A New Proposal Offers Bitcoin Holders a Way to Prove Ownership Without Revealing Their Identity

Concerns surrounding the impact of quantum computing on Bitcoin have long been intertwined with the enigma of Satoshi Nakamoto, the cryptocurrency's pseudonymous creator. Approximately 1.1 million Bitcoins, valued at around $84 billion and attributed to Nakamoto, are currently stored in older wallets with exposed public keys, making them potentially vulnerable to quantum computer attacks. The most straightforward solution is to implement a soft fork that would gradually phase out the use of these legacy addresses, compelling holders to transition to quantum-resistant formats before potential attackers can exploit them. However, this approach poses a significant challenge for dormant holders like Nakamoto, as they would need to publicly acknowledge their assets or risk losing access to them. In response, Dan Robinson of Paradigm has proposed an alternative solution called Provable Address-Control Timestamps (PACTs), which enables holders to generate a proof of ownership without actually moving their coins. This involves creating a unique cryptographic commitment using a random salt and the BIP-322 standard for signing messages from a Bitcoin address. The commitment is then timestamped and stored privately through OpenTimestamps, a service that anchors data onto the Bitcoin blockchain. If Bitcoin were to adopt a soft fork that freezes quantum-vulnerable coins, holders could use a STARK proof to demonstrate that they created their commitment before the advent of quantum computers, thereby securing their assets without revealing sensitive information. While PACTs address a critical gap in the existing proposal by providing a rescue path for wallets derived through the BIP-32 standard, they also require the eventual adoption of a STARK verification protocol, which would necessitate a separate soft fork and broad community consensus. The implementation of PACTs would necessitate substantial infrastructure development, including multisig wallets and hardware wallet support. Ultimately, the success of PACTs in protecting assets like Nakamoto's depends on the willingness of holders to create these commitments, as the protocol cannot retroactively safeguard coins if the owner is no longer active or able to make the commitment.