
A Coinbase-convened advisory board of leading cryptographers has issued comprehensive recommendations for Bitcoin's quantum security preparations, declining to take a position on the most contentious aspect of the migration debate. The board, which includes Scott Aaronson of the University of Texas at Austin, Dan Boneh of Stanford, and Justin Drake of the Ethereum Foundation, emphasizes that quantum computers are not yet a threat to blockchains but urges immediate technical planning for post-quantum signatures. The council notes that technical migration planning should start now because it is separate from the abandoned-coins question, stating that users need clarity so the issue does not fester. They commit to only two directives: start technical migration work immediately and communicate clearly to users that the problem is being taken seriously. The June report, authored by the advisory board, states that quantum computers do not currently threaten Bitcoin but warns that uncertainty around future advances warrants early planning to avoid disruption later.
Rather than endorsing either position, Coinbase's advisory board has declined to recommend a preferred outcome for legacy Bitcoin holdings, leaving the governance decision to the Bitcoin community itself. The report states "We refrain from providing any specific recommendation regarding the treatment of vulnerable coins" and argues that the final outcome should emerge through Bitcoin's consensus process rather than being dictated by a small group of researchers. According to the advisory board, "The decision should be made by the Bitcoin community" as the debate centers on approximately 6.7 million bitcoin considered vulnerable to future quantum attacks. The report notes that some community members support establishing a migration deadline after which existing ECDSA and Schnorr signatures would no longer be accepted, effectively freezing coins that have not moved to quantum-resistant addresses. However, critics argue that rendering coins unspendable would amount to confiscation of private property and would conflict with Bitcoin's long-standing principles of immutability and user control over assets.
The quantum migration debate centers on approximately 6.7 million bitcoin considered vulnerable to future quantum attacks, with 1.7 million coins in early addresses likely tied to Bitcoin's pseudonymous creator Satoshi Nakamoto and other lost key holders. According to the advisory board, roughly 1.7 million BTC are held in older pay-to-public-key addresses whose public keys are already exposed, making them potentially vulnerable to future quantum attacks. The report notes that many of those coins are believed to belong to lost wallets, including holdings commonly attributed to Bitcoin creator Satoshi Nakamoto. Drawing on research from Project11, the report also notes that as many as 5 million BTC could face exposure through address reuse, though a substantial portion of those holdings are believed to remain under the control of active users and institutions. The exposure is concentrated in Bitcoin's early pay-to-public-key addresses, a format that publishes the owner's public key directly on the blockchain and leaves it open to quantum attack.
Multiple technical proposals have emerged to address Bitcoin's quantum vulnerability, with the Coinbase advisory board noting these solutions are compatible and could be adopted together. Hourglass would cap how many vulnerable coins can be spent per block to prevent a supply flood, while BIP-361 from developer Jameson Lopp would let migrated holders prove ownership after the cutoff with quantum-resistant proof. PACTs from Paradigm's Dan Robinson would allow owners to timestamp private claims now and move funds later without revealing anything today. The report also discusses Post Quantum Address Commitments (PACTs), a mechanism that would let users commit to future quantum-safe addresses before a migration deadline without immediately moving funds on-chain. The advisory board delivered two clear conclusions: development of quantum-resistant migration tools should begin immediately, and Bitcoin users should receive clear information about potential risks and available migration paths well before quantum computing becomes a practical threat.
The quantum risk assessment has significant implications for institutional holders of digital assets, with the debate intensifying as Moody's Ratings warned in June 2026 that late adoption of post-quantum cryptography can be a source of credit risk. The G7 Cyber Expert Group published a coordinated financial sector roadmap in January 2026, with compliance architecture extending to digital asset treasury holdings over time. The Quantum Safe Financial Forum warned in February 2025 that quantum machines could be available in 10-15 years' time, though this timeline may come much faster than previously anticipated. The publication comes as Coinbase pursues a wider expansion of its platform, with the company recently outlining plans to integrate trading, lending, payments, derivatives, and AI-powered services into a unified financial ecosystem. The advisory board's refusal to choose between frozen and unconstrained coins reflects the complexity of balancing security with Bitcoin's fundamental property rights.