📈 Get daily crypto insights that make you smarter about your money

Bitcoin Quantum Threat Just Got a Fix — But It Cannot Save Satoshi 1.1 Million Coins

A research outfit called Project Eleven has built a zero-knowledge proof system that could let Bitcoin owners recover their coins after quantum computers break today’s cryptography — but the fix has one glaring exception: it cannot save the roughly 1.1 million Bitcoin mined by Satoshi Nakamoto, the cryptocurrency’s mysterious creator.

By Keisha Williams | July 20, 2026

The Hook: A Countdown Called Q-Day

For years, cryptographers have warned about something called Q-Day — the theoretical moment when a sufficiently powerful quantum computer can break the encryption that protects Bitcoin wallets. When that day arrives, anyone whose public key has been exposed on the blockchain could see their funds stolen by an attacker who forges their digital signature.

According to BIP-361, a proposal published in April by Jameson Lopp and five co-authors, more than 34 percent of all Bitcoin currently sits in this vulnerable category. The proposal suggests freezing new deposits to quantum-vulnerable addresses after three years and locking whatever remains after five — a dramatic step that would strand coins in over a third of Bitcoin’s total supply.

That plan always came with a promise: there would be a way for legitimate owners to get their coins back using zero-knowledge proofs, a technology that lets someone prove they know something without revealing what it is. Now, Project Eleven says it has built exactly that tool — and it is fast enough to actually use.

On-Chain Evidence: How the Fix Works

To understand why this matters, you need to know a little about how Bitcoin keys work — and why quantum computers threaten them.

Bitcoin signatures rely on elliptic curve cryptography, a system where a private key generates a public key through math that only runs one way. Anyone can verify the public key, but no one can reverse-engineer the private key from it. At least, not with a regular computer. A quantum computer running Shor’s algorithm — a method published all the way back in 1994 for problems that ordinary computers cannot solve — could take a public key and work backward to the private key. At that point, an attacker could sign transactions from any address whose public key has been exposed.

But there is a second layer of math that quantum computers struggle with: hashing. A hash function scrambles an input into a fixed-length fingerprint and cannot be reversed. The best quantum attack on hashing — called Grover’s algorithm — only halves the difficulty, taking a 256-bit hash from an impossibly large number of guesses down to a number that is still so large it would take machines making a billion guesses per second longer than the lifetime of the universe to crack.

Modern Bitcoin wallets are built on this hashing layer. They generate addresses in a tree-like structure, deriving each key from its parent through a one-way function. Even if an attacker breaks a specific address key after Q-Day, they cannot climb up the tree to the master key. Project Eleven and Jim Posen, lead developer of the Binius proof system, built a zero-knowledge proof around exactly this property.

The user proves they know the key material sitting above their address in the wallet’s derivation tree, that it connects to the address in question, and binds the proof to a specific transaction message. None of the actual key material is ever revealed. Think of it like proving you know a password by answering a question about it correctly, without ever typing the password itself.

The Core Conflict: Why Satoshi’s Coins Are Doomed

Here is the catch. The entire recovery scheme depends on there being a key above a user’s address — a parent key in the tree. That tree structure arrived with BIP-32, which was introduced on February 11, 2012.

Before BIP-32, Bitcoin wallets generated every key independently and at random. There was no tree, no parent key, no derivation path. And Satoshi Nakamoto mined Bitcoin from 2009 through 2010 and was gone by 2011 — years before hierarchical wallets existed. Those early coins sit in a format called pay-to-public-key, where the public key is written directly on the blockchain, generated by software that had no seed phrase, no tree structure, and no parent key.

There is nothing above those keys in a tree, because trees did not exist yet. The same problem applies to every other pre-2012 wallet — which happens to be some of the oldest, most dormant, and most valuable Bitcoin in existence. These are exactly the coins that BIP-361 was designed to protect, and they are the ones the recovery tool cannot reach.

Project Eleven has acknowledged that the prototype is unaudited, supports only a limited set of wallet types, and would require contentious changes to Bitcoin’s rules before it could protect any live coins. In other words, the math works — but the politics of activating it on the Bitcoin network could be just as hard as the cryptography.

Market Implications: The Numbers Behind the Breakthrough

The performance benchmarks are what make this proposal genuinely interesting rather than just a theoretical exercise. On a consumer M5 MacBook Air, Project Eleven’s prototype generates a zero-knowledge proof in 243 milliseconds on four CPU cores. Verification takes just 40 milliseconds. The entire process uses about 2 gigabytes of memory and requires no graphics processing unit at all.

For context, prior approaches were dramatically slower. Project Eleven reports its system is roughly 16 times faster than previous methods when counting all steps, and when excluding the one-time setup that a real user would build once and reuse, the speed advantage grows to about 60 times. There is also no trusted setup — meaning no hidden keys or secret parameters that could later undermine the system’s security.

  • 243 milliseconds to generate a proof on a laptop
  • 40 milliseconds to verify it
  • 2 gigabytes of memory needed
  • No GPU required — runs entirely on a consumer CPU
  • 16x faster than prior work overall, 60x faster excluding setup

For everyday Bitcoin holders, this means the quantum recovery tool could eventually be built directly into standard wallet software — not just run on specialized servers. But that day is still years away, contingent on both Q-Day timelines and the Bitcoin community reaching consensus on a protocol upgrade.

The Verdict: What This Means for Your Bitcoin

If you bought Bitcoin any time in the last several years using a modern wallet — anything with a seed phrase — your coins would theoretically be protectable by this technology once it is adopted. Your keys exist in a tree structure, and the zero-knowledge proof can demonstrate ownership without exposing your private keys to a quantum attacker.

But there are important caveats every investor should understand:

  • Q-Day is not here yet — No one knows exactly when quantum computers will be powerful enough to break Bitcoin cryptography. Estimates range from five to twenty years, but the threat is taken seriously enough that researchers are building defenses now.
  • The software is unaudited — Project Eleven’s prototype has not gone through formal security review. It would need rigorous testing before anyone trusted it with real funds.
  • Bitcoin would need a protocol upgrade — Activating BIP-361 and its recovery mechanism requires the Bitcoin community to agree on changes to the network’s rules, which is historically difficult and politically charged.
  • Old coins stay at risk — Pre-2012 Bitcoin, including Satoshi’s stash, cannot use this recovery path. Those coins would be permanently vulnerable after Q-Day unless a different solution is found.

The big picture is that Bitcoin is preparing — slowly, methodically, and with the usual dose of internecine debate — for a threat that may still be a decade away. Project Eleven’s work suggests the cryptography is solvable. Whether the Bitcoin community can agree on how to deploy it is an entirely different question, and one that has derailed simpler upgrades in the past.

For now, the best thing ordinary investors can do is make sure their Bitcoin is stored in modern, hierarchical wallet addresses — the kind generated from a seed phrase — rather than legacy formats. If you are using any mainstream wallet created in the last decade, you are almost certainly already covered.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

22 thoughts on “Bitcoin Quantum Threat Just Got a Fix — But It Cannot Save Satoshi 1.1 Million Coins”

  1. 34% of supply at risk and people still think Q-Day is science fiction. Shor’s algorithm has been around since 94, the only question is engineering

    1. shor’s algorithm existing on paper vs a working quantum computer with enough qubits are very different things. we are decades out minimum

  2. The Satoshi coins are the interesting part. Even with ZK proofs, you cant prove ownership of keys nobody has moved in 15 years. Those coins are gone on day one.

    1. imagine being Satoshi, watching your 1.1M BTC become unrescuable while everyone else gets a life raft. rough.

      1. deadpixel42 satoshi watching 1.1M BTC become permanently locked while everyone else gets a life raft. the creator of the whole system gets the worst deal

    2. Rashid O. exactly. you cant ZK proof keys that nobody has signed with in 15 years. the protocol would need the private key to generate the proof

    3. Rashid O. exactly right. ZK proofs require the private key to generate. satoshis keys havent touched in 15 years so theres no way to prove ownership

  3. 34% of supply sitting in vulnerable addresses is staggering. the 3 year freeze idea from BIP-361 sounds reasonable until you realize how many people will lose access in that window

    1. qubit_skeptic_ agreed, the 3 year freeze in BIP-361 is the real problem. most people cannot find their seed phrase from 2013 let alone migrate keys on a deadline

      1. Henrik W. most people cant find their password from last month let alone a seed phrase from 2013. the 3 year migration window assumes a level of competence that most BTC holders simply dont have

  4. Shor’s algorithm has been around since 1994 and we still dont have a quantum machine that can actually run it at scale. not saying Q-day is fake but the timeline keeps getting pushed back every year

    1. Naledi S. exactly this. we have been 10 years away from quantum breaking RSA for 25 years now. BIP-361 is good insurance but the urgency is overblown

      1. Niamh C. 25 years of being 10 years away is fair but lattice cryptography exists NOW and NIST already finalized standards. the migration path matters more than the countdown

  5. 34 percent of bitcoin supply exposed to quantum attacks and people are worried about ETF flows. BIP-361 is literally the most important proposal of the decade and nobody is talking about it

    1. qday_skep_ BIP-361 matters but the real question is timeline. Project Eleven says 5-10 years before a CRQC exists. we had time to prepare and still barely started

    2. qday_skep_ BIP-361 is important but the 3 year freeze basically guarantees Satoshi coins never move. even if someone found those keys the lockup makes them worthless to a thief anyway

  6. the satoshi coins being unprotected is actually a feature not a bug. those 1.1M BTC staying unmoved forever is deflationary pressure for the rest of us

    1. post_quantum_rat

      Henrik O. calling 1.1M BTC permanently locked a feature is wild. thats 5% of supply gone forever. supply shock on top of the halving

      1. lattice_bridges_

        post_quantum_rat 1.1M BTC locked forever is 5% of supply but its already priced in. those coins havent moved in 15 years. the market already treats them as burned

  7. q_day_skeptic_

    Project Eleven built a post-quantum migration path that excludes the 1.1M coins that started the whole thing. the irony is not lost on anyone

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,743.00+0.9%ETH$1,912.44+2.4%SOL$75.30+1.5%BNB$572.87+1.1%XRP$1.10+0.4%ADA$0.1652+0.2%DOGE$0.0731+2.6%DOT$0.8223+0.2%AVAX$6.69+1.9%LINK$8.54+1.9%UNI$3.93+7.1%ATOM$1.39+0.4%LTC$47.39+2.9%ARB$0.0826-0.4%NEAR$1.80+0.1%FIL$0.7454+3.1%SUI$0.7188+1.4%BTC$64,743.00+0.9%ETH$1,912.44+2.4%SOL$75.30+1.5%BNB$572.87+1.1%XRP$1.10+0.4%ADA$0.1652+0.2%DOGE$0.0731+2.6%DOT$0.8223+0.2%AVAX$6.69+1.9%LINK$8.54+1.9%UNI$3.93+7.1%ATOM$1.39+0.4%LTC$47.39+2.9%ARB$0.0826-0.4%NEAR$1.80+0.1%FIL$0.7454+3.1%SUI$0.7188+1.4%
Scroll to Top