Finst

Project Eleven Builds Bitcoin Recovery Tool Amid Quantum Risk

The tool uses zero-knowledge proofs to verify wallet ownership, but it does not solve the problem of early Bitcoin outputs like Satoshi Nakamoto's.

Project Eleven Builds Bitcoin Recovery Tool Amid Quantum Risk

Key Takeaways

  • Project Eleven has built a recovery tool for Bitcoin wallets in case quantum computers ever become able to forge signatures.
  • The proof runs in 243 milliseconds on a laptop and uses zero-knowledge proofs without revealing key data.
  • For old Bitcoin coins, including the roughly 1.1 million BTC linked to Satoshi Nakamoto, this approach does not provide a solution.

Project Eleven says it has developed a recovery tool that could help Bitcoin wallets if quantum computers ever get good enough to forge signatures. The company says the proof takes 243 milliseconds on a laptop and relies on zero-knowledge proofs to confirm wallet ownership without exposing key data. Even so, the method does not solve the problem for the oldest Bitcoin coins, including the roughly 1.1 million BTC tied to Satoshi Nakamoto.

Quantum Threat to Bitcoin

The concern here is a future event often referred to as Q-Day, when a quantum computer could potentially work out a private key from a public key. If that happens, a normal signature would no longer be enough to prove ownership, since an attacker could generate one just as easily as the real holder. According to BIP-361, more than 34 percent of all Bitcoin would fall into that risk bucket because the public key has at some point been visible onchain.

The main exposure is in the elliptic curve cryptography that Bitcoin signatures use. Hashing is less exposed, since quantum computers do not have the same direct path to break it, but wallets are built from both pieces in practice. That is why the industry has been working on post-quantum fixes for some time, along with ways to protect older coins without disrupting the network more than necessary. It also brings up a bigger question: what should happen to Satoshi's Bitcoin if quantum risk ever becomes real?

Recovery Through a Derivation Path

The idea behind the new system is that a user can prove they know the key material above a certain address in the derivation tree, and that the tree leads to the address in question. The proof is also linked to a specific message, which means the same setup can be used to authorize a migration transaction. The key data itself never has to be revealed.

Project Eleven built the system with Jim Posen, the lead developer behind the Binius proof system. The company says the proof completes in 243 milliseconds on an M5 MacBook Air using four cores, while verification takes 40 milliseconds. It does not require a trusted setup, and the test was run without a GPU, using about 2 gigabytes of memory.

That timing matters because BIP-32, the wallet derivation standard, was only introduced in 2012. Before that, wallets created each key separately and at random. As a result, Satoshi's early coins, which are stored in pay-to-public-key outputs, do not have a derivation path that can be used to prove knowledge. For those older outputs, there is no earlier key path to fall back on.

Why This Matters for Europe

For European crypto investors, the main takeaway is that quantum security is not just a technical problem. It also affects wallet management and the process of moving older coins. If Bitcoin ever shifts toward a broad post-quantum setup, exchanges, custodians, and self-custody providers could all need to adjust their infrastructure and procedures. The broader lesson is that any move to new cryptography in a decentralized network will likely happen in stages and require a lot of coordination.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.