CatBitcoin

What happens to Satoshi's coins in the quantum debate

Updated August 6, 2026

About 1.1 million BTC, something like five percent of Bitcoin's entire 21 million coin supply, hasn't moved since around 2010. It sits in addresses widely believed to belong to Satoshi Nakamoto, mined in Bitcoin's first year and never touched since. That stillness is exactly why this single pile of coins sits at the center of nearly every serious conversation about Bitcoin and quantum computing.

Why this particular pile of coins matters so much

Bitcoin has roughly 5.4 million BTC sitting in addresses where the public key is already visible on-chain, about a quarter of the total supply, as covered in more detail in our explainer on Bitcoin and quantum computers. Satoshi's coins are part of that larger group, but they're the part everyone actually pictures when the topic comes up. A few things stack together to make that true: the size of the holding is enormous on its own, the identity attached to it carries obvious symbolic weight, and, unlike almost every other exposed address, nobody can step in and move these coins to safety even if they wanted to. Whoever held the keys either lost them, is deliberately staying silent, or is no longer around to act. The coins are exposed and permanently passive at the same time, which is a combination nothing else on the network really matches.

How the exposure actually works

Coins from Bitcoin's earliest period were typically sent using an old output format, often called P2PK, that wrote the raw public key onto the chain the moment the coins were received rather than hiding it behind a hash. That's different from later formats like P2PKH or SegWit, where only a hash is visible until the owner spends, and it's structurally close to how Taproot addresses work today, where the key is visible from the start by design. You can see the distinction for a specific address using the wallet checker, which shows whether an address's key has surfaced on-chain yet. The theoretical risk here is Shor's algorithm, a quantum method that could, on a sufficiently capable machine, work backward from a public key to the private key behind it. No such machine exists today, and serious estimates for when one might range from several years to a decade or more, genuinely uncertain rather than a fixed date anyone can point to.

The idea that makes people uneasy

Inside the wider draft discussion around BIP-360 and BIP-361, a genuinely contentious idea keeps surfacing: some proposals would eventually restrict spending from addresses that are both long-dormant and publicly exposed, if their owners haven't migrated them to a quantum-resistant format within some defined window. Nothing here is settled. These are drafts, not activated protocol rules, and the specifics keep shifting as people argue about them. But the target of the idea is obvious even when nobody says it outright: 1.1 million BTC that hasn't moved in about sixteen years, sitting there as the clearest possible test case for what happens if a rule like this ever gets written down.

The tension is that Bitcoin has never had a mechanism for deciding whose coins get to keep moving and whose don't. Ownership has always been enforced purely by who holds a working private key, full stop, with no committee, foundation, or majority vote sitting above that. A rule that freezes specific coins because they've sat still too long, however carefully reasoned, introduces exactly the kind of discretionary power the system was built to avoid needing in the first place.

Case for eventual restrictionCase against it
If a real quantum computer ever arrives, whoever cracks a key first could sweep the coins, an abrupt shock nobody chose and nobody can stop after the fact.Bitcoin's whole premise is that no outside party decides who can spend what. A rule aimed at dormant coins is still a rule about somebody's coins, made without their consent.
An orderly, telegraphed migration window feels less disruptive than an uncontrolled loss of 1.1 million BTC happening all at once, whenever it happens."Dormant" is impossible to verify. A holder sitting on keys for sixteen years looks identical on-chain to a wallet with a permanently lost key. There's no way to tell intent apart from loss.
Treating known-exposed, unmigrated coins as a shared risk to the network, not just a private one, mirrors how other protocol upgrades have prioritized system-wide safety before.Once the protocol can freeze coins by rule, that capability doesn't disappear afterward. It becomes a precedent other arguments can reach for later, against other coins.

Where this actually stands right now

Nothing close to consensus exists on the restriction question, and getting there would require the kind of broad agreement across node operators, miners, and the wider community that Bitcoin has historically been slow, deliberately, to grant. BIP-360 and BIP-361 remain drafts, and the specific mechanics around migration windows or dormant-address handling are still being argued over rather than decided. There's also no immediate deadline forcing the issue: with no quantum computer close to threatening secp256k1 today, this is a debate happening well ahead of any technical necessity, which is arguably the best possible time to have it carefully rather than in a rush. If you want a feel for the scale involved, running 1.1 million BTC through the sats converter makes the number a lot more concrete than "million" on its own ever does.

None of this changes what's true for everyone else's coins today, which is the more immediate and practical question most holders actually face. The mechanics of which address types are already exposed, what changed in the field during 2026, and what BIP-360 and BIP-361 are actually trying to fix are laid out fully in the main quantum computing explainer, and it's the better next stop for anyone whose real concern is their own wallet rather than Satoshi's.