BTCSOQ · reference implementation · demonstrated on Bitcoin testnet4 and Soqucoin stagenet, July 2026

Bitcoin, on the wrong side of the quantum boundary.

Roughly 4,000,000 BTC sit in outputs whose public keys are already exposed: early coinbases, reused addresses, Satoshi's coins. For those coins there is no harvest-now-decrypt-later; the keys are public now, and only hardware stands between them and a forged signature. BTCSOQ is a reference implementation of Bitcoin-backed receipts for licensed custodians. A custodian running it holds Bitcoin under classical keys on the Bitcoin side and issues receipts guarded by ML-DSA-44 on Soqucoin. The July 2026 demonstration ran on test networks with test coins. Soqucoin Labs operates no live deployment.

Exposure estimate: Deloitte, "Quantum computers and the Bitcoin blockchain" (~25% of circulating BTC in quantum-exposed outputs). Methodology notes in what is trusted.

JULY 2026 A record of the July 2026 demonstration is available. Testnet4 Bitcoin became an ML-DSA-44 receipt, paid a machine over L2SOQ and returned to Bitcoin. Open the record →
The boundary

Below are two signatures from the July 2026 test-network demonstration, byte for byte. The left one guarded the Bitcoin deposit before it crossed. The right one is the kind that guards receipt events on the Soqucoin side.

Classical · secp256k1 Schnorr
64 bytes
The signature that guarded the deposit on Bitcoin. Every coin on Bitcoin rests on one of these.
79951ad1f8498399759bcfda3eb0263ffe254d2af3b5f91d0097a0faf6562ef4d6425664e62daa77cc4fe107210c7926e169443bdd3ee719be5fde3772f7c377
Broken by Shor's algorithm on a cryptographically relevant quantum computer. Elliptic-curve keys fall in polynomial time.
Source: input 0 of deposit 7b6ee4aa…0adb, the first testnet4 deposit the demonstration round-tripped.
Post-quantum · ML-DSA-44 (NIST FIPS 204)
2,420 bytes
The signature that guards receipt events on the Soqucoin side. Lattice mathematics, no known quantum attack.
An ML-DSA-44 signature is 2,420 bytes, about 38 times the classical one on the left. In the July 2026 demonstration every receipt event was signed with one and published in an attestation feed. The feed was served for the demonstration and is no longer online; the verification code below reproduces the check against any saved record.
No known quantum attack. Security rests on the hardness of lattice problems, the basis of NIST FIPS 204.
The ledger, signed

Every event in the July 2026 demonstration was signed with ML-DSA-44 and published: deposit confirmed, receipt minted, receipt returned, Bitcoin released. Each record carried the payload, the signature and the signer's public key, so a browser could verify it as it loaded. The feed is no longer served. The code that reproduces each check is printed below and runs anywhere against a saved record.

A signature that verified then verifies anywhere, forever.

// Verify one saved attestation record (Node or browser): import { ml_dsa44 } from '@noble/post-quantum/ml-dsa.js'; // v0.6.1 const hexToBytes = (h) => Uint8Array.from(h.match(/.{2}/g).map((b) => parseInt(b, 16))); // a = one record from the feed: { payload, signatureHex } // pubkeyHex = the signer's ML-DSA-44 public key, published with the feed const digest = new Uint8Array(await crypto.subtle.digest( 'SHA-256', new TextEncoder().encode(a.payload))); ml_dsa44.verify(hexToBytes(a.signatureHex), digest, hexToBytes(pubkeyHex)); // true
Reserves

The invariant the reference design enforces: Bitcoin held by the custodian covers every receipt outstanding. Both numbers come from chain data, and the receipt ledger is rebuildable by anyone from the on-chain mint tags, without the operator's database. The design also writes the ledger's merkle root into a Bitcoin transaction on a schedule, so the books are anchored to Bitcoin itself.

The reserve counters that ran on this page during the July 2026 demonstration read from a feed that is no longer served, and the figures were not captured on the page. They are not shown.

What is trusted here, exactly

The demonstration ran on test networks. In the July 2026 demonstration the Bitcoin was testnet4 coin with no monetary value and Soqucoin Labs held the test keys. A production deployment would be run by a licensed custodian, who holds the Bitcoin-side keys, the same trust shape as the Bitcoin leg of every bridge in production today. What the demonstration shows is the post-quantum shield around it.

The receipt is an overlay asset. Receipt accounting is tracked by the operator's gateway software and tagged on-chain so anyone can rebuild the ledger; it is not enforced by Soqucoin consensus. USDSOQ, the stablecoin issuance technology built into the Soqucoin protocol, is consensus-enforced. A consensus-native BTCSOQ asset is a roadmap item.

The Bitcoin leg signs with classical cryptography, because Bitcoin's consensus accepts nothing else. Receipt custody, redemption authorization and the signed ledger are ML-DSA-44 in the reference implementation.

The USDSOQ hop is a design note. The reference design can settle a receipt into USDSOQ through an issuer's treasury. Supply does not change; only the issuer's authority keys can change supply, and they are nowhere in this path. USDSOQ is stablecoin issuance technology for licensed issuers. Soqucoin Labs is not an issuer and holds no reserves. USDSOQ is not active on mainnet.

The Lightning hop is a channel. The reference design pays over an L2SOQ channel. The Lightning service provider is a channel counterparty, never a key custodian. The proof that matters is the seller's ML-DSA-44 receipt, which binds the invoice, the question and the answer and verifies anywhere.

The exposure figure is an estimate. The ~4M BTC number comes from published analyses of pay-to-public-key outputs and address reuse (Deloitte and subsequent studies). One more detail: taproot addresses, including the deposit addresses the demonstration used, expose their public key from the moment they are funded. On Bitcoin that is unavoidable by design, which is the point of receipts guarded by post-quantum signatures.

Confirmation policy: the demonstration used one confirmation on testnet4. A production deployment by a licensed custodian would hold at six.