A live governance fight is playing out in the Bitcoin community over how — and whether — to defend the network against future quantum computers. A proposal called BIP-361 would eventually freeze coins in wallets that don't upgrade to quantum-resistant addresses, and it has split developers, miners and prominent holders including Strategy's Michael Saylor. Here's what the debate is actually about, how real the quantum threat is today, and what it means for anyone holding Bitcoin.
Bitcoin's security relies on elliptic-curve cryptography (ECDSA), which today's computers cannot break in any practical timeframe. The concern is that a sufficiently powerful quantum computer — a machine that uses quantum mechanics rather than classical bits to perform certain calculations far faster — could one day derive a private key from a public one, potentially exposing coins held in older address types.
In March 2026, Google's Quantum AI team published research suggesting elliptic-curve cryptography could be broken with fewer resources than previously thought — as low as roughly 1,200-1,450 logical qubits, rather than earlier estimates in the tens of millions of physical qubits (CoinDesk, The Protocol, 1 April 2026). But Google's own Willow chip has only around 105 qubits, and a company spokesperson said plainly that “the Willow chip is incapable of breaking modern cryptography” (Cryptopolitan). Google has set 2029 as its own internal target for migrating its authentication services to post-quantum cryptography — a planning deadline, not a claim that a Bitcoin-cracking machine will exist by then (CryptoRank.io).
A Google-commissioned study estimated around 6.9 million BTC currently sit in address types that would be vulnerable if a cryptographically relevant quantum computer existed today.
Estimates for when such a machine might exist vary widely: IBM targets 200 logical qubits by 2029 with its Starling system, while Blockstream chief executive Adam Back has argued the practical threat is 20 to 40 years away (altFINS).
BIP-361, put forward by developer Jameson Lopp and others, sets out a three-phase plan to retire Bitcoin's current signature schemes (ECDSA and Schnorr) in favour of quantum-resistant alternatives. In its later phase, it would stop new transfers from — and eventually freeze — coins that remain in unmigrated address types (Bitcoin Magazine).
The proposal would affect an estimated 170,000 BTC held in older P2PK-style addresses, including roughly 1.1 million BTC widely attributed to Bitcoin's pseudonymous creator, Satoshi Nakamoto. Because those wallets cannot migrate — their owners are unreachable, deceased, or simply inactive — critics argue the plan effectively confiscates coins that were never at risk of being stolen in practice.
Strategy executive chairman Michael Saylor has dismissed the near-term concern as overblown and instead launched a separate Bitcoin Security Program to coordinate industry research, framing quantum risk as an engineering challenge rather than an emergency (The Block). Other prominent voices have been sharper: Bitcoin Magazine's editor rejected the proposal outright, and one widely shared comment called it “highly authoritarian and confiscatory”. Because Bitcoin has no central authority, BIP-361 can only take effect if it wins broad consensus among developers, miners and node operators — a process that has historically taken years for far less contentious changes.
170K BTC
Coins in scope of BIP-361
1.1M BTC
Estimated Satoshi-linked coins
6.9M BTC
Vulnerable at CRQC threshold (Autheo)
BIP-361 is not the only quantum-related proposal in front of the Bitcoin community. A related but separate change, BIP-360, has already been merged and takes a less disruptive approach.
| Proposal | Status | What it does | Forces a freeze? |
| BIP-360 | Merged, testnet (Feb 2026) | Introduces a new quantum-resistant address type (bc1z) for future use | No |
| BIP-361 | Draft, under debate | Phases out legacy signatures; later phase could freeze unmigrated coins | Yes, in Phase B |
| “Hourglass” proposal | Alternative draft | Would throttle stolen coins to limited batches per block rather than freezing them | No |
In short: BIP-360 gives new users and wallets a safer address format to move to; BIP-361 is the more contentious question of what happens to coins that never move. (altFINS)
Beyond the technical debate, UK holders of Bitcoin and other cryptoassets are also entering a new regulatory environment that will shape how they buy, hold and trade crypto going forward.
Beyond BIP-361, UK holders of Bitcoin and other cryptoassets are entering a new regulatory phase. On 30 June 2026, the FCA published the core of its final cryptoasset regime under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. The authorisation window for firms opens 30 September 2026, with the full regime in force from 25 October 2027 (FCA.gov.uk). The changes bring standardised risk warnings, a mandatory cooling-off period, and access to the Financial Ombudsman Service for UK retail investors using authorised platforms.
Tax treatment depends on individual circumstances and may be subject to change. Seek independent advice.
Learn more about crypto
Explore IG's cryptocurrency trading
Bernstein analysts have characterised the situation as a standard upgrade cycle rather than an existential threat, while acknowledging the debate itself is a turning point for how the network handles long-term security questions (The Block). For most holders, the practical takeaways are:
Is Bitcoin quantum resistant right now?
Not fully. Bitcoin's current signature scheme (ECDSA) is not quantum-resistant, but no existing quantum computer has the scale needed to exploit that. A separate proposal, BIP-360, has already introduced an optional quantum-resistant address type.
Could BIP-361 freeze my Bitcoin?
Only if it is adopted by the network — which has not happened — and only in its later phase, and only for coins that remain in specific older address types after a migration window. Coins in modern address formats are not the focus of the freeze mechanism.
When could quantum computers actually threaten Bitcoin?
Estimates vary significantly, from around 2030 on the more cautious end to 20-40 years away according to some industry figures. There is no consensus date, which is itself part of why the governance debate is contentious.
Start trading crypto with IG
FCA-regulated access to Bitcoin and other cryptoassets
This information has been prepared by IG, a trading name of IG Markets Limited. In addition to the disclaimer below, the material on this page does not contain a record of our trading prices, or an offer of, or solicitation for, a transaction in any financial instrument. IG accepts no responsibility for any use that may be made of these comments and for any consequences that result. No representation or warranty is given as to the accuracy or completeness of this information. Consequently any person acting on it does so entirely at their own risk. Any research provided does not have regard to the specific investment objectives, financial situation and needs of any specific person who may receive it. It has not been prepared in accordance with legal requirements designed to promote the independence of investment research and as such is considered to be a marketing communication. Although we are not specifically constrained from dealing ahead of our recommendations we do not seek to take advantage of them before they are provided to our clients. See full non-independent research disclaimer and quarterly summary.