Quantum security firm Project Eleven has developed a tool to recover Bitcoin from wallets compromised by future quantum computers. The zero-knowledge proof allows owners to reclaim funds from wallets frozen under the proposed BIP-361 protocol. However, the tool only works for modern wallets created after 2012 and cannot save the estimated 1.1 million BTC belonging to Satoshi Nakamoto.
Project Eleven recovery tool
- ▪On a laptop, the proof generation takes 243 milliseconds, which is 16 times faster than a previous prototype
- ▪Quantum security startup Project Eleven has developed a tool to recover Bitcoin from wallets compromised by quantum computers
- ▪The tool is a zero-knowledge proof system developed with Jim Posen, lead developer of the Binius proof system
- ▪The tool is currently unaudited, supports three older Bitcoin address types but not Taproot, and is not yet accepted by any blockchain
Quantum computing threat
- ▪The theoretical point at which a quantum computer could break Bitcoin's encryption is known as "Q-Day"
- ▪Over 34% of all bitcoin sits in wallets with exposed public keys, making them vulnerable to quantum attacks
- ▪In 2026, Google's quantum research reduced the hardware required for such attacks by a factor of 20
- ▪Quantum computers using Shor's algorithm could derive a private key from a public key, allowing attackers to forge signatures
BIP-361 freeze proposal
- ▪Project Eleven's tool provides a potential recovery path, turning the proposed freeze from a "burn" into a "lock"
- ▪BIP-361, co-authored by Jameson Lopp, is a proposal to freeze quantum-vulnerable Bitcoin after a multi-year transition
- ▪A primary objection to BIP-361 was its lack of a recovery path, which would make the freeze permanent
- ▪The proposal would block deposits to vulnerable addresses after three years and freeze any remaining coins after five years
Zero-knowledge proof mechanism
- ▪The concept, called "signature lifting," was introduced by academics Or Sattath and Shai Wyborski in 2023
- ▪Only the true owner, who holds the master key, can produce the proof even after an address's private key is compromised
- ▪The mechanism works because quantum computers cannot reverse the one-way hashing used in modern wallet key derivation to find the master key
- ▪The recovery proof demonstrates ownership of a wallet's master key without revealing the key itself
Satoshi's inaccessible coins
- ▪An estimated 1.1 million BTC attributed to Satoshi are in "pay-to-public-key" outputs, making them highly vulnerable quantum targets
- ▪Satoshi's wallets, created in 2009-2010, generated each key independently and lack the master key and derivation path needed for the proof
- ▪The tool relies on the BIP-32 hierarchical wallet structure, which was introduced on February 11, 2012, after Satoshi had disappeared
- ▪The recovery tool cannot be used for coins belonging to Satoshi Nakamoto or other pre-2012 wallets
Story comments
Loading comments…