The Quantum Problem
Bitcoin has a quantum problem. Not today, maybe not tomorrow, but eventually. And the developers who’ve spent the last year arguing about spam and data limits are now staring down a threat that makes those fights look quaint.
BIP-360, introduced as a draft proposal in 2026, wants to replace Bitcoin’s current output model with something called Pay-to-Merkle-Root, or P2MR. The idea is straightforward: instead of exposing a public key on-chain, P2MR commits funds to a Merkle root. That means an attacker with a quantum computer can’t derive a private key from a visible public key, because there’s no public key to see.
The proposal comes as quantum-related discussions have surged on the Bitcoin development mailing list. More than 10% of technical communications now touch on post-quantum security, up from years of near silence. Coinbase even formed an independent advisory board on quantum computing and blockchain security, bringing in Stanford’s Dan Boneh, UT Austin’s Scott Aaronson, and Ethereum Foundation researcher Justin Drake.
I think the timing is telling. Bitcoin’s development community spent most of 2026 tearing itself apart over BIP-110, a proposal to limit data storage on-chain. Now the conversation is shifting to something far more existential.
Why P2MR Matters More Than You Think
The core vulnerability is elliptic-curve cryptography. Bitcoin’s ECDSA and Schnorr signatures rely on it. A sufficiently powerful quantum computer running Shor’s algorithm could derive private keys from public keys, allowing attackers to drain exposed wallets.
The exposure isn’t limited to old Pay-to-Public-Key outputs. Any address whose public key has been revealed through a previous spend is vulnerable. Transactions can also expose keys while waiting for confirmation, creating a shorter but still dangerous attack window.
BIP-360’s P2MR output would commit funds to a Merkle root, reducing long-term public-key exposure while providing a structure for future quantum-resistant signatures. But here’s the catch. P2MR alone wouldn’t protect against attacks during the period when spending reveals a vulnerable key. Its role is to create an upgrade path.
That’s where SHRINCS comes in. It’s a Blockstream Research proposal that relies on SHA-256 and combines two signing paths under one public key. For spending, its compact, stateful signatures start at 324 bytes, requiring wallets to track signing history. If that history disappears after a backup restoration, a larger, stateless signature provides a recovery path.
Sounds elegant, right? It’s not. SHRINCS remains experimental. Its formal security proof and independent review are incomplete.
The Governance Fight Nobody Wants
Here’s where it gets messy. BIP-360 is a draft. It’s not ready. The cryptography isn’t fully proven. And yet the pressure to move fast is mounting because quantum computers, while still years away from breaking Bitcoin, are advancing.
Jameson Lopp, Casa’s chief security officer, made the case bluntly in December 2025: “No, quantum computers won’t break Bitcoin in the near future. We’ll keep observing their evolution. Yet, making thoughtful changes to the protocol (and an unprecedented migration of funds) could easily take 5 to 10 years. We should hope for the best, but prepare for the worst”.
I think Lopp is right about the timeline. A migration of billions of dollars in exposed funds wouldn’t just be technically complex. It would require coordination across exchanges, custodians, wallet providers, and individual holders. It would increase demand for block space, raise fees, and create logistical nightmares for institutional custody arrangements.
But the real fight isn’t about whether to prepare. It’s about how.
The Quiet War Over Bitcoin’s Cryptographic Future
BIP-360 and SHRINCS represent two different philosophies. P2MR is a structural change, a new output type that creates an upgrade path. SHRINCS is a signature scheme, a new way to prove ownership.
Some developers argue that P2MR should come first, establishing the foundation before worrying about signatures. Others say the signature scheme is the real problem and should be solved before changing output formats. There’s no consensus on sequencing, no agreed-upon activation mechanism, and no clear timeline.
This is Bitcoin governance in 2026. The BIP-110 fight showed how quickly a technical disagreement can turn into a chain split and a public spectacle. The BIP editor who championed that proposal, Luke Dashjr, was removed from his role in August after a conflict-of-interest motion that passed in 26 hours with 31 GitHub approvals. The motion cited his conduct around BIP-110, including bypassing editorial procedures and favoring his own proposal.
I mention that not to relitigate BIP-110, but to illustrate the mood. The Bitcoin development community is exhausted. Trust is low. And now they’re being asked to make decisions about cryptography that could determine whether Bitcoin survives the next decade.
Who Decides When The Stakes Are This High?
Michael Saylor has framed protocol changes as a threat in themselves. In January 2026, he called the greatest risk to Bitcoin “ambitious opportunists advocating protocol changes”. He argued that Bitcoin’s primary defense is ossification, the refusal to change unless absolutely necessary.
That philosophy has served Bitcoin well for its first fifteen years. But quantum computing isn’t a spam attack. It’s not a debate about block space or data limits. It’s an existential threat that requires proactive engineering, not defensive ossification.
The Bitcoin development mailing list is buzzing with quantum proposals. There’s a draft BIP for 24 bits in the nVersion nonce space, proposals for minimum viable PQC protection without a fork, Falcon post-quantum signature schemes, and zk-STARK recovery methods for BIP-32 seeds. The energy is real.
But energy without consensus produces forks. And forks without broad support produce dead chains. Just ask the BLAKE2b minority chain, which lost 84% of its value after launching in September and is now locking newly mined coins for 45 days to stop miners from “blind hashing” the network into oblivion.
Summary
BIP-360 is a draft, and it should stay that way until the cryptography is proven and the community is ready. But the conversation it’s sparked is necessary. Bitcoin can’t afford to wait until quantum computers are on the doorstep to start planning its defense. The real test isn’t whether P2MR or SHRINCS becomes a BIP. It’s whether Bitcoin’s governance model, battered by a year of infighting, can still make hard decisions when the stakes are existential. I think it can. But the next few months will tell.
Comments
Please login to comment
Login