New Proposal Offers Bitcoin Holders a Way to Prove Control Without Exposing Themselves
The issue of quantum computing has long been a concern for Bitcoin, with millions of coins in old wallets with exposed public keys at risk of being stolen by powerful quantum computers, including the 1.1 million coins attributed to Satoshi Nakamoto, currently valued at around $84 billion. A proposed soft fork, or upgrade to the existing network rules, would stop allowing transactions from these legacy address types, forcing holders to move to quantum-safe formats before attackers can derive their private keys. However, this proposal created a new problem, as holders like Satoshi would have to publicly move their coins or risk losing access to them. A new proposal by Dan Robinson, a general partner at Paradigm, offers a way around this trade-off through the concept of Provable Address-Control Timestamps, or PACTs. This involves generating a proof of ownership and timestamping it without revealing any information to the public until the owner needs to spend their coins. The proof is created using a random salt and BIP-322, a standard for signing messages from a Bitcoin address without spending from it, and is then bundled into an on-chain commitment and timestamped through OpenTimestamps. If Bitcoin later activates a soft fork that freezes quantum-vulnerable coins, the protocol could include a rescue path that accepts a STARK proof, showing the holder created their commitment before quantum hardware existed. The holder can then submit this proof when they want to spend their coins, and the network will release them without revealing any information about the address, amount, or original timestamp. This proposal addresses a specific gap in the previous proposal by including a rescue path for wallets derived through BIP-32, and also provides a way to make the debate around the freeze proposal less binary, allowing holders to protect themselves against quantum theft while also respecting dormant property rights.