New Quantum Proposal Provides Satoshi Nakamoto with a Secure Way to Verify Control Over Bitcoin Without Transferring Funds

Concerns surrounding the impact of quantum computing on Bitcoin have long been intertwined with the enigma of Satoshi Nakamoto. Millions of bitcoins, including approximately 1.1 million attributed to Satoshi, currently valued at around $84 billion, are stored in old wallets with exposed public keys, rendering them susceptible to theft by sufficiently powerful quantum computers. The obvious solution involves implementing a soft fork that would eventually disallow transactions from these legacy addresses, compelling holders to migrate to quantum-resistant formats before potential attackers can deduce their private keys. Prominent developer Jameson Lopp, alongside five other developers, proposed this approach in mid-April through BIP-361, outlining a five-year timeline for phasing out quantum-vulnerable addresses and freezing unmigrated coins. However, this proposal introduces a new dilemma: dormant holders like Satoshi would need to publicly reactivate their assets or risk losing access. Dan Robinson, a general partner at Paradigm, has introduced an alternative solution centered around Provable Address-Control Timestamps (PACTs), which allows holders to generate a proof of ownership without moving their coins, using a random salt and BIP-322 to create a unique, unguessable cryptographic commitment. This proof, bundled with the salt, is then timestamped via OpenTimestamps, a service that anchors data to the Bitcoin blockchain, all while keeping the salt, proof, and timestamp files private. If Bitcoin implements a soft fork freezing quantum-vulnerable coins, the protocol could incorporate a rescue mechanism accepting a STARK proof, demonstrating the holder created their commitment prior to the existence of quantum hardware, thereby enabling the holder to spend their coins without revealing the original address, amount, or timestamp. These PACTs address a specific gap in BIP-361 by providing a rescue path for wallets derived through BIP-32, although they require the eventual adoption of a STARK verification protocol in Bitcoin, necessitating a separate soft fork with broad community consensus. The necessity for substantial new infrastructure, including multisig wallets and hardware wallet support, poses a significant constraint. Ultimately, the protocol's effectiveness in protecting Satoshi's coins hinges on whether he or the current controller of those keys creates the commitment, as no PACT can be retroactively established if Satoshi is indeed no longer involved. What PACTs offer is a nuanced approach to the BIP-361 debate, mitigating the binary choice between safeguarding against quantum theft and respecting the rights of dormant holders.