Quantum Computers Haven't Arrived Yet, But Satoshi's 1.1 Million Bitcoins Are Already a Problem

By: rootdata|2026/07/21 12:47:02

The answer to this question lies not in cryptography, but in politics.


Written by: Clow


A zero-knowledge proof tool can help your Bitcoin escape quantum attacks in just 243 milliseconds. But what about Satoshi's 1.1 million? There's no hope.


It's not that quantum computers aren't powerful enough; it's that they haven't arrived yet, and the Bitcoin community is already in conflict.


Project Eleven has just released a zero-knowledge proof recovery tool that allows modern wallet holders to safely migrate their assets before quantum attacks arrive. In a benchmark test on an M5 chip MacBook Air, it generated proofs in 243 milliseconds, verified in 40 milliseconds, with a peak memory usage of 2.1 GB. Fast, light, and elegant.


However, this solution has a significant flaw: it only works for HD wallets created after 2012.


Old coins created before 2012, including the approximately 1.1 million Bitcoins mined by Satoshi, are scattered across about 22,000 P2PK addresses, with each address holding about 50 BTC. These addresses lack parent keys, mnemonic phrases, or any derivation paths that could construct zero-knowledge proofs. Cryptographically, they are dead ends.


So the real question has never been "When will quantum computers arrive?" but rather, "What to do with these 1.1 million old coins?"


The answer to this question lies not in cryptography, but in politics.


01 Who Can Save Themselves, Who Is Sentenced to Death


To understand this crisis, one must first clarify one thing: not all Bitcoins are equally vulnerable.


On-chain assets can be roughly divided into three categories based on the exposure of their public keys.


The safest are unused addresses protected by hashes, where the public key is hidden behind the hash, making them impervious to quantum computers, accounting for over 65% of the total supply.


The middle category consists of modern addresses with exposed public keys, due to address reuse or Taproot design, with public keys permanently recorded on-chain, totaling about 4.5 to 5.2 million BTC.


The most dangerous are early P2PK addresses, where the public key is directly written into the transaction script, totaling about 1.7 to 1.9 million.


The middle category can be saved. Project Eleven's tool is designed specifically for them.


The principle is called "signature amplification," proposed by researchers Or Sattath and Shai Wyborski in 2023, where Shor's algorithm can crack elliptic curve signatures but is powerless against hash functions.


The private keys of sub-addresses in modern HD wallets are derived from the master key using HMAC-SHA512 hashing. Even if a quantum computer retrieves the private key of a sub-address, it cannot reverse-engineer it past the hash barrier.


Wallet holders only need to prove they possess the parent key upstream in the derivation path, generating a zero-knowledge proof linked to a quantum-resistant address to complete the migration. No exposure of the master private key, no exposure of the mnemonic phrase, verifiable on-chain.


But the old coins from before 2012 lack this "key tree." During Satoshi's active years from 2009 to 2010, Bitcoin wallets generated addresses completely randomly, independently of each other.


There are no parent-child hierarchies, no master keys, no BIP-39 mnemonic phrases. Logically, Project Eleven's solution is completely ineffective for them.


1.7 million Bitcoins are blocked from the self-rescue path by a technical dividing line drawn in 2012.


02 Four Solutions, Four Ways to Die


Problems that technology cannot solve must be handed over to politics. The community faces four paths, each leading to some form of disaster.


The first path: inaction, allowing liquidation. Strictly adhering to "private keys equal justice," whoever has a quantum computer takes it. It sounds the purest, but the cost is the highest.


1.7 million Bitcoins, deemed "permanently lost" by the market, suddenly flooding into the secondary market would equate to an increase of 8% to 9% in circulating supply. The narrative of "digital gold" would be shaken by the actual change of underlying property rights.


The second path: forced freezing. The BIP-361 proposal plans to prohibit new funds from being deposited into vulnerable addresses three years after activation and to completely abolish the spending power of traditional signatures in the fifth year. Unmigrated coins would be permanently locked.


Economically, this would mean actively destroying 1.7 million Bitcoins, creating a permanent deflationary event. But the community's reaction was direct: to prevent assets from being stolen, you decide to first help users confiscate their money?


Protocol developer Mark Erhardt faced a backlash when sharing this proposal on social media.


The third path: "hourglass" throttling. Developer Hunter Beast proposed a compromise, acknowledging the possibility that old coins could be stolen but setting a very low threshold for spending P2PK addresses.


Each block would confirm at most one P2PK expenditure, with a single transaction limit of 1 BTC. Even if all of Satoshi's 1.1 million coins were controlled by quantum hackers, selling them would take hundreds of years.


Attackers wishing to cash out would have to compete fiercely in the fee market, and this money would ultimately flow to miners, becoming a long-term subsidy for network security.


The fourth path: forced redistribution. The most radical option. By hard forking to "nationalize" unclaimed old coins, redistributing them proportionally to active holders who migrate to quantum-resistant addresses.


The total supply would still be 21 million, but the ledger's commitments would be directly overturned. The result is almost predictable: community division, multiple "orthodox chains" running parallel, and catastrophic valuation divergence.


Charles Hoskinson, founder of Cardano, sharply criticized BIP-361: this is not a soft fork, this is a hard fork.


Any attempt to enforce a deadline to freeze early assets is a violation of Bitcoin's property principles. BIP-361 co-author Jameson Lopp also admitted that this proposal resembles an "emergency backup plan draft," not a final answer.


Ironically, all four proposals aim to protect Bitcoin's value, yet each one undermines what it seeks to protect. Allowing theft undermines value storage, forced freezing undermines property commitments, throttling acknowledges the legitimacy of theft, and redistribution undermines the immutability of the ledger.


This is not a technical question; it is a political question without a correct answer.


03 The Market Has Already Started Voting


Most investors still view the quantum threat as a long-term issue of "when will the hardware meet the standards."


But the market is already pricing it in.


In January 2026, Jefferies announced it had liquidated 10% of its Bitcoin holdings in its pension model portfolio.


The strategist made it clear: the reason for liquidation is not that quantum computers have already emerged, but that the Bitcoin community has shown governance uncertainty in "how to deal with early vulnerable coins."


This is the real expectation gap. Physicists are still battling error correction logic in laboratories, while Wall Street is already discounting governance risks.


For institutional capital seeking legal certainty, the logic is simple: if Satoshi's coins can be forcibly frozen by code, then any future coins can be deprived by consensus.


Also noteworthy is the latent risk of "harvesting now, decrypting later." The blockchain ledger is public, and attackers are currently downloading and storing the entire Bitcoin ledger.


Once practical quantum computers emerge, they won't need to access the network; they can crack those old wallets with exposed public keys offline. This delayed attack makes governance games more urgent.


The differing statistics on vulnerable Bitcoins from various institutions are also worth noting. The BIP-361 proposal claims that over 34% of the supply has exposed public keys, Citibank's figure is 25% to 37%, Glassnode estimates about 30%, and Talos's full ledger scan gives 34.5%. Regardless of which number is chosen, it means at least a quarter of Bitcoins are under long-term quantum threat.


Moreover, Project Eleven's tool is currently just an early prototype that hasn't undergone security audits, supporting only three types of wallets, and requires highly controversial consensus rule changes before going live. Treating it as an immediately available emergency channel is premature.


Returning to that fundamental question: how can Bitcoin complete a historical technological liquidation without undermining its own property principles?


No one has the answer. Quantum computers haven't arrived yet, but the crisis of faith has already begun.

-- Price

--

Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]