New Quantum Proposal Offers Solution for Bitcoin's Satoshi Conundrum
The Bitcoin network has long been concerned about the potential risks posed by quantum computing, particularly with regards to the vast amounts of bitcoin held in older wallets with exposed public keys. This includes the approximately 1.1 million bitcoin linked to the pseudonymous creator Satoshi Nakamoto, currently valued at around $84 billion. A potential solution involves implementing a soft fork that would phase out the use of legacy address types, thereby forcing holders to transition to quantum-resistant formats before their private keys can be compromised. However, this approach poses a significant challenge for long-dormant holders like Satoshi, who would need to publicly reclaim their assets or risk losing access to them. In response, Dan Robinson of Paradigm has introduced a proposal for Provable Address-Control Timestamps, or PACTs, which would enable holders to generate a private proof of ownership and timestamp it on the blockchain without revealing any sensitive information. This approach relies on the use of a random salt and BIP-322 to produce a proof of ownership, which is then bundled with the salt and timestamped using OpenTimestamps. If a soft fork is implemented that freezes quantum-vulnerable coins, the protocol could include a rescue path that accepts a zero-knowledge proof, demonstrating that the holder created their commitment prior to the existence of quantum hardware. The holder can then submit this proof when they wish to spend their coins, and the network will release the funds without revealing any information about the original address, amount, or timestamp. While this proposal addresses a key gap in the existing BIP-361 proposal, it requires the adoption of a STARK verification protocol, which would necessitate a separate soft fork and broad community consensus. The implementation of PACTs would also require significant infrastructure development, including multisig wallets, complex scripts, and hardware wallet support. Ultimately, the success of this proposal hinges on whether Satoshi, or the current controller of the keys, creates the necessary commitment. If Satoshi is indeed gone, no PACT can be created retroactively, leaving the coins vulnerable to quantum theft or community freeze. Nevertheless, PACTs offer a potential solution to the BIP-361 debate, providing a more nuanced approach that balances the need to protect against quantum threats with the need to respect dormant property rights.