Christine Kim Details Four-Proposal Bitcoin (BTC) Quantum Defense Roadmap
Christine D. Kim outlines a Bitcoin (BTC) quantum security roadmap combining BIP-360, SHRINCS, Lifeboat and DropKick — all drafts, none live on-chain yet.
AI SummaryAI
- Christine D. Kim published a Bitcoin quantum security roadmap analysis on Sept. 14, 2026.
- BIP-360 proposes P2MR outputs that hide public keys until the moment of spending.
- SHRINCS uses SHA-256 with 48-byte public keys and minimum 548-byte signatures.
- Tadge Dryja presented Lifeboat at a New York Bitdevs meetup weeks before publication.
Bitcoin's Quantum Defense Takes Shape
Bitcoin (BTC) developers are consolidating years of scattered research into a coordinated answer to quantum computing risk. In an assessment posted to X on Sept. 14, 2026, researcher Christine D. Kim maps four parallel efforts — BIP-360, SHRINCS, Lifeboat and DropKick — as pieces of a potential quantum security roadmap for the network, her evaluation on X states. The threat model centers on a cryptographically relevant quantum computer (CRQC): a machine powerful enough to derive a private key from a public key already exposed on the blockchain and push a fraudulent spend ahead of the rightful owner. Nothing known today can do that, but the public keys behind long-dormant coins remain permanently visible, which is exactly the exposure the proposals target.
@christine_dkim · X post
Her evaluation on X.
View on X
BIP-360, a soft-fork proposal still in draft status, introduces a new output type called Pay-to-Merkle-Root (P2MR). Users who shift funds into P2MR outputs could keep their public keys hidden until the moment of spending and hold multiple spending paths — a preventive design that removes the long-term exposure baked into Bitcoin's current model, where revealing the public key at spend time is unavoidable. Backward-compatible upgrades of this kind have precedent on the network, from Segregated Witness (SegWit) onward. SHRINCS, developed by Blockstream researchers, is the complementary signature layer: a hash-based post-quantum scheme built on SHA-256, the same function that secures Bitcoin's proof-of-work mining, adding no new mathematical assumptions. Per the contributor behind the draft, public keys run 48 bytes, minimum signatures 548 bytes and the stateless alternative 5,777 bytes — roughly an order of magnitude smaller than comparable hash-based designs, with faster verification. SHRINCS remains experimental, however, and its specification has not yet passed independent security review. None of the four proposals is live on the network today — each remains a draft or research item, a point the assessment itself flags.
Lifeboat and DropKick Target Exposed Coins
The harder problem is the long-term HODL cohort that never migrates. If a CRQC arrives before a holder moves coins out of legacy address formats, an attacker who derives the private key from the exposed public key could front-run the withdrawal and seize the funds. Two recovery protocols aim at exactly this group: Lifeboat, from Tadge Dryja, the researcher best known for his work on the Lightning Network and Utreexo, and DropKick, from conduition, a
Bitcoin (BTC) Core contributor backed by the Brink development fund. Both rest on a commit-reveal construction, in which the user proves on-chain that they knew specific address information before any attacker could — establishing priority for a rescue transaction.
Dryja presented Lifeboat at a Bitdevs developer meetup in New York several weeks before the assessment was published, and he has specified the deeper design: an on-chain proof that a CRQC exists, which would automatically trigger a soft fork. Conduition, who published the SHRINCS BIP draft in late August 2026 — one day before Lifeboat's presentation — has left DropKick's activation mechanism deliberately undecided, per the developer interviews underpinning the analysis. Open items stack up. SHRINCS security proofs are unfinished, with insufficient test vectors and no third-party specification review yet. Signatures run roughly 10 times the size of today's Schnorr signatures, and grow larger under key reuse or the stateless fallback; conduition is studying aggregation techniques that compress multiple signatures into a single proof, drawing on research by Ethereum developers. What happens to inaccessible “lost”
Bitcoin (BTC) once a CRQC materializes remains unanswered. Both rescue protocols are classified as suggestions rather than active code, so users gain nothing until consensus changes. Readers tracking the market in real time can follow live spot and futures prices on Gate.
Drafts, Not Deployed Code
A practical test datapoint has surfaced alongside the roadmap: Blockstream published results in August 2026 showing that hash-based post-quantum signatures could be generated on hardware wallets including Jade, Trezor, Ledger and BitBox02. The demonstration matters because SHRINCS is explicitly designed to keep signature sizes from ballooning — most existing quantum-resistant schemes produce far more data than today's Schnorr signatures, which would fill block space faster, cut transaction throughput and push fees upward. The same reporting frames BIP-360 as structurally similar to Taproot, with one key difference: the direct public-key spending path is removed and replaced by a Merkle root representing the transaction conditions. Notably, BIP-360 on its own does not make
Bitcoin (BTC) fully quantum-resistant; it targets long-term public-key exposure, while faster attacks during the brief window between broadcast and confirmation would still require quantum-resistant signature schemes.
(as of 14:43 UTC) The weight of the primary document — the Sept. 14 X post — lies in its explicit caveat: none of BIP-360, SHRINCS, Lifeboat or DropKick is active on the Bitcoin network today, and no CRQC capable of breaking its cryptography is known to exist. As of Sept. 15, COINOTAG's read is that the significance is architectural rather than immediate: prevention before a CRQC arrives, recovery after, each layer deliberately separate. The gating factor is soft-fork consensus, and the open cost questions — block space for large signatures, SHRINCS security review, the treatment of lost coins — will decide whether this roadmap stays theoretical.
Primary sources
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

