New Quantum Proposal Offers Satoshi Nakamoto a Discreet Way to Verify Control Over Bitcoin

Concerns about quantum computing have long been intertwined with the issue of Satoshi Nakamoto's involvement. Millions of bitcoins, including approximately 1.1 million attributed to Satoshi, are stored in outdated wallets with exposed public keys, making them susceptible to theft by powerful quantum computers. The obvious solution is a soft fork that would eventually disallow transactions from these legacy addresses, forcing holders to transfer their assets to quantum-resistant formats before potential attackers can derive their private keys. Prominent developer Jameson Lopp, along with five other developers, proposed a plan in mid-April through BIP-361 to phase out quantum-vulnerable addresses over a five-year period, freezing any coins that fail to migrate. However, this proposal created a new issue: Satoshi and other dormant holders would have to publicly reveal themselves or risk losing access to their assets. Dan Robinson, a general partner at Paradigm, has introduced an alternative solution called Provable Address-Control Timestamps, or PACTs, which would allow holders to timestamp proof of ownership without moving their coins. The process involves generating a random salt and using BIP-322 to produce a proof of ownership, which is then bundled into an on-chain commitment and timestamped through OpenTimestamps. If Bitcoin implements a soft fork that freezes quantum-vulnerable coins, the protocol could include a rescue path that accepts a STARK proof, showing the holder created their commitment before quantum hardware existed. This solution addresses a specific gap in BIP-361 by including a rescue path for wallets derived through BIP-32. However, it requires Bitcoin to adopt a STARK verification protocol, which would need a separate soft fork with broad community consensus. The verification infrastructure does not currently exist in Bitcoin and would require substantial new development. Ultimately, the proposal offers a way to make the BIP-361 debate less binary, providing a choice between protecting against quantum theft and respecting dormant property rights, but it remains uncertain whether Satoshi will utilize this solution.