BIP-361, co-authored by Casa CTO Jameson Lopp and five others and introduced on April 14, 2026, goes further. It proposes a three-phase, five-year phase-out of legacy ECDSA and Schnorr signatures, ultimately freezing all wallets that have not migrated to quantum-resistant addresses . The proposal targets an estimated 1.7 million BTC in early wallets, including Satoshi's 1.1 million coins . Some estimates put the total vulnerable P2PK (Pay-to-Public-Key) supply as high as 5.6 to 6.9 million BTC — roughly a third of all Bitcoin ever mined .
Proponents argue it is safer to permanently lock these coins than to let a state actor with a sufficiently advanced quantum computer steal them first . The coins are often described as effectively "lost" already — many have not moved in over a decade — so freezing them is framed as causing no real economic harm while preventing a catastrophic supply shock if stolen.
The "No freeze" camp — immutability first.
Opponents argue that forcibly freezing coins — especially those of Bitcoin's anonymous creator — represents a fundamental violation of Bitcoin's core principle that no entity can censor, seize, or freeze transactions . They see any such action as a dangerous precedent that could later be expanded to freeze other coins. Critics contend that a freeze would undermine trust in Bitcoin's fixed supply and sound-money properties, effectively proving that Bitcoin's rules can be changed retroactively by developer and miner consensus . The proposal has been described as "the most controversial discussion in cryptocurrency" and a "governance test Bitcoin has never passed" . Some critics labeled BIP-361 as "authoritarian confiscation," though Lopp responded that he would rather freeze the coins than see them stolen .
The developmental middle path — BIP-360.
BIP-360, introduced earlier in 2026, takes a less aggressive approach. It proposes a new quantum-resistant output type called Pay-to-Merkle-Root (P2MR) that removes Taproot's key-path spend vulnerability and provides a voluntary migration pathway for holders — without freezing anyone's coins . This represents a middle path: upgrade the cryptography but preserve opt-in choice.
The debate is no longer theoretical. Developers and security experts believe a sufficiently powerful quantum computer could break Bitcoin's ECDSA cryptography within a foreseeable timeframe, possibly 5 to 10 years . The network transition to post-quantum signatures would itself take years to design, test, and deploy.
The dormant coin time bomb. Satoshi's coins — and roughly 5.6 million other BTC in legacy P2PK addresses — have their public keys visible on the blockchain, making them immediately vulnerable to a quantum attack once capable hardware exists . An attacker wouldn't need to guess private keys; they would simply compute them from the exposed public key using Shor's algorithm. This creates a race: either the network migrates first and freezes unmoved coins, or quantum attackers claim them.
No known owner to act. Satoshi has not moved any of their coins in over a decade and is widely assumed to be deceased or permanently inactive. Even if alive, they have no mechanism to prove ownership without exposing themselves. This means Satoshi's 1.1 million BTC will almost certainly never self-migrate, making them the focal point of the freeze debate . A Google study has indicated that by 2029, cybercriminals could potentially use advanced quantum computing methods to access Satoshi's wallets in as little as nine minutes .
Market stability risk. The sudden theft or release of 1.1 million BTC (roughly 5% of total supply) by a quantum attacker would devastate Bitcoin's price and credibility. Preemptive freezing is framed as a lesser evil compared to that outcome .
Both BIP-361 and CZ's proposal are still in early, unofficial stages — BIP-361 is a draft proposal in Bitcoin's improvement repository, while CZ has explicitly said his idea is a theoretical question, not an active protocol change . Implementing either would require a contentious network fork or supermajority consensus, and there is no clear resolution as of late June 2026.
Ultimately, the debate is a foundational tension between preventive security (freeze unclaimed coins before quantum thieves can steal them) and immutability (no entity should have the power to freeze anyone's coins, ever). How — or whether — the Bitcoin community resolves this may define the network's governance for decades to come.