---
title: "15 years after Satoshi Nakamoto disappeared, his 1.1 million Bitcoins are now being targeted."
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/291154801.md"
description: "Satoshi Nakamoto's 1.1 million BTC face threats from quantum computing vulnerabilities and legal challenges. In 2026, Binance founder CZ proposed a protocol upgrade to freeze unmigrated coins, while a lawsuit sought ownership of dormant addresses. Developers submitted BIP-361 to phase out vulnerable signature formats. With ~6 million BTC in exposed states, the community faces a critical decision on securing legacy assets against future quantum risks."
datetime: "2026-06-29T13:29:28.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/291154801.md)
  - [en](https://longbridge.com/en/news/291154801.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/291154801.md)
generator: "portal-rs"
---

# 15 years after Satoshi Nakamoto disappeared, his 1.1 million Bitcoins are now being targeted.

Not your keys, not your money.This is the first tenet of the Bitcoin world.

Whoever holds the private key owns the coins. Bitcoin is valuable because this rule has never been broken.

However, Satoshi Nakamoto's 1.1 million Bitcoins are under the intense scrutiny of quantum computing.

On June 18, 2026, Binance founder Changpeng Zhao proposed on the Galaxy Brains podcast that Bitcoin should be upgraded to a quantum-resistant encryption system, giving all holders 6 to 12 months to transfer their coins to a new address. After the window closes, coins that have not moved will be frozen by the protocol and will never be usable.

 This includes freezing Satoshi Nakamoto's 1 million Bitcoins. However, if the protocol can freeze them, it means that even if you still have the private key, the consensus rules may no longer recognize that private key's control over this asset. 

## It wasn't just hackers targeting these 110 bitcoins

In early 2026, an anonymous individual using the pseudonym Noah Doe filed a lawsuit in a New York court. He stored 39,000 long-untouched bitcoin addresses on a USB drive, handed it over to the New York Police Department, and invoked New York State's lost and found law, requesting the court to award him these "ownerless bitcoins." 

These addresses involve approximately 3.7 million BTC, worth about $274 billion, including addresses belonging to Satoshi Nakamoto.

 The chances of this succeeding legally are low, but this case exposes a fact: when Bitcoin encounters the real-world legal system, "not your keys, not your money" is not always decisive. Courts can potentially re-determine asset ownership through judicial proceedings, even if this conflicts with Bitcoin's technical rules. On April 15th, Casa CTO Jameson Lopp and six other developers submitted the BIP-361 proposal, suggesting a phased phase-out of the old signature format, ultimately freezing unmigrated quantum fragile addresses. Lopp wrote on X: "I don't like this proposal, and I hope it never needs to be implemented. But I dislike the other ending even more." Noah Doe took the legal route, Changpeng Zhao offered an industry perspective, and BIP-361 took the protocol upgrade route. There is no direct relationship between the three, but they address the same issue in different ways: Bitcoin, left behind 15 years after Satoshi Nakamoto's disappearance, is transforming from a symbol of faith into a problem to be solved. Why are 6.04 million BTC a target? Bitcoin's security model has two layers. The first layer is the hash function (SHA-256), responsible for mining and address generation. Quantum computers have limited speedup capabilities for this layer and pose no threat in the short term. The second layer is the Elliptic Curve Signature Algorithm (ECDSA), responsible for transaction verification. Quantum computers' Shor's algorithm can deduce the private key from the public key, which is the real risk. The key lies in whether the public key has been exposed on the blockchain. According to Glassnode's research in May 2026, approximately 6.04 million BTC are currently in a "statically exposed" state (i.e., the public key is already visible on the blockchain), accounting for 30.2% of the issued supply. If you hold Bitcoin and are using addresses with long-term public key exposure, such as P2PK addresses, or Taproot outputs that have already been spent, some of these 6.04 million BTC may belong to the same type of asset. Satoshi Nakamoto's coins are among the riskiest. Between 2009 and 2010, Satoshi Nakamoto mined approximately 22,000 blocks using an early client, with each block rewarding 50 BTC, distributed across 22,000 unique addresses. All these addresses used the P2PK format, and the public key was permanently exposed on the blockchain from the moment the coins were received. All addresses are controlled by a single file called wallet.dat. If this file still existed, Satoshi Nakamoto could theoretically have completed the migration in one go. It hasn't been touched for 15 years; either the file is no longer there, or he chose not to. In March 2026, Google Quantum AI's research reduced the theoretical quantum resources required to crack ECDSA from millions of physical qubits previously estimated to less than 500,000, corresponding to a theoretical cracking time of a few minutes. This is only a significant reduction in resource estimates; it doesn't mean that existing quantum computers already possess the capability to crack it. Quantum-resistant cryptographic schemes already exist; the National Institute of Standards and Technology (NIST) approved three production-grade standards in 2024. The technology itself is not the problem. The problem is that old addresses accumulated over 17 years cannot be automatically upgraded, and many address owners have lost their private keys, passed away, or disappeared. BIP-360 is on the testnet, and BIP-361 is in the draft stage. Bitcoin developers are not sitting idly by waiting for an explosion. The BIP-360 proposal introduces a new address format called P2MR (Pay-to-Merkle-Root), similar to Taproot, but avoids long-term exposure of public keys on the chain through a new verification method, thereby reducing the quantum attack surface. This is the technical basis for quantum-resistant upgrades. BIP-361 proposes a migration plan based on BIP-360: For approximately three years after activation, transfers to quantum-vulnerable old addresses will be prohibited; after five years (in two phases), old ECDSA/Schnorr signatures will be encapsulated by a quantum-safe rescue protocol, rather than becoming invalid. True holders can continue to use these coins through the rescue mechanism, while quantum attackers will find it difficult to exploit. Whether or not usage is ultimately frozen or restricted depends on a consensus upgrade within the Bitcoin community, not a single proposal. Everyone agrees on the upgrade. The focus of the debate is whether the upgrade plan can include the option of "freezing other people's coins." Blockstream CEO Adam Back publicly responded at Paris Blockchain Week on April 16th: Technical upgrades should begin now, but migration must be voluntary; there shouldn't be a timetable for confiscation if migration isn't implemented. His reasoning was that Bitcoin has historically been able to fix urgent vulnerabilities within hours, and "in a real emergency, consensus will naturally form." Could Satoshi Nakamoto's address be frozen for security reasons? The BIP-361 proposal text quotes Satoshi Nakamoto to defend the freezing plan: "The lost coins make the remaining coins more valuable," attempting to use the founder's own words to justify freezing the founder's coins. Phil Geiger, Head of Business Development at Metaplanet, responded with a single sentence: "We have to steal other people's money to prevent other people's money from being stolen." This is the contradiction Bitcoin is facing. The rule "Not your keys, not your money" has protected every coin holder for 17 years. But this rule is based on the premise that current consensus rules always recognize the validity of signatures corresponding to private keys. Quantum computing is shaking this premise. If the community eventually upgrades the consensus mechanism, rendering the old signature scheme obsolete, then even if the private key remains, the network may no longer accept such signatures. This means that for the first time, an exception has appeared to this rule. Once the community accepts the logic that 'certain addresses can be frozen for security reasons,' the next freeze could be for anything. If the community chooses not to freeze, the first person to crack the code will take over 6 million BTC when quantum computers mature, and all coin holders will bear the consequences. When Satoshi Nakamoto designed this system in 2009, he chose an extreme solution: the rules were hardcoded, there were no administrators, and no exceptions. He mined over 1 million coins himself and then disappeared, not touching a single one for 15 years. He defined the spirit of this system through his actions: even the founder himself did not interfere. Fifteen years later, this system encountered a problem it couldn't solve on its own. The technology could be upgraded, the algorithm could be replaced, but whether the upgrade plan should include the option of "freezing other people's coins" was still a draft issue in BIP-361, with no activation timetable yet. The final decision didn't rest with Changpeng Zhao, nor with Lopp, but with the consensus of the Bitcoin community.

### Related Stocks

- [GBTC.US](https://longbridge.com/en/quote/GBTC.US.md)
- [ARKB.US](https://longbridge.com/en/quote/ARKB.US.md)
- [EZBC.US](https://longbridge.com/en/quote/EZBC.US.md)
- [FBTC.US](https://longbridge.com/en/quote/FBTC.US.md)
- [BRRR.US](https://longbridge.com/en/quote/BRRR.US.md)
- [BTCO.US](https://longbridge.com/en/quote/BTCO.US.md)
- [BITB.US](https://longbridge.com/en/quote/BITB.US.md)
- [BTCW.US](https://longbridge.com/en/quote/BTCW.US.md)
- [DEFI.US](https://longbridge.com/en/quote/DEFI.US.md)
- [BITO.US](https://longbridge.com/en/quote/BITO.US.md)
- [IBIT.US](https://longbridge.com/en/quote/IBIT.US.md)
- [HODL.US](https://longbridge.com/en/quote/HODL.US.md)
- [BTCE.DE](https://longbridge.com/en/quote/BTCE.DE.md)
- [03008.HK](https://longbridge.com/en/quote/03008.HK.md)
- [03042.HK](https://longbridge.com/en/quote/03042.HK.md)
- [03430.HK](https://longbridge.com/en/quote/03430.HK.md)
- [GOOGL.US](https://longbridge.com/en/quote/GOOGL.US.md)
- [GOOG.US](https://longbridge.com/en/quote/GOOG.US.md)

## Related News & Research

- [GoMining Launches Instant Funds for Digital Bitcoin Miner Holders](https://longbridge.com/en/news/297160037.md)
- [Binance Founder CZ Says His X Follower Count Has Been a 'Consistent Early Indicator’ of Crypto Cycles](https://longbridge.com/en/news/297631208.md)
- [Capital B Raises €21 Million to Accelerate Bitcoin Treasury Strategy](https://longbridge.com/en/news/297279683.md)
- [Hilbert Group shifts strategy to monetization, targets revenue growth after integration phase](https://longbridge.com/en/news/297739875.md)
- [First quantum-resistant Bitcoin transaction successfully executed, StarkWare says](https://longbridge.com/en/news/297113162.md)

---
> **Disclaimer: This article is for reference only and does not constitute any investment advice.**