New Quantum Proposal for Bitcoin Offers a Solution for Proving Control Without Moving Funds
Concerns about quantum computing have long plagued Bitcoin, with a particular challenge being the vast amount of bitcoin held in outdated wallets with exposed public keys, vulnerable to potential theft by powerful quantum computers. This includes approximately 1.1 million bitcoin attributed to Bitcoin's pseudonymous creator, Satoshi Nakamoto, valued at around $84 billion. The obvious solution is a soft fork that would eventually disallow transactions from these legacy addresses, forcing holders to move their assets to quantum-resistant formats before attackers can derive their private keys. However, a recent proposal by prominent developer Jameson Lopp and others, known as BIP-361, which aims to phase out quantum-vulnerable addresses over a five-year timeline, poses a new problem: dormant holders like Satoshi would have to publicly move their assets or risk losing access to them. To address this issue, Dan Robinson from Paradigm has proposed a concept called Provable Address-Control Timestamps (PACTs), which enables holders to generate a proof of ownership without spending their coins. This is achieved by creating a random salt and using BIP-322 to produce a proof of ownership, which is then timestamped through OpenTimestamps and kept private. If Bitcoin implements a soft fork that freezes quantum-vulnerable coins, the protocol could include a rescue path that accepts a STARK proof, showing the holder created their commitment before quantum hardware existed, thereby allowing them to spend their coins without revealing any information about the original timestamp. This solution also addresses a gap in BIP-361 by providing a rescue path for wallets derived through BIP-32. However, the implementation of PACTs requires Bitcoin to adopt a STARK verification protocol, which would need a separate soft fork with broad community consensus and substantial new infrastructure. Ultimately, PACTs offer a way to make the BIP-361 debate less binary, providing a choice between protecting against quantum theft and respecting dormant property rights, but the question remains whether Satoshi or other dormant holders will utilize this solution.