Bitcoin Improvement Proposal 361, titled “Post Quantum Migration and Legacy Signature Sunset,” was first assigned on February 11, 2026 and updated on July 20, 2026. Jameson Lopp authored the proposal with Christian Papathanasiou, Ian Smith, Joe Ross, Steve Vaile and Pierre-Luc Dallaire-Demers.
The draft would gradually stop Bitcoin users from creating outputs protected only by legacy cryptography and later impose stricter conditions on coins that were not migrated. Wallet providers, exchanges, custodians, miners and individual holders would receive several years to prepare.
BIP-361 is classified as a draft informational proposal. It has not been activated and does not currently require Bitcoin holders to move their funds.
The plan also depends on a separate BIP defining a post-quantum signature scheme and output type. Developers would need to agree on that cryptographic standard, test its effect on verification and block space, and secure sufficient network support before the migration timeline could begin.
Phase A would begin 160,000 blocks after activation, which the authors estimate at approximately three years.
Transactions spending coins from legacy scripts would generally be permitted only when the funds are sent to a post-quantum destination. Existing wallets would not immediately be frozen, but users could no longer move their BTC into another output protected solely by the same legacy signature system.
This approach is planned to reduce the creation of new quantum-vulnerable outputs while keeping a migration path open. Wallet software would need to generate compatible destinations, and exchanges and custodians would need to support the new address format for deposits and withdrawals.
Phase B would follow approximately two years after Phase A, placing the full transition roughly five years after activation.
At that stage, spending unmigrated coins would require a quantum-safe recovery process designed to distinguish the legitimate wallet owner from an attacker who had derived a private key from an exposed public key.
Funds that could not satisfy an accepted recovery method could become effectively unspendable. That is supposed to stop a quantum attacker from taking them, but it could also affect owners who missed the migration window and lacked the information required to prove control.
A quantum attacker might be able to calculate a private key from a public key exposed on-chain. That attack would not necessarily reveal the wallet’s original seed phrase or the parent keys from which the address was derived.
Many wallets created since 2012 use BIP-32 hierarchical deterministic wallets. When hardened derivation is used, a legitimate holder may possess parent-key information that cannot be reconstructed by attacking one exposed public key.
BIP-361 discusses zero-knowledge systems, including ZK-STARK-based approaches, and commit-and-reveal mechanisms that could allow owners to prove knowledge of the original wallet structure without publishing the underlying secret.
No final recovery method has been selected, and the proposal acknowledges that researchers do not yet know how much legacy Bitcoin could be covered by these techniques.
Early Pay-to-Public-Key outputs present a more difficult problem because their public keys have been visible since the coins were received.
For these outputs, the draft identifies no established proof that would reliably separate the original holder from an attacker who had calculated the corresponding private key.
The authors support compatibility with a separate “Hourglass” style mechanism for affected P2PK coins, provided such a proposal is developed and activated before Phase B. Without an additional solution, some early or dormant holdings may not have the same recovery path as newer hierarchical wallets.
Bitcoin currently relies on ECDSA and Schnorr signatures to prove that a transaction was authorized by the holder of a private key.
Outputs whose public keys have not yet been revealed receive an additional layer of protection because the blockchain initially contains only a hash. Once coins are spent, the public key normally appears in the transaction data.
The authors estimate that, as of March 1, 2026, more than 34% of all bitcoin had already revealed a public key on-chain. This is an estimate presented by the BIP’s authors rather than a separate network consensus statistic.
A sufficiently capable quantum computer could theoretically use Shor’s algorithm to derive a private key from an exposed public key and authorize a competing transaction. BIP-361 does not claim that machines capable of doing this exist today. It argues that migration would take long enough that the network should establish a process before the danger becomes immediate.
The urgency has increased after Google Quantum AI researchers estimated that an attack on the elliptic-curve cryptography used by Bitcoin could require roughly 1,200 to 1,450 logical qubits, while revised estimates for the necessary physical hardware were reported to be about 20 times lower than earlier projections. Grayscale’s research team has argued that blockchain networks should begin preparing now, because replacing the cryptography may be easier than coordinating millions of users, wallets and service providers through a secure migration. BIP-361 is one attempt to define that process before the threat becomes practical.
The proposed migration would require more than individual holders moving coins between addresses.
Exchanges and custodians would need to update deposit systems, withdrawal infrastructure and cold-storage procedures. Hardware-wallet manufacturers would need to support post-quantum keys and signatures, which may be substantially larger than those used by Bitcoin today.
Miners and fully validating nodes would also need software capable of enforcing the new spending conditions. The changes are envisioned as soft forks, allowing older nodes to remain connected while leaving them unable to independently verify all of the new post-quantum rules.
BIP-361 has no activation block, implementation release or approved post-quantum signature scheme. Its update on July 20 did not begin the proposed five-year transition.
Developers still need to determine which cryptographic system Bitcoin could support without creating unreasonable signature sizes, verification costs or pressure on block space. The recovery process for unmigrated funds also needs to be designed and tested, particularly for early P2PK outputs.
The proposal gives the ecosystem a possible order of operations: introduce a quantum-resistant destination, stop creating new legacy exposure and later restrict coins that were never migrated. Whether that sequence becomes part of Bitcoin will depend on the missing signature standard, the viability of the recovery methods and wider agreement over how to handle dormant funds.
This article is provided for informational purposes only and does not constitute financial, legal or investment advice.
The post Bitcoin Proposal Targets Future Quantum Attacks appeared first on Coindoo.