Bitcoin BIP-360 and BIP-361 Explained: The Quantum Upgrade Proposals
Status first
Both proposals are drafts. They are not active on Bitcoin, no activation date exists, and Bitcoin changes slowly on purpose. Anyone telling you a quantum upgrade has "shipped" is ahead of the facts. With that said, the drafts are detailed and the discussion is serious, which is encouraging.
BIP-360: Pay-to-Merkle-Root (P2MR)
According to the BIP text (authors Hunter Beast, Ethan Heilman and Isabel Foxen Duke, latest changelog entry dated 2026-07-24), P2MR works like Taproot with one thing removed: the key-path spend. A Taproot output can be spent by a simple key signature, which reveals a public key. P2MR commits only to a Merkle root of scripts. When you spend, you reveal one script leaf and a path to prove it belongs to the root.
- It uses SegWit version 2, and mainnet addresses start with bc1z.
- It is a soft fork, so upgrading is voluntary.
- A depth-1 spend has a reported witness of 135 bytes, 69 bytes larger than a Taproot key-path witness of 66 bytes.
- It uses a 256-bit hash, giving 128 bits of collision resistance, the same level as P2WSH.
The text is candid about what it does not do: it protects against long exposure attacks but not short exposure attacks, because stopping those needs post-quantum signatures, which are not part of this proposal. In plain terms, P2MR is a door that stays shut until needed, and it is a stepping stone towards schemes like the post-quantum signatures compared here. Lightning, BitVM and Ark style scripting is reportedly preserved because script trees remain.
BIP-361: migration and legacy signature sunset
BIP-361 (authors Jameson Lopp and five co-authors) is also a draft and needs a still-to-be-written post-quantum signature BIP. It proposes phases:
| Phase | What changes | Timing in the draft |
|---|---|---|
| A | Sends allowed only from legacy scripts to post-quantum scripts, so no new coins go into vulnerable addresses | 160,000 blocks (about 3 years) after activation |
| B | Legacy ECDSA and Schnorr spends tightened, with a quantum-safe rescue protocol needed for legacy coins | About 5 years after activation, 2 years after Phase A |
The draft says coins never migrated would stay unspendable, which is the most debated idea in the Bitcoin community, because it touches the principle that nobody can freeze another person's coins. The authors argue the aim is to block quantum thieves while still letting the true holder spend through a rescue protocol, for example using BIP-32 hardened derivation as proof of a parent key. They add that it remains to be seen how much supply such rescue methods could cover, and that P2PK coins have no known rescue method. Reasonable people disagree on all of this, and the text is a starting point for debate, not a decision.
What is still missing
- A chosen post-quantum signature scheme and its size trade-offs (see the block space guide).
- Wallet, exchange, custodian and hardware wallet support, which a Cointelegraph feature says would need to be planned years ahead.
- Community agreement on old and lost coins.
A March 2026 vendor press release (BTQ Technologies) claimed a testnet implementation of BIP-360 and said Bitcoin Core had not progressed on it. That is a company statement we have not independently checked.
Why to be optimistic
The Bitcoin ecosystem has a long record of careful, years-long upgrades like SegWit and Taproot. Having concrete BIP numbers, authors, phases and test vectors this early gives the community time. The BIP-361 draft cites academic estimates for a cryptographically relevant quantum computer as early as 2027 to 2030, though those are estimates and other experts expect longer; see government deadlines for the official timetable.
Education only, not financial advice and not a price view on bitcoin or any token. The QNT memecoin is independent of Quantinuum Ltd and of Bitcoin development.
Sources and further reading
- BIP-360 text (Pay-to-Merkle-Root), bitcoin/bips
- BIP-361 text (Post Quantum Migration and Legacy Signature Sunset), bitcoin/bips
- Cointelegraph: Bitcoin's quantum upgrade path
- PostQuantum.com: fixing Bitcoin, signature sizes and throughput
Reported as of 2026-10-09. Roadmaps and proposals change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
Is BIP-360 active on Bitcoin?
No. It is a draft proposal. The BIP text lists it as a draft soft fork, and no activation has been set.
Does BIP-360 make Bitcoin quantum proof?
No. It hides public keys until spend time to defend against long exposure attacks, but it does not add post-quantum signatures.
What does BIP-361 propose for old coins?
A phased plan that first blocks new sends to legacy addresses, then restricts legacy signatures, with a rescue protocol for true owners. It is a draft and heavily debated.
Keep reading
- Exposed Public Keys and Address Reuse: Who Is Actually Vulnerable to Quantum?
Why some coins are more exposed to a future quantum attack than others, and how address reuse and Taproot play into it. - Post-Quantum Signature Sizes and Block Space: Why Blockchains Feel the Squeeze
Post-quantum signatures are many times bigger than today's. Here is what that means for block space, fees and throughput, in plain English. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - Quantum and Crypto Roadmaps Compared: Bitcoin, Ethereum, Solana and Others
Side by side: how Bitcoin, Ethereum, Solana, Algorand and Aptos are planning for post-quantum security, with dates and status as reported in 2026.
All Quantum events, catalysts and roadmap guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary