New Proposal Allows Satoshi Nakamoto to Prove Control Over Bitcoin Without Transferring Funds

Concerns over quantum computing have long been intertwined with the issue of Satoshi Nakamoto's dormant bitcoin holdings. Approximately 1.1 million bitcoin, valued at around $84 billion and attributed to the pseudonymous creator, remain vulnerable to theft should sufficiently powerful quantum computers emerge. This vulnerability also applies to millions of other bitcoin stored in older wallets with exposed public keys. The straightforward solution involves implementing a soft fork that would eventually disallow transactions from these legacy addresses, thus forcing holders to transfer their bitcoin to quantum-resistant formats before potential attackers can exploit their private keys. However, this approach poses a dilemma for long-dormant holders like Satoshi, who would need to publicly move their assets or risk losing access. To address this, Dan Robinson of Paradigm has put forth a proposal centered around Provable Address-Control Timestamps (PACTs), which allow holders to timestamp proof of ownership without revealing any information until they choose to spend their bitcoin. This is achieved by generating a unique cryptographic commitment using a random salt and BIP-322, then privately timestamping this commitment through OpenTimestamps. If a soft fork that freezes vulnerable coins is implemented, the protocol could include a mechanism for holders to submit a zero-knowledge proof (STARK proof) demonstrating that their commitment was made before the existence of quantum hardware, thereby allowing them to spend their coins without compromising their privacy. This approach also provides a rescue path for wallets generated through BIP-32, addressing a specific gap in the previously proposed BIP-361. Nonetheless, the implementation of PACTs would require significant infrastructure development, including the adoption of a STARK verification protocol through a separate soft fork. Ultimately, while PACTs offer a potential solution for protecting vulnerable bitcoin holdings, they do not resolve the issue if the owner, such as Satoshi, fails to create the necessary commitment, leaving the coins susceptible to either quantum theft or community-enforced freeze.