Full story
BIP-361 Freeze, Then Proof
Bitcoin’s quantum problem is getting a recovery tool, but Project Eleven says it does not cover Satoshi Nakamoto’s roughly 1.1 million BTC attributed holdings under BIP-361.
“Bitcoin’s quantum problem gets a recovery tool, but not for Satoshi’s 1”
CoinDesk says BIP-361, published in April by Jameson Lopp and five co-authors, would block new deposits after three years and freeze whatever remained after five, stranding coins in more than a third of bitcoin’s supply.

CoinDesk also describes Q-Day as a theoretical point where a quantum computer could derive a private key from a public key, letting an attacker sign transactions from any address whose public key has ever been exposed.
The same CoinDesk account says Project Eleven built a zero-knowledge proof that lets a user prove they know key material above an address in a wallet’s derivation tree without disclosing any key material.
CoinDesk adds that the prototype is unaudited and “recovers nothing on any live blockchain as of today.”
Benchmarks and Limits
Project Eleven’s prototype is presented with concrete performance figures, including that generating the proof takes 243 milliseconds on an M5 MacBook Air using four CPU cores and verification takes 40 milliseconds.
CoinDesk says the whole process uses about 2 gigabytes of memory and no GPU at all, and that Project Eleven’s CPU-only run counts circuit construction, proof generation and self-checking in 910 milliseconds.

DailyCoin similarly reports that Project Eleven announced on July 15, 2026 that it had developed a faster zero-knowledge proof prototype and that it generated proofs in 243 milliseconds and verified them in 40 milliseconds on an Apple M5 MacBook Air using four CPU cores and no GPU acceleration.
DailyCoin also states that Project Eleven reported peak memory usage of 2.1 GB and a proof size of 358 KiB, while describing the release as an early, unaudited prototype.
CoinDesk frames the core limitation as structural: the recovery method depends on there being a key above a user’s address in a tree, and it says Satoshi’s coins sit in pay-to-public-key outputs with the public key written directly onchain, with “There is nothing above them in a tree, because trees did not exist yet.”
What Changes, What Doesn’t
The recovery approach is described as a way to make BIP-361’s freeze more reversible for holders who can prove upstream ownership, but it still leaves the oldest coins outside the mechanism.
“The proposal to freeze bitcoin's quantum-vulnerable coins has always carried an asterisk”
CoinDesk says the objection to freezing coins assumes the freeze is final, and that a working recovery proof would make the freeze a lock rather than a burn, while also noting that “Satoshi never had one.”
FinanceFeeds describes how BIP-361 targets coins on addresses whose public keys have already been exposed on-chain, and it says this category accounts for more than 34% of the Bitcoin supply including about 1.1 million BTC attributed to Satoshi Nakamoto.
FinanceFeeds also says the recovery path depends on hierarchical deterministic key trees and enhanced derivation steps that use HMAC-SHA512 to produce child keys from parent key material.
Both sources converge on the stakes: CoinDesk says the prototype would require “contentious changes to blockchain rules before it could protect any live coins,” and FinanceFeeds says the prototype is not audited and currently recovers no coins on a production blockchain.



