A draft plan designed to protect Bitcoin from future advances in quantum computing has taken the discussion in a different direction. The discussion is no longer about encryption, but governance. Can a system that is set up to withstand change be agreed upon before significant upgrades are needed?
The issue was brought back to the spotlight this week when Cardano co-founder Charles Hoskinson argued that Bitcoin’s biggest problem is not quantum computing itself, but whether it can proactively organize a response before a threat is identified.
Hoskinson says Bitcoin may struggle with correction
In a conversation on The Starting Block on Friday, Hoskinson noted that quantum computing could threaten Bitcoin’s status as the world’s top digital currency, currently worth about $1.3 trillion, if the network fails to reach agreement on an upgrade.
“The problem with Bitcoin is that time is frozen. It’s very difficult to change anything,” he said, according to The Block.
According to Hoskinson, Cardano’s governance model is in stark contrast to Bitcoin’s. “If you want to migrate, you can vote and there may be on-chain functionality to do that,” he said.
This process has been previously described by Cardano. In June, elected delegates rejected a summit funding proposal from the Cardano Foundation on the grounds that it did not have the necessary two-thirds majority. Bitcoin does not have such a voting system, which means that the differences between the currencies are currently causing debate on the issue.
BIP-361 forces gradual migration
The proposal on which the conversation is based is BIP-361, titled “Post-Quantum Transition and Legacy Signature Sunset.” The proposal was developed by Jameson Lopp, a founding member of Casa, and five co-authors who created the transition plan from Bitcoin’s signature schemes (currently ECDSA and Schnorr).
According to the proposal, as of March 1, 2026, more than 34% of all Bitcoins will have their public keys published on-chain, making them theoretically at risk of being stolen if a sufficiently powerful quantum computer emerges.
Migration occurs in several stages. Stage A will begin approximately three years after the rollout begins and will prohibit users from sending money to legacy addresses that are at risk. Stage B will arrive two years after Stage A, and users will no longer be able to use unmigrated coins. Nevertheless, the coins will continue to be kept in the vault by the user, but will no longer be available for use.
Freeze proposal sparks backlash
The final step proved to be the most controversial part of the proposal.
Developer forums and critics of X have called the plan “authoritarian and confiscatory,” while some have called it “predatory,” IG reported, according to Yahoo Finance.
Mr. Lopp did not take the opportunity to say that BIP-361 is now a final product. “This is not a specification, it is not something proposed for activation. It is a rough idea of a contingency plan that requires further research and development,” Ropp said in April, BigGo Finance reported, stressing that he was interested in investigating the issue rather than turning a blind eye to it.
The road to recovery remains early and incomplete
Developers began exploring ways to minimize the impact of the proposal.
The prototype, created by Project 11 Security Group and Jim Posen of Binius, uses a special technique called zero-knowledge proofs that allows owners of modern seed-based wallets to prove ownership and recover frozen funds. This solution addresses one of the major concerns about this proposal, which is that people will permanently lose access to the affected coins.
However, this technology is only applicable to wallets that comply with the BIP-32 standard, introduced in 2012, and does not include older technologies such as payment output to public keys. This will cover approximately 1.1 million BTC (equivalent to approximately $84 billion) believed to belong to Satoshi Nakamoto. Another proposal from a paradigm called PACT has a potential solution, as long as those with the keys act aggressively enough by the migration deadline.
As Cryptopolitan previously reported, Bitcoin developers have already largely avoided discussions about the need for post-quantum security. With the integration of BIP-360 and its Pay-to-Merkle-Root output type, the focus has switched to its implementation. The question that remains is whether miners, exchanges, custodians, and users can come together to orchestrate a transition before the advent of quantum computing makes it necessary.
What’s next post-quantum?
Paradigm general partner Dan Robinson proposed a research proposal called Provable Address-Control Timestamps (PACT) that would allow Bitcoin holders to privately timestamp proof of ownership in their wallets before quantum computers become a reality.
If Bitcoin later adopts a quantum transition such as BIP-361, users who created PACT could potentially recover frozen coins using quantum-resistant STARK zero-knowledge proofs, but implementing this proposal would require additional protocol changes and broad community consensus.
Some researchers and developers have proposed alternative recovery mechanisms, including zero-knowledge proof approaches and other cryptographic techniques, but none of these are currently part of BIP-361. Any recovery mechanism will require unique proposals and broad community consensus.
Since BIP-361 is still a draft, its transition rules, schedule, and treatment of legacy coins are all subject to change prior to future implementation.

