{"id":89415,"date":"2026-05-04T11:31:36","date_gmt":"2026-05-04T11:31:36","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=89415"},"modified":"2026-05-04T11:31:36","modified_gmt":"2026-05-04T11:31:36","slug":"new-bitcoin-quantum-proposal-gives-satoshi-a-silent-ownership-path","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=89415","title":{"rendered":"New Bitcoin Quantum Proposal Gives Satoshi A Silent Ownership Path"},"content":{"rendered":"<div>\n<p>Paradigm researcher Dan Robinson has proposed a new mechanism that could let long-dormant Bitcoin holders, including Satoshi Nakamoto, preserve a future claim to their coins if Bitcoin ever has to restrict spending from quantum-vulnerable addresses. The proposal, called Provable Address-Control Timestamps, or PACTs, is designed to let holders prove they controlled an address before cryptographically relevant quantum computers emerged, without moving their BTC today.<\/p>\n<p>The <a href=\"https:\/\/x.com\/danrobinson\/status\/2050229837768663232\" target=\"_blank\" rel=\"noopener nofollow\">idea<\/a> addresses one of the most sensitive questions in Bitcoin\u2019s post-quantum debate: what happens to early coins sitting in addresses with exposed public keys. In a May 1 research post titled \u201cPACTs: Protecting Your Bitcoin From a Quantum Sunset,\u201d Robinson warned that \u201can attacker with a powerful enough quantum computer could steal hundreds of billions of dollars of Bitcoin.\u201d He argued that the community may one day choose to \u201csunset\u201d the ability to spend from addresses whose public keys have already been revealed onchain.<\/p>\n<h2>PACTs Offer Satoshi A Quiet Bitcoin Rescue Option<\/h2>\n<p>That path would be controversial. Bitcoin\u2019s culture strongly protects the right of holders to remain inactive for years, even decades. But Robinson frames the issue as a dilemma with no clean default if cryptographically relevant quantum computers, or CRQCs, become unavoidable.<\/p>\n<p>\u201cIf an upgrade sunsets support for those addresses, these dormant holders will be forced to publicly move their coins or let them be frozen. But if <a href=\"https:\/\/bitcoinist.com\/bitcoin-ethereum-post-quantum-plan-now-coinbase\/\" target=\"_blank\" rel=\"noopener \">quantum computers are coming<\/a> and we don\u2019t sunset those addresses, those holders will be forced to move those coins or let them be stolen. Either path seems to force long-time holders to give up some of their privacy by publicly moving their funds.\u201d<\/p>\n<p>The problem is especially acute for Satoshi-era Bitcoin. Robinson notes that wallets believed to belong to Satoshi Nakamoto hold around 1.1 million BTC, worth more than $75 billion based on the figures used in the post. Many of those coins predate modern deterministic wallet standards such as BIP-32, making them harder to rescue through some of the zero-knowledge proof paths already discussed in relation to <a href=\"https:\/\/bitcoinist.com\/bitcoin-faces-quantum-risk-new-proposal-could-lock-vulnerable-coins\/\" target=\"_blank\" rel=\"noopener \">BIP-361<\/a>.<\/p>\n<p>BIP-361, in draft form, has proposed a soft fork that would eventually sunset spending from addresses with exposed public keys. Rescue paths have also been discussed for certain wallet types, particularly where a holder can prove knowledge of a parent key that a quantum attacker would not have. Robinson\u2019s point is that this does not solve the earliest address problem.<\/p>\n<p>PACTs attempt to create that missing escape hatch. The proposal would let holders make a private, off-chain commitment today showing that they controlled a vulnerable UTXO before any quantum attacker could derive the relevant private key. They would do so by generating a secret salt, producing a BIP-322 full message signing proof for the vulnerable scriptPubKey, hashing that proof into a commitment, and timestamping the commitment through OpenTimestamps.<\/p>\n<p>The holder would not broadcast a Bitcoin transaction. They would store the salt, the BIP-322 proof, and the OpenTimestamps proof file as a recovery artifact. The timestamp itself would reveal nothing about the address, public key, control proof, salt, or coins involved.<\/p>\n<p>\u201cThis does not require Bitcoin to decide today whether a sunset is necessary,\u201d Robinson wrote. \u201cIt only gives holders a silent, no-onchain-cost way to preserve evidence that may become useful if such a sunset is ever adopted.\u201d<\/p>\n<p>If a future Bitcoin fork did freeze or sunset ECDSA spending from exposed public keys, a holder could later provide a post-quantum-secure proof, such as a STARK, showing that the timestamped commitment existed before a cutoff date and that it corresponds to a valid control proof for the frozen UTXO. Crucially, the salt and control proof would remain hidden, and the rescue proof would be tied to a specific transaction to prevent replay or redirection.<\/p>\n<p>Robinson is careful to present PACTs as an illustrative design rather than a formal Bitcoin proposal. The commitment phase relies on existing primitives, but the rescue phase would require \u201csubstantial new plumbing\u201d inside Bitcoin\u2019s protocol. There is also no guarantee that Bitcoin would ever adopt such a rescue path, or even choose to sunset quantum-unsafe keys at all.<\/p>\n<p>Still, the proposal is notable because it separates two decisions that are often bundled together: whether Bitcoin should ever impose a quantum sunset, and whether holders can begin preserving evidence of legitimate ownership before that debate is resolved. For early holders, that distinction matters. PACTs would not eliminate the quantum problem, but they could give <a href=\"https:\/\/bitcoinist.com\/cardano-founder-bitcoin-entered-shitcoin-land\/\" target=\"_blank\" rel=\"noopener \">dormant wallets<\/a> a way to prepare without revealing themselves first.<\/p>\n<p>\u201cBitcoin is about preparing for the long term, hedging for tail risks, and self-reliance,\u201d Robinson concluded. \u201cIf there is a way to plant a seed now that will give us an advantage over cryptographic attackers in a possible future, then long-term holders should take it.\u201d<\/p>\n<p>At press time, BTC traded at $79,690.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"size-full wp-image-679031\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?resize=1024%2C502\" alt=\"Bitcoin price chart\" width=\"1024\" height=\"502\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=3628 3628w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=980 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=130 130w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=1536 1536w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=2048 2048w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=750 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=1140 1140w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/05\/BTCUSDT_2026-05-04_11-07-38.png?w=3000 3000w\" sizes=\"(max-width: 1000px) 100vw, 1000px\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Paradigm researcher Dan Robinson has proposed a new mechanism that could let long-dormant Bitcoin holders, including Satoshi Nakamoto, preserve a future claim to their coins if Bitcoin ever has to restrict spending from quantum-vulnerable addresses. The proposal, called Provable Address-Control Timestamps, or PACTs, is designed to let holders prove they controlled an address before cryptographically [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-89415","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/89415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=89415"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/89415\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=89415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=89415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=89415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}