Why 6.7 Million Coins Could Be Frozen Forever

Paxful
Coinmama


There is a proposal circulating among Bitcoin developers that would, if adopted, make roughly a third of all Bitcoin permanently unspendable. Not stolen. Not confiscated by a government. Simply frozen by the rules of the network itself, including an estimated 1.7 million coins widely believed to belong to Bitcoin’s anonymous creator.

The proposal is not a fringe idea. It was authored by a group including Jameson Lopp, a co-founder of the custody firm Casa and one of the most established security researchers in the field. It has a formal number in Bitcoin’s official proposal system. And it exists because of a threat that has moved, over the past eighteen months, from a distant theoretical concern to something developers now treat as a scheduling problem.

This piece explains what is actually being proposed, why the threat is considered credible, and why the proposed cure is more contested than the disease.

What is being proposed, in plain terms?

Bitcoin developers publish formal change proposals in a numbered system. Each one is called a Bitcoin Improvement Proposal, abbreviated BIP. A number does not mean a proposal is approved or scheduled. It means the idea has been documented in a standard format so the community can examine it. Most BIPs are never adopted.

bybit

Two of them matter here, and they work in sequence.

  • The first, BIP-360, creates a new type of Bitcoin address that a quantum computer could not break. This is the constructive half. It adds an option without removing anything, and it is comparatively uncontroversial.
  • The second, BIP-361, formally titled “Post Quantum Migration and Legacy Signature Sunset,” is the contested half. It sets a deadline. Coins that have not moved to the new quantum-safe address type by that deadline would become unspendable. The proposal was assigned its number on 11 February 2026 and remains in draft status. No activation has occurred, and no date has been fixed.

The critical detail, and the one most coverage skips: BIP-361 cannot function until BIP-360 is activated first. The deadline clock only begins after the safe destination exists.

Why can a quantum computer steal Bitcoin at all?

To follow the argument, one piece of technical vocabulary is unavoidable.

Every $Bitcoin wallet holds two mathematically linked numbers. The private key is the secret that authorizes spending. The public key is derived from it and can be shared safely. The relationship runs one way: deriving the public key from the private key is trivial, while working backwards from the public key to the private key would take a conventional computer longer than the age of the universe.

That one-way property is what secures Bitcoin. It is also precisely what a sufficiently powerful quantum computer would dismantle. Quantum machines can run algorithms that make this reverse calculation practical rather than impossible.

The vulnerability therefore depends on a single question: has the public key ever been revealed on the blockchain?

For most modern addresses, it has not. The address you share is a scrambled shortened version of the public key, and the key itself only becomes visible at the moment you spend from that address. But two categories of coin are permanently exposed. The first is Bitcoin’s oldest address format, used in 2009 and 2010, which published the raw public key directly on the chain. The second is any address that has been used to spend and then received funds again, a habit known as address reuse, which is still common and which permanently exposes the key.

There is a further problem that makes detection unreliable. An attacker who broke a key would not need to spend immediately. The proposal’s authors describe a scenario in which private keys are computed quietly and funds are drained gradually over weeks or months, specifically to avoid alerting anyone. Under that scenario, the industry might not learn a quantum attack had begun until long after it did.

Buy and Sell cryptos using the best crypto exchanges. Check out our comparisons hereBuy and Sell cryptos using the best crypto exchanges. Check out our comparisons here

How much Bitcoin is actually exposed?

The proposal’s own figure is that as of 1 March 2026, more than 34 percent of all Bitcoin had revealed a public key on the blockchain. A Google-commissioned study puts the total at approximately 6.7 million BTC sitting in quantum-vulnerable addresses.

Within that total, roughly 1.7 million coins sit in the oldest address format from Bitcoin’s first two years. These are widely believed to include Satoshi Nakamoto’s holdings. They have never moved. If the keys are lost, as is generally assumed, no migration is possible, because there is nobody left to perform it.

At current prices, the exposed supply is worth somewhere in the region of $425 billion. That figure is what turns a cryptography question into a market question. A successful attack would not only transfer those coins to an attacker. It would introduce enormous unexpected supply and, more damaging still, demonstrate that Bitcoin’s security guarantee had failed.

How close is the threat, realistically?

No machine capable of this exists today. That point deserves emphasis, because the topic attracts considerable exaggeration.

What has changed is the shape of the estimates. McKinsey’s research places the arrival of a cryptographically relevant quantum computer, meaning one actually powerful enough to break this class of encryption, as early as 2027 to 2030. Expert surveys put the probability of arrival before the late 2030s at above 50 percent.

The more significant shift is in software rather than hardware. Google’s security researchers have tracked improvements in quantum algorithms of up to twentyfold, which lowers the amount of physical hardware an attacker would need. In other words, the target is moving closer even in periods when quantum computers themselves are not improving quickly.

The standards bodies have already responded. The US National Institute of Standards and Technology finalized three post-quantum cryptography standards in 2024, giving the industry approved replacement algorithms to build on. Bitcoin’s difficulty is not the absence of a solution. It is that no major blockchain has completed a migration of this kind, and Bitcoin’s governance is deliberately designed to make change slow.

What would the migration actually involve?

BIP-361 sets out three phases. The following table reflects the proposal text directly.

Phase

What happens Timing

A

Funds can no longer be sent to old vulnerable addresses. They may only be sent from old addresses to new quantum-safe ones. Existing coins remain spendable. 160,000 blocks, roughly 3 years, after activation

B

Signatures from the old system stop being valid. Coins that have not migrated can no longer be spent at all. 2 years after Phase A, so roughly 5 years after activation

C

A proposed recovery route for frozen coins, using a cryptographic proof that you hold the original wallet recovery phrase, without revealing it. Undefined, pending further research

Phase C is the part that determines how severe this actually is, and it is also the least developed. If it works, holders with their recovery phrase could unlock frozen funds even after the deadline, and the freeze becomes a strong inconvenience rather than a permanent loss. If it does not, Phase B is final. The proposal explicitly lists Phase C as pending research, demand, and consensus.

One activation detail is worth noting for anyone tracking timelines. The proposal specifies that miner signalling would not begin before 1 January 2027, and would require 90 percent support. That is a deliberately high bar. For comparison, the BIP-110 proposal that reached its signalling window this August has attracted under 2 percent miner support.

Why is this so controversial?

Because it collides directly with Bitcoin’s central promise.

The phrase “not your keys, not your coins” expresses the idea that possession of the private key is absolute and that no authority can interfere with your funds. BIP-361 proposes that the network itself decide certain coins can no longer move. Critics argue this is confiscation in effect even if not in form, since the coins are not transferred to anyone else, and that the precedent is more dangerous than the threat it addresses. If the network can render one category of output unspendable for a good reason, the mechanism exists to do so again for a worse one.

There is also a legitimate question of authority. Who determines what counts as vulnerable, and on what timetable? Bitcoin has no chief executive and no foundation empowered to ship a consensus change. The last one, Taproot, activated in November 2021, and nothing has changed the rules since.

This is why the debate has shifted from cryptography to governance. The underlying question is whether a system engineered specifically to resist change can agree on a significant upgrade before it becomes urgent.

Ledger, Trezor, or BitBox? Don't make mistakes with your backup – find the test winner for your crypto assets nowLedger, Trezor, or BitBox? Don’t make mistakes with your backup – find the test winner for your crypto assets now

What is the case in favour?

Supporters frame the choice as one between two bad outcomes rather than between a bad outcome and a clean one.

Their central argument is that doing nothing does not preserve the vulnerable coins. It hands them to whoever reaches quantum capability first. The proposal describes three possible approaches: allow anyone to take vulnerable coins, allow them to be taken gradually, or allow nobody to take them. There is no fourth option in which the coins simply remain safe. Freezing, on this reading, preserves ownership rather than removing it, particularly if the Phase C recovery route is built.

A second argument concerns attacker motivation. An economically motivated attacker would want to stay hidden and extract value quietly. A politically motivated one might simply want to destroy confidence in Bitcoin. Since it is impossible to know which you face in advance, the authors argue the defensive position has to be established well before any attack.

A third argument is about time. Coordinating wallet providers, exchanges, hardware manufacturers and custodians has historically taken years in Bitcoin. A fixed, published deadline is what converts a collective problem everyone can defer into a private one each participant has to solve. That is the proposal’s actual mechanism: it does not force anyone to do anything today, but it removes the option of indefinite delay.

What does this mean for Bitcoin holders now?

Nothing is required today. BIP-361 is a draft. It has not been activated, it depends on a prerequisite that has not been activated either, and signalling could not begin before 2027 under its own terms. Anyone claiming holders must act immediately is misinformed or selling something.

That said, the direction of travel is clear enough to justify a few observations.

Coins held in modern address formats that have never been spent from are not currently exposed, because the public key has not been published. Address reuse is the practice that converts a safe address into an exposed one, and it remains a reasonable habit to avoid regardless of quantum considerations. Holders using custodial services or exchange-traded products face an institutional question rather than a personal one, since the migration burden would fall on the custodian.

The more consequential point is for the long term. Any Bitcoin intended to sit untouched for a decade or more, including inheritance arrangements and long-dated corporate treasury positions, now carries a migration requirement that did not exist two years ago. Estate planning that assumes a seed phrase in a safe will remain sufficient indefinitely may need revisiting.

What should be watched next?

Three markers will indicate whether this moves from debate to implementation.

  • The first is BIP-360 progress, since nothing in BIP-361 can proceed without it. It has reached testnet implementation, which is a meaningful step but well short of activation.
  • The second is Phase C research. If a workable recovery mechanism is demonstrated, much of the opposition loses its strongest argument, because permanent loss becomes recoverable friction.
  • The third is the January 2027 signalling window written into the proposal, and specifically whether miner support approaches the 90 percent threshold. Recent Bitcoin governance offers little reason for optimism on that front.

The most likely outcome over the next two years is neither adoption nor rejection, but continued deadlock while the estimated arrival of quantum capability draws closer. That is an uncomfortable position, and it is the one Bitcoin currently occupies.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*