Written by: Clow
A zero-knowledge proof tool can help your Bitcoin evade a quantum attack in 243 milliseconds. But Satoshi's 1.1 million? Beyond saving.
It's not that quantum computers aren't powerful enough; it's that they haven't arrived yet, and the Bitcoin community is already at war.
Project Eleven just released a zero-knowledge proof recovery tool that allows modern wallet holders to safely migrate their assets before a quantum attack arrives. Running a benchmark test on an M5 chip MacBook Air, proof generation took 243 ms, verification 40 ms, with a peak memory usage of 2.1 GB. Fast, lightweight, elegant.
But this solution has a fundamental flaw: it only works for HD wallets created after 2012.
Old coins from before 2012, including the roughly 1.1 million Bitcoin mined by Satoshi, are scattered across about 22,000 P2PK addresses, each containing about 50 BTC. These addresses have no parent key, no mnemonic seed, no derivation path on which to build a zero-knowledge proof. Cryptographically, they are dead ends.
So the real question has never been "When will quantum computers arrive?" but rather "What should we do about these 1.1 million old coins?"
The answer to this question lies not in cryptography, but in politics.
01 Who Can Save Themselves, Who is Sentenced to Death
To understand this crisis, one must first grasp a key fact: not all Bitcoin is equally vulnerable.
On-chain assets can be roughly categorized into three tiers based on the exposure level of their public keys.
The safest are hashed unspent addresses, where the public key is hidden behind a hash. Quantum computers cannot touch these, accounting for over 65% of the circulating supply.
The middle tier consists of modern addresses with exposed public keys, permanently recorded on-chain due to address reuse or Taproot design, totaling approximately 4.5 to 5.2 million BTC.
The most dangerous are early P2PK addresses, where the public key is written directly into the transaction script, amounting to about 1.7 to 1.9 million coins.
The middle tier is salvageable. Project Eleven's tool is precisely designed for them.
The principle is called "signature uplifting," proposed by researchers Or Sattath and Shai Wyborski in 2023. Shor's algorithm can crack elliptic curve signatures but is powerless against hash functions.
The private keys for child addresses in modern HD wallets are all derived from a master key via HMAC-SHA512 hashing. Even if a quantum computer deduces the private key of a child address, it cannot bypass the hash barrier to reverse-engineer upwards.
Wallet holders only need to prove they control a parent key upstream in the derivation path, generate a zero-knowledge proof, bind it to a quantum-resistant address, and complete the migration. The master private key and mnemonic remain unexposed, and the proof is verifiable on-chain.
But pre-2012 old coins lack this "key tree." During Satoshi's active period from 2009 to 2010, Bitcoin wallets generated addresses completely randomly each time, independent of one another.
No parent-child hierarchy, no master key, no BIP-39 mnemonic. Cryptographically, Project Eleven's solution is completely ineffective for them.
1.7 million Bitcoin are stranded beyond the self-rescue path, blocked by a technical dividing line drawn in 2012.
02 Four Plans, Four Kinds of Doom
Problems that technology cannot solve can only be handed over to politics. Four paths lie before the community, each leading to some form of disaster.
First: Do nothing, let liquidation happen. Strictly adhere to "private key equals ownership," whoever gets a quantum computer first takes the coins. Sounds purest, carries the heaviest cost.
1.7 million Bitcoin, long considered "permanently lost" by the market, would suddenly flood the secondary market, equivalent to magically adding 8% to 9% to the circulating supply. The "digital gold" narrative would be shaken by the actual transfer of underlying property rights.
Second: Force a freeze. BIP-361 proposes prohibiting new funds from being sent to vulnerable addresses starting in year three after activation, and completely invalidating the spending power of traditional signatures in year five. Unmigrated coins are permanently locked.
Economically, this is actively destroying 1.7 million Bitcoin, creating a permanent deflation. But the community's reaction is straightforward: To prevent assets from being stolen, you decide to confiscate users' money first?
When protocol developer Mark Erhardt shared this proposal on social media, the comments section was scathing.
Third: "Hourglass" throttling. Developer Hunter Beast proposed a compromise, acknowledging the possibility of old coins being stolen but setting extremely low spending limits for P2PK addresses.
A maximum of one P2PK spend per block confirmed, with a single transaction limit of 1 BTC. Even if all 1.1 million of Satoshi's coins were controlled by a quantum hacker, liquidation would be stretched over a century.
Attackers seeking to cash out would have to fiercely compete in the fee market, with those fees ultimately flowing to miners, becoming a long-term subsidy for network security.
Fourth: Forced redistribution. The most radical option. Through a hard fork, "nationalize" the ownerless old coins and distribute them proportionally to active holders who have migrated to quantum-resistant addresses.
The total supply remains 21 million, but the ledger's promise is directly overturned. The outcome is almost predictable: community schism, multiple "legitimate chains" running in parallel, catastrophic valuation divergence.
Cardano founder Charles Hoskinson's criticism of BIP-361 hits the nail on the head: This isn't a soft fork; it's a hard fork.
Any plan that tries to force a freeze on early assets by setting a deadline is a trampling of Bitcoin's property rights principle. BIP-361 co-author Jameson Lopp also admits the proposal is more like a "draft emergency backup plan," not the final answer.
The irony is that all four plans aim to protect Bitcoin's value, yet each one undermines what it seeks to protect. Letting theft happen destroys value storage, forced freezing destroys property rights commitment, throttling legitimizes theft, redistribution destroys ledger immutability.
This isn't a technical puzzle; it's a political dilemma with no right answer.
03 The Market Has Already Started Voting
Most investors still treat the quantum threat as a distant problem of "when will the hardware be ready."
But the market is already pricing it in.
In January 2026, Jefferies announced clearing 10% of the Bitcoin holdings from its pension model portfolio.
The strategist was clear: The reason for clearing wasn't that quantum computers already exist, but the governance uncertainty the Bitcoin community displayed regarding "how to handle early vulnerable coins."
This is the real expectation gap. While physicists are still wrestling with error-correcting logical qubits in labs, Wall Street is already discounting governance risk.
For institutional capital seeking legal certainty, the logic is simple: If Satoshi's coins can be forcibly frozen by code, then any coin can be deprived by consensus in the future.
The hidden risk of "harvest now, decrypt later" cannot be ignored either. The blockchain ledger is public; attackers are already downloading and storing the entire Bitcoin ledger.
Once a practical quantum computer emerges, they won't need to connect to the network; they can crack those old wallets with exposed public keys offline. This delayed-attack vector makes the governance game even more urgent.
The variance in how different institutions count vulnerable Bitcoin is also noteworthy. BIP-361 claims over 34% of the supply has exposed public keys; Citibank's figure is 25% to 37%; Glassnode estimates about 30%; Talos's full-ledger scan gives 34.5%. Whichever number you take, it means at least a quarter of Bitcoin is under long-term quantum threat.
Furthermore, Project Eleven's tool is currently just an unaudited early prototype, supporting only three wallet types, and still requires highly contentious consensus rule changes before going live on mainnet. It's premature to treat it as a readily available emergency exit.
Returning to the fundamental question: How can Bitcoin complete the liquidation of a historical technological break without undermining its own property rights principles?
No one has the answer. Quantum computers haven't arrived yet, but the crisis of faith is already here.







