BIP-360-361 · Quantum resistance · Updated Apr 21, 2026

BIP 360 + BIP 361

Pay-to-Merkle-Root output type and a phased sunset of legacy signatures to address quantum-computing risk.

Draft / Contested
Affects ~6.7M BTC with exposed public keys
01 — Does it affect you?

Let's get the personal question out of the way.

Tell us roughly when and how you hold, and we'll tell you how exposed you are. No wallet connection, no tracking — this is a lookup, not a scan.

I hold bitcoin from
in a
address.
High risk · Before 2013 / P2PK (early)
Highest risk — zk-recovery likely unavailable

Your coins are in P2PK addresses with permanently exposed public keys and no BIP-39 seed. If BIP 361 activates, your only recovery hope is Phase C, which may not support early wallet formats. Move them to a modern wallet as soon as P2MR is available.

High risk · Before 2013 / Legacy (1…)
High risk — public key exposed on first spend

If you have ever spent from this address, your public key is visible on-chain. BIP 361's sunset would eventually freeze any coins still in legacy formats. Migrate to a P2MR-compatible wallet before Phase A.

High risk · Before 2013 / Taproot (bc1p…)
High risk — key-path spend exposed

Taproot key-path spends reveal your internal public key. BIP 360 removes this path entirely in P2MR. Re-send your taproot UTXOs to P2MR addresses once wallets support them.

Medium risk · Before 2013 / SegWit (bc1q…)
Medium risk — migrate before Phase A

SegWit v0 (P2WPKH) still uses ECDSA and will be sunset. You likely have a seed phrase, so zk-recovery may work in Phase C, but do not rely on it. Migrate proactively.

High risk · Before 2013 / Not sure
High risk — identify your wallet first

Pre-2013 wallets are almost certainly P2PK or early P2PKH. Both have exposed public keys. Treat this as highest risk until you confirm otherwise.

High risk · 2013 – 2021 / P2PK (early)
Highest risk — zk-recovery likely unavailable

Your coins are in P2PK addresses with permanently exposed public keys and no BIP-39 seed. If BIP 361 activates, your only recovery hope is Phase C, which may not support early wallet formats. Move them to a modern wallet as soon as P2MR is available.

Medium risk · 2013 – 2021 / Legacy (1…)
Medium risk — migrate before sunset

Standard P2PKH addresses are vulnerable once spent. You have time, but do not wait until Phase B. Move to a P2MR-compatible wallet well before the deadline.

High risk · 2013 – 2021 / Taproot (bc1p…)
High risk — key-path spend exposed

Taproot key-path spends reveal your internal public key. BIP 360 removes this path entirely in P2MR. Re-send your taproot UTXOs to P2MR addresses once wallets support them.

Low urgency · 2013 – 2021 / SegWit (bc1q…)
Low urgency — but verify your backup

You have a modern seed phrase and SegWit v0 outputs. The risk is manageable if you migrate before Phase A (~3 years post-activation). Use this time to verify your backup and wait for wallet support.

Medium risk · 2013 – 2021 / Not sure
Medium risk — check your address prefix

Addresses starting with '1' are P2PKH; 'bc1q' is SegWit; 'bc1p' is Taproot. If you don't know, check your wallet's receive history or use a block explorer.

High risk · 2021 or later / P2PK (early)
Highest risk — zk-recovery likely unavailable

Your coins are in P2PK addresses with permanently exposed public keys and no BIP-39 seed. If BIP 361 activates, your only recovery hope is Phase C, which may not support early wallet formats. Move them to a modern wallet as soon as P2MR is available.

Medium risk · 2021 or later / Legacy (1…)
Medium risk — migrate before sunset

Standard P2PKH addresses are vulnerable once spent. You have time, but do not wait until Phase B. Move to a P2MR-compatible wallet well before the deadline.

High risk · 2021 or later / Taproot (bc1p…)
High risk — key-path spend exposed

Taproot key-path spends reveal your internal public key. BIP 360 removes this path entirely in P2MR. Re-send your taproot UTXOs to P2MR addresses once wallets support them.

Low urgency · 2021 or later / SegWit (bc1q…)
Low urgency — verify backup and wait for wallets

You are in the best position: modern seed backup, plenty of time, and no exposed public keys if unspent. Verify your backup, watch for P2MR wallet support, and migrate casually before Phase A.

Medium risk · 2021 or later / Not sure
Medium risk — identify your address type

Most wallets created after 2021 default to SegWit or Taproot. Check your receive addresses: 'bc1q' = SegWit, 'bc1p' = Taproot, '1' = legacy P2PKH.

High risk · Not sure / P2PK (early)
Highest risk — zk-recovery likely unavailable

Your coins are in P2PK addresses with permanently exposed public keys and no BIP-39 seed. If BIP 361 activates, your only recovery hope is Phase C, which may not support early wallet formats. Move them to a modern wallet as soon as P2MR is available.

Medium risk · Not sure / Legacy (1…)
Medium risk — migrate before sunset

Standard P2PKH addresses are vulnerable once spent. You have time, but do not wait until Phase B. Move to a P2MR-compatible wallet well before the deadline.

High risk · Not sure / Taproot (bc1p…)
High risk — key-path spend exposed

Taproot key-path spends reveal your internal public key. BIP 360 removes this path entirely in P2MR. Re-send your taproot UTXOs to P2MR addresses once wallets support them.

Low urgency · Not sure / SegWit (bc1q…)
Low urgency — verify backup and wait

You likely have a modern seed phrase and unspent SegWit outputs. Risk is low if you migrate before Phase A. Use this time to verify your backup and wait for wallet updates.

Informational · Not sure / Not sure
How to identify your wallet

Open your wallet and check a receive address. '1...' = legacy P2PKH (medium risk). '3...' = P2SH (medium risk). 'bc1q...' = SegWit (low risk if unspent). 'bc1p...' = Taproot (high risk due to key-path). If your wallet was created before 2013 or you mined early coins, treat as highest risk.

Informational
How to identify your wallet

Open your wallet and check a receive address. '1...' = legacy P2PKH (medium risk). '3...' = P2SH (medium risk). 'bc1q...' = SegWit (low risk if unspent). 'bc1p...' = Taproot (high risk due to key-path). If your wallet was created before 2013 or you mined early coins, treat as highest risk.

The page never tells you what to do. This is the closest we come: a lookup of public information against the combination you described.
02 — Understand it

Read up to the level you need.

Four passes over the same proposal. Each one adds detail without contradicting the last. Expand the next tier when you want more.

Bitcoin uses math puzzles to prove you own your coins. A powerful enough quantum computer could solve some of those puzzles instantly, letting thieves steal from addresses whose public keys are visible on the blockchain. BIP 360 creates a new, safer address type that hides the risky piece. BIP 361 sets a timeline to slowly freeze the old, vulnerable coins so they can't be stolen — but also can't be spent by their owners unless they move them in time.

BIP 360 introduces Pay-to-Merkle-Root (P2MR), a new output type similar to Taproot but without the quantum-vulnerable "key-path spend." That means your public key is never revealed on-chain, closing the window for a quantum attacker to derive your private key.

BIP 361 is the migration plan. It sunsets legacy ECDSAThe original Bitcoin signature scheme. Quantum-vulnerable once the public key is revealed. and SchnorrTaproot's signature scheme. Also quantum-vulnerable when the public key is exposed. signatures in three phases after activation:

  • Phase A · year 3 no new deposits to vulnerable address types.
  • Phase B · year 5 legacy signatures become invalid; unmigrated coins are frozen.
  • Phase C · TBD a zero-knowledge recovery path for owners who still hold their seed phrases.

About 34% of all bitcoins have exposed public keys. The proposal does not recommend an algorithm yet; that will come in a follow-up BIP.

BIP 360 defines P2MR as a SegWit version 2 output using bech32m encoding (prefix bc1z). It preserves the full tapscript Merkle-tree semantics but omits the internal public key, eliminating the key-path spend entirely. All spends must provide a script path and Merkle proof. This removes the long-exposure attack surface where a public key sits visible on-chain indefinitely, while keeping compatibility with Lightning, BitVM, Ark, and complex custody scripts.

Trade-offs
  • P2MR spends are larger than P2TR key-path spends because they always reveal a script path and Merkle proof.
  • Fees are slightly higher, but the size increase is modest compared to typical post-quantum signature schemes.
  • It is a soft fork: non-upgraded nodes see P2MR outputs as anyone-can-spend, but upgraded nodes enforce the rules.

BIP 361 attaches a consensus-level sunset to legacy signature verification. Phase A is a relay/policy rule: standard nodes reject transactions that create new outputs to P2PK, P2PKH, P2WPKH, and P2TR key-path templates. Phase B is a consensus change: the script interpreter no longer accepts ECDSAThe original Bitcoin signature scheme. Quantum-vulnerable once the public key is revealed. or SchnorrTaproot's signature scheme. Also quantum-vulnerable when the public key is exposed. signatures for those legacy output types. Phase C proposes a zk-proof circuit tied to BIP-39 seed entropy, allowing owners to unlock frozen UTXOs into a P2MR output without revealing the original private key. The zk circuit is not yet specified.

The proposal explicitly does not choose a post-quantum signature algorithm. Authors expect a separate BIP for ML-DSA (Dilithium) or SLH-DSA integration. BIP 360 is therefore a preparatory structural change, not a complete post-quantum solution.

03 — The shape of it

Three phases, one clock.

The years are illustrative — activation hasn't happened and the clock starts from there, not today. What matters is the ordering.

now
year 0
year 3
year 5
TBD
year 0
Hypothetical activation
Soft fork lock-in. P2MR outputs (bc1z…) become spendable. Nothing freezes yet.
year 3 advisory
Phase A — no new deposits
Standard nodes reject new outputs to P2PK, P2PKH, P2WPKH, P2TR key-path. Existing coins are untouched.
year 5 freeze risk
Phase B — signatures invalid
Consensus change: ECDSA and Schnorr verifications stop succeeding for legacy output types. Unmigrated coins are frozen.
TBD recovery
Phase C — zk-recovery
A zero-knowledge circuit lets owners with BIP-39 seeds move frozen coins to P2MR. Not yet specified. Pre-2013 wallets likely excluded.
04 — Readiness

How close is this to actually happening?

A composite read, not a forecast. Every item below moves independently; today most of them are flat.

proposed drafting implementing signaling activated
8% — early draft
Core implementation None
Node signaling N/A
Prediction market No market yet
Historical analog Taproot took ~4.5 years from BIP to activation

Taproot took ~4.5 years from BIP to activation. BIP 360/361 has no reference implementation yet. If you are pricing urgency, price years, not months.

05 — Where it's contested

Four live disagreements, mapped by type.

Not all arguments are the same argument. The top row could in principle be resolved with evidence or shared definitions. The bottom row is genuinely unresolvable — reasonable people can disagree.

Resolvable
Definitional
Is it really a soft fork?
Some developers argue that disabling legacy signatures is a de-facto hard fork because it invalidates previously valid transactions. Others maintain that because the change only tightens validation rules for old output types, it fits the standard definition of a soft fork.
Same word, different meaning primary source →
Factual
Pre-2013 coins can't use zk-recovery
Satoshi-era P2PK outputs and early mined blocks have no BIP-39 seed phrase. Phase C's zk-recovery mechanism assumes modern wallet backups. If Phase B activates before Phase C is complete, those coins are frozen with no known recovery path.
Evidence could settle it primary source →
Irreducible
Values
Is freezing better than allowing theft?
The proposal frames freezing as a defensive measure: frozen coins slightly increase everyone else's purchasing power, whereas stolen coins destroy trust and value. Critics call this a taking of property rights, arguing that the network should not sacrifice individual ownership for collective security.
No single correct answer primary source →
Technical judgment
How urgent is the quantum threat?
Expert surveys estimate a 28–49% chance of a cryptographically relevant quantum computer within 10 years, but timelines vary wildly. Some argue that premature action burdens users now for a threat that may not materialize for decades; others point to Google's recent qubit advances and federal 2035 deadlines as evidence that preparation cannot wait.
Experts weigh trade-offs differently primary source →
06 — Who's saying what

Positioned, not ranked.

Author and critic sit on a For ↔ Against axis. Alternative proposals sit above it — they don't oppose, they reroute.

Alternative proposals Against For
JL
Jameson Lopp
Co-author, BIP 361
author
"I don't like it either. I wrote it because I like the alternative even less." Advocates a phased sunset as the least-bad defense against a quantum theft event.
Primary source →
CH
Charles Hoskinson
Founder, Cardano / IOG
critic
Characterized BIP 361 as authoritarian confiscation and argued that freezing coins violates the core social contract of Bitcoin. Suggested that user-driven migration is preferable to consensus-enforced freezes.
Primary source →
EB
Eli Ben-Sasson / StarkWare
Co-founder, StarkWare
alternative
Proposes replacing ECDSA with hash-based cryptography and STARK proofs (QSB/NTC), which could compress large post-quantum signatures into small on-chain footprints without freezing legacy coins.
Primary source →
BR
BitMEX Research
Research team
alternative
Proposed a "Canary Fund" reactive model: publish a quantum-vulnerable canary address; a valid spend from it triggers an emergency soft fork, avoiding premature freezes while preserving a rapid response option.
Primary source →