
Around 6.04 million Bitcoin — roughly 30% of the total supply — already have their public keys exposed on the blockchain. That single statistic is what makes quantum security for Bitcoin wallets not a theoretical worry but an active, measurable risk. Now, researchers at AmericanFortress, a Wyoming-based blockchain security company, have put forward a system they believe could protect those wallets without forcing holders to move their funds.
Key takeaways
- AmericanFortress proposed ZKPoSP (Zero-Knowledge Proof of Seed Provenance), a post-quantum system letting wallet owners prove ownership without revealing their seed phrase.
- The system supports the most widely used wallet standards: BIP32, BIP44, and SLIP-10.
- Proof generation benchmarks ran at 12 to 13 seconds; verification took just 9 to 10 milliseconds.
- Blockchain analytics firm Glassnode estimated about 6.04 million BTC have exposed public keys vulnerable to quantum attacks.
- ZKPoSP is currently a research proposal — real-world use requires buy-in from wallet providers, exchanges, developers, and miners.
AmericanFortress Proposes ZKPoSP to Secure Crypto Wallets Against Quantum Threats
The system is called ZKPoSP, short for Zero-Knowledge Proof of Seed Provenance, and it represents a fundamental rethink of how wallet ownership gets verified. The research is published in a paper titled “ZKPoSP: Post-Quantum Zero-Knowledge Proofs for Hierarchical Deterministic Wallets.”
Standard wallets today rely on elliptic curve cryptography to prove ownership. The problem is that this method exposes public keys — and a sufficiently powerful quantum computer could work backward from a public key to derive the private key, giving an attacker full control of the funds. ZKPoSP sidesteps this entirely by replacing elliptic curve signatures with zero-knowledge proofs.
Using Zero-Knowledge Proofs Instead of Elliptic Curve Signatures
Zero-knowledge proofs let someone demonstrate they control a wallet’s seed phrase without ever revealing the seed itself. That distinction matters enormously: even if a private key were somehow exposed, the seed phrase — the true root of wallet ownership — remains hidden. The researchers argue this design keeps wallets secure even in a post-quantum environment.
The team built a working implementation of ZKPoSP in Rust, using the RISC Zero zero-knowledge virtual machine. The paper also describes a faster operational mode specifically designed to activate after Q-Day — the hypothetical point at which quantum computers become capable of breaking current encryption standards.
Compatibility with BIP32, BIP44, and SLIP-10 Wallet Standards
One of the more practical aspects of the proposal is its compatibility with the most common wallet infrastructure already in use. ZKPoSP is built to work with wallets that follow BIP32, BIP44, and SLIP-10 key derivation standards — the specifications that underpin the vast majority of hierarchical deterministic wallets used today. That compatibility reduces the barrier to adoption compared to systems that would require entirely new wallet architectures.
Technical Innovations and Performance Benchmarks of ZKPoSP
Beyond the core proof system, the AmericanFortress team introduced a new cryptographic component called QBIP32 — a key derivation method engineered to work across multiple elliptic curves. This multi-curve compatibility is designed to future-proof the system as cryptographic standards continue to evolve.
QBIP32: Multi-Elliptic Curve Compatible Key Derivation
QBIP32 extends the logic of existing derivation standards while building in support for multiple curve types. This is a meaningful technical contribution because different blockchain ecosystems use different elliptic curves, and a derivation method locked to a single curve limits portability across networks.
Proof Generation and Verification Times
Early benchmarks place proof generation at 12 to 13 seconds, with verification completing in just 9 to 10 milliseconds. The asymmetry is intentional and practical: slow proof generation is acceptable as a one-time or infrequent operation, while fast verification is what matters at the network level where transactions need to be processed quickly. Whether these benchmarks hold across different hardware configurations in production environments remains to be tested.
Quantum Computing Threats and the Urgency for Post-Quantum Cryptography
The quantum threat to Bitcoin is not hypothetical engineering — it has a specific mechanism. A powerful enough quantum computer could deploy Shor’s algorithm to calculate a wallet’s private key directly from its public key. Every time a Bitcoin transaction is broadcast, the sender’s public key becomes visible on the blockchain. That moment of exposure is the attack window.
The Risk of Exposed Public Keys on Bitcoin Blockchain
According to Glassnode, approximately 6.04 million BTC already have permanently exposed public keys — meaning those wallets are sitting in a state of latent vulnerability right now. The threat isn’t active today because no quantum computer yet has the scale to execute Shor’s algorithm against Bitcoin’s cryptography. But the window between “not yet possible” and “already possible” is exactly what researchers like those at AmericanFortress are trying to close before it arrives.
Shor’s Algorithm and the Path from Public Key to Private Key
Researchers cited progress in quantum hardware — including developments like Google’s Willow processor — as evidence that the timeline is compressing. Shor’s algorithm has been understood theoretically for decades; what changes over time is the scale of quantum hardware needed to run it against real-world key sizes. When that hardware threshold is crossed, wallets with exposed public keys become immediately vulnerable.
This is what makes the 6.04 million BTC figure so consequential. It represents a known, quantifiable pool of funds that cannot be made safe simply by changing behavior going forward — the public keys are already out there, permanently embedded in the blockchain’s history.
Current Status and Challenges for Adoption of Quantum-Resistant Wallets
ZKPoSP is, for now, a research proposal. No blockchain network has adopted it, and moving from paper to production would require coordinated action across a wide ecosystem: wallet providers, exchanges, developers, and miners would all need to support the new standard before it could offer meaningful protection at scale.
Other Industry Efforts and Governmental Support
AmericanFortress is not working in isolation. Project Eleven has proposed a related method allowing wallet ownership to be proven through a seed phrase after Q-Day. BTQ Technologies has gone a step further, testing BIP-360 on a Bitcoin quantum testnet specifically designed to trial quantum-resistant transaction formats.
On the institutional side, the Bitcoin Security Consortium — whose members include BlackRock, Coinbase, Strategy, Fidelity Digital Assets, and Galaxy — pledged $15 million over three years toward Bitcoin security research, with quantum defense as a primary focus. The U.S. Department of Commerce has also committed more than $2 billion to quantum computing research, development, and manufacturing programs.
The convergence of private consortium funding and government investment signals that the broader technology and finance establishment has moved past debating whether quantum risk is real. The open question now is sequencing: whether cryptographic standards like ZKPoSP can achieve the industry coordination they need before quantum hardware reaches the capability threshold that makes the threat operational. For roughly 6 million Bitcoin already sitting with exposed public keys, that race has already started.
FAQ
What is ZKPoSP and how does it protect Bitcoin wallets?
ZKPoSP, or Zero-Knowledge Proof of Seed Provenance, is a post-quantum cryptographic system proposed by AmericanFortress. It allows a wallet owner to prove control of their seed phrase without actually revealing it, replacing traditional elliptic curve signatures. Because the seed stays hidden, the wallet remains secure even if a private key is exposed — making it resistant to quantum attacks.
Why are quantum computers a threat to Bitcoin wallet security?
Quantum computers could use Shor’s algorithm to derive a private key from a publicly visible public key. Every Bitcoin transaction exposes the sender’s public key on the blockchain, creating a window of vulnerability. A sufficiently advanced quantum computer could exploit that exposure to forge signatures and steal funds.
Which wallet standards does ZKPoSP support?
ZKPoSP supports hierarchical deterministic wallets that use the BIP32, BIP44, and SLIP-10 key derivation standards — the most widely adopted specifications in the cryptocurrency wallet ecosystem today.
Is ZKPoSP currently implemented or widely adopted?
No. ZKPoSP remains a research proposal with no real-world adoption to date. For it to become operational, it would require broad industry cooperation from wallet providers, exchanges, developers, and miners across the blockchain ecosystem.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

1 hour ago
9









English (US) ·