News/Bitcoin/Project Eleven’s 243ms Quantum Proof Can’t…
Bitcoin

Project Eleven’s 243ms Quantum Proof Can’t Unlock Satoshi’s 1.1M BTC

A new 243-millisecond zero-knowledge proof lets owners reclaim quantum-exposed BTC — but Satoshi's 1.1 million coins stay frozen under BIP-361.

Project Eleven’s 243ms Quantum Proof Can’t Unlock Satoshi’s 1.1M BTC

Quantum research firm Project Eleven says it has funded a zero-knowledge proof that runs in just 243 milliseconds on a laptop, giving Bitcoin holders a practical way to reclaim coins if quantum computers ever become capable of forging their signatures. The catch: it cannot help the roughly 1.1 million BTC attributed to pseudonymous creator Satoshi Nakamoto, which would remain locked out of any recovery under a related proposal circulating among developers.

The tool is designed to work alongside BIP-361, a proposal published in April by Bitcoin developer Jameson Lopp and five co-authors. That plan would block new deposits to quantum-vulnerable addresses after three years and freeze whatever balances remain in them after five years — a category that currently covers more than a third of Bitcoin’s entire circulating supply, or over 34% of all coins in existence.

How the 243ms proof works

The core insight behind Project Eleven’s system is that a future quantum computer capable of breaking Bitcoin’s elliptic curve signatures still cannot break the one-way hashing used in modern hierarchical deterministic wallet key derivation. That asymmetry lets a real owner generate a zero-knowledge proof showing they control the seed material behind a wallet’s derivation path — without ever exposing the seed itself — even after an attacker has forged the address’s public signature.

Benchmarked at 243 milliseconds per proof on standard laptop hardware, Project Eleven’s prototype is described as dramatically faster than prior attempts at similar zero-knowledge recovery schemes. Speed matters here because any real-world deployment would need to process proofs for a large share of Bitcoin’s roughly 34%-plus vulnerable supply without creating network bottlenecks.

Why Satoshi’s 1.1 million BTC stay out of reach

The recovery mechanism only works for wallet owners who still hold the original seed material tied to a key-derivation path. Satoshi Nakamoto’s holdings — estimated at 1.1 million BTC and untouched since Bitcoin’s earliest years — predate the HD wallet standards the proof relies on, and there is no evidence anyone retains the seed data needed to generate a valid proof of ownership.

That means even if BIP-361’s freeze-and-recover framework were adopted exactly as designed, Satoshi’s coins would sit permanently outside any reclaim path once a genuine “Q-Day” — the theoretical point at which a quantum computer can derive a private key from an exposed public key — arrives.

Still unaudited, still theoretical

Project Eleven’s proof system remains unaudited and incomplete, and nothing about it changes Bitcoin’s consensus rules today. Implementing BIP-361 alongside a working recovery mechanism would require a contentious protocol change accepted by miners, node operators and the broader community — a process with no fixed timeline and a history of disagreement over how aggressively Bitcoin should respond to a threat that has not yet materialized.

For holders, the practical takeaway is narrower than the headline suggests: a faster proof-of-concept exists for reclaiming quantum-exposed coins, but it protects only wallets whose owners still have their original seed phrases — leaving the largest single pile of vulnerable Bitcoin, Satoshi’s own stash, permanently outside the fix.

Read more: Strategy’s 843,775 BTC Sits at 15% Paper Loss as Saylor Teases “What’s Next”

Sources

Related articles