[DigitalToday reporter Jinju Hong (홍진주)] Debate is growing in the Bitcoin (BTC) community over whether Bitcoin should restrict spending of coins with cryptographic weaknesses to prepare for the era of quantum computers. It is not only about adopting new cryptographic technology. It is also intertwined with how far existing ownership should be guaranteed and how network security should be ensured.
On Sept. 16 (local time), Bitcoin Magazine reported that Bitcoin’s ECDSA and Schnorr signatures could be threatened if sufficiently powerful quantum computers emerge. Older P2PK outputs and Taproot outputs where public keys are already exposed, and addresses that reuse public keys, are cited as vulnerable targets.
The concern is if quantum computers are used in real attacks. The technology could enable calculating private keys from public keys, creating the possibility of stealing coins. The article analysed that even if users move to quantum-resistant methods, at least 2.6 million BTC could still remain exposed. It estimated that about 1.7 million BTC of that total is in older P2PK outputs.
Some developers argue that simply adding new quantum-resistant addresses is not enough. If vulnerable coins remain, quantum attackers could steal them and sell them into the market. If large volumes move at once, it could affect not only prices but also trust in the Bitcoin network.
Others strongly counter that forcibly freezing existing coins could undermine Bitcoin’s core principles. Preventing coins that can be transacted with valid signatures from being used after a certain point is effectively a restriction on ownership, they argue. It is also difficult to distinguish between coins at risk of quantum attacks and coins held long term, assets in inheritance procedures, or wallets that have simply not moved for a long time.
BIP-361 is cited as a representative response. Under the plan, quantum-resistant addresses would be introduced first, after which new coins would be restricted from moving to vulnerable addresses. After a set grace period, it would block spending of coins that rely on existing ECDSA and Schnorr signatures.
Critics also say this would require sufficient preparation time rather than immediate application. Quantum-resistant cryptography can have larger key and signature sizes than existing cryptography, which could lead to higher on-chain costs. It is also necessary to consider the possibility that the new cryptographic method could be replaced again in the future. Some analyses estimate that moving all UTXOs to a quantum-resistant method could take years.
Compromise options between forced freezes and maintaining the current approach have also been proposed. They include restricting only new vulnerable outputs, locking coins for a certain period, and limiting the amount of spending of older P2PK coins to a set level per block.
The core of the debate is less about exactly when quantum computers will threaten Bitcoin than about what response rules to agree on before then. For now, opinion is shifting toward not applying a specific proposal immediately, but reducing address reuse and preparing long-term migration procedures while researching quantum-resistant signatures and recovery methods.