Quantum Computers Haven't Arrived Yet, but Satoshi's 1.1 Million Bitcoin Pose the First Problem

marsbitPublished on 2026-07-22Last updated on 2026-07-22

Abstract

A zero-knowledge proof tool can help modern Bitcoin wallets migrate assets before quantum attacks in milliseconds. However, approximately 1.1 million bitcoins mined by Satoshi Nakamoto before 2012 are fundamentally unprotected by such solutions, as they reside in older P2PK addresses lacking the hierarchical structure required for this cryptographic rescue. This exposes a critical divide: post-2012 HD wallets can potentially "upgrade" signatures using tools like Project Eleven's, while early coins are cryptographically isolated. The community faces a political, not technical, dilemma with four contentious options: 1) Let quantum attackers seize the coins, risking market instability; 2) Hard fork to freeze vulnerable addresses, seen as violating property rights; 3) Implement extreme spending limits to slow any attack; 4) Redistribute "orphaned" coins, breaking immutability. Each solution threatens a core Bitcoin tenet. The market is already pricing in this governance risk, as evidenced by institutional divestment citing uncertainty. The true crisis isn't the arrival of quantum computing, but the community's inability to reconcile its foundational principles with an existential technological shift.

Written by: Clow

A zero-knowledge proof tool can help your Bitcoin evade a quantum attack in 243 milliseconds. But Satoshi's 1.1 million? Beyond saving.

It's not that quantum computers aren't powerful enough; it's that they haven't arrived yet, and the Bitcoin community is already at war.

Project Eleven just released a zero-knowledge proof recovery tool that allows modern wallet holders to safely migrate their assets before a quantum attack arrives. Running a benchmark test on an M5 chip MacBook Air, proof generation took 243 ms, verification 40 ms, with a peak memory usage of 2.1 GB. Fast, lightweight, elegant.

But this solution has a fundamental flaw: it only works for HD wallets created after 2012.

Old coins from before 2012, including the roughly 1.1 million Bitcoin mined by Satoshi, are scattered across about 22,000 P2PK addresses, each containing about 50 BTC. These addresses have no parent key, no mnemonic seed, no derivation path on which to build a zero-knowledge proof. Cryptographically, they are dead ends.

So the real question has never been "When will quantum computers arrive?" but rather "What should we do about these 1.1 million old coins?"

The answer to this question lies not in cryptography, but in politics.

01 Who Can Save Themselves, Who is Sentenced to Death

To understand this crisis, one must first grasp a key fact: not all Bitcoin is equally vulnerable.

On-chain assets can be roughly categorized into three tiers based on the exposure level of their public keys.

The safest are hashed unspent addresses, where the public key is hidden behind a hash. Quantum computers cannot touch these, accounting for over 65% of the circulating supply.

The middle tier consists of modern addresses with exposed public keys, permanently recorded on-chain due to address reuse or Taproot design, totaling approximately 4.5 to 5.2 million BTC.

The most dangerous are early P2PK addresses, where the public key is written directly into the transaction script, amounting to about 1.7 to 1.9 million coins.

The middle tier is salvageable. Project Eleven's tool is precisely designed for them.

The principle is called "signature uplifting," proposed by researchers Or Sattath and Shai Wyborski in 2023. Shor's algorithm can crack elliptic curve signatures but is powerless against hash functions.

The private keys for child addresses in modern HD wallets are all derived from a master key via HMAC-SHA512 hashing. Even if a quantum computer deduces the private key of a child address, it cannot bypass the hash barrier to reverse-engineer upwards.

Wallet holders only need to prove they control a parent key upstream in the derivation path, generate a zero-knowledge proof, bind it to a quantum-resistant address, and complete the migration. The master private key and mnemonic remain unexposed, and the proof is verifiable on-chain.

But pre-2012 old coins lack this "key tree." During Satoshi's active period from 2009 to 2010, Bitcoin wallets generated addresses completely randomly each time, independent of one another.

No parent-child hierarchy, no master key, no BIP-39 mnemonic. Cryptographically, Project Eleven's solution is completely ineffective for them.

1.7 million Bitcoin are stranded beyond the self-rescue path, blocked by a technical dividing line drawn in 2012.

02 Four Plans, Four Kinds of Doom

Problems that technology cannot solve can only be handed over to politics. Four paths lie before the community, each leading to some form of disaster.

First: Do nothing, let liquidation happen. Strictly adhere to "private key equals ownership," whoever gets a quantum computer first takes the coins. Sounds purest, carries the heaviest cost.

1.7 million Bitcoin, long considered "permanently lost" by the market, would suddenly flood the secondary market, equivalent to magically adding 8% to 9% to the circulating supply. The "digital gold" narrative would be shaken by the actual transfer of underlying property rights.

Second: Force a freeze. BIP-361 proposes prohibiting new funds from being sent to vulnerable addresses starting in year three after activation, and completely invalidating the spending power of traditional signatures in year five. Unmigrated coins are permanently locked.

Economically, this is actively destroying 1.7 million Bitcoin, creating a permanent deflation. But the community's reaction is straightforward: To prevent assets from being stolen, you decide to confiscate users' money first?

When protocol developer Mark Erhardt shared this proposal on social media, the comments section was scathing.

Third: "Hourglass" throttling. Developer Hunter Beast proposed a compromise, acknowledging the possibility of old coins being stolen but setting extremely low spending limits for P2PK addresses.

A maximum of one P2PK spend per block confirmed, with a single transaction limit of 1 BTC. Even if all 1.1 million of Satoshi's coins were controlled by a quantum hacker, liquidation would be stretched over a century.

Attackers seeking to cash out would have to fiercely compete in the fee market, with those fees ultimately flowing to miners, becoming a long-term subsidy for network security.

Fourth: Forced redistribution. The most radical option. Through a hard fork, "nationalize" the ownerless old coins and distribute them proportionally to active holders who have migrated to quantum-resistant addresses.

The total supply remains 21 million, but the ledger's promise is directly overturned. The outcome is almost predictable: community schism, multiple "legitimate chains" running in parallel, catastrophic valuation divergence.

Cardano founder Charles Hoskinson's criticism of BIP-361 hits the nail on the head: This isn't a soft fork; it's a hard fork.

Any plan that tries to force a freeze on early assets by setting a deadline is a trampling of Bitcoin's property rights principle. BIP-361 co-author Jameson Lopp also admits the proposal is more like a "draft emergency backup plan," not the final answer.

The irony is that all four plans aim to protect Bitcoin's value, yet each one undermines what it seeks to protect. Letting theft happen destroys value storage, forced freezing destroys property rights commitment, throttling legitimizes theft, redistribution destroys ledger immutability.

This isn't a technical puzzle; it's a political dilemma with no right answer.

03 The Market Has Already Started Voting

Most investors still treat the quantum threat as a distant problem of "when will the hardware be ready."

But the market is already pricing it in.

In January 2026, Jefferies announced clearing 10% of the Bitcoin holdings from its pension model portfolio.

The strategist was clear: The reason for clearing wasn't that quantum computers already exist, but the governance uncertainty the Bitcoin community displayed regarding "how to handle early vulnerable coins."

This is the real expectation gap. While physicists are still wrestling with error-correcting logical qubits in labs, Wall Street is already discounting governance risk.

For institutional capital seeking legal certainty, the logic is simple: If Satoshi's coins can be forcibly frozen by code, then any coin can be deprived by consensus in the future.

The hidden risk of "harvest now, decrypt later" cannot be ignored either. The blockchain ledger is public; attackers are already downloading and storing the entire Bitcoin ledger.

Once a practical quantum computer emerges, they won't need to connect to the network; they can crack those old wallets with exposed public keys offline. This delayed-attack vector makes the governance game even more urgent.

The variance in how different institutions count vulnerable Bitcoin is also noteworthy. BIP-361 claims over 34% of the supply has exposed public keys; Citibank's figure is 25% to 37%; Glassnode estimates about 30%; Talos's full-ledger scan gives 34.5%. Whichever number you take, it means at least a quarter of Bitcoin is under long-term quantum threat.

Furthermore, Project Eleven's tool is currently just an unaudited early prototype, supporting only three wallet types, and still requires highly contentious consensus rule changes before going live on mainnet. It's premature to treat it as a readily available emergency exit.

Returning to the fundamental question: How can Bitcoin complete the liquidation of a historical technological break without undermining its own property rights principles?

No one has the answer. Quantum computers haven't arrived yet, but the crisis of faith is already here.

Trending Cryptos

Related Questions

QWhat is the fundamental problem with the 1.1 million Bitcoins mined by Satoshi Nakamoto in the context of the quantum threat, and why can't Project Eleven's solution help?

AThe fundamental problem is that these coins are stored in early P2PK addresses created before 2012. These addresses were generated randomly and independently, with no hierarchical derivation paths, parent keys, or BIP-39 mnemonics. Project Eleven's zero-knowledge proof recovery tool relies on the hierarchical deterministic (HD) wallet structure introduced in 2012, which allows users to prove possession of a parent key to migrate funds to quantum-resistant addresses. Since Satoshi's coins lack this cryptographic 'key tree' structure, they are a cryptographic dead-end, and the tool is completely ineffective for them.

QWhat are the four political solutions proposed by the Bitcoin community to address the quantum threat to vulnerable old coins, and what is the primary criticism or drawback of each?

A1. Inaction (Let them be looted): Adheres strictly to 'private key is ownership' but risks a massive, destabilizing supply shock if coins are stolen and sold. 2. Mandatory Freezing (BIP-361): Proposes to permanently lock un-migrated vulnerable coins via a hard fork. Criticized as a violation of property rights, essentially confiscating user funds to prevent theft. 3. 'Hourglass' Throttling: Limits spending from vulnerable addresses (e.g., 1 BTC per block) to slow down any potential mass liquidation. Critics argue it legitimizes theft and creates long-term uncertainty. 4. Mandatory Redistribution: A hard fork to reallocate 'abandoned' old coins proportionally to active users who migrated. This directly breaks the immutability of the ledger, likely causing a catastrophic community split and valuation collapse.

QHow does the 'signature lifting' technique, as utilized by Project Eleven's tool, theoretically protect modern HD wallets from a quantum attack?

AThe 'signature lifting' technique, based on research by Or Sattath and Shai Wyborski, leverages the structure of modern HD wallets. While a quantum computer using Shor's algorithm could derive the private key from a publicly exposed address-specific public key, it cannot reverse the HMAC-SHA512 hash function used to derive child keys from a parent/master key. Therefore, a wallet holder can generate a zero-knowledge proof that demonstrates knowledge of an upstream parent key in the derivation path, without revealing the key itself. This proof can then authorize moving funds to a quantum-resistant address, securing the assets even if a specific address key is compromised.

QWhy did Jefferies cite 'governance uncertainty' as a reason to reduce its Bitcoin holdings in early 2026, rather than the immediate arrival of quantum computers?

AJefferies cited governance uncertainty because the core issue is no longer just the technical timeline for quantum computers. The market is preemptively pricing in the risk stemming from the Bitcoin community's inability to reach a consensus on how to handle the vulnerable early coins, especially Satoshi's 1.1 million BTC. For institutional investors seeking legal and regulatory certainty, the prospect that the protocol's rules (like property rights based on private keys) could be changed via a contentious hard fork to freeze or redistribute assets introduces a fundamental and unacceptable risk to the asset's value proposition, regardless of when the quantum threat materializes.

QWhat is the 'harvest now, decrypt later' risk mentioned in the article, and why does it increase the urgency for governance decisions?

AThe 'harvest now, decrypt later' risk refers to the fact that attackers can download and archive the entire public Bitcoin ledger today. Once a practical quantum computer is available in the future, they can use it offline to decrypt the private keys from the publicly exposed addresses (like old P2PK addresses) recorded in this archived data. This means the attack does not require real-time network access when the quantum computer is ready. This possibility makes the governance debate over how to handle these vulnerable coins more urgent, as the community cannot wait until quantum computers are online to decide on a mitigation strategy; the theft could happen as soon as the decryption capability exists.

Related Reads

Can Japan Buy Growth with AI? Will the Bond Market Believe It?

Japan's cabinet has introduced the 2026 Basic Policy on Economic and Fiscal Management and Reform, shifting its primary fiscal target. The new framework moves away from the traditional annual primary balance goal and instead prioritizes a stable reduction of the debt-to-GDP ratio. This change is tied to a strategy of increased "responsible proactive fiscal" spending, aiming to boost long-term growth through investments in strategic sectors like AI, semiconductors, energy, and robotics. The government estimates total public and private investment in 62 key technologies could exceed 370 trillion yen by 2040. The market reaction has been mixed and cautious. While equity markets may respond to policy signals, bond markets are focused on fiscal credibility. Concerns center on whether the weakening of the clear primary balance anchor could lead to looser fiscal discipline. If investors doubt that these strategic investments will generate sufficient productivity gains, tax revenue, and nominal growth to outpace rising interest costs, they may demand higher yields on Japanese Government Bonds (JGBs). Recent volatility in the yen and JGB yields, with the 10-year yield briefly reaching 2.9%, reflects this skepticism. The success of this new framework hinges on two factors: whether Japan can achieve a nominal growth rate consistently higher than its long-term interest rates, and whether future budgets demonstrate disciplined control over bond issuance. The government's narrative is that strategic investment is essential to break Japan's cycle of low growth, aging, and labor shortages. However, the bond market will continuously assess the credibility of this plan, pricing the risk that it may represent fiscal expansion rather than a viable growth strategy.

marsbit20m ago

Can Japan Buy Growth with AI? Will the Bond Market Believe It?

marsbit20m ago

Misjudged A-Shares: Resilience, Expectations, and Confidence

China's A-share market recently faced selling pressure, especially in tech sectors, initially triggered by a global tech sell-off that began in South Korea. However, the article argues this is a case of "mistaken injury" and highlights the market's underlying resilience. This resilience stems from three main pillars: **1) Tech Sector Fundamentals:** Unlike Korea's market dominated by a few memory chip stocks, China's tech sector is diversified across computing, communications, electronics, and semiconductors, supported by dual narratives of global AI supply chains and domestic substitution. Core areas like optical modules and fiber optics continue to show strong earnings growth. **2) "National Team" Support:** State-backed institutions and large corporations have made significant market purchases and announced buybacks, providing liquidity and signaling confidence. This is seen as a stabilizing policy signal, often associated with market bottoms. **3) Broader Market Pillars:** Other major sectors are showing endogenous recovery momentum. Consumer stocks benefit from stabilizing CPI and signs of sector recovery (e.g., liquor price hikes). Cyclical sectors like aluminum have high earnings, potential price increases due to tight supply, and low valuations. The financial sector offers stable dividends and low valuations. The conclusion is that the sell-off was driven by external contagion, not a collapse in fundamentals. With strong policy support and recovering momentum across key sectors, the A-share market possesses the toughness to regain stability.

marsbit51m ago

Misjudged A-Shares: Resilience, Expectations, and Confidence

marsbit51m ago

The Clarity Act's Journey Through Congress: The Thorny Path of Bipartisan Compromise in the U.S.

The U.S. Congress is struggling to advance the crypto market structure bill known as the Clarity Act, with bipartisan compromise proving difficult. Key hurdles include unresolved disputes over "yield" products and, more critically, the inclusion of strong ethics provisions for elected officials—a non-negotiable demand for many Democrats. While a compromise on yield was reached in May, securing only limited Democratic support in committee, the separate Senate Agriculture Committee version later passed with no Democratic votes due to the ethics impasse. As Republicans push for a full Senate vote in July, demands for ethics rules have expanded, and other contentious issues like developer protections and concerns from law enforcement and large banks further complicate negotiations. Despite consensus on the need for legislation, the path forward is unclear. Recent discussions between senators and White House officials aim to find acceptable ethics language. Some lawmakers question whether a compromise text can garner enough bipartisan support, with one Democrat stating the current proposal lacks the strong ethics provisions required for their vote. Potential short-term goals for the crypto community include symbolic Senate action before the August recess, a longer-term aim for passage by 2026, or establishing a detailed framework that addresses ethics and other compromises. The process remains arduous, relying on the traditional, vote-by-vote effort to build bipartisan support.

marsbit1h ago

The Clarity Act's Journey Through Congress: The Thorny Path of Bipartisan Compromise in the U.S.

marsbit1h ago

Trading

Spot

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

972 Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片