Charles Hoskinson: Bitcoin's Quantum Solution Is a Hard Fork That Fails to Protect Satoshi's Coins

Earlier this week, Bitcoin's core developers suggested freezing 8 million coins as a defense mechanism against quantum attacks. However, Charles Hoskinson, the founder of Cardano, believes that this solution is still insufficient to protect the coins owned by Bitcoin's pseudonymous creator, Satoshi Nakamoto, as stated in a video posted on his YouTube channel. Hoskinson argues that the proposed defense against quantum computers, BIP-361, is both technically incorrect and structurally incapable of safeguarding the network's oldest coins, including the approximately 1 million bitcoin attributed to Satoshi Nakamoto. He asserts that BIP-361, which aims to phase out quantum-vulnerable bitcoin addresses, is being misrepresented as a soft fork when it would actually require a hard fork, as it would invalidate existing signature schemes that users are currently relying on. The distinction between a soft fork and a hard fork is crucial, as Bitcoin's development culture has historically opposed hard forks, viewing them as violations of the network's immutability. According to Hoskinson, the BIP-361 authors' characterization of the proposal as a soft fork is inaccurate. A soft fork tightens the rules, allowing old software to still function but not utilize new features, whereas a hard fork changes the rules fundamentally, causing old software to stop working entirely and resulting in a network split unless all users upgrade. BIP-361 proposes that users with frozen quantum-vulnerable funds could reclaim them by creating a zero-knowledge proof tied to their BIP-39 seed phrase, a standard for generating wallet keys from a recoverable phrase. Nevertheless, Hoskinson contends that this approach cannot rescue approximately 1.7 million bitcoin that predate BIP-39's introduction in 2013, including the roughly 1 million coins associated with Satoshi's early mining activity. These early coins were generated using a different key derivation method from the original Bitcoin wallet software, which relied on a local key pool rather than a deterministic seed. If the proposal is implemented in its current form, those coins would remain permanently frozen, regardless of whether their original owners attempt to migrate, as migration would require cryptographic proof that they are unable to provide. Jameson Lopp, the core developer who co-authored BIP-361, acknowledged that he does not like the proposal and hopes it never needs to be adopted, describing it as a rough idea for a contingency plan rather than a finalized specification. Lopp has argued that freezing dormant coins, which he estimates at 5.6 million bitcoin, would be preferable to allowing a future quantum attacker to recover and dump them on the market. Hoskinson's broader critique extends beyond the technical details, arguing that Bitcoin's lack of formal on-chain governance leaves the network unable to resolve these tradeoffs through a structured process, forcing contentious upgrades to be negotiated through developer mailing lists and social pressure.