Wire
04:22ZPRESSTVItaly debates US use of its bases for potential strikes on Iran04:16ZTASNIMNEWSMeteorological Organization: Rain, Thunderstorms Forecast for Iran's Southeast04:06ZHONGKONGFPHong Kong workers report AI reduced pay, raised workloads without easing jobs04:01ZDDGEOPOLITMajor Fire Breaks Out at Chabad Pilgrimage Site in Ukraine04:00ZPRESSTVIsraeli military deploys five additional companies in West Bank near Jenin04:00ZTASNIMNEWSIsraeli military attacks western Dara'a, Syria - Syrian media reports03:59ZDDGEOPOLITRussia destroys several gas stations in Valka, Kharkiv oblast03:58ZJAHANTASNIIsraeli military patrol enters Al-Makar area near Quneitra, Syria
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusCrypto

A quantum deadline lands on Satoshi's coins

A new proposal would freeze vulnerable legacy Bitcoin addresses within five years and stop new coins from flowing into them. The hard part is what to do with the roughly 1.7 million BTC already sitting in wallets that cannot sign with today's quantum-safe algorithms.

Graphic placeholder image featuring a "CRYPTO" header under a "MONEXUS NEWS" banner, with text noting "No photograph on file."
Graphic placeholder image featuring a "CRYPTO" header under a "MONEXUS NEWS" banner, with text noting "No photograph on file." Monexus News

A draft Bitcoin Improvement Proposal published on 19 July 2026 sets a five-year clock on the oldest wallets in the network. BIP-361, written under the working title "Post Quantum Migration and Legacy Signature Sunset," would, in its first phase, refuse to relay transactions that move coins into addresses secured only by legacy signature schemes. Five years later, those signatures would stop being valid at the consensus layer altogether. The proposal lands while Bitcoin trades through one of its loudest debates about who counts as an owner and what counts as safe.

The political fight is not the cryptography. It is the roughly 1.7 million BTC sitting in addresses whose owners have not moved funds since 2010 or earlier, including coins attributed to Bitcoin's pseudonymous creator. A sunset clause does not simply retire an algorithm. It retires the right of a class of holders to move their coins under the network's own rules. Whoever controls that clock controls a one-time redistribution of property rights worth, at recent prints, more than $100 billion.

What the draft actually says

BIP-361 proposes two stages. The first is a relay-side filter: nodes would drop any transaction sending BTC to an address whose script uses only pre-quantum signature schemes, meaning the older pay-to-public-key format and the legacy ECDSA path inside SegWit outputs. New coins would still be allowed to leave those addresses, but they could not land in them. The second stage is a hard fork roughly five years after activation that invalidates legacy signatures outright. From that block height, any unspent output signed with ECDSA over secp256k1 becomes inert: still recorded on the ledger, no longer spendable.

The framing inside the BIP text is technical, but the practical effect is a forced migration window. Holders of legacy coins have until the fork to move funds into quantum-resistant addresses, typically understood to mean schemes such as ML-DSA (formerly CRYSTALS-Dilithium) or SLH-DSA (SPHINCS+) that the U.S. National Institute of Standards and Technology has already standardised. After the fork, the migration door closes.

The proposal does not yet name a specific quantum computer, a specific attack budget, or a specific date. It commits to a clock rather than to a threat. That choice is the political one.

Where the cold coins sit

The address classes affected by BIP-361 are not abstract. Pay-to-public-key outputs, in which the public key sits directly in the locking script, became common in Bitcoin's first two years before the network shifted to hash-locked addresses for efficiency. Roughly a million BTC sits in that early format. A separate, smaller cohort of legacy ECDSA coins lives inside SegWit addresses where the public key was revealed by a prior spend. Neither cohort can produce a post-quantum signature today, and neither cohort can be retrofitted without an active owner willing to move the funds.

Analysts who track these dormant stashes, including Glassnode and Chainalysis in earlier public estimates, put the total in the range of 1.7 million BTC, with a long tail concentrated in a few thousand addresses holding 1,000 BTC or more. The single most-cited account is the so-called Satoshi hoard, a set of addresses mined in 2009 and 2010 that have never moved. Whether those addresses are still controlled by their original miner, by an early collaborator, or by nobody at all is the kind of question BIP-361 forces into daylight, because the only way to keep them spendable after the fork is to move them first.

The case for waiting

The strongest counter-argument is that the threat is not here. Today's quantum hardware is measured in hundreds of noisy physical qubits, far short of the millions of error-corrected logical qubits that cryptographers estimate would be required to break secp256k1 inside any meaningful time budget. The U.S. National Institute of Standards and Technology, which has been standardising post-quantum algorithms since 2022, has framed migration as a multi-decade programme aimed first at systems whose compromise has shorter shelf lives than Bitcoin's UTXO set. A five-year sunset, on that read, is a solution to a problem that arrives in 2035 at the earliest, paid for by holders who can least afford a forced move.

There is also a procedural objection. Hard forks on Bitcoin have historically required overwhelming community consensus, because a chain that loses a meaningful slice of economic weight stops being Bitcoin in any meaningful sense. BIP-361 is published, not yet merged. It has no signalling mechanism, no reference implementation, and no commit from any of the four or five core teams that would actually have to ship it. Treating the draft as policy, rather than as one contributor's opening position, is itself a form of misreading.

The case for acting now

The counter to the wait-and-see camp is that cryptography timelines and hardware timelines have repeatedly surprised the people who set them. The original SHA-1 deprecation debate ran for more than a decade and ended faster than most institutions were ready for once practical collision attacks arrived. RSA-1024 was retired under similar pressure. Bitcoin's threat model is unusual only in the scale of the assets at stake: a successful break would not leak one secret key, it would drain a billion-dollar address class in public view.

There is also a question of coordination cost. The longer a migration is delayed, the larger the population of legacy addresses grows, because every newly created wallet that fails to adopt post-quantum schemes adds to the future migration queue. A 2031 sunset compresses the planning window and forces wallet vendors, exchanges, and self-custody users to ship code on a known timetable. The same logic drove the 2021 Taproot upgrade, which gave the network a clean forward step in part by forcing the ecosystem to commit to it.

What this publication reads between the lines

BIP-361 is best understood as a marker, not a mandate. It tells the market that a credible contributor has decided the post-quantum conversation belongs on the main timeline rather than in a research branch, and that the conversation will centre on dormant coins rather than on algorithm choice. The interesting question for the next twelve months is whether other BIP editors pick up the thread, whether wallet vendors begin to ship optional post-quantum address paths, and whether institutional buyers, who have spent 2026 arguing that Bitcoin is a corporate treasury asset, demand clarity on the migration roadmap before they add to their stacks.

Saylor's recent framing of Bitcoin as a "global monetary network" with corporate adoption as "necessary, inevitable, and welcome" sits in obvious tension with a five-year sunset clause that would force every treasury desk to coordinate a key-rotation exercise. Markets can price either message. They cannot easily price both at once.

What remains unresolved

The draft does not specify what happens to coins that are unmoved at fork time. The choice between a true burn, a recoverable escrow, or a multi-signature recovery path run by the community is the part of the proposal that will draw the loudest objection. Nor does it address quantum-vulnerable outputs whose public keys have already been revealed, which is a larger and less politically charged class than the early-format coins. And the draft is silent on miner signalling, on activation thresholds, and on the role of the BIP process itself in resolving a dispute of this scale.

This desk note: Monexus treats BIP-361 as a published proposal with technical and political weight, not as adopted policy. The wire coverage surfaced the headline mechanics; the structural read here adds the migration-coordination frame and the dormant-coin stakes, which the original Telegram reports did not address.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/cointelegraph
  • https://t.me/cointelegraph
  • https://t.me/cointelegraph
Intelligence ThreadFollow on terminal ↗
© 2026 Monexus Media · AI-native reporting from public-source material