The outputs remain 32-byte hashes, tagged as “TapBranch,” offering 128-bit collision resistance comparable to P2WSH. Developers describe it as a conservative first step toward quantum resistance rather than a sweeping cryptographic overhaul.
The proposal has already undergone multiple rewrites and renames. Originally drafted in 2024 as P2QRH (“Pay to Quantum Resistant Hash”), it became P2TSH (“Pay-to-Tapscript-Hash”) in late 2025 before settling on P2MR (“Pay-to-Merkle-Root”) after community feedback that the name should more accurately reflect what the output commits to.
Why Quantum Concerns ExistP2MR does not solve short-exposure risk during a mempool window, and it does not introduce post-quantum signatures. Instead, it addresses what developers call the “long-exposure” threat — coins sitting for years with publicly visible keys.
For a network that prefers incremental soft forks to sweeping redesigns, that tone is deliberate. Quantum alarms may be distant, but BIP 360 signals that developers are at least checking the exits — calmly, methodically and with their cryptographic homework in hand.
FAQ What is P2MR in Bitcoin’s BIP 360? P2MR (Pay-to-Merkle-Root) is a proposed output type that removes Taproot’s key-path spend while preserving full Tapscript functionality. Why are some bitcoin addresses vulnerable to quantum attacks? Addresses that expose public keys on-chain could, in theory, allow a quantum computer using Shor’s algorithm to derive private keys. Does BIP 360 introduce post-quantum signatures? No, it is a conservative step that does not add new signature schemes or opcodes. Is BIP 360 active on Bitcoin today? No, it remains a draft pull request under active review with no activation timeline.

















