For years, developers have warned that advances in quantum computing could eventually threaten the cryptography that protects Bitcoin. Although that threat is not yet a reality, a new proposal suggests the network should begin preparing long before quantum computers become powerful enough to exploit vulnerable wallets.
Known as Bitcoin Improvement Proposal (BIP) 361, the draft proposal introduces a long-term migration plan that would eventually phase out Bitcoin’s legacy cryptographic signatures and replace them with quantum-resistant alternatives. If adopted, it would become one of the most significant security upgrades ever proposed for the Bitcoin network.
What is quantum computing, and why are Bitcoin developers concerned?
Quantum computing is a new type of computing technology that processes information very differently from today’s computers. Instead of solving problems one calculation at a time, quantum computers use the principles of quantum mechanics to perform many calculations simultaneously, making them significantly more powerful for certain tasks. Although the technology is still developing, researchers believe future quantum computers could eventually solve mathematical problems that would take today’s most advanced computers thousands or even millions of years to complete.
That possibility has caught the attention of Bitcoin developers because the network relies on cryptography to keep users’ funds secure. If quantum computers become powerful enough, they could eventually break some of the cryptographic methods that protect Bitcoin wallets, allowing attackers to gain access to funds stored in vulnerable addresses.
Today, Bitcoin relies on two digital signature schemes,ECDSA and Schnorr,to prove ownership of coins and authorise transactions. These cryptographic systems are considered secure against today’s computers.
Quantum computers, however, operate very differently from classical computers. Researchers believe that sufficiently powerful quantum machines could eventually use Shor’s algorithm to derive private keys from exposed public keys, allowing attackers to steal Bitcoin from vulnerable wallets. While experts disagree on when quantum computers will become powerful enough to pose this risk, governments and technology companies have already begun preparing for the transition to post-quantum cryptography.
The proposal notes that more than 34% of all Bitcoin is currently held in addresses whose public keys have already been exposed on the blockchain, making those coins potential targets if cryptographically relevant quantum computers become a reality.
What BIP-361 proposes
Authored by Jameson Lopp, Christian Papathanasiou, Ian Smith, Joe Ross, Steve Vaile and Pierre-Luc Dallaire-Demers, BIP-361 is titled “Post Quantum Migration and Legacy Signature Sunset.” It builds on earlier work toward introducing quantum-resistant Bitcoin address types and proposes a phased transition rather than an immediate network change.
The proposal contains three main phases.
Phase A would begin after quantum-resistant address types become available on Bitcoin. During this stage, users would no longer be able to send newly created Bitcoin to addresses that rely on legacy ECDSA or Schnorr signatures. Instead, all new payments would be directed to post-quantum addresses, encouraging gradual migration across the network.
Phase B would take effect after a publicly announced transition period of roughly five years. At that point, Bitcoin’s consensus rules would reject spending transactions signed with the old cryptographic methods. Any Bitcoin still stored in quantum-vulnerable addresses would effectively become frozen until a secure recovery method exists.
The proposal also discusses a possible Phase C, although this remains under research. Developers are considering a future recovery mechanism that could allow legitimate owners to reclaim frozen coins using quantum-safe cryptographic proofs, potentially linked to a wallet’s recovery seed. However, this idea has not yet been specified in a separate proposal.
Why is the proposal generating debate?
Although the proposal is intended to strengthen Bitcoin’s long-term security, it has already sparked debate within the developer community.
Supporters argue that introducing a clear migration deadline gives wallet providers, exchanges and users enough time to upgrade while protecting the network before quantum computers become a genuine threat.
Critics, however, question whether freezing unmigrated coins is the right approach. Some developers argue that users could permanently lose access to their Bitcoin if they fail to migrate in time, while others believe activation should not depend on predictions about when quantum computing will become practical. The proposal is expected to undergo extensive technical review before any decision is made.
What happens next?
It is important to note that BIP-361 is only a draft proposal. Publishing a Bitcoin Improvement Proposal does not mean it will automatically become part of the Bitcoin protocol.
Before any changes could be activated, the proposal would need to undergo peer review, community discussion, testing and broad consensus among Bitcoin developers, miners, node operators and the wider ecosystem. There is currently no activation date for BIP-361.
Even so, the proposal marks one of the clearest signs yet that Bitcoin’s developer community is preparing for a post-quantum future. Whether or not BIP-361 is adopted in its current form, it has already pushed one of the network’s biggest long-term security questions into the spotlight: how to protect Bitcoin before quantum computing becomes a real-world threat rather than a theoretical one.

