>_ Skip to main content
Menu
Search

What’s the headline that scares you most? For me it would certainly be “Bitcoin Moves to Post-Quantum Cryptography, All Existing Seed Phrases Now Worthless! You Have 90 Days to Migrate or Lose Access to Your Coins.”

Luckily, this isn’t going to happen. In principle, your seed phrase outlives the cryptography built on top of it, even if PQC adoption forces other parts of self-custody to change.

Welcome to the durable layer. The seed phrase you wrote down on metal and hid in your closet for years is, technically, just entropy. Twelve or twenty-four words representing 128 or 256 bits of randomness. That randomness gets fed through key derivation to produce private keys. The private keys do the actual signing, and the underlying cryptography is replaceable. The randomness is forever.

The seed phrase did nothing wrong

Let’s look at what BIP-39 (the seed phrase standard since 2013) actually specifies. You pick or generate entropy, 128 bits for 12 words and 256 bits for 24. The entropy is checksummed and split into 11-bit chunks. Each chunk maps to one of 2048 words in a fixed wordlist. That’s your phrase.

To turn the phrase back into a key, you feed it through PBKDF2 with 2048 iterations of HMAC-SHA512. The output is the seed. That seed feeds into BIP-32 derivation, which produces every key in your wallet.

Notice what’s missing from this pipeline. Nothing about ECDSA. Nothing about elliptic curves. The seed phrase produces entropy. What you do with that entropy is up to whatever cryptography is in vogue at the time.

What PQC replaces

So when “Bitcoin moves to PQC,” what actually changes?

The signature scheme. Right now Bitcoin uses ECDSA (and Schnorr for Taproot). Both are based on the discrete logarithm problem on elliptic curves, which Shor’s algorithm dismantles on a sufficiently powerful quantum computer. A PQC migration would replace the signature scheme with something quantum-resistant. NIST finalized three post-quantum standards in August 2024, covering key encapsulation (ML-KEM) and digital signatures (ML-DSA and SLH-DSA).

The key derivation path also changes. BIP-32 was designed around the math of ECDSA keys, where you can derive child keys deterministically using elliptic curve operations. Lattice schemes like ML-DSA don’t share that math. A PQC migration probably needs a new derivation standard, something that takes seed entropy and produces ML-DSA or SLH-DSA keypairs in a deterministic, reproducible way.

Here’s the good news for your existing seed phrase. A new derivation standard can still take BIP-39 entropy as input. The keys produced on the other end are different. The entropy you wrote down is still the entropy you wrote down.

Hardware wallets are about to get heavier

About the hardware. Lattice-based PQC keys are big. ML-DSA-65 public keys are 1.95 KB. Signatures are 3.3 KB. SLH-DSA signatures are even bigger, up to 49 KB at higher security levels.

For comparison, ECDSA secp256k1 public keys are 33 bytes. Signatures are 71-72 bytes.

A PQC Bitcoin wallet has keys and signatures around 30 to 60 times larger than what your hardware wallet handles today.

What does this mean for the actual physical device sitting on your desk? More onboard storage. A beefier processor. Possibly bigger QR codes, or none at all, because the big keys may need NFC or wired transfers instead. Slower signing time. Larger on-chain transactions, which means higher fees per spend.

Hardware wallets that exist today (Trezor, Ledger, Coldcard, Foundation, etc.) will need firmware updates to support PQC signing. Some of them may not have enough resources to handle the larger keys. New device generations may end up being required for PQC self-custody.

The good news is that your seed phrase isn’t on the device. It’s in your closet, on a piece of metal, in the same form it was in five years ago. The hardware wallet is the disposable part. The entropy is the durable part.

The backup format question

Here’s where it gets interesting for self-custody.

Common backup setups include engraved metal plates and split-key schemes like Shamir’s Secret Sharing (SLIP-39). Some users add a BIP-39 passphrase as a 25th word for extra security. These backups are all about the entropy. They survive PQC.

What might need to change is the derivation path that converts your seed phrase into actual keys. Today’s wallets use various derivation paths under BIP-44/84/86. A PQC era would introduce new derivation paths that map seed entropy to ML-DSA or SLH-DSA keypairs instead of ECDSA ones.

The same physical metal plate, the same words, just decoded by a wallet that knows how to derive PQC keys instead of ECDSA ones. In principle.

The catch (and there’s always a catch) is that any coins controlled by your current ECDSA keys are still controlled by those keys after a PQC migration.

Why?

Because PQC keys produce different addresses than ECDSA keys. To move your coins from old addresses to new ones, you have to sign a regular Bitcoin transaction with the old ECDSA key. The signature exposes the old public key, which is exactly what you were trying to avoid.

Self-custody migration is a transaction. Transactions reveal keys (or, for Taproot, confirm what was already on chain). The order in which the Bitcoin ecosystem rolls out PQC support and the order in which individual users migrate is going to be a thing.

What hasn’t been decided yet

The Bitcoin community has not picked a PQC signature scheme. BIP-360 is a draft proposal co-authored by Hunter Beast with Ethan Heilman and Isabel Foxen Duke, introducing a Pay-to-Merkle-Root (P2MR) address type, but the specific cryptographic primitives are still under discussion. Other approaches exist, and the politics of which scheme to adopt are nontrivial.

There’s also no standardized derivation path for PQC keys. BIP-32-style derivation works for ECDSA because of specific elliptic-curve math. Lattice schemes don’t share that property, so PQC derivation may end up structurally different from what we have now.

Practically speaking, don’t panic. The transition will probably involve wallet developers shipping firmware updates that handle the new schemes, and your seed phrase will continue to work as the entropy input. Your backups don’t need to change today. The math underneath them will.

(What should you actually memorize)

Probably the same 12 or 24 words you already memorized. Entropy is still entropy. The math built on top of it might change, and so will the hardware running that math. The backup format you laminated on metal is, almost certainly, fine.

What might need rethinking is your assumption that “I have my seed phrase backed up, so I’m safe forever.” You’re safe in the sense that the entropy survives. The funds controlled by today’s derived keys are a different question. The seed phrase guarantees you can rebuild a wallet. It doesn’t guarantee the wallet you rebuild controls coins that are still where you left them.

That’s the actual shape of the PQC transition for self-custody. The durable layer holds. The disposable layers churn. Memorize accordingly.