How does a network build a rescue mechanism for coins it cannot legally define as lost, without accidentally rescuing the ones nobody wants moved? That is the actual question underneath the quantum-recovery proposal now circulating through Bitcoin developer channels. The number that matters is 1.1 million — the coin count attributed to wallets mined in the first eighteen months of the network, sitting in address formats the proposal explicitly cannot touch. Not because of malice. Because of a key-derivation choice made in January 2009 that predates every recovery primitive the proposal relies on. The exclusion is architectural, and it is being reported as a scandal.
January 2009: The Coins That Cannot Be Moved Were Mined With a Key Format That Cannot Be Rescued
Let me concede something upfront. The reporting is not technically wrong. Any quantum-recovery mechanism designed for Bitcoin in 2026 will, in fact, leave Satoshi's coinbase outputs exposed. That much is true. What the reporting misses is that this outcome was decided in the first eighteen months of the network's existence, before Satoshi disappeared, and before anyone was writing rescue primitives for anything.
The wallets in question are Pay-to-Public-Key outputs. P2PK. Not P2PKH — that is the important distinction and the one every headline glosses. In a P2PK output, the receiving script contains the full uncompressed public key, sitting in plaintext on the ledger, permanently visible to anyone who wants to scrape the chain. A future adversary running Shor's algorithm against a sufficiently large quantum computer does not need to wait for the coins to move. The key is already there.
Every recovery proposal circulating in Bitcoin developer channels shares a common assumption: the vulnerable output must be resigned by its rightful owner using a post-quantum signature scheme, within some grace window, before an attacker can construct the equivalent classical signature. That assumption works for owners who are alive, aware, and holding keys. It does not work for coins whose owner is functionally absent from the network and whose keys have not moved in fifteen years.
The pattern you see in the wallet-age data is unambiguous. Coins mined before mid-2010 that have never transacted are, by any reasonable actuarial framing, coins whose keys are gone. Rescuing them and putting them under the control of whoever files the resignation first is not recovery. It is confiscation with extra steps.
July 2010: The P2PKH Migration That Split Bitcoin Into Two Cryptographic Populations
The migration from P2PK to Pay-to-Public-Key-Hash was quiet at the time. It was a small optimization: instead of storing a 65-byte uncompressed public key in the output script, store a 20-byte hash of the key. Smaller outputs, smaller blocks, cheaper storage. That was the marketed benefit.
The unmarketed benefit turned out to matter more. In a P2PKH output, the public key is not revealed on the chain until the moment the coin is spent. Between the moment of receipt and the moment of spending, an observer sees only the hash. A quantum adversary running Shor's algorithm needs the public key itself, not the hash, to derive the private key. The hash buys the wallet a partial defense — the address is quantum-safe until the first time it is used to spend.
By late 2010 essentially all new wallet software was generating P2PKH addresses by default. The user-facing change was invisible. The cryptographic consequence was that Bitcoin's UTXO set fractured into two populations: pre-migration outputs where the public key was exposed on-chain forever, and post-migration outputs where the public key was hidden behind a hash until spending revealed it.
The public record shows the pre-migration cohort is small, static, and dominated by early coinbase rewards mined at the 50 BTC subsidy tier. That is the population where Satoshi's estimated 1.1 million coins sit. Every recovery proposal being drafted in 2026 has to decide what to do about outputs where the public key is already visible on-chain, has been visible for over a decade, and where any rescue mechanism cannot distinguish the rightful owner from an attacker who spends a year building a resignation payload.
I think the honest answer is what the current proposal does: it excludes them. That is not a bug. That is the only intellectually defensible position for a rescue mechanism that has no way to verify claimant identity.
October 2022: The FTX Collapse Rewrote What "Recoverable" Means to a Retail Holder
The reason the current quantum-recovery discourse reads the way it does — as a scandal, as an exclusion, as a governance failure — is downstream of a shift in retail expectations that has nothing to do with cryptography and everything to do with FTX.
Before November 2022, "recoverable" in the Bitcoin context meant "the keys still work if you can find them." The seed phrase, the paper wallet, the encrypted USB stick in the drawer. Recovery was a personal-custody problem, and the network did not owe you a rescue. That was the culture. It was harsh, but it was consistent.
FTX inverted the frame. Overnight, the definition of "recoverable" shifted to include coins where the user had done nothing wrong except deposit on an exchange that lied about its reserve position. Public postmortems from the bankruptcy proceedings put the shortfall in the multi-billion range, with retail creditors receiving fractional distributions denominated in petition-date USD rather than in-kind BTC. The message that got absorbed, correctly or not, was that "your coins" is a phrase with more asterisks than the culture had previously admitted.
That shift matters here. The reader who now sees a headline about "Bitcoin's quantum recovery tool skipping Satoshi's 1.1 million coins" is not reading it through a 2010 lens. They are reading it through a post-FTX lens where recovery is expected to be a systemic property, where exclusion reads as unfairness, and where the technical reason for the exclusion is often not investigated before the outrage is published.
The Trustpilot rating gap between Binance at 2.3 and Bybit at 4.5 is a downstream artifact of the same shift. Retail no longer distinguishes between exchange failure risk and protocol-level rescue failure. Both read as "the system did not protect me." A quantum recovery mechanism that structurally cannot touch pre-migration outputs walks into that expectation gap headfirst.
March 2025: The Proof-of-Reserves Cycle That Exposed Which Exchanges Still Custody Legacy Formats
The March 2025 proof-of-reserves cycle is worth looking at carefully, because it produced the first public snapshot of how the largest custodians treat pre-P2PKH outputs — and the answer, quietly, is that most of them do not custody any.
Per the GROUNDING CONTEXT, Binance's last audit landed on 2025-03-01 with reserves marked verified and a security score of 9.4. OKX also audited on 2025-03-01, verified, score 9.3. Bybit followed on 2025-03-12, verified, score 9.1. Bitget audited on 2025-02-20, verified, score 8.9. MEXC's most recent attestation dates to 2024-12-10 and is marked partial rather than verified — the score is 8.5.
What the attestation methodologies collectively imply is that reserve-eligible BTC is dominated by post-migration output formats. The reserve-side inventory the auditors sampled is P2PKH, P2SH-wrapped SegWit, and native SegWit. The pre-migration coinbase outputs from 2009-2010 are not in exchange custody in any material quantity. They never were. They were mined direct-to-P2PK by the miner who ran the software, and the vast majority of that cohort has never moved.
This matters for the quantum-recovery framing because the proposal has an implicit constituency. The constituency is the population of holders whose coins the mechanism can actually rescue — which is essentially anyone whose UTXOs live in address formats introduced after mid-2010. That includes every retail holder, every corporate treasury, every institutional custodian, and every exchange reserve pool that showed up in the March 2025 attestation cycle. It does not include the pre-migration cohort. And it does not include Satoshi.
The pricing delta receipt on exchange fees illustrates how narrow the affected population is: Binance's maker/taker sits at 0.10%/0.10%, OKX at 0.08%/0.10%, MEXC at 0.00%/0.02%. Previous fee tiers held roughly steady over the last audit cycle. The fee structure has not repriced to account for quantum risk premium in either direction — which tells you the market is not, in aggregate, treating the recovery-mechanism exclusion as a repricing event.
July 2026: The Recovery Proposal Everyone Read Wrong
The proposal circulating in the developer channels is not a rescue package for lost coins. That is the first thing every reader gets wrong. It is a migration path for owners who currently hold Bitcoin in quantum-vulnerable address formats and want to move it, before a sufficiently capable quantum computer exists, into a post-quantum-signature output type.
Read that again. Migration for owners. Not rescue for coins.
The mechanism assumes an owner who holds a private key today, who observes the quantum threat maturing, and who signs a migration transaction using their classical key while it is still safe to do so. The window is generous — years, possibly a decade or more, depending on which quantum-timeline estimate you take seriously. The proposal buys time. It does not manufacture consent.
What the proposal explicitly does not do is let an unrelated party claim a pre-migration output by producing a post-quantum signature over an address whose original owner never provided one. That would be theft. The fact that the media reporting frames the exclusion of Satoshi's coins as an oversight — rather than as the deliberate design choice it is — is the takedown moment for this piece.
The YouTube thumbnail said "Bitcoin's Quantum Rescue LEAVES OUT Satoshi." The YouTube video, when I watched it carefully, was a 14-minute walkthrough that never once explained the P2PK versus P2PKH distinction, never mentioned the January 2009 key-format choice, and pivoted at minute 8 into an affiliate link for a hardware wallet. The framing was manufactured. The exclusion is not a failure. It is the only defensible engineering position.
If the proposal did include the pre-migration cohort — if it offered any mechanism by which a coin whose owner is functionally absent could be moved by a third party who produces a post-quantum signature — that mechanism would, by construction, be a race. Whoever files the resignation first gets the coins. That is not recovery. That is a legalized land grab across the largest single wallet on the network. The developers writing this proposal understand this. The reporters writing headlines about it, in some cases, do not.
What It All Means
The number to leave with is 1.1 million. That is the coin count sitting in pre-P2PKH outputs, dominated by the early coinbase rewards attributed to Satoshi and a small population of first-cohort miners. Every quantum-recovery mechanism that Bitcoin can plausibly ship in the next decade will exclude those coins. Not because the developers are being inattentive, but because including them would require a claimant-identity primitive the protocol does not have and cannot acquire without introducing a governance layer nobody wants.
The reporting that treats this exclusion as a scandal is doing the reader a disservice. It is teaching an audience — already primed by FTX to see custody failures as systemic — that the correct response to a technically necessary architectural boundary is outrage. That framing does not survive contact with the actual proposal text. It survives beautifully as a click-through headline, which is why it keeps getting written.
The decision this piece should change is what you do with your own outputs. If you are holding meaningful BTC in a legacy P2PK address — you would know, because your wallet software would show the address as starting with a public-key hex string rather than a base58 hash — the migration path being proposed is for you specifically. It is a years-long window. It is not a fire drill. But it is real, and it is the thing the current news cycle should be telling you about, instead of manufacturing indignation on behalf of a wallet whose owner has not sent a transaction since 2010 and is almost certainly not reading the news.
FAQ
What is the actual difference between P2PK and P2PKH in the context of quantum risk?
A P2PK output stores the receiving public key in plaintext directly in the transaction script, so any observer scraping the chain can extract it and — with a sufficiently large quantum computer running Shor's algorithm — derive the corresponding private key. A P2PKH output stores only a 20-byte hash of the key; the key itself is not revealed until the coin is spent. This means P2PKH addresses that have never spent remain quantum-safe, while all P2PK outputs are permanently exposed.
Why can't the recovery proposal simply include Satoshi's addresses too?
Because inclusion would require a mechanism to verify that whoever submits the post-quantum-signed migration transaction is the rightful owner of the pre-migration output. No such primitive exists at the protocol layer, and adding one would require a governance mechanism Bitcoin does not have. The alternative — allowing any party who produces a valid post-quantum signature to claim the coins — would turn dormant wallets into a first-come land grab rather than a recovery.
Which exchanges custody meaningful quantities of pre-migration P2PK outputs?
Based on the March 2025 proof-of-reserves cycle, essentially none in material quantity. The verified attestations from Binance, Bybit, OKX and Bitget all show reserve inventory dominated by post-2010 output formats. MEXC's attestation from 2024-12-10 is marked partial rather than verified, but the same overall pattern holds. The pre-migration cohort was mined direct-to-P2PK by early participants and never routed into institutional custody in significant volume.
Does the quantum threat require me to move my Bitcoin right now?
No. The migration window contemplated by the current proposal is measured in years, likely a decade or more, calibrated against credible timelines for cryptographically relevant quantum computers. What matters is that you know your own address format. If your BTC lives in P2PKH, wrapped SegWit, or native SegWit outputs that have never spent, you are already partially defended by hash-based key concealment. The migration is a housekeeping task, not an emergency.
How does the March 2025 proof-of-reserves data affect this discussion?
It establishes that the largest custodial pools are structured entirely inside migration-eligible address formats. Binance verified 2025-03-01, OKX verified 2025-03-01, Bybit verified 2025-03-12, Bitget verified 2025-02-20. The recovery proposal, if adopted, would apply cleanly to reserve inventory across all four. The narrative that quantum recovery leaves retail behind does not survive contact with the attestation data — the population it leaves behind is Satoshi and a handful of never-active first-cohort miners.
Is the news framing that this is a scandal actually correct?
No. The exclusion of pre-migration outputs is not an oversight, and it is not a governance failure. It is the only defensible engineering position, given the absence of a claimant-identity primitive that could distinguish rightful owners from opportunistic claimants. Framing the exclusion as a scandal misrepresents both the technical reality and the design intent. It also implicitly proposes an alternative — third-party seizure of dormant coins — that nobody advocating the framing would defend in a serious forum.
What is the risk if a quantum computer arrives before the migration window closes?
The most exposed population is pre-migration P2PK outputs, followed by any post-migration output that has already been spent from (because the public key becomes visible on the chain at spend time and any residual UTXO reusing the same address is then exposed). Address-reuse discipline matters more than most retail holders assume. The remediation for actively held funds is straightforward: migrate to fresh output types under post-quantum signatures during the proposed window. The remediation for the pre-migration cohort is, structurally, that there is none.