Quantum Resistance
Bitcoin Quantum Resistance
Toward Quantum Resistance: BIP 360 & SHRIMPS
Bitcoin’s elliptic curve cryptography has served us well for over 15 years, but quantum computers running Shor’s algorithm could one day break it. The good news? The Bitcoin development community is already shipping practical solutions instead of waiting for a crisis.
Two key pieces of the puzzle have emerged recently:
- BIP 360 — A new output type that protects against long-term exposure of public keys.
- SHRIMPS — A hash-based post-quantum signature scheme optimized for Bitcoin’s constraints, roughly 3× smaller than current NIST standards.
Together, they form a realistic, step-by-step path toward a quantum-resistant Bitcoin.

The Quantum Threat in Simple Terms
Quantum computers threaten two scenarios:
- Long-exposure attacks — An attacker has years to break a public key that has already been published on-chain (common with P2PK coins, reused addresses, and Taproot key-path spends).
- Short-exposure attacks — An attacker must break a key while a transaction is in the mempool (seconds to minutes).
BIP 360 tackles the first. SHRIMPS (and future follow-ups) tackle the second by replacing vulnerable signatures with quantum-safe ones.
What Is BIP 360? (Pay-to-Merkle-Root / P2MR)
Merged into the official Bitcoin BIPs repository on February 11, 2026, BIP 360 introduces a new native SegWit output type called Pay-to-Merkle-Root (P2MR).
It is modeled closely after Taproot (P2TR) but with one critical change: the quantum-vulnerable key-path spend is completely removed. Every P2MR output commits only to the Merkle root of a script tree.
- Address prefix: bc1z (Bech32m)
- ScriptPubKey: OP_2 + 32-byte Merkle root
- Requires: BIPs 340, 341, and 342
Key benefits:
- Preserves all the powerful scripting capabilities of Taproot (Lightning, BitVM, Ark, etc.).
- No internal public key is ever exposed on-chain until a script-path spend occurs.
- Makes long-exposure attacks impractical.
Comparison Table:
| Feature | Pay-to-Taproot (P2TR) | Pay-to-Merkle-Root (P2MR / BIP 360) |
|---|---|---|
| Key-path spend | Yes (Schnorr signature) | Removed (quantum protection) |
| Script-path spend | Yes | Yes (identical to Taproot) |
| Quantum long-exposure safe | No | Yes |
| Witness size (typical) | Smaller | Larger (always script path) |
| Address prefix | bc1p | bc1z |
BIP 360 is intentionally conservative — it is “Step 1” that creates a safe on-ramp for future post-quantum signatures without breaking existing scaling tools.
Current status: Draft BIP, first live implementation running on BTQ Technologies’ Bitcoin Quantum testnet (v0.3.0, released March 19, 2026). No activation date yet.
What Is SHRIMPS?
Announced at the end of March 2026 by Jonas Nick (Blockstream researcher), SHRIMPS is a stateful, hash-based post-quantum signature scheme built specifically for Bitcoin.
- Signature size: ~2.5 KB (roughly 3× smaller than NIST’s SLH-DSA at similar security levels).
- Multi-device friendly: Multiple devices loaded from the same seed (like BIP-32) can independently generate signatures without coordination issues.
- Design goal: Fit Bitcoin’s tight block space and fee constraints while remaining quantum-resistant.
It builds on the same hash-based family as related proposals (e.g., SHRINCS for single-device ultra-compact signatures). SHRIMPS removes the single-device limitation, making it more practical for real-world wallets and hardware signers.
SHRIMPS is not yet a BIP, but it is explicitly discussed as a strong candidate to pair with output types like P2MR.
How BIP 360 and SHRIMPS Work Together
Think of it as layers of defense:
- BIP 360 (P2MR) provides the output wrapper — a quantum-safe address format that never exposes a long-lived public key.
- SHRIMPS provides the signature primitive — compact, quantum-resistant signatures that can be used inside script paths.
This combination allows Bitcoin to keep Taproot-style efficiency for complex contracts while migrating the actual cryptography to post-quantum algorithms. Future soft forks could activate specific signature schemes inside P2MR outputs.
The full migration will likely take several years (estimates range from 3–7 years once activation begins), involving node software, wallets, exchanges, and user education. Starting now gives the ecosystem time to move calmly.
Why This Matters for Bitcoin Users
- HODLers: You’ll eventually have a clear path to migrate legacy and Taproot coins to safer bc1z addresses.
- Developers: Lightning, BitVM, Ark, and other Layer 2/3 solutions can continue building on familiar scripting primitives.
- Institutions & Governments: Signals that Bitcoin is taking quantum risks seriously (aligning with broader timelines like U.S. CNSA 2.0).
Even if a powerful quantum computer is still years away, proactive upgrades protect network credibility and your sats.
Current Status & Next Steps (as of April 2026)
- BIP 360 → Merged as Draft; live on BTQ Quantum testnet.
- SHRIMPS → Newly proposed; under discussion in Bitcoin developer circles.
- Broader roadmap → Expect more BIPs for signature activation, test vectors, and migration tools.
Watch the authors and discussions:
- BIP 360: Hunter Beast (@cryptoquick), Ethan Heilman, Isabel Foxen Duke
- SHRIMPS: Jonas Nick (@n1ckler)
Official Resources
- BIP 360: bip360.org and GitHub BIP text
- BTQ Bitcoin Quantum testnet announcement
- SHRIMPS proposal discussions (Delving Bitcoin, recent developer mailing lists, and X threads)
Bottom line: Bitcoin is not sitting idle. BIP 360 gives us a safer output type today, and SHRIMPS shows how compact post-quantum signatures can fit Bitcoin’s unique needs. Combined, they represent a thoughtful, engineering-driven approach to quantum resistance — preserving what makes Bitcoin great while preparing for the future.
The quantum clock is ticking, but the protocol is already moving. Stay informed, use fresh addresses where possible, and support the developers doing the hard work.This page was last updated April 2026 and combines the latest public information on both proposals.
Bitcoin Quantum Resistance:

Ready for Full Sovereignty?
Bitcoin belongs to everyone. Claim yours securely — no banks, no middlemen.
Start now.
Bitcoin Consulter™
Bitcoin Consulter™ offers training, support, and best practices to help independent Bitcoiners worldwide strengthen their sovereignty and navigate their Bitcoin journey.
FREE BITCOIN ART
Subscribe — stay ahead with BTC news, deals & new lessons.
Next Bitcoin Halving
Expected ~ April 2028
(Block reward: 3.125 → 1.5625 BTC)
Established @ Block Height : 449,049
©2026 Bitcoin Consulter™ - Privacy | Terms
