HomeEverythingEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Bitcoin quantum recovery tool unveiled, but won't unlock Satoshi's coins

Created at 19 Jul · 10:06 AM1 source↑ Market-relevant
IN SHORT

Project Eleven has developed a zero-knowledge proof system designed to recover Bitcoin locked by proposed freezes of quantum-vulnerable coins. However, the system cannot access Satoshi Nakamoto's estimated 1.1 million BTC due to how those early coins were generated.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

1.1 millionBTC attributed to Satoshi Nakamoto
34%Bitcoin supply in quantum-vulnerable addresses
3 yearsTime before new deposits blocked under BIP-361
5 yearsTime before coins frozen under BIP-361
243 millisecondsProof generation time on M5 MacBook Air (4 cores)
40 millisecondsVerification time on M5 MacBook Air
2 gigabytesMemory usage for Project Eleven's prototype
910 millisecondsProject Eleven's full run time (circuit construction, proof generation, self-che

Who's Involved

Project Eleven
Quantum research outfit that built a zero-knowledge proof system for Bitcoin recovery
Satoshi Nakamoto
Pseudonymous inventor of Bitcoin whose early holdings are inaccessible to the new tool
Jameson Lopp
Co-author of BIP-361, a proposed standard for freezing quantum-vulnerable Bitcoin
Jim Posen
Lead developer of the Binius proof system
Bitcoin quantum recovery tool unveiled, but won't unlock Satoshi's coins

↳ Why This Matters

This development introduces a potential technical solution to a future threat posed by quantum computing to Bitcoin's security, but highlights the enduring challenge of recovering funds from the earliest, non-derivation-tree wallets, including those of Bitcoin's pseudonymous creator.

Key facts

  • Project Eleven has developed a zero-knowledge proof system to recover Bitcoin from addresses vulnerable to quantum computing attacks.
  • The proposed BIP-361 standard would freeze such vulnerable coins after a five-year period.
  • The new system cannot recover Bitcoin held by Satoshi Nakamoto because those coins were generated before wallet derivation trees existed.
  • Quantum computers could break elliptic curve signatures, but one-way hashing used in modern wallets remains secure.
  • Project Eleven's prototype shows faster proof generation and verification times compared to prior research.

A new zero-knowledge proof system developed by quantum research outfit Project Eleven offers a potential method to recover Bitcoin locked in addresses vulnerable to quantum computing attacks. This technology is designed to work with BIP-361, a proposed standard that would freeze such coins after a set period.

The system exploits the fact that while quantum computers could break current elliptic curve signatures, the one-way hashing used in modern wallet key derivation remains secure. This allows true owners to prove control of their funds without revealing sensitive key material.

However, the proposed recovery tool faces significant hurdles. Project Eleven's prototype is still unaudited and incomplete, and its implementation would require contentious changes to Bitcoin's blockchain rules. Crucially, the system cannot recover the approximately 1.1 million Bitcoin attributed to Satoshi Nakamoto. These early coins were mined before the advent of wallet derivation trees (BIP-32), meaning there is no parent key or seed material above them to prove ownership of.

This limitation also applies to other pre-2012 wallets, which hold a substantial portion of the oldest and most dormant Bitcoin. The BIP-361 proposal itself has been met with criticism, primarily concerning the potential for permanent loss of ownership. A functional recovery proof, even with its limitations, could reframe the freeze as a temporary lock rather than a permanent loss, provided users still possess their seed phrases.

Frequently asked questions

Quantum computers, using Shor's algorithm, could potentially break the elliptic curve cryptography used for Bitcoin signatures, allowing attackers to derive private keys from exposed public keys and steal funds.

BIP-361 is a proposed Bitcoin improvement proposal that would gradually freeze coins in addresses whose public keys have been exposed, aiming to protect them from future quantum attacks.

Satoshi Nakamoto's coins were mined before wallet derivation trees (BIP-32) existed. The recovery tool relies on proving knowledge of a parent key in a derivation tree, which is absent for these early coins.

It uses zero-knowledge proofs to allow users to demonstrate they know the key material above their address in a wallet's derivation tree, enabling them to authorize a migration transaction without revealing the keys.

What Happens Next

01Project Eleven's prototype requires further auditing and development.
02Changes to Bitcoin's blockchain rules would be necessary for the system's implementation.
03The debate around BIP-361 and its implications for Bitcoin's permanent ownership promise is likely to continue.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A new zero-knowledge proof system from Project Eleven aims to recover Bitcoin locked under BIP-361's proposed freeze of quantum-vulnerable coins.
The system exploits the difference between quantum-vulnerable elliptic curve signatures and one-way hashing used in modern wallet key derivation.
BIP-361, published in April, would block new deposits to vulnerable addresses after three years and freeze remaining coins after five.
More than 34% of Bitcoin supply is in addresses whose public keys have been exposed, making them vulnerable to quantum attacks after 'Q-Day'.
Satoshi Nakamoto's approximately 1.1 million BTC, mined before 2012, are in addresses with public keys directly on-chain, lacking a derivation tree.
Project Eleven's prototype is significantly faster than previous work but remains unaudited and incomplete, requiring blockchain rule changes.
The recovery path relies on proving knowledge of key material above an address in a wallet's derivation tree, which predates Satoshi's coins.

Sources

T1
Bitcoin’s quantum problem gets a recovery tool, but not for Satoshi’s 1.1 million coinsCoinDesk

Related Stories

Michael Saylor calls Bitcoin Improvement Proposal 110 a 'bad idea'
19 Jul · 3:26 PM
Zcash Node Aims for Visa-Scale Privacy at 50,000 TPS
19 Jul · 5:46 AM
Kraken launches USD-settled BTC and ETH options
19 Jul · 1:06 PM
Amazon Japan Logistics Partner to Use JPYC Stablecoin for Payments
19 Jul · 4:56 PM
Polymarket Odds for Clarity Act Passage Hit Record Low Amid Senate Delays
19 Jul · 11:56 AM