A New Proposal Enables Bitcoin Holders to Prove Control Over Funds Without Transferring Them
Quantum computing has long posed a concern for Bitcoin, with a particular issue surrounding the creator, Satoshi Nakamoto. There are approximately 1.1 million bitcoins, valued around $84 billion, attributed to Satoshi, which could be at risk of theft if powerful quantum computers emerge. These funds are currently held in older wallets with exposed public keys. The obvious solution involves a soft fork that would eventually disallow transactions from these legacy addresses, forcing holders to move their funds to quantum-safe formats before potential attackers can access their private keys. However, this approach poses a different problem, as dormant holders like Satoshi would need to publicly move their funds or risk losing access to them. To address this issue, Dan Robinson from Paradigm has proposed a concept called Provable Address-Control Timestamps, or PACTs. This method involves generating a proof of ownership without spending any funds and creating a timestamped commitment that remains private until the holder needs to spend their coins. The holder creates a random salt and uses a standard for signing messages to produce a proof of ownership. This proof, along with the salt, is then bundled and timestamped on the blockchain. If Bitcoin were to activate a soft fork that freezes vulnerable coins, the protocol could include a rescue path that accepts a special proof, known as a STARK proof, which remains secure against quantum computers. This proof would show that the holder created their commitment before the existence of quantum hardware, allowing them to spend their coins without revealing any information about the original timestamp or address. PACTs also address a gap in a previous proposal by including a rescue path for wallets derived through a specific key generation standard. However, for PACTs to work, Bitcoin would need to adopt a STARK verification protocol, requiring a separate soft fork and broad community consensus. The verification infrastructure is not currently available in Bitcoin and would require substantial new developments, such as multisig wallets and complex scripts. Ultimately, the success of PACTs depends on the holders, including Satoshi, taking proactive steps to protect their funds. If Satoshi is no longer active, no PACT can be created, leaving the coins vulnerable to potential quantum theft or community freeze.