A quantum-security startup called Project Eleven has released a zero-knowledge proof system built to sit alongside BIP-361, the draft proposal that would eventually freeze bitcoin parked in legacy addresses exposed to quantum computing attacks. The system gives holders a way to prove they own frozen funds using their BIP-39 seed phrases, and it does this without ever revealing their private keys. On paper, that solves one of the ugliest problems with any freeze plan: how do you give people back coins the network has locked, without forcing them to expose the very keys a quantum attacker would want?
The catch is that the tool has a hard limit. It cannot help the network's most famous holder. Roughly 1.1 million BTC attributed to Satoshi Nakamoto fall entirely outside its reach, and the reason is baked into how those coins were created.
Why Satoshi's Coins Fall Outside the Recovery Path
Project Eleven's approach leans on BIP-39 seed phrases as the mechanism for proving ownership. Satoshi's bitcoin was mined long before seed phrases became a standard, so there is nothing for the system to verify against. The wallets predate the entire framework the tool depends on.
Cardano founder Charles Hoskinson flagged this incompatibility earlier in the year. He pointed out that a very large slice of exposed coins — around 1.7 million, including Satoshi's roughly 1.1 million — simply can't be reclaimed through any seed-based scheme, because those pre-2013 wallets were never built around one. It isn't a matter of building a better tool. The recovery model and the oldest wallets speak different languages.
Inside BIP-361: A Three-Phase Plan to Retire Legacy Signatures
BIP-361 was submitted to the Bitcoin BIPs repository by Casa Chief Security Officer Jameson Lopp and five co-authors. It sets out a staged plan to phase out legacy ECDSA and Schnorr signatures, the signature types most exposed to a future quantum attack.
The proposal moves in three parts:
- Phase A would begin roughly three years after activation. It stops new transactions from sending funds into quantum-vulnerable addresses, cutting off fresh exposure without touching existing balances yet.
- Phase B, arriving two years after Phase A, goes further. It invalidates all legacy signatures at the consensus level, which effectively freezes any coins that haven't been migrated to a safer address type by then.
- Phase C is still exploratory. This is where the zero-knowledge recovery path lives — the route Project Eleven has now prototyped — giving stranded holders a way to reclaim frozen funds after the freeze takes hold.
The order of events is important. The freeze isn't meant to catch anyone off guard; it comes with plenty of advance notice, giving holders years to move their coins before signatures stop working. The recovery tool acts as a safety net for anyone who misses that time frame.
The BIP-360 Foundation
None of this stands on its own. BIP-361 builds on BIP-360, which was merged into Bitcoin's official BIP repository earlier in the year. BIP-360 introduces an optional quantum-resistant address type known as Pay-to-Merkle-Root. Crucially, it carries no freeze mechanism at all — it simply gives holders a safer place to move their coins, entirely by choice.
That distinction is the heart of the debate. BIP-360 offers a door. BIP-361 is the proposal that would eventually close the old one behind everyone. BTQ Technologies has already put BIP-360 through its first working run, deploying an implementation on a testnet.
A Community Split Over Freezing Dormant Coins
The idea of freezing dormant bitcoin has divided the community, and the fault line is philosophical as much as technical.
Binance founder Changpeng Zhao floated a much shorter timeline on a recent podcast, suggesting a migration window of six to twelve months rather than the multi-year runway BIP-361 describes. On the other side sit people who argue the network shouldn't touch property rights at the protocol level at all — that Bitcoin should accept the risk of quantum theft rather than freeze coins their owners never consented to lock, even if some of those owners are gone for good.
The scale of the exposure is what keeps the argument alive. According to CoinDesk, more than 34 percent of all bitcoin sits in addresses where the public key is already visible on-chain. Those addresses become theoretically vulnerable the moment quantum computers reach sufficient scale, because a visible public key is exactly what a quantum attacker would need to derive the private one.
For now, the whole discussion remains hypothetical in the most important sense. BIP-361 is still a draft. It has no activation timeline and no formal path to adoption. The recovery tool, the phases, the freeze — all of it hinges on a proposal the network hasn't agreed to, and may never agree to in this form.

