Web Analytics
Bitcoinist
2026-05-04 11:30:24

New Bitcoin Quantum Proposal Gives Satoshi A Silent Ownership Path

Paradigm researcher Dan Robinson has proposed a new mechanism that could let long-dormant Bitcoin holders, including Satoshi Nakamoto, preserve a future claim to their coins if Bitcoin ever has to restrict spending from quantum-vulnerable addresses. The proposal, called Provable Address-Control Timestamps, or PACTs, is designed to let holders prove they controlled an address before cryptographically relevant quantum computers emerged, without moving their BTC today. The idea addresses one of the most sensitive questions in Bitcoin’s post-quantum debate: what happens to early coins sitting in addresses with exposed public keys. In a May 1 research post titled “PACTs: Protecting Your Bitcoin From a Quantum Sunset,” Robinson warned that “an attacker with a powerful enough quantum computer could steal hundreds of billions of dollars of Bitcoin.” He argued that the community may one day choose to “sunset” the ability to spend from addresses whose public keys have already been revealed onchain. PACTs Offer Satoshi A Quiet Bitcoin Rescue Option That path would be controversial. Bitcoin’s culture strongly protects the right of holders to remain inactive for years, even decades. But Robinson frames the issue as a dilemma with no clean default if cryptographically relevant quantum computers, or CRQCs, become unavoidable. “If an upgrade sunsets support for those addresses, these dormant holders will be forced to publicly move their coins or let them be frozen. But if quantum computers are coming and we don’t sunset those addresses, those holders will be forced to move those coins or let them be stolen. Either path seems to force long-time holders to give up some of their privacy by publicly moving their funds.” The problem is especially acute for Satoshi-era Bitcoin. Robinson notes that wallets believed to belong to Satoshi Nakamoto hold around 1.1 million BTC, worth more than $75 billion based on the figures used in the post. Many of those coins predate modern deterministic wallet standards such as BIP-32, making them harder to rescue through some of the zero-knowledge proof paths already discussed in relation to BIP-361 . BIP-361, in draft form, has proposed a soft fork that would eventually sunset spending from addresses with exposed public keys. Rescue paths have also been discussed for certain wallet types, particularly where a holder can prove knowledge of a parent key that a quantum attacker would not have. Robinson’s point is that this does not solve the earliest address problem. PACTs attempt to create that missing escape hatch. The proposal would let holders make a private, off-chain commitment today showing that they controlled a vulnerable UTXO before any quantum attacker could derive the relevant private key. They would do so by generating a secret salt, producing a BIP-322 full message signing proof for the vulnerable scriptPubKey, hashing that proof into a commitment, and timestamping the commitment through OpenTimestamps. The holder would not broadcast a Bitcoin transaction. They would store the salt, the BIP-322 proof, and the OpenTimestamps proof file as a recovery artifact. The timestamp itself would reveal nothing about the address, public key, control proof, salt, or coins involved. “This does not require Bitcoin to decide today whether a sunset is necessary,” Robinson wrote. “It only gives holders a silent, no-onchain-cost way to preserve evidence that may become useful if such a sunset is ever adopted.” If a future Bitcoin fork did freeze or sunset ECDSA spending from exposed public keys, a holder could later provide a post-quantum-secure proof, such as a STARK, showing that the timestamped commitment existed before a cutoff date and that it corresponds to a valid control proof for the frozen UTXO. Crucially, the salt and control proof would remain hidden, and the rescue proof would be tied to a specific transaction to prevent replay or redirection. Robinson is careful to present PACTs as an illustrative design rather than a formal Bitcoin proposal. The commitment phase relies on existing primitives, but the rescue phase would require “substantial new plumbing” inside Bitcoin’s protocol. There is also no guarantee that Bitcoin would ever adopt such a rescue path, or even choose to sunset quantum-unsafe keys at all. Still, the proposal is notable because it separates two decisions that are often bundled together: whether Bitcoin should ever impose a quantum sunset, and whether holders can begin preserving evidence of legitimate ownership before that debate is resolved. For early holders, that distinction matters. PACTs would not eliminate the quantum problem, but they could give dormant wallets a way to prepare without revealing themselves first. “Bitcoin is about preparing for the long term, hedging for tail risks, and self-reliance,” Robinson concluded. “If there is a way to plant a seed now that will give us an advantage over cryptographic attackers in a possible future, then long-term holders should take it.” At press time, BTC traded at $79,690.

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.