A draft plan developed to protect Bitcoin against future quantum computing advancements has turned the debate in a different direction. The discussion is no longer related to cryptography, but governance. Is a system that was set up to resist changes capable of agreeing on an important upgrade before it is imperative?
This week, the issue got renewed attention when Cardano co-founder Charles Hoskinson claimed that the biggest problem for Bitcoin is not quantum computing in itself but the ability to organize a response ahead of time before the threat is confirmed.
During a conversation on The Starting Block on Friday, Hoskinson pointed out that quantum computing could pose a threat to Bitcoin’s position as the world’s top digital currency, currently valued at about $1.3 trillion, should the network be unable to come to an agreement on an upgrade.
“The issue with Bitcoin is it’s frozen in time. It’s very difficult to change anything,” he said, according to The Block.
According to Hoskinson, Cardano’s governance model stands in stark contrast to that of Bitcoin. “If there needs to be a migration, we can have a vote, and then there could be an onchain function to do that,” he said.
The process has been previously illustrated by Cardano. In June, elected delegates turned down a Summit funding plan from the Cardano Foundation on account of it not obtaining the needed two-thirds majority. Bitcoin lacks any systems of voting of that sort, which means that the discrepancies between the currencies are causing discussions on the matter now.
The proposal that the conversation is based on is BIP-361 titled, “Post Quantum Migration and Legacy Signature Sunset”. The proposal was formulated by Jameson Lopp, a founding member of Casa, and five co-authors who created a plan for transitioning from Bitcoin’s signature methods, currently being ECDSA and Schnorr.
As per the proposal, as of March 1, 2026, over 34% of all Bitcoin had revealed a public key on-chain and, thus, they are theoretically at risk to be stolen, should the sufficiently powerful quantum computers emerge.
The migration will take place in several stages. Stage A will begin approximately three years after the start of the implementation, prohibiting users from transferring money to legacy addresses that are in danger. Stage B will come two years after stage A and will prevent users from using coins that have not been migrated. Nevertheless, the coins will still be held by users in their safes but will no longer be usable.
The last step became the most controversial part of the proposal.
IG reports that critics on developer forums and X called the plan “authoritarian and confiscatory,” while others dubbed it “predatory,” according to Yahoo Finance.
Lopp did not take the opportunity to say that BIP-361 is currently a final product. “It isn’t a spec, nor is it proposed for activation. It’s a rough idea for a contingency plan that needs more R&D,” Lopp stated in April as reported by BigGo Finance, emphasizing that he was more interested in investigating the subject than in turning a blind eye to the problem.
Developers have initiated the search for methods to minimize the effects of the proposal.
The prototype created by Project Eleven security group and Jim Posen of Binius uses a special technique called zero-knowledge proofs that allows the owners of modern wallets based on seeds to prove ownership and retrieve frozen funds. This solution responds to one of the major concerns about the proposal, that it will leave people without access to their affected coins forever.
Yet, this technique can be applied only to wallets complying with the BIP-32 standard that was introduced in 2012 and does not include older technologies like pay-to-pub-key outputs, which would cover the approximately 1.1 million BTC believed to belong to Satoshi Nakamoto, equivalent to about $84 billion. Another proposal by Paradigm called PACTs has a potential solution as long as the people who have the keys are proactive enough before the migration deadline.
As reported earlier by Cryptopolitan, Bitcoin’s developers have already largely moved past the debate about the necessity of post-quantum security. With BIP-360 and its Pay-to-Merkle-Root output type merged, the focus has now switched to its implementation. The question that remains is whether miners, exchanges, custodians and users can come together and coordinate their migration before the advent of quantum computing makes it necessary.
Paradigm General Partner Dan Robinson has proposed “Provable Address-Control Timestamps” (PACTs), a research proposal that would let Bitcoin holders privately timestamp proof of wallet ownership before quantum computers become practical.
If Bitcoin later adopts a quantum migration such as BIP-361, users who created a PACT could potentially recover frozen coins using quantum-resistant STARK zero-knowledge proofs, although the proposal would require additional protocol changes and broad community consensus before it could be implemented.
Some researchers and developers have suggested alternative recovery mechanisms, including zero-knowledge proof approaches and other cryptographic techniques, but none of these are part of BIP-361 today. Any recovery mechanism would require its own proposal and broad community consensus.
Because BIP-361 is still a draft, its migration rules, timelines, and treatment of legacy coins could all change before any future implementation.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.