The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Satoshi's bitcoin: why 1.1 million coins could be frozen

Around 1.1 million bitcoin, worth a good $91 billion today, are attributed to Bitcoin's inventor Satoshi Nakamoto. A draft from Bitcoin developers would freeze them before a quantum computer can steal them. What lies behind BIP-361, what argues against it, and which addresses of yours would also be affected.

A bronze bust of Satoshi Nakamoto in a hood, with a mirrored face and a Bitcoin sign on the chest, in Graphisoft Park in Budapest
8 min read
Share:

Around 1.1 million bitcoin are attributed to Bitcoin's inventor, Satoshi Nakamoto. At Sunday morning's price of $83,045 that is a good $91 billion, or roughly 81.5 billion euros, spread across early addresses from the network's first year. The coins are regarded as untouched. They sit nonetheless at the centre of one of the fiercest debates among Bitcoin developers: a draft numbered BIP-361 would freeze them before a quantum computer can one day steal them.

The question of what happens if Satoshi returns is as old as Bitcoin itself. New is the question of whether his coins could be moved at all once the network hardens itself against quantum attacks. There is a practical lesson in that for your own addresses too.

How many bitcoin belong to Satoshi Nakamoto?

Nobody knows exactly, because Satoshi never disclosed his addresses. The usual figure goes back to the computer scientist Sergio Demian Lerner. In 2013 he found a pattern in the early blocks of the Bitcoin blockchain that points to a single, very early miner. Later analyses of this so-called Patoshi pattern arrive at around 1.1 million bitcoin. That is about 5.5 percent of the 20.10 million bitcoin in circulation today.

Satoshi published the white paper on October 31, 2008 and started the network on January 3, 2009. He withdrew in the spring of 2011. The coins attributed to him sit in an early address format called pay-to-public-key, P2PK for short, and it is precisely that format which makes them a special case today.

Bar chart: 20.10 million bitcoin in circulation, 6.80 million with a public key, 1.10 million attributed to Satoshi
Satoshi's estimated holding is one part of the bitcoin whose keys lie exposed. Sources: blockchain.info, BIP-361, estimate after S. D. Lerner; own calculation.

The chart puts the scale in order. Satoshi's estimated holding is only a part of what lies exposed: according to the figures in the BIP-361 draft, more than 34 percent of all bitcoin had a public key visible on the blockchain on March 1, 2026.

Why quantum computers endanger Satoshi's bitcoin

Bitcoin protects balances with digital signatures. Whoever knows the private key can spend, and today's computers cannot work back from the public key to the private one. A sufficiently large quantum computer could do exactly that. When that point arrives is open. The authors of BIP-361 point to roadmaps that consider such a machine possible as early as 2027 to 2030, while other experts reckon on considerably more time.

Only coins whose public key is already visible are at risk. At the P2PK addresses from Satoshi's day it has stood in the blockchain from the outset. With more modern formats it appears only once an address has been spent from. The draft is explicit on this point: should quantum computers continue their development, the keys of all P2PK outputs would be found with near certainty and the balances stolen.

What BIP-361 proposes: freezing instead of letting them be stolen

BIP-361 carries the title "Post Quantum Migration and Legacy Signature Sunset" and has stood since February 2026 as a draft in the official register of Bitcoin improvement proposals. Its lead author is the developer Jameson Lopp. The plan presupposes that Bitcoin first gains a quantum-safe address type, for instance through BIP-360, also at draft stage. After that it would proceed in two stages:

  • Phase A: around three years after activation, 160,000 blocks later to be precise, the network stops accepting payments to vulnerable addresses. New money then flows only into quantum-safe formats.
  • Phase B: five years after activation, on a date announced long in advance, spending with the old signatures is possible only through a quantum-safe rescue procedure.

That rescue procedure relies on the true owner knowing something an attacker does not. Anyone using a modern wallet with a seed phrase can demonstrate knowledge of the original key, which an attacker does not hold. For P2PK addresses that advantage does not exist, as the authors themselves concede. On today's reading, Satoshi's coins would therefore stay locked permanently, unless a further proposal creates a separate, slow spending route for such legacy holdings.

A metal sculpture of a seated figure with a laptop, made of vertical steel slats on a rust-red plinth in a park in Lugano
Valentina Picozzi's Satoshi sculpture in Lugano. Photo: StellarDancingDuck, Wikimedia Commons, CC BY-SA 4.0

The authors invoke Satoshi himself. He wrote in the Bitcoin forum in 2010 that lost coins only make everyone else's coins slightly more valuable, and that one could regard them as a donation to all. Frozen coins tighten supply; stolen ones would enlarge it at a stroke.

The case against freezing

The resistance is fundamental. Bitcoin promises that nobody can lock up someone else's coins, and that is exactly what BIP-361 would do, albeit after years of notice. Critics hold it to be a breach of the property promise, no matter whose coins they are. Even Lopp does not like his own proposal. In April he called it a crude contingency plan and said, according to CoinDesk: "I wrote it because I like the alternative even less."

This is not decided in any committee. A soft fork needs broad assent from miners, node operators, wallets and exchanges. Both drafts are far from that; BIP-360 and BIP-361 carry the status "Draft" to this day.

What a return by Satoshi would mean for the bitcoin price

Were Satoshi's coins to move before such a cut-off date, the market would at first not know who was behind it: Satoshi himself, an heir, or an attacker with a quantum computer. The mere possibility that a holding of a good $91 billion might come to market would be likely to set off considerable pressure, without a single coin being sold. A definitive freeze would take that risk out of the calculation. Supporters of a US bill that would lock up state-held bitcoin for 20 years argue along similar lines: what cannot be sold does not weigh on the price.

Which of your own bitcoin addresses would be affected

For the vast majority of investors in Germany this is no acute danger today. It is, though, a good occasion to look at your own addresses:

  • Coins on an exchange: here the provider decides which address formats it holds them in. A later move to quantum-safe addresses would be up to them.
  • Your own wallet with a seed phrase: modern wallets generate a new address for every payment. With addresses beginning "1", "3" or "bc1q", the public key lies exposed only once you have spent from them. Not reusing addresses is therefore a simple rule of protection.
  • Taproot addresses with "bc1p": here a key is visible from the outset, and BIP-361 counts them explicitly among the vulnerable formats. That is no reason for haste today, but it is a point on the list for a later move.
  • Very old wallets: anyone holding coins from the earliest years should check which format they sit in. A move to a new address of your own is not a sale and triggers no tax in Germany.

If you hold your own coins, the hardware wallet comparison lists devices that manage a seed phrase and fresh addresses cleanly. If you are only getting started, the comparison for buying bitcoin lists vetted providers.

Frequently asked questions about Satoshi's bitcoin and BIP-361

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.

Related articles

Which topics should we dive deeper into?

Select what genuinely interests you. Your picks feed directly into our editorial planning.

Crypto news that's actually worth your time.

Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.

Subscribe

More on this topic

View All

More from CryptoTicker