Around 1.1 million bitcoin are attributed to Bitcoin’s inventor, Satoshi Nakamoto. At Sunday morning’s price of $83,045 that is a good $91 billion, or roughly 81.5 billion euros, spread across early addresses from the network’s first year. The coins are regarded as untouched. They sit nonetheless at the centre of one of the fiercest debates among Bitcoin developers: a draft numbered BIP-361 would freeze them before a quantum computer can one day steal them.
The question of what happens if Satoshi returns is as old as Bitcoin itself. New is the question of whether his coins could be moved at all once the network hardens itself against quantum attacks. There is a practical lesson in that for your own addresses too.
How many bitcoin belong to Satoshi Nakamoto?
Nobody knows exactly, because Satoshi never disclosed his addresses. The usual figure goes back to the computer scientist Sergio Demian Lerner. In 2013 he found a pattern in the early blocks of the Bitcoin blockchain that points to a single, very early miner. Later analyses of this so-called Patoshi pattern arrive at around 1.1 million bitcoin. That is about 5.5 percent of the 20.10 million bitcoin in circulation today.
Satoshi published the white paper on October 31, 2008 and started the network on January 3, 2009. He withdrew in the spring of 2011. The coins attributed to him sit in an early address format called pay-to-public-key, P2PK for short, and it is precisely that format which makes them a special case today.

The chart puts the scale in order. Satoshi’s estimated holding is only a part of what lies exposed: according to the figures in the BIP-361 draft, more than 34 percent of all bitcoin had a public key visible on the blockchain on March 1, 2026.
Why quantum computers endanger Satoshi’s bitcoin
Bitcoin protects balances with digital signatures. Whoever knows the private key can spend, and today’s computers cannot work back from the public key to the private one. A sufficiently large quantum computer could do exactly that. When that point arrives is open. The authors of BIP-361 point to roadmaps that consider such a machine possible as early as 2027 to 2030, while other experts reckon on considerably more time.
Only coins whose public key is already visible are at risk. At the P2PK addresses from Satoshi’s day it has stood in the blockchain from the outset. With more modern formats it appears only once an address has been spent from. The draft is explicit on this point: should quantum computers continue their development, the keys of all P2PK outputs would be found with near certainty and the balances stolen.
What BIP-361 proposes: freezing instead of letting them be stolen
BIP-361 carries the title “Post Quantum Migration and Legacy Signature Sunset” and has stood since February 2026 as a draft in the official register of Bitcoin improvement proposals. Its lead author is the developer Jameson Lopp. The plan presupposes that Bitcoin first gains a quantum-safe address type, for instance through BIP-360, also at draft stage. After that it would proceed in two stages:
- Phase A: around three years after activation, 160,000 blocks later to be precise, the network stops accepting payments to vulnerable addresses. New money then flows only into quantum-safe formats.
- Phase B: five years after activation, on a date announced long in advance, spending with the old signatures is possible only through a quantum-safe rescue procedure.
That rescue procedure relies on the true owner knowing something an attacker does not. Anyone using a modern wallet with a seed phrase can demonstrate knowledge of the original key, which an attacker does not hold. For P2PK addresses that advantage does not exist, as the authors themselves concede. On today’s reading, Satoshi’s coins would therefore stay locked permanently, unless a further proposal creates a separate, slow spending route for such legacy holdings.

The authors invoke Satoshi himself. He wrote in the Bitcoin forum in 2010 that lost coins only make everyone else’s coins slightly more valuable, and that one could regard them as a donation to all. Frozen coins tighten supply; stolen ones would enlarge it at a stroke.
The case against freezing
The resistance is fundamental. Bitcoin promises that nobody can lock up someone else’s coins, and that is exactly what BIP-361 would do, albeit after years of notice. Critics hold it to be a breach of the property promise, no matter whose coins they are. Even Lopp does not like his own proposal. In April he called it a crude contingency plan and said, according to CoinDesk: “I wrote it because I like the alternative even less.”
This is not decided in any committee. A soft fork needs broad assent from miners, node operators, wallets and exchanges. Both drafts are far from that; BIP-360 and BIP-361 carry the status “Draft” to this day.
What a return by Satoshi would mean for the bitcoin price
Were Satoshi’s coins to move before such a cut-off date, the market would at first not know who was behind it: Satoshi himself, an heir, or an attacker with a quantum computer. The mere possibility that a holding of a good $91 billion might come to market would be likely to set off considerable pressure, without a single coin being sold. A definitive freeze would take that risk out of the calculation. Supporters of a US bill that would lock up state-held bitcoin for 20 years argue along similar lines: what cannot be sold does not weigh on the price.
Which of your own bitcoin addresses would be affected
For the vast majority of investors in Germany this is no acute danger today. It is, though, a good occasion to look at your own addresses:
- Coins on an exchange: here the provider decides which address formats it holds them in. A later move to quantum-safe addresses would be up to them.
- Your own wallet with a seed phrase: modern wallets generate a new address for every payment. With addresses beginning “1”, “3” or “bc1q”, the public key lies exposed only once you have spent from them. Not reusing addresses is therefore a simple rule of protection.
- Taproot addresses with “bc1p”: here a key is visible from the outset, and BIP-361 counts them explicitly among the vulnerable formats. That is no reason for haste today, but it is a point on the list for a later move.
- Very old wallets: anyone holding coins from the earliest years should check which format they sit in. A move to a new address of your own is not a sale and triggers no tax in Germany.
If you hold your own coins, the hardware wallet comparison lists devices that manage a seed phrase and fresh addresses cleanly. If you are only getting started, the comparison for buying bitcoin lists vetted providers.





Be the first to comment