Bg c> [!summary] Distinct from the analytical Quantum computing threat to Bitcoin criticism, the post-quantum migration debate is the event-level controversy about how the contested upgrade process should actually proceed. The principal contested matters: the Satoshi-coins consensus problem (~1.7M BTC in old-P2PK addresses, including Satoshi’s ~1.1M, that no holder-side action can move); the cultural traction of “weeks of network downtime” framing in mainstream coverage despite developer rejection; BIP-360 deployment specifics (Ethan Heilman’s bc1z address-type proposal, contested activation path); community-coordination feasibility if quantum-threat urgency forces faster-than-normal upgrade dynamics; and the governance question of who decides what scheme is “good enough.” NVK’s 2026 Bitcoin & Quantum Computing research series consolidates substantial post-quantum-BIP work but does not resolve the contested-process questions. As of 2026-05-15, no post-quantum BIP has activated, BIP-360 is in testnet, and the Satoshi-coins problem remains genuinely unresolved.


Why this note matters

The post-quantum migration debate is the contested-upgrade-process counterpart to the Quantum computing threat to Bitcoin analytical critique. The Criticism note engages whether the threat is real; this note engages the much harder question of what to actually do about it. The note matters because:

  • It surfaces the contested-process dimension that the Criticism note can’t fully address (the Criticism focuses on the analytical question; this note focuses on the migration mechanics)
  • It engages the Satoshi-coins consensus problem specifically — the load-bearing unresolved question that no proposal currently solves cleanly
  • It articulates the migration-downtime debate that has substantive traction in adjacent media coverage even though most developers consider extended downtime unnecessary
  • It distinguishes the specific BIP-360 deployment path from broader post-quantum considerations
  • It engages the governance dimension — who decides, how, and under what coordination dynamics

The defensible position: the migration debate will become increasingly load-bearing as quantum-hardware progress accumulates. The Bitcoin community is doing substantive proactive work (NVK’s research series, multiple BIP authors, OpenSats funding), but the contested-process questions remain genuinely unresolved.


What happened

A condensed event-level chronicle of the migration debate. See Quantum computing threat to Bitcoin for the analytical-threat chronicle (timeline estimates; hardware progress; physicist skeptics; etc.).

2017-2022 — Early post-quantum BIP discussions. Various early proposals for post-quantum signature additions to Bitcoin emerge in developer-mailing-list discussions; no proposal advances to formal activation. Most discussion is exploratory; the threat is not yet seen as urgent.

2022-2024 — NIST PQC standardization completes. NIST’s multi-year post-quantum cryptography standardization process produces final standards (FIPS 204, 205, 206 — CRYSTALS-Dilithium, Falcon, SPHINCS+) in 2024. The Bitcoin community now has standardised post-quantum primitives to build on.

2024 — BIP-360 emerges. Ethan Heilman proposes a new bc1z address type that removes the quantum-vulnerable key-path from Taproot while deferring the specific post-quantum signature algorithm selection. BIP-360 enters active proposal-and-testnet phase via BTQ Technologies (50+ miners, 100K+ blocks of testnet operation).

2024 — SHRINCS deployed on Liquid sidechain. Jonas Nick’s SHRINCS hash-based signature scheme is deployed on Liquid as production demonstration. SHRINCS produces 324-byte signatures at NIST Level 1 security; verification is sub-millisecond. The deployment shows post-quantum signatures are operationally workable.

2024-2026 — Multiple proposals in active engagement. SHRIMPS (Jonas Nick variant supporting multiple backup devices), Quantum Safe Bitcoin (Avihu Levy, StarkWare; no-soft-fork hash-to-signature puzzle), PQ HD Wallets (jesseposner), Raccoon-G (HD-wallet threshold construction), zk-STARK BIP-32 Escape (Olaoluwa Osuntokun) — multiple concrete proposals in active development.

April 2026 — NVK consolidates the landscape. Rodolfo Novak (NVK) publishes the 4-part Bitcoin & Quantum Computing research series at bitcoinquantum.space, surveying 14 mitigation proposals from 17 named researchers. The series substantially shifts the Bitcoin-community discourse from generic panic-or-dismissal toward specific engagement with named BIPs and concrete migration mechanics.

Ongoing as of 2026-05-15. No post-quantum BIP has activated. BIP-360 in testnet phase. The Satoshi-coins consensus problem remains genuinely unresolved among proponents of various positions (“Move them now”; “Burn them by consensus”; “Accept the supply shock”; “It depends on who has the CRQC first”).


The contested matters

The migration debate operates at multiple distinct layers.

Layer 1: The Satoshi-coins consensus problem

The single most-contested unresolved question. Approximately 1.7M BTC sits in old-P2PK addresses with permanently-visible public keys (NVK Tier A, per Quantum computing threat to Bitcoin). This includes Satoshi Nakamoto’s estimated ~1.1M BTC plus other early-mining-era coins. No holder-side action can move these coins — Satoshi has not signed transactions since 2010; many other early-P2PK coins are presumed lost. If a CRQC emerges, these coins are spendable by whoever holds the CRQC.

The contested positions:

“Move them now” (voluntary migration):

  • Owners of legacy P2PK coins who still have keys should voluntarily migrate to post-quantum addresses while time permits
  • Strengths: respects existing custody rights; preserves “rules-don’t-change” Bitcoin property
  • Weaknesses: Satoshi’s coins remain exposed regardless (no signing since 2010); doesn’t solve the structural problem

“Burn them by consensus” (consensus-rule invalidation):

  • Add a consensus rule that invalidates spending from legacy ECDSA addresses after a certain block height; legacy coins become unspendable
  • Strengths: solves the structural supply-shock problem; prevents CRQC-holders from extracting value
  • Weaknesses: highly controversial; conflicts with Bitcoin’s “rules-don’t-change” property; effectively confiscates property from any legitimate Satoshi successor or unknown-but-alive holder

“Accept the supply shock” (laissez-faire):

  • Don’t add new consensus rules; if a CRQC emerges, exposed coins become spendable by whoever holds the CRQC; market absorbs the supply shock
  • Strengths: maximally consistent with Bitcoin’s neutrality; respects property rights
  • Weaknesses: a sudden 1.7M BTC supply shock (~8% of mined supply) would materially affect price and confidence in Bitcoin’s “fixed supply” property; could undermine the long-term monetary case

“It depends on who has the CRQC first”:

  • State actors (US, China) developing CRQC may use it differently from open-market criminal exploitation; the outcome depends on specific actor incentives
  • A state-developed CRQC might result in a controlled disclosure; criminal-actor CRQC might result in chaotic supply shock
  • This position implicitly accepts that the outcome is contingent on actors beyond Bitcoin’s governance

Why this is unresolved: each position has substantive merit; the trade-offs are genuine; no position has emerged as community-consensus. The dispute may persist indefinitely or may be forced into resolution by CRQC emergence.

Layer 2: The migration-downtime debate

Some media coverage and adjacent commentary suggests post-quantum migration would require “weeks of network downtime” — a framing that has cultural traction even though most developers reject it.

The “weeks of downtime” framing:

  • Cited in some mainstream coverage (Forbes; CoinDesk; some industry commentary)
  • The framing suggests Bitcoin would need to pause normal operations during migration
  • Source: speculation about hard-fork-style migration requirements; partly informed by general unfamiliarity with soft-fork upgrade dynamics

The developer rebuttal:

  • Post-quantum signature support can be added via standard soft-fork mechanism (new address types) without any network downtime
  • BIP-360’s bc1z address-type approach demonstrates the soft-fork-only path
  • Migration is a per-holder action over time, not a network-wide pause
  • The “weeks of downtime” framing reflects misunderstanding of soft-fork upgrade dynamics
  • However: actual migration completion takes years (holder-by-holder action; not network-wide); the “migration window” in the Mosca’s-theorem sense is long but doesn’t require operational downtime

Why this matters: even though the developer rebuttal is technically correct, the “weeks of downtime” framing affects mainstream perception of the migration challenge. The dispute is partly about technical reality and partly about public-discourse framing.

Layer 3: BIP-360 deployment specifics

The BIP-360 approach (Ethan Heilman, BTQ Technologies):

  • New bc1z address type removing quantum-vulnerable key-path from Taproot
  • Defers specific post-quantum signature algorithm selection (allows future choice among NIST PQC standards or adjacent schemes)
  • Operating on testnet since 2024-2025; substantial deployment experience
  • Soft-fork activation path; backward-compatible with existing wallets

Contested elements of BIP-360:

  • The deferred-algorithm approach: proponents argue it provides flexibility; skeptics argue it adds complexity and may not fully solve the problem until specific algorithm is chosen
  • The Taproot-key-path-removal: technically clean but creates two parallel address types (existing P2TR + new bc1z) which may produce ecosystem fragmentation
  • The mining-pool-coordination requirement: standard BIP-9 / BIP-8 activation requires substantial pool support; current pool positions on BIP-360 are not publicly aligned

Alternative migration paths:

  • SHRINCS direct deployment (Jonas Nick) — already operational on Liquid; mainnet deployment would be more direct than BIP-360’s deferred approach
  • Quantum Safe Bitcoin (Avihu Levy) — no-soft-fork approach using hash-to-signature puzzle; trades computational cost ($75-150/transaction) for activation simplicity
  • Combined approaches — BIP-360 plus subsequent algorithm-specific activation

The within-proponent debate about which path is best is itself a substantive contested matter.

Layer 4: Community-coordination feasibility under threat pressure

The migration debate intersects with broader Protocol-evolution constraints dynamics in a distinctive way: what happens to Bitcoin’s normal slow-and-conservative upgrade process if quantum-threat urgency emerges?

The proactive position:

  • Bitcoin should activate post-quantum infrastructure ahead of urgency to provide schedule margin
  • The work is technically additive (new address types) rather than restrictive; soft-fork design is simplified
  • NVK’s research-consolidation and BIP-360’s testnet deployment demonstrate the development community is moving proactively
  • Community-coordination is workable at normal pace if begun early enough

The skeptical position:

  • Bitcoin’s normal upgrade process takes years (SegWit ~2; Taproot ~3); post-quantum migration is more complex
  • The post-Block-Size-Wars community fragmentation makes contentious upgrades difficult; even uncontentious upgrades can stall
  • If CRQC emerges before migration is well-advanced, the upgrade process may be forced into emergency mode (similar to the 2010 inflation-bug response but at much larger scope)
  • The “who decides what’s good enough” question becomes acute under time pressure

The trade-off: proactive migration provides schedule margin but commits to specific design choices that may be suboptimal in hindsight; reactive migration preserves design flexibility but risks insufficient time if CRQC emerges suddenly.

Layer 5: The “who decides what’s good enough” governance question

Post-quantum scheme selection involves complex security trade-offs:

  • Hash-based schemes (SPHINCS+; SHRINCS) — most-conservative; large signatures (324-2,500+ bytes); state-management complexity
  • Lattice-based schemes (CRYSTALS-Dilithium; Falcon) — smaller signatures; faster; less battle-tested than hash-based
  • Newer schemes still in early-research phase
  • Hybrid approaches combining classical and post-quantum signatures — reduce catastrophic-weakness risk but add complexity

The community must accept whatever choices the development process produces. The “who decides” question is:

  • Bitcoin Core developers — typical proposal-and-review process
  • BIP authors — specific proposal authors carry weight in their proposals
  • Mining-pool operators — signal acceptance via activation support
  • Node operators and users — accept or reject via running code
  • Academic cryptographers — provide external review

The current development process distributes governance across these groups; whether the distribution functions well for the high-stakes post-quantum decision is itself contested.


Where the dispute stands (as of 2026-05-15)

  • Satoshi-coins consensus problem: genuinely unresolved; no community-consensus position; will likely persist until forced into resolution
  • Migration-downtime debate: technically resolved (no downtime needed for soft-fork) but framing-resolution incomplete (mainstream coverage continues to invoke the framing)
  • BIP-360: in active testnet phase; no mainnet activation underway; substantial development progress
  • SHRINCS, SHRIMPS, QSB, others: various development states; no clear consensus on which is preferred path
  • Community-coordination state: developers proactively engaged (NVK’s research series; multiple BIP authors); broader community discourse less mature
  • Likely 2026-2030 trajectory: continued development without activation is most likely; BIP-360 or adjacent soft-fork activation possible toward end of window; Satoshi-coins resolution unlikely without external forcing event

Counter-arguments and tensions (criticisms of how this note frames the controversy)

“The Satoshi-coins consensus problem is overstated”

The framing concern: Treating the Satoshi-coins question as a primary unresolved controversy may overstate its practical significance. Most analysts believe Satoshi is unable to move the coins (lost keys or death); the coins have remained dormant for 15+ years; the supply-shock concern may be cushioned by gradual market absorption.

Response: Partially valid. The Satoshi-coins question is more theoretical than imminent in 2026; its prominence in the migration debate reflects long-horizon concerns rather than immediate threats. The note’s prominence is consistent with how the debate operates in practice — proponents and skeptics of various positions do treat the Satoshi-coins question as load-bearing — but readers should weight the long-horizon framing appropriately.

”The ‘weeks of downtime’ framing isn’t a serious debate”

The framing concern: No serious developer believes Bitcoin needs weeks of downtime for post-quantum migration. Including the framing as a “contested matter” gives credibility to a position that doesn’t deserve it.

Response: Real but partial. The technical reality is settled (no downtime needed). The framing’s cultural traction in mainstream coverage is also real and affects public-discourse perception. The note distinguishes the two — the technical reality is stated; the framing is engaged as a public-discourse phenomenon that the Bitcoin community must respond to. Treating it as a “contested matter” doesn’t mean the technical question is contested; it means the public-discourse handling of the question is part of the broader migration dynamics.

”BIP-360 is too narrow to be the principal migration path”

The framing concern: BIP-360 defers the specific post-quantum algorithm; it doesn’t actually solve the problem until that selection is made. Treating it as the principal contemporary path may give false confidence about migration readiness.

Response: Real. BIP-360 is one important step but not the complete migration path. The note attempts to be honest about this; the deferred-algorithm question is itself a contested matter. Readers should understand that BIP-360 enables future post-quantum signature support but doesn’t itself complete the migration.

”NVK’s research-series framing may give NVK undue weight in the controversy”

The framing concern: Citing NVK’s 2026 research series as the consolidating reference may give him disproportionate authority in the dispute. Multiple researchers (Heilman, Nick, Wuille, others) have done the actual technical work; NVK’s role is synthesis and curation.

Response: Valid concern, acknowledged in Rodolfo Novak. NVK’s contribution is synthesis-and-accessibility; the technical work is distributed across 17+ named researchers. Citing the series reflects its consolidating function in the public discourse; the underlying technical work has multiple authors. The note attempts to credit specific researchers (Heilman for BIP-360; Nick for SHRINCS; Osuntokun for zk-STARK escape; others) appropriately.

”The note understates the urgency”

The framing concern: The “real but distant” framing (from Quantum computing threat to Bitcoin) may produce complacency. Some analysts believe CRQC emergence could be substantially closer than the realistic central estimate (10-30 years); the migration debate may need to operate under tighter time pressure than current framing suggests.

Response: Real concern. The trajectory is uncertain in both directions. The note’s framing reflects the realistic central estimate per NVK’s research-series consolidation; if CRQC emerges substantially faster, the migration debate becomes immediately load-bearing. Readers tracking quantum-hardware progress should update urgency accordingly.


Verdict: Remains genuinely contested as of 2026-05-15; the Satoshi-coins consensus problem is the load-bearing unresolved element

The post-quantum migration debate is the contested-process counterpart to the Quantum computing threat to Bitcoin analytical engagement. Substantial development progress (BIP-360, SHRINCS, multiple adjacent proposals); substantial unresolved questions (Satoshi-coins; specific algorithm choice; community-coordination dynamics).

A serious assessment:

  • The Satoshi-coins consensus problem is the load-bearing unresolved question; no clean resolution exists
  • The migration-downtime debate is technically resolved but culturally persistent
  • BIP-360 and adjacent proposals demonstrate substantial proactive work; activation path uncertain
  • Community-coordination feasibility intersects with broader Protocol-evolution constraints dynamics
  • Governance question distributed across developers, BIP authors, miners, node operators, users; functioning at normal pace but may face stress if CRQC emerges suddenly
  • Trajectory: continued development without activation most likely through 2026-2028; activation in 2028-2032 window possible; Satoshi-coins resolution unlikely without external forcing event

This is a controversy worth tracking actively. The trajectory depends substantially on quantum-hardware progress (per Quantum computing threat to Bitcoin); shifts in that landscape will shift this debate’s urgency and contours.


Open questions for further development

  • What’s the realistic process for resolving the Satoshi-coins consensus problem? Each proposed position has substantive merit; community-consensus seems unlikely without external pressure.
  • BIP-360 testnet operations continue accumulating data; what’s the realistic path from testnet maturity to mainnet activation?
  • The community-coordination question is genuinely uncertain; what would functioning community-coordination under quantum-threat pressure look like, and would it differ from past upgrade processes?
  • The intersection with OP_CAT and the covenants programmability debate is unclear; would covenant activation make post-quantum migration easier or harder?
  • The Lightning-adaptor-signatures unsolved gap (per Quantum computing threat to Bitcoin) is partly its own debate; how does it interact with the broader migration timeline?

Canonical sources for this note

The consolidating Bitcoin-community reference:

  • Rodolfo Novak (NVK)Bitcoin & Quantum Computing research series at bitcoinquantum.space (4 parts, April 2026; 17 named researchers; 14 mitigation proposals). See Rodolfo Novak for the thinker treatment.

Specific BIPs and proposals:

  • BIP-360 (Ethan Heilman, BTQ Technologies) — bc1z address type
  • SHRINCS / SHRIMPS (Jonas Nick, Blockstream) — hash-based signatures; SHRINCS deployed on Liquid sidechain
  • Quantum Safe Bitcoin (QSB) (Avihu Levy, StarkWare)
  • PQ HD Wallets (jesseposner); Raccoon-G (March 2026)
  • zk-STARK BIP-32 Escape (Olaoluwa Osuntokun)
  • Adjacent research across 15+ Delving Bitcoin threads and 20+ Optech newsletter issues

Mainstream coverage (often poorly calibrated):

  • Forbes — Why Crypto is Facing its Toughest Challenges Yet (April 2026)
  • CoinDesk — Bitcoin Quantum Threat is Real and Closer than it Looks, Says Nobel Physicist (April 2026)
  • 247wallst — The Crypto Industry Just Had its Worst Month of Hacks (April 2026)
  • Bitget — various quantum-coverage articles
  • Mixed-quality treatments; useful as examples of public-discourse framing

Standardization sources:

  • NIST FIPS 204, 205, 206 (2024) — post-quantum signature standards
  • NIST PQC standardization process documentation (2016-2024)
  • NSA CNSA 2.0 (2022) — migration guidance

Adjacent technical context:

As of 2026-05-15: BIP-360 in testnet phase; SHRINCS deployed on Liquid; no mainnet post-quantum BIP activation underway; Satoshi-coins consensus problem unresolved.


Paired Criticism note (cross-section):

  • Quantum computing threat to Bitcoin — the analytical critique of the threat (is it real; is the response adequate in principle); this controversy note treats the event-level migration-process specifics

Within the Controversies section:

Criticisms-section adjacency:

Technical foundations section:

Adjacent thinker pages:

  • Rodolfo Novak — NVK; research-series consolidator
  • Pieter Wuille — Bitcoin Core; Taproot author; cited in NVK’s series
  • Greg Maxwell — Bitcoin cryptographer; cited in NVK’s series
  • Adam Back — Bitcoin engineer; engaged in quantum discussions
  • Peter Todd — Bitcoin protocol contributor

The sub-MOC home: