Bitcoin’s developers spent all of 2026 screaming at each other about spam, data limits and a two-block joke fork. Then they quietly moved on to the one argument that actually decides whether your coins survive the next decade — and they have already admitted, in writing, that they don’t agree on how to win it.
That is not a hot take. That is the state of BIP-360.
WHAT THEY ACTUALLY ADMITTED
BIP-360 is a draft proposal that wants to replace Bitcoin’s current output model with something called Pay-to-Merkle-Root — P2MR. The pitch is clean: instead of exposing your public key on-chain, P2MR commits your coins to a Merkle root. No public key, nothing for a quantum computer running Shor’s algorithm to reverse-engineer into your private key.
Wonderful. Except it isn’t finished. And the developers say so themselves.
BIP-360 is a draft. The cryptography underneath it is not fully proven. SHRINCS — the Blockstream Research signature scheme built on SHA-256 that is supposed to do the actual quantum-proof signing — has no completed formal security proof and no finished independent review. Its compact stateful signatures start at 324 bytes and require your wallet to track signing history. Lose that history after a backup restore and you fall back to a bigger, slower stateless path. That is not a finished product. That is an experiment with a wallet-support burden attached.
And even P2MR, on its own, does not protect you. It reduces long-term public-key exposure. It does nothing about the window where spending reveals a vulnerable key. It is an upgrade path, not a shield.
There is no consensus on sequencing. No agreed activation mechanism. No timeline. Bitcoin’s plan for the biggest existential threat in its history is currently a draft BIP, a competing signature scheme, and a mailing list.
THE FIGHT THEY CAN’T EVEN AGREE TO HAVE
Read the actual state of play and it gets worse. Some developers want P2MR first — build the structure, then worry about signatures. Others say the signature scheme is the real problem and should be solved before anyone touches output formats. P2MR is not even the only candidate anymore; P2TRv2 and P2TRH are in the same conversation. Quantum traffic on the Bitcoin development mailing list has gone from years of near-silence to more than 10% of all technical communications.
Coinbase formed an independent advisory board on quantum computing and blockchain security, pulling in Stanford’s Dan Boneh, UT Austin’s Scott Aaronson and the Ethereum Foundation’s Justin Drake. Coinbase’s CEO has been publicly warning about 2029. The exchange everyone in this space loves to hate is doing more visible quantum preparation than the protocol itself.
Meanwhile the governance machine is exhausted and openly hostile. The BIP-110 fight ended with Luke Dashjr — the BIP editor who championed it — removed from his role after a conflict-of-interest motion passed in 26 hours with 31 GitHub approvals. That is the room in which Bitcoin now has to decide how to migrate billions of dollars worth of exposed coins. A room with no consensus mechanism, no vote, and no agreed authority. Trust is low. Everyone is tired.
And into that room walks the most existential engineering problem Bitcoin has ever faced.
MEANWHILE, THE MAN WHO TELLS YOU TO NEVER SELL CALLS THE FIX A THREAT
Here is where I stop being diplomatic.
Michael Saylor — the guy whose entire public persona is built on the words “never sell” — has called the greatest risk to Bitcoin “ambitious opportunists advocating protocol changes.” He argues Bitcoin’s real defense is ossification: refuse to change unless absolutely necessary. Don’t touch it. Don’t fix it. Don’t move.
Ossification served Bitcoin beautifully for fifteen years. It protected the network from the block-size wars, from corporate capture, from every well-meaning committee that wanted to make Bitcoin convenient by making it controllable. I get the instinct. I share it.
But quantum computing is not a spam attack. It is not a debate about block space or Ordinals or data limits. It is not an opportunist looking for a grant.
It is a mathematical countdown on elliptic-curve cryptography — the thing every Bitcoin address you have ever used depends on. Jameson Lopp put the real problem in plain language: quantum computers won’t break Bitcoin in the near future, but a thoughtful protocol change plus an unprecedented migration of funds could easily take five to ten years. Hope for the best. Prepare for the worst.
Five to ten years. That is the honest estimate for the FIX. Not the threat — the fix. And the loudest voice in Bitcoin is telling the people doing that work to stop being so ambitious.
You cannot call the developers rebuilding the cryptography “opportunists” and then tell holders their exposure is somebody else’s problem. Someone has to do the boring, unpopular, decade-long engineering. Someone has to write the formal security proofs and get them independently reviewed. Someone has to migrate billions in exposed coins, coordinate exchanges, custodians, wallet providers and hardware vendors, and absorb the fee spike and block-space demand that migration will cause.
Nobody is volunteering. Saylor certainly isn’t — he’s busy telling you not to worry about it while his company owns the single largest concentrated stack of the asset he says needs to stay frozen forever.
THE RECEIPTS ON WHY THIS ISN’T HYPOTHETICAL
This stopped being theoretical months ago. Recall what already happened in 2026:
- The first quantum-safe transaction hit mainnet on August 26. Block 964,199. A 10,000-satoshi spend, 1,403 bytes, 5,179 sats in fees.
- That “miraculous fix” costs up to $200 per transaction, needs a miner’s permission because it bypasses the public mempool entirely, and is strictly opt-in. Roughly 7 million BTC sits in exposed-key UTXOs with zero protection.
- Then 100 volunteers and AI agents cut the cost of attacking Bitcoin’s cryptography by 86% — in one campaign.
So the research is moving fast. The defense is moving slowly. And the most powerful voice in the room is arguing the defense shouldn’t move at all.
SO WHO IS ACTUALLY FIGHTING FOR YOU?
Not Congress. The Senate killed the Digital Asset Market Clarity Act in a 49-50 cloture vote. The SEC is improvising around it. Not the exchanges, who will happily custody the same coins they can’t upgrade. Not the treasury companies, who need the price to stay up more than they need the protocol to survive the decade.
And not the ossification crowd, who have confused “don’t be reckless” with “don’t do anything.” Those are not the same idea. Recklessness is shipping unaudited cryptography because a deadline frightened you. Doing nothing is also a choice, and it is the only choice that guarantees an outcome, because the clock doesn’t need consensus to keep ticking.
I’ll say the part nobody wants to hear: if you are holding Bitcoin in an address whose public key has ever been exposed — and you probably are — this is not a debate you get to sit out. You are the collateral in someone else’s governance argument.
PICK A SIDE
Bitcoin does not need a rushed fork. It needs a funded, reviewed, boring, decade-long migration plan — and it needs the people who shout “never sell” loudest to stop publicly calling the engineers doing that work a threat to the asset.
Real self-custody means you plan for the failure mode, not just the price. That is exactly why I keep pointing people at the same thing: hold your own keys, know what your wallet can actually do, and stop outsourcing the question of your own survival to whoever has the biggest podcast.
Grab a hardware wallet, verify your own backups, and keep your coins somewhere you control. Use coupon code LOVEISBITCOIN at loveisbitcoin.com/bull and take the deal while it’s still a discount and not a panic buy.
Now tell me straight: is Saylor right that changing Bitcoin is the real threat — or is “don’t touch it” the single most dangerous thing a Bitcoin billionaire has ever said? Sound off in the comments. I’ll be reading.