# Researchers Publish a Bitcoin Recovery Tool for the Quantum Era, With One Large Exception

Project Eleven says its proof lets a wallet's own key-derivation path serve as proof of ownership after quantum machines can forge signatures, running in 243 milliseconds on a laptop.

- Published: 2026-07-20T05:27:14.675Z
- Canonical: https://polylog.news/crypto/2026-07-20/researchers-publish-a-bitcoin-recovery-tool-for-the-quantum
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/07/19/bitcoin-s-quantum-problem-gets-a-recovery-tool-but-not-for-satoshi-s-1-1-million-coin)

A research group called Project Eleven says it has funded a working proof that could let Bitcoin owners reclaim funds even after a sufficiently powerful quantum computer can forge the signatures that currently protect them. The [scheme](https://www.coindesk.com/tech/2026/07/19/bitcoin-s-quantum-problem-gets-a-recovery-tool-but-not-for-satoshi-s-1-1-million-coin) lets a wallet's own key-derivation path, the deterministic recipe used to generate its addresses, serve as evidence of ownership, so a legitimate holder can prove control without exposing a signature a quantum attacker could copy. The group reports that the proof runs in 243 milliseconds on a laptop.

The tool has a clear limit. It cannot protect coins whose public keys are already fully exposed on-chain, which includes the roughly 1.1 million coins associated with Bitcoin's pseudonymous creator, Satoshi Nakamoto, held in an early address format that reveals the public key directly. Those balances would remain vulnerable to a future quantum adversary because the mathematical target is already visible.

The work moves quantum resistance from a theoretical concern into a concrete design question for wallets and custodians. It also brings forward a debate the network has avoided: what happens to long-dormant coins that no one can or will migrate to a safer scheme, and whether the community would ever endorse freezing exposed balances rather than letting an attacker seize them.

## What this means

Quantum risk is becoming a custody engineering problem rather than a distant abstraction, and the exposure is uneven. Holders who move funds to derivation-path-based recovery could be protected, while owners of old exposed-key addresses, including dormant early coins, cannot be, which concentrates the risk on the least active supply. The channel of loss is signature forgery, and the parties exposed are custodians and long-term holders who never migrate address formats.

## What to watch

- Whether major wallets and institutional custodians adopt derivation-path recovery or opt-in post-quantum signatures, which would show the industry treating the threat as operational.
- Any Bitcoin improvement proposal to handle exposed dormant coins, since a freeze-versus-seize debate would test the network's willingness to alter balances.
