Code executes exactly as written, not as intended. For Bitcoin, the intended execution path toward post-quantum security is currently an empty whiteboard. BIP-361, drafted by Jameson Lopp, is a proposal to migrate Bitcoin signatures to a quantum-resistant alternative. It has no code, no testnet, no activation window. It is a placeholder for a problem nobody wants to think about until the market forces them to.
Context: The Silence Before the Storm
BIP-361 is a draft. It exists in the Bitcoin Improvement Proposal repository as a signal, not a solution. The author, Jameson Lopp, is CTO of Casa, a respected voice in the Bitcoin ecosystem. The proposal outlines the need to transition from ECDSA (vulnerable to Shor's algorithm) to a post-quantum signature scheme. It does not specify which scheme. It does not provide migration paths for old UTXOs. It does not address the 4.8 million BTC estimated in lost or dormant addresses. It is a conversation starter. But in a bull market, conversations are dangerous because they distract from the code.
Based on my audit of the 0x protocol v2 in 2017, I learned that deceptive metrics often mask systemic flaws. Here, the flaw is not deception but absence—the absence of any concrete path. BIP-361 is a ghost in the machine: it signals intent without substance. The market has priced this at exactly zero. That is correct for today. But history repeats, and the code changes the syntax.
Core: Systematic Teardown of a Ghost Proposal
Let me be clinical about what BIP-361 actually contains. It is 1,200 words of problem statement. Zero lines of code. Zero references to specific post-quantum algorithms such as SPHINCS+, CRYSTALS-Dilithium, or FALCON. Zero discussion of signature sizes (Lamport signatures are 8192 bytes vs. ECDSA's 72 bytes) or verification gas costs. The proposal claims 'phased migration,' but phases are undefined. This is not a technical document. It is a governance artifact.
Technical Vacuum
The proposal ignores three critical areas:
- Signature Choice: Every post-quantum scheme has trade-offs. Lattice-based (Dilithium) requires larger signatures but faster verification. Hash-based (SPHINCS+) has even larger signatures. Zero-knowledge STARKs are powerful but computationally heavy. BIP-361 chooses none. According to my DeFi lending vulnerability audit in 2020, undefined parameters are the root cause of cascading failures. Here, the undefined parameters could trigger a network-wide split if two competing signature schemes gain community support.
- UTXO Migration: There are approximately 80 million Bitcoin addresses with non-zero balances. Roughly 25% of those have not been active in over five years. BIP-361 proposes no mechanism to force migration. If a user loses their private key, their coins become unspendable after a 'signature sunset.' That is a permanent supply shock. Based on my NFT utility vacuum exposé in 2021, I learned that avoiding hard questions about asset rights leads to legal battles. Bitcoin's legal foundation rests on the assumption that private keys equal ownership. Any proposal that undermines that trust without consensus is a systemic risk.
- Consensus Upgrade Procedure: BIP-361 suggests a soft fork. Soft forks require 95% miner approval. Achieving that for a technical change with no immediate benefit (quantum computers are not yet a real threat) is politically impossible. The Ethereum community took three years to implement EIP-1559, which had clear economic incentives. BIP-361 has no incentive. Miners gain nothing. Users gain nothing except the abstract feeling of preparedness. Utility is the vacuum where hype goes to die. This proposal has zero utility today.
Risk Quantification
Let me put numbers on this. The NIST (National Institute of Standards and Technology) is expected to finalize post-quantum standards in 2024. Even then, industry adoption takes 5-10 years. The probability of a quantum computer breaking ECDSA within the next decade is estimated at <5% by leading cryptographers like Bruce Schneier. The probability of a Bitcoin community consensus on a migration path within that same period? Lower, given the history of contentious upgrades (BIP-101, SegWit2X). BIP-361 is a hedge against a tail risk that is likely not real for 20 years, but the cost of implementing it poorly is a fork, a supply shock, or both. The risk-reward ratio is asymmetric: the upside is slightly enhanced long-term confidence; the downside is network fragmentation.
Governance Paralysis
Based on my experience auditing the Compound finance interest rate model, I learned that edge cases in decentralized systems are often ignored until they manifest. BIP-361's edge case is the treatment of 'lost' coins. The proposal mentions 'handling old addresses and dormant wallets' but provides no technical or social solution. If the migration ultimately requires users to voluntarily move funds, millions of BTC will remain in legacy addresses, creating a two-tier Bitcoin ecosystem: one with quantum-safe signatures, one without. That is not a network. That is a schism.
Contrarian: What the Bulls Got Right
The proposal exists. That is a positive signal. Bitcoin's governance is often criticized as slow, but that slowness is a feature, not a bug. BIP-361 demonstrates that the core developers are thinking decades ahead. In a market obsessed with quarterly returns, that long-term perspective is valuable. The contrarian angle here is that the very absence of detail is a strength: it allows the community to debate the hardest problems without being locked into a rigid solution. The author, Lopp, explicitly states this is a 'discussion starter.' In the context of Bitcoin's history, every major upgrade (SegWit, Taproot) started as a draft that took years to refine. Rushing would be worse.
Furthermore, the narrative of 'quantum threat' is overblown by some, but the proposal itself is measured. It does not claim imminent doom. It calls for planning. If you believe in Bitcoin as a long-term store of value, you must believe in its capacity to evolve. BIP-361 is evidence of that evolution. The bulls are correct that this is a sign of network maturity, not weakness.
Takeaway: The Clock Is Ticking, but Nobody Winded It
BIP-361 will likely remain a draft for years. It may never activate. The real test will come when a quantum breakthrough becomes newsworthy—when Google announces a 1,000-qubit error-corrected machine, or when the first real-world attack on an RSA key is demonstrated. At that moment, the Bitcoin community will scramble. And they will look back at BIP-361 as either a missed opportunity or a foresight that saved the network.
I have been in this industry long enough to know that the most dangerous proposals are not the ones with flawed code. They are the ones without code. BIP-361 is a warning, not a plan. Treat it as such.
Chaos reveals itself only when the noise stops. The noise today is bullish. The code has not changed. The next cycle may not be so kind.