 50 BTC. These addresses have no parent key, no mnemonic phrase, and no derivation path to construct a zero-knowledge proof. Cryptographically, they are dead ends.

So the real question has never been "when will quantum computers arrive," but "what to do with these 1.1 million old coins."

The answer to this question lies not in cryptography, but in politics.

01 Who can save themselves, who is sentenced to death

To understand this crisis, first understand one thing: not all Bitcoins are equally vulnerable.

On-chain assets can be roughly divided into three tiers based on public key exposure.

The safest are hash-protected unused addresses, where the public key is hidden behind a hash, immune to quantum computers, accounting for over 65% of the circulating supply.

The middle tier consists of modern addresses with exposed public keys, due to address reuse or Taproot design, where the public key is permanently recorded on-chain, totaling about 4.5 to 5.2 million BTC.

The most dangerous are early P2PK addresses, where the public key is directly written in the transaction script, totaling about 1.7 to 1.9 million BTC.

The middle tier can be saved. Project Eleven's tool is designed for them.

The principle is called "signature lift," proposed by researchers Or Sattath and Shai Wyborski in 2023. Shor's algorithm can break elliptic curve signatures but is powerless against hash functions.

The private keys of sub-addresses in modern HD wallets are derived from the master key via HMAC-SHA512 hashing. Even if a quantum computer derives the private key of a sub-address, it cannot reverse the hash barrier to go upward.

The wallet holder only needs to prove they possess the parent key upstream of the derivation path, generate a zero-knowledge proof, bind it to a quantum-resistant address, and complete the migration. No master private key or mnemonic phrase is exposed, and it is verifiable on-chain.

But old coins before 2012 do not have this "key tree." During Satoshi's active period from 2009 to 2010, Bitcoin wallets generated addresses completely randomly, independent of each other.

No parent-child hierarchy, no master key, no BIP-39 mnemonic. Cryptographically, Project Eleven's solution is completely ineffective for them.

1.7 million Bitcoins are blocked from self-rescue by a technical dividing line drawn in 2012.

02 Four solutions, four ways to die

Problems that technology cannot solve must be left to politics. The community faces four paths, each leading to some form of disaster.

First: Inaction, let the chips fall. Strictly adhere to "private key is justice," whoever gets a quantum computer first takes it. Sounds the purest, but the cost is greatest.

1.7 million Bitcoins, previously considered "permanently lost, would suddenly flood the secondary market, increasing circulating supply by 8% to 9%. The narrative of "digital gold" would be shaken by the actual transfer of underlying property rights.

Second: Forced freeze. BIP-361 proposes to ban new deposits to vulnerable addresses in the third year after activation, and completely abolish the spending power of traditional signatures in the fifth year. Unmigrated coins are permanently locked.

Economically, this is equivalent to actively destroying 1.7 million Bitcoins, creating a permanent deflation. But the community's reaction is direct: to prevent assets from being stolen, you decide to confiscate users' money first?

When protocol developer Mark Erhardt shared this proposal on social media, the comments section was flooded with criticism.

Third: "Hourglass" rate limiting. Developer Hunter Beast proposed a compromise, acknowledging that old coins might be stolen, but setting extremely low spending limits for P2PK addresses.

Each block can confirm at most one P2PK spending, with a single transaction limit of 1 BTC. Even if all of Satoshi's 1.1 million coins are controlled by a quantum hacker, the sell-off would take over a century.

Attackers wanting to cash out must compete fiercely in the fee market, and the fees eventually flow to miners, becoming a long-term subsidy for network security.

Fourth: Forced redistribution. The most radical option. Through a hard fork, the unowned old coins are "nationalized" and distributed proportionally to active holders who have migrated to quantum-resistant addresses.

Total supply remains 21 million, but the ledger commitment is directly overturned. The result is almost predictable: community split, multiple "orthodox chains" running in parallel, and catastrophic valuation divergence.

Cardano founder Charles Hoskinson's criticism of BIP-361 hit the nail on the head: This is not a soft fork; it's a hard fork.

Any attempt to forcibly freeze early assets by setting a deadline is a trampling of Bitcoin's property rights principles. BIP-361 co-author Jameson Lopp also admitted that this proposal is more like a "draft emergency backup plan," not the final answer.

Ironically, all four solutions aim to protect Bitcoin's value, but each undermines what it seeks to protect. Allowing theft destroys value storage, forced freeze destroys property rights promises, rate limiting acknowledges the legitimacy of theft, and redistribution destroys the immutability of the ledger.

This is not a technical problem; it's a political problem with no correct answer.

03 The market is already voting

Most investors still view the quantum threat as a long-term issue of "when hardware will be ready."

But the market is already pricing it in.

In January 2026, Jefferies announced it would liquidate 10% of its Bitcoin holdings in its pension model portfolio.

The strategist made it clear: the reason for liquidation was not that quantum computers had arrived, but the governance uncertainty shown by the Bitcoin community in "how to handle early vulnerable coins."

This is the real expectation gap. Physicists are still wrestling with error-corrected logical qubits in the lab, while Wall Street is already discounting governance risk.

For institutional capital seeking legal certainty, the logic is simple: if Satoshi's coins can be forcibly frozen by code, then any coin can be deprived by consensus in the future.

Also not to be ignored is the hidden risk of "harvest now, decrypt later." The blockchain ledger is public, and attackers are already downloading and storing the entire Bitcoin ledger.

Once a practical quantum computer is available, they don't need to connect to the network; they can crack old wallets with exposed public keys offline. This delayed attack makes the governance game more urgent.

The differences in statistical口径 among institutions regarding vulnerable Bitcoin are also noteworthy. BIP-361 claims over 34% of supply has exposed public keys, Citigroup's figure is 25% to 37%, Glassnode estimates about 30%, and Talos's full ledger scan gives 34.5%. Regardless of which number is taken, it means at least a quarter of Bitcoin is under long-term quantum threat.

Moreover, Project Eleven's tool is currently an early prototype without security audit, supporting only three types of wallets, and requires highly controversial consensus rule changes before going mainnet. It is premature to consider it a ready-to-use emergency channel.

Back to the fundamental question: How can Bitcoin complete a historical technological transition without destroying its own property rights principles?

No one has the answer. Quantum computers haven't arrived yet, but the crisis of faith has already come.