New Bitcoin Proposal Enables Satoshi Nakamoto to Prove Ownership Without Transferring Funds
The concern over quantum computing has long been intertwined with the enigma of Satoshi Nakamoto's bitcoin holdings. Millions of bitcoins, including the approximately 1.1 million attributed to Nakamoto, currently valued at around $84 billion, are at risk of being compromised by powerful quantum computers due to exposed public keys in outdated wallets. A potential solution involves a soft fork that would eventually render these legacy addresses obsolete, forcing holders to migrate to quantum-resistant formats before potential attackers can derive their private keys. Prominent developer Jameson Lopp, along with five other developers, proposed a solution in mid-April through BIP-361, which would phase out vulnerable addresses over a five-year period and freeze any coins that fail to migrate. However, this proposal creates a new dilemma: Satoshi and other dormant holders would need to publicly reclaim their assets or risk losing access to them. Dan Robinson, a general partner at Paradigm, has introduced a proposal that offers an alternative solution, revolving around the concept of Provable Address-Control Timestamps, or PACTs. The core idea is for holders to generate a proof of ownership at a specific date without revealing any information publicly until they need to spend their coins. To achieve this, a holder creates a random salt and uses BIP-322 to produce a proof of ownership, which is then bundled with the salt into an on-chain commitment and timestamped through OpenTimestamps. If Bitcoin implements a soft fork that freezes vulnerable coins, the protocol could include a rescue path that accepts a STARK proof, demonstrating that the holder created their commitment before the existence of quantum hardware. When the holder is ready to spend, they submit the proof, and the network releases the coins without revealing any information about the address, amount, or original timestamp. PACTs also address a specific gap in BIP-361 by providing a rescue path for wallets derived through BIP-32, which is not applicable to pre-2012 wallets, including most of Satoshi's known addresses. For PACTs to be effective, Bitcoin would need to adopt a STARK verification protocol, requiring a separate soft fork with broad community consensus and substantial new infrastructure. The protocol's effectiveness relies on the holder making the commitment, and if Satoshi is no longer involved, no PACT can be created retroactively, leaving the coins vulnerable to either quantum theft or community freeze. PACTs offer a way to make the BIP-361 debate less binary, providing an alternative to the choice between protecting against quantum theft and respecting dormant property rights. The question remains whether Satoshi will utilize this proposal.