Bitcoin quantum migration is becoming a wallet and governance issue, not only a cryptography question. Ledger CTO Charles Guillemet says Bitcoin faces no immediate quantum-computer threat. However, preparing wallets, hardware devices, and existing coins for a future transition could take years.
Table of Contents
Guillemet said no known quantum computer can break Bitcoin’s signatures today. A sufficiently powerful machine running Shor’s algorithm could threaten ECDSA and Schnorr signatures if such hardware is eventually built.
Planning for the Bitcoin quantum thus becomes an issue of time. Time is needed to develop the protocol, make modifications to software, and gain users. Guillemet broke the problem down into selecting the signature algorithm, wallet modification, and migration of existing BTC.
Some coins have been inactive for years, and some users might have lost their keys. The migration process would have to account for that issue.
Why Is SHRINCS Part of the Bitcoin Quantum Debate?
Guillemet examined SHRINCS, which was a proposed post-Bitcoin quantum signature scheme. The current proposal uses a compact stateful signing algorithm alongside a relatively large stateless one.
Also Read: Circle’s Arc Mainnet Goes Live With 100+ Institutional Partners
In the proposal, SHA-256 is used, and it aims at providing 128 bits of classical security and 64 bits of quantum security. The public key size is 48 bytes. Stateful signatures have sizes between 548 bytes and 4,619 bytes, whereas the stateless variant has a size of 5,777 bytes.
Such sizes are larger than Bitcoin’s 64-byte Schnorr signatures. Blockstream Research claims that hash-based signatures provide conservative assumptions along with reasonable verification costs, albeit larger sizes mean more block space usage.
The standardization of SLH-DSA as FIPS 205 took place in August 2024 by NIST. SHRINCS uses a stateless hash-based algorithm from SLH-DSA, but it uses different parameters and has a stateful signature as well.
How Do Stateful Signatures Change Wallet Security?
The most significant Bitcoin quantum trade-off related is found in wallets. SHRINCS relies on the compact signing path to determine whether the particular slot was already used.
If the same slot signs two distinct messages, data in the form of signatures might help to forge funds. The draft mandates that wallets need to maintain their state while providing a signature.
Backups provide yet another threat. Recovering an older wallet means recovering an outdated counter. If two wallets derive from the same seed and operate using the stateful path, then there might be a conflict between two such devices.
This issue was identified by Project Eleven’s researchers Alex Pruden and Conor Deegan. According to their analysis, SHRINCS delegates an important aspect of security to the wallet and custodial infrastructure, where state reset or reuse can become a silent flaw.
SHRINCS also offers a stateless recovery mechanism if the state in the wallet becomes uncertain. Although users are able to sign transactions using the larger signature, the stateful path must never be used again for that key.
What Existing Bitcoin Features Need New Designs?
Quantum Bitcoin preparation will have its impact on ordinary wallet features as well. Guillemet states that hash-based signatures lack natural support for non-hardened BIP32 derivation, which underlies many watch-only wallet arrangements.

Also, threshold signing gets more complicated. The current Schnorr-based protocols allow efficient participation of parties, while hash-based schemes often demand larger signatures or more interactions between them.
Performance of hardware should also be taken into account. Ledger noted that post-quantum key pair generation and stateless signing procedure may take minutes on certain hardware because of many SHA-256 computations and higher memory usage.
Blockstream showed SHRINCS signature verification using Simplicity in Liquid sidechain. It should be noted that these experiments do not imply the activation of the protocol on the Bitcoin mainnet, which will still require careful consideration.
Where Does Bitcoin Quantum Planning Stand?
SHRINCS is not the only proposed solution being considered. BIP 360, or Pay-to-Merkle-Root, is still a draft proposal whose purpose is to eliminate Taproot’s quantum-vulnerable key-path spending method.
BIP 361 focuses on the process of migration. This draft proposes the phase-out of ECDSA and Schnorr spending once the post-quantum spending method is implemented. Both drafts are still labeled as “drafts” in the BIP official repository.
Coinbase’s independent Quantum Advisory Council has also called for early planning. Its June report examined how abandoned or unmigrated coins might be handled without backing a single approach.
No quantum migration has been adopted on the Bitcoin mainnet. SHRINCS remains an unfinished draft without a BIP number, while BIP 360 and BIP 361 are still under discussion.
Also Read: Crypto Custody Gains Ground as Deutsche Bank Prepares 2026 Launch



