Top cryptographers can't agree on Bitcoin's biggest quantum question
A Coinbase-backed cryptography panel says Bitcoin should prepare for quantum attacks now, but it won't choose whether vulnerable coins should later be frozen.
Intelligence analysis by GPT-5.4 Mini

A high-profile group of cryptographers says the technical work for post-quantum Bitcoin should start now, even though quantum computers are not an immediate threat. The unresolved fight is over whether millions of exposed coins, including many tied to early Bitcoin addresses and possibly Satoshi Nakamoto, should remain spendable or be frozen.
Bitcoin is like a treasure chest with some locks that might someday be easy for a super-powered computer to open. The experts agree the locks should be replaced soon, but they cannot agree on whether old locked chests should stay available or be sealed forever.
Analysis
What the panel says
A Coinbase-convened advisory council featuring cryptographers including Scott Aaronson, Dan Boneh, and Justin Drake says Bitcoin does not face a quantum threat today, and no one knows when that threat will arrive. Their main recommendation is simple: begin planning the technical migration to post-quantum signatures now instead of waiting for a countdown.
Why the debate is hard
The most difficult issue is not replacing Bitcoin’s current signature schemes, ECDSA and Schnorr. It is deciding what to do with coins that may never be moved. The article says about 1.7 million bitcoin sit in roughly 20,000 early pay-to-public-key addresses, which reveal public keys on-chain and would be exposed to a future quantum attacker. Many of those coins are believed to belong to Satoshi Nakamoto or to have lost keys. Another roughly 5 million bitcoin are exposed through address reuse, though most of those are thought to be active exchange holdings.
One camp wants a hard cutoff: after a deadline, unmigrated vulnerable coins would become unspendable. Supporters argue that leaving them live could let a future attacker, possibly a sanctioned state like North Korea, seize a huge stash and damage Bitcoin’s credibility. The opposing camp calls that confiscation and says it would violate Bitcoin’s property-rights ethos.
Proposals on the table
The report does not endorse one fix. It notes that several ideas could work together: Hourglass would limit how many vulnerable coins can move per block, BIP-361 would let holders prove ownership after the cutoff using quantum-resistant proofs, and PACTs would let owners make a private claim now and move funds later without revealing a key.
The council’s bottom line is that the community must decide the abandoned-coins question, but it should not delay engineering work or clear communication. The article frames this as a debate Bitcoin has not yet acted on, even as Ethereum has prepared for years.
Key points
- A Coinbase-convened cryptography panel says quantum computers are not an immediate threat, but Bitcoin should start preparing now.
- About 1.7 million bitcoin are said to sit in early address types that would be exposed to a future quantum attack.
- Another 5 million bitcoin are described as exposed through address reuse, though many are likely active exchange holdings.
- The main dispute is whether vulnerable unmigrated coins should later be frozen or left spendable.
- The panel declines to choose among proposals and says the community must decide, while engineering work should begin immediately.
If Bitcoin starts the technical migration early, the network could reduce the chance that quantum computers ever threaten user funds. Clear communication and compatible proposals could make the transition smoother and give holders time to adapt.
If the community delays, vulnerable coins could remain exposed for longer than necessary, including coins that may never be recoverable. A rushed or heavy-handed freeze of unmigrated coins could also trigger backlash over confiscation and weaken trust in Bitcoin’s rules.



