Satoshi Nakamoto’s Coins Likely Irrecoverable Despite New Proof
Satoshi Nakamoto’s Coins Likely Irrecoverable Despite New Proof
Developer Jim Pozen and Project Eleven unveiled a prototype that uses zero-knowledge proofs to recover bitcoins exposed to quantum risks.
Quantum threat and scope
A quantum computer applying Shor’s algorithm could in theory derive a private key from its public counterpart and forge transaction signatures.
Analysts estimate that more than 34% of all bitcoins are currently at risk if such capabilities become practical.
Proposed mitigations
One community proposal, BIP-361, suggests freezing wallets judged vulnerable to quantum computation to prevent theft before migration.
Pozen’s tool instead generates a zero-knowledge proof that demonstrates knowledge of key material above a wallet address in an HD derivation tree, specifically referencing BIP-32 and HMAC-SHA512.
The proof is bound to a migration transaction and does not reveal private keys, preserving custody while enabling controlled transfer to safer addresses.
Performance and limitations
Reported performance metrics state proof generation takes 243 milliseconds and verification 40 milliseconds, using about ~2 GB of memory and no GPU.
According to the developers, this approach turns an irreversible burn into a reversible lock, provided the owner retains the original seed phrase.
Satoshi coins and deployment status
Approximately 1.1 million BTC mined in 2009–2010 predate the BIP-32 standard introduced in February 2012 and therefore lack a derivation tree to prove.
Those coins reside in pay-to-public-key outputs with exposed public keys, so the proposed proof cannot be produced for them and they will likely remain inaccessible.
The prototype has not undergone public audit nor been deployed on any live blockchain, though several prominent figures in the crypto sector have expressed cautious support for the concept.
Related posts

