Post-Quantum Planning Gains Structure in Bitcoin's Ongoing Migration Debate
Bitcoin's post-quantum planning is gaining structure, but no network-wide migration has been adopted. Two draft proposals, BIP 360 and BIP 361, remain in discussion: BIP 360 focuses on a new output design to reduce long-exposure risk and support future post-quantum script paths, while BIP 361 outlines a phased migration policy following the introduction of a suitable post-quantum output type. As of September 17, these proposals are still under review.
BIP 360, also known as Pay-to-Merkle-Root, removes the Taproot-style key-path spend from its proposed output and relies on a script-tree commitment. Its authors aim to reduce public key exposure and create a foundation for future post-quantum signature schemes. However, BIP 360 does not provide a complete migration solution.
BIP 361 addresses the issue of migrating away from legacy ECDSA and Schnorr signatures after a post-quantum output type exists. The draft proposes staged restrictions to encourage migration over time, but it is essential to note that these phases are still under discussion and should not be considered as an active Bitcoin timetable or consensus among developers, miners, wallets, or users.