>_ Skip to main content
Menu
Search
Post-Quantum Security

The Proposal to Freeze What Bitcoin Was Built Never to Freeze


Changpeng Zhao wants Bitcoin to freeze coins on a chain engineered so that nobody, not even its creators, can freeze anything. The Binance founder floated the idea during a discussion about how Bitcoin would survive a future quantum computer, and the reaction split the people who build and hold Bitcoin into two camps that don’t agree on the premise, the timeline, or whether the cure does more damage than the disease.

Nothing has been decided yet, be it fork or code. CZ himself says the network can’t do this without consensus, and he means it as a constraint, not a formality. What exists is a question that Bitcoin has to answer eventually. A large pile of coins sit in address formats where the public key is visible on the chain, and a sufficiently powerful quantum machine could work backward from that key to the private one.

Why some want Bitcoin to freeze vulnerable coins

In a video shared by Vivek Sen on July 29, CZ presented his version as a sequence. If Bitcoin ever adopts quantum-resistant cryptography, holders in old vulnerable wallets get a migration window of 6 to 12 months to move funds to safe addresses. When that window closes, the community could vote to freeze whatever’s left. His logic is blunt about what inaction means. As CZ said:

“If we don’t do anything with it, then we’re basically giving it to somebody who’s going to hack it.”

The point behind that line is that coins that can’t be moved by their owner and can be stolen by an attacker aren’t really protected by doing nothing. About 1.1 million BTC attributed to Satoshi Nakamoto sit in early formats with exposed public keys. A quantum thief cracking those wallets would dump an enormous supply of “new” coins onto a market that assumed they were gone forever, and every holder would suffer the consequences.

Jameson Lopp’s BIP-361, drafted in April 2026 with six authors, tries to formalize the mechanics in three phases. These include blocking inflows to vulnerable address types about three years after activation, freezing the legacy coins two years after that, and leaving the door open to a future zero-knowledge recovery method so honest owners might reclaim funds later. The proposal targets all at-risk coins, something near 1.7 million BTC in P2PK addresses, worth around $74 billion. So, Lopp’s scope is wider than CZ’s.

But here’s the part that complicates the otherwise easy narrative. Lopp doesn’t like his own proposal. He’s described it as adversarial contingency thinking, the kind of plan you write because someone has to game out the ugly scenario, not because you’re eager to see it happen.

Why others say a freeze would change Bitcoin forever

The objection revolves around the belief that freezing coins, for any reason, hands the network a power its designers never intended it to have.

Bitcoin’s entire proposition rests on the idea that a valid coin stays yours and moves only when you sign for it. Introduce a mechanism that confiscates funds after a deadline, even a well-intentioned one, and you’ve established that the community can vote to seize a balance. Critics call this authoritarian and a departure from Bitcoin’s founding principles. Once the network freezes coins to stop a quantum thief, the precedent emerges for freezing coins to stop the next thing, whatever that turns out to be.

There’s a timing argument stacked on top of the principled one. Adam Back estimates a Bitcoin-breaking quantum computer is probably 20 to 40 years out. On his read, there’s no emergency, so there’s no reason to rush a contentious change that mutilates the network’s core guarantee. That said, several expert surveys put a cryptographically relevant quantum machine inside 10 to 15 years, which is a good deal sooner than Back’s floor. But both can’t be right.

Is there a version that doesn’t require a freeze at all?

Meanwhile, Matt Hougan of Bitwise floated a different route. Instead of freezing vulnerable coins through a protocol change, he suggests putting them into a legal trust structure. According to him, the exposed BTC should go through proper law and custody arrangements and not rewriting what the chain permits.

This sidesteps the precedent problem. No confiscation power is integrated into the protocol, so the concern over what could be frozen next loses its strength. Whether a legal wrapper can actually corral coins whose owners are unknown or long dead is a separate question. Satoshi isn’t signing a trust agreement.

Where this leaves things

Weigh the proposals objectively and you’ll see that neither side is arguing in bad faith. The freeze camp is trying to prevent a supply shock and a theft that nobody can undo, and they’ve built phased mechanisms to do it carefully. The opposing camp is defending the one property that makes Bitcoin different from everything it aimed replace, and they’re right that a confiscation precedent doesn’t un-set itself.

CZ’s own condition is the genuine frame: this needs a vote, and the vote hasn’t happened yet. The migration windows are hypothetical, as is the fork, and even Lopp, who wrote the most detailed version, would rather it never ships.

At the very least, the quantum question forces Bitcoin to confront something it has dodged since 2009: what happens to coins whose owners can never move them again? Respond with a freeze and you’ve changed what Bitcoin is. Do nothing and you might be, in CZ’s words, handing them to whoever cracks the key first. Neither response is clean, and the network will have to pick one before the hardware picks for it.