Coinbase, Stanford University cryptographers Dan Boneh and Localhost Research recently held a post-quantum seminar on Bitcoin at Stanford. On September 9th, the key points of the conference were announced: participants included Bitcoin developers, cryptography researchers, institutional custodians, and hardware wallet experts. The discussions covered advancements in quantum computing, post-quantum signature schemes, potential new output types, operational requirements for institutions, and how those who did not migrate their assets in time should proceed. The official positioning of the conference was very modest; it was not about releasing new protocols, nor was a final algorithm chosen. Instead, it served as a working meeting to sort out the constraints in advance.
The ownership of Bitcoin relies on digital signatures. Current elliptic curve signatures are highly secure against classical computers, but theoretically, a sufficiently powerful fault-tolerant quantum computer could use the Shor algorithm to derive the private key from the public key. No one can provide a reliable timeline for when such a capability will become available, and today's quantum devices do not pose an immediate threat as described by Coinbase. The problem is that both Bitcoin upgrades and user migrations are very slow. If we wait until the threat becomes a reality before starting to coordinate, it will be difficult for protocols, wallets, exchanges, and long-term offline coin holders to complete a secure transition in a short period of time.
The signature scheme is just the first hurdle; transaction volume and hardware constraints will affect system costs.
There are indeed candidate solutions for post-quantum cryptography, but each comes with its own set of trade-offs. Some of these solutions result in public keys or signatures that are significantly larger than those used in Bitcoin, which can increase the size of transactions, the amount of space occupied by blocks, and the computational burden for verification. Other solutions have particular requirements regarding the number of signatures that can be generated, the management of random numbers, or the storage of state information. Still others may be feasible in software, but they could exceed the limited computational power and storage capacity of hardware wallets. Simply comparing the security levels mentioned in academic papers is not enough to determine which solution is suitable for a public network that requires verification by nodes around the world.
The output type is one of the key focuses of the seminar discussions. Bitcoin can adopt post-quantum protection gradually for users who wish to do so through new scripts or output formats, rather than replacing the entire network's rules all at once. This gradual approach reduces coordination risks, but it also results in a long period of coexistence: old addresses, new addresses, exchange recharge systems, hosting strategies, and wallet backup methods all need to be supported simultaneously. How nodes will identify new transactions, how fees will be calculated, and how old software will handle new transactions all require extensive testing before deployment.
What is truly sensitive are assets whose public keys have been exposed, but for which the holders have not taken any action for a long time. Bitcoin addresses usually only display the public key hash before a transaction is made; however, addresses that are reused or certain early outputs may expose the public key earlier. If the threat of quantum computing gradually approaches, active users can migrate their assets, but those who have lost their private keys or have been offline for many years will not take any proactive action. The community must face a difficult choice: whether, when, and with what rules to restrict older outputs, in order to prevent quantum attackers from stealing assets without arbitrarily depriving legitimate holders. Any approach will involve both technical and social consensus.
Institutional hosting further exacerbates the complexity of migrations. Large hosting providers employ multi-layered approval processes, cold and hot wallets, hardware security modules, geographically dispersed backups, and auditing systems. Replacing the signature system involves not only generating new addresses but also re-verifying devices, modifying policy engines, training personnel, arranging on-chain transfers, and proving to customers that their assets are still under control. During migration periods, large-scale concentrated transactions can also expose the operational rhythm, leading to transaction fees and liquidity pressures. Seminars bring hosting providers and protocol developers together precisely to avoid designing solutions that are mathematically secure but impractical in operation.
The value of preparing in advance lies in having time for testing and reconsideration.
The first consensus point summarized by Coinbase is: rather than predicting the exact date of the arrival of quantum computers, it is more important to ensure that a credible and thoroughly tested plan is in place in advance. The history of password migrations shows that standard establishment, library implementation, hardware support, application adaptation, and user upgrades often take many years. Bitcoin also lacks a central operator, and any change to the consensus rules must go through development, review, testing, and adoption by miners and nodes. The earlier compatibility and fault tolerance drills begin, the less need there will be to make hasty decisions in the midst of market panic in the future.
This also means that “quantum resistance upgrades” are more likely to be a process rather than a single event at a certain block height. The community can first standardize candidate signatures, establish test vectors and benchmarks, then verify transaction volume, node performance, and wallet interactions on the test network. Subsequently, they can discuss whether to activate new types of voluntary outputs. When research is more mature, the ability to replace earlier candidates should still be retained. Coinbase states that there is currently no perfect solution, and no specific consensus has been reached on the ground. This is not a failure, but an honest acknowledgment that the technology is still evolving.
For ordinary coin holders, there is no need to hastily move assets due to this seminar at this time, and certainly not to believe in marketing claims that "quantum cracking has occurred." Realistic risks still include the leakage of mnemonic phrases, phishing attacks, malicious signatures, theft of exchange accounts, and unreliable hosting services, which are far more imminent than quantum attacks. A reasonable approach is to use wallets that are still being maintained, avoid reusing addresses, pay attention to official upgrade announcements from mainstream clients and development communities, and remain vigilant against any unfamiliar messages that urge immediate transfer of coins to "quantum-resistant addresses."
For industry companies, preparations can start with not changing user assets: identifying which types of addresses may expose public keys, assessing the support of managed devices for candidate algorithms, testing the impact of larger signature sizes on fees and throughput, establishing a list of password agility requirements, and clarifying decision-making authority in the event of quantum risk upgrades. Exchanges also need to consider compatibility with deposits and withdrawals, on-chain monitoring, and customer communication. Hardware wallet manufacturers need to assess whether existing chips can be supported through firmware updates or whether device replacements are necessary.
The most important signal from this meeting is not that Coinbase has mastered some secret scheme, but rather that the Bitcoin ecosystem has begun to break down a long-standing theoretical risk into specific issues related to protocols, hardware, hosting, and user migration. The goal of post-quantum preparedness is not to create a sense of urgency, but to give the community enough time to compare different schemes, identify failure modes, and make corrections for wrong choices. It is still unknown when quantum computing will cross the threshold of posing a threat, but whether a decentralized financial network has the capability to smoothly migrate from the old cryptographic system can be verified starting today.












