Project Eleven develops quantum-proof Bitcoin recovery tool for compromised wallets
Quantum security firm Project Eleven has developed a tool to recover Bitcoin from wallets compromised by future quantum computers. The zero-knowledge proof allows owners to reclaim funds from wallets frozen under the proposed BIP-361 protocol. However, the tool only works for modern wallets created after 2012 and cannot save the estimated 1.1 million BTC belonging to Satoshi Nakamoto.
Project Eleven recovery tool
▪On a laptop, the proof generation takes 243 milliseconds, which is 16 times faster than a previous prototype.
▪Quantum security startup Project Eleven has developed a tool to recover Bitcoin from wallets compromised by quantum computers.
▪The tool is a zero-knowledge proof system developed with Jim Posen, lead developer of the Binius proof system.
▪The tool is currently unaudited, supports three older Bitcoin address types but not Taproot, and is not yet accepted by any blockchain.
Quantum computing threat
▪The theoretical point at which a quantum computer could break Bitcoin's encryption is known as "Q-Day".
▪Over 34% of all bitcoin sits in wallets with exposed public keys, making them vulnerable to quantum attacks.
▪In 2026, Google's quantum research reduced the hardware required for such attacks by a factor of 20.
▪Quantum computers using Shor's algorithm could derive a private key from a public key, allowing attackers to forge signatures.
BIP-361 freeze proposal
▪Project Eleven's tool provides a potential recovery path, turning the proposed freeze from a "burn" into a "lock".
▪BIP-361, co-authored by Jameson Lopp, is a proposal to freeze quantum-vulnerable Bitcoin after a multi-year transition.
▪A primary objection to BIP-361 was its lack of a recovery path, which would make the freeze permanent.
▪The proposal would block deposits to vulnerable addresses after three years and freeze any remaining coins after five years.
Zero-knowledge proof mechanism
▪The concept, called "signature lifting," was introduced by academics Or Sattath and Shai Wyborski in 2023.
▪Only the true owner, who holds the master key, can produce the proof even after an address's private key is compromised.
▪The mechanism works because quantum computers cannot reverse the one-way hashing used in modern wallet key derivation to find the master key.
▪The recovery proof demonstrates ownership of a wallet's master key without revealing the key itself.
Satoshi's inaccessible coins
▪An estimated 1.1 million BTC attributed to Satoshi are in "pay-to-public-key" outputs, making them highly vulnerable quantum targets.
▪Satoshi's wallets, created in 2009-2010, generated each key independently and lack the master key and derivation path needed for the proof.
▪The tool relies on the BIP-32 hierarchical wallet structure, which was introduced on February 11, 2012, after Satoshi had disappeared.
▪The recovery tool cannot be used for coins belonging to Satoshi Nakamoto or other pre-2012 wallets.
Story comments
Loading comments…