Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Technology

Bitcoin’s BIP-361 Sets a Five-Year Sunset—but the Clock Hasn’t Started

|Updated: |Author: QUASA Editorial Team|6 min read| 1987
Bitcoin’s BIP-361 Sets a Five-Year Sunset—but the Clock Hasn’t Started

Bitcoin’s BIP-361 still proposes retiring quantum-vulnerable ECDSA and Schnorr spending paths over roughly five years, but the countdown has not begun. As of August 13, 2026, the document remains a draft, depends on a post-quantum signature proposal that has not yet been specified, and imposes no current deadline on holders.

The most important development since the proposal attracted attention in April is technical rather than political: researchers have demonstrated a faster proof-of-ownership method for some hierarchical deterministic wallets. That prototype could make recovery from a future restriction less destructive for eligible owners, but it is unaudited, incomplete and inactive on Bitcoin.

What BIP-361 currently proposes

BIP-361 is not itself a post-quantum signature system. It describes what would happen after Bitcoin had already adopted a suitable post-quantum output type: legacy destinations would first stop receiving funds, and conventional signatures would later face stricter spending conditions designed to distinguish authentic owners from quantum attackers.

The current BIP-361 draft lists Jameson Lopp and five co-authors, carries an assignment date of February 11, 2026, and explicitly requires a still-undetermined post-quantum signature BIP. It places Phase A 160,000 blocks, or approximately three years, after activation; Phase B would follow two years later.

Phase A would permit transfers from legacy scripts into post-quantum scripts while preventing new payments into vulnerable destinations. Phase B is no longer described simply as invalidating every old signature: the draft says ECDSA and Schnorr spending would be encumbered by a quantum-safe rescue protocol. That distinction matters because “freezing millions of coins” compresses several technically different outcomes into one phrase.

Why the five-year clock is not running

The schedule is relative to a future activation, not to the date on which the BIP received its number or entered public discussion. Neither the three-year interval nor the later two-year interval has a calendar start date. A holder therefore cannot calculate a migration deadline from the draft as it stands.

The dependency is substantial. Bitcoin would first need an agreed post-quantum destination and signature-verification design, followed by implementation, review and an activation decision accepted by network participants. BIP-361 supplies none of those missing decisions by itself; its draft status records a proposal for discussion, not a deployed consensus rule.

This also means there is currently no native BIP-361 migration transaction for a wallet or exchange to perform. Operators can evaluate their exposure and preserve the records needed to prove ownership, but they cannot move mainnet funds into a BIP-361-mandated format that has not been selected or activated.

“Freeze” does not describe every legacy coin equally

The draft says that more than 34% of bitcoin had revealed a public key on-chain as of March 1, 2026. That figure is the authors’ stated snapshot, not a live measurement supplied by the protocol, and it should not be translated automatically into a count of coins destined for permanent immobilization.

Exposure and recoverability are separate questions. A sufficiently capable quantum computer could theoretically derive a private key from a revealed elliptic-curve public key, making an ordinary signature inadequate evidence of the original owner. A rescue design would therefore need some additional fact that the legitimate owner knows but an attacker who reconstructed only the child private key does not.

Hierarchical deterministic wallets may provide that asymmetry when the owner retains parent key material from hardened derivation. Early pay-to-public-key outputs present a harder case: they predate modern wallet trees and may offer no parent secret with which to establish superior knowledge. BIP-361 consequently leaves open how much legacy supply could be covered and discusses a separate “Hourglass” approach for P2PK outputs.

A recovery prototype narrows one part of the problem

In July 2026, Project Eleven and developer Jim Posen disclosed a zero-knowledge prototype built around hardened wallet derivation. In tests reported by CoinDesk’s recovery-tool report, proof generation took 243 milliseconds on four CPU cores and verification took 40 milliseconds on an M5 MacBook Air.

The prototype is meaningful because it demonstrates a possible ownership signal that is different from the vulnerable transaction signature. An eligible owner could prove knowledge of an ancestor in the wallet’s derivation tree without disclosing that secret, then bind the proof to a migration instruction.

It is not yet a rescue system for live bitcoin. The researchers described the work as unaudited, limited to three address types and unable to recover funds on any active blockchain. It also does not solve the oldest P2PK case: wallets used before hierarchical deterministic derivation do not have the parent-key structure on which this particular proof relies.

Post-quantum standards do not settle Bitcoin’s governance dispute

The cryptographic concern is not fictional merely because BIP-361 is unactivated. The NIST post-quantum standards announcement finalized FIPS 203, 204 and 205 in August 2024, including two standards for digital signatures, and encouraged administrators to begin migration because integration takes time.

Those standards show that practical defensive algorithms exist for conventional systems. They do not demonstrate that a cryptographically relevant quantum computer can break Bitcoin today, select the best signature construction for Bitcoin’s constraints, or resolve whether restricting old outputs is legitimate.

That last question is the central conflict. Allowing conventionally signed legacy coins to remain spendable could permit a future quantum attacker to claim them. Restricting those spends could protect the wider system while denying access to owners who missed the migration or cannot satisfy a rescue proof. A cryptographic mechanism can reduce that trade-off, but it cannot decide which risk Bitcoin users should accept.

What the current status means for holders

No BIP-361 deadline is currently in force. The proposal has not activated, its prerequisite signature BIP remains unspecified, and its recovery conditions are still research topics. Claims that legacy coins will automatically freeze five years after the proposal’s publication confuse a conditional block-based schedule with an active rule.

The practical dividing line is therefore evidence of deployment, not another debate headline. A material status change would require at least a concrete post-quantum signature proposal, implementation suitable for Bitcoin, defined activation terms and adoption by network participants. Until those elements appear, BIP-361 is best understood as a controversial migration design that has gained a promising but limited recovery experiment—not as a running timer over dormant bitcoin.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0