New Quantum Proposal Offers a Solution for Bitcoin's Satoshi Problem

Concerns over quantum computing have long plagued Bitcoin, with millions of coins in old wallets vulnerable to theft if powerful quantum computers emerge. This includes the approximately 1.1 million bitcoin attributed to Satoshi Nakamoto, worth around $84 billion. A proposed soft fork, or upgrade to existing network rules, could phase out legacy address types, forcing holders to move to quantum-safe formats. However, this would require long-dormant holders like Satoshi to publicly reveal their presence or risk losing access to their assets. Dan Robinson, a general partner at Paradigm, has proposed a solution called Provable Address-Control Timestamps, or PACTs. This involves generating a proof of ownership and timestamping it without revealing any information to the public until the owner needs to spend their coins. The proof is created using a random salt and BIP-322, a standard for signing messages from a Bitcoin address without spending from it. The salt and proof are then bundled into an on-chain commitment and timestamped through OpenTimestamps. If Bitcoin later activates a soft fork that freezes quantum-vulnerable coins, the protocol could include a rescue path that accepts a STARK proof, showing the holder created their commitment before quantum hardware existed. The holder submits this proof when they want to spend, and the network releases the coins without revealing any information about the original timestamp. PACTs address a specific gap in the proposed soft fork by including a rescue path for wallets derived through BIP-32. However, the verification infrastructure for PACTs does not currently exist in Bitcoin and would require substantial new development, including multisig wallets, complex scripts, and hardware wallet support. Ultimately, PACTs offer a way to make the debate over freezing outdated addresses less binary, but their effectiveness depends on whether holders like Satoshi take advantage of them.