CatBitcoin
A printed government cryptography standard resting on a desk under cool daylight, the cover page showing a draft seal and a list of modules in small type.

Custody, not cryptography

The NIST deadline hits, and Bitcoin has not packed

Updated 6 October 2026

That is a deadline. It is not a vulnerability. The lock on every Bitcoin box still works the same way it did yesterday, and the lock on the boxes that matter most is broken in the same way it was yesterday. What changed on 6 October 2026 is that a government cryptography office has put a publicly readable date on the schedule, and the people who hold open boxes on the time-chain can read it too.

What NIST actually signed off

FIPS 206, the Falcon-derived signature scheme long tracked as ML-DSA or CRYSTALS-Dilithium, left draft on 6 October 2026. NIST's own initial public draft confirms the timeline: classical RSA, ECDSA and EdDSA are slated for retirement across federal use by 2030, with FIPS 186-5 already naming the new modules. CatBitcoin does not run a fork. The chain still verifies secp256k1, and every address that exists today still spends the same way. The schedule is the story, not the software.

A small wooden puzzle box sits closed on a metal shelf, late afternoon daylight falling across the surface, no labels, no cables, no screens in frame.

Why a deadline is not an exploit

An attacker needs a cryptographically relevant quantum computer, not a calendar. The widely cited resource estimate, including IonQ's 26-day secp256k1 figure that we read through the box in 2024, is for breaking one key in serial, against a large error-corrected machine that does not yet run. The deadline says the cryptography the rest of the internet uses will be phased out by 2030. It does not say Bitcoin's boxes are cracked tonight, and any post that says otherwise is selling something.

Which boxes the deadline is for

What changes in your wallet today

Nothing, and that is the point. The on-chain rules are the rules, and secp256k1 still signs. Watch-only tools, hardware devices and seed phrases continue to do exactly what they did in September. If a piece of software is promising you a post-quantum upgrade path on Bitcoin today, it is either a sidechain, a rollup or a marketing deck. The honest reading of October 2026 is that the runway is now drawn on a federal page, and the time to plan a move, not to panic, is earlier than it looked in 2024. See when the runway ends for the mechanic.

What the open-box holders should actually do

Move the coins, once, to an address type whose public key is not on-chain. A P2WPKH or P2TR output, generated on a device that has never broadcast the key, is a box that the deadline does not touch until the day it is spent. Do not paste a seed into a website to do this. Do not trust a browser extension that promises a one-click quantum migration. Use a wallet you control, generate a fresh receiving address, sweep, and verify the new UTXO on a block explorer before you delete the old one. The deadline is about cryptography, and the migration is about custody.

What the closed-box holders should do

Wait, and read. The boxes that have never been spent are the boxes that benefit most from a slow, well-tested upgrade path. BIP-360 and the P2MR and P2TRv2 proposals we have covered are still drafts, and the standard CatBitcoin wants is one that defaults to a closed box, not one that opens it on arrival. Hold the position, hold the device, hold the seed. The deadline is a planning tool, not a fire alarm.

Quick answers

Did NIST ban secp256k1 on 6 October 2026?
No. NIST retired its classical signature suites for federal procurement, with full deprecation in 2030. Bitcoin's consensus rules are unchanged and secp256k1 still signs every spend on the main chain.
Does the deadline crack reused P2PK addresses?
No. A deadline is not a key extraction. The boxes whose public keys are already on-chain remain as exposed as they were last week; the deadline just makes the schedule legible to the people who had not read it.
Should I move my coins right now?
If your coins sit in an address whose public key is already on-chain, yes, and slowly, using a wallet you control. If your coins sit in a fresh P2WPKH or P2TR output that has never been spent, the deadline is not aimed at you. Never paste a seed into a watch-only field.