Block height

Cutoff

H0 is published in advance. Before it, ECDSA still spends. At H0 and after, only a hash-based signature does.

Before H0

One ECDSA transaction moves the full balance onto a new bc1q address. The address that revealed its key ends at zero.

H0 and after

Auth is SPHINCS over SHA-256 or BLAKE. An ECDSA signature is dropped, including one made from a recovered private key.

NS(out) = 1  iff
    version = 0
    program = HASH160(pk)
    length(program) = 20
    pk is not in the output

VALID(tx, h) = 1  iff
    h <  H0  and auth = ECDSA and outputs are NS
 or h >= H0  and auth = SPHINCS(SHA-256 | BLAKE)

ECDSA at h >= H0  →  rejected

What a node checks

Before H0, a transaction is valid if its authorization is an ECDSA signature and every output that holds the value is native segwit. That is the migration. One signature, full balance, new bc1q.

At H0 and after, the same ECDSA signature is not an authorization. The node does not need to decide whether the signature is mathematically correct. The rule is that ECDSA is no longer sufficient. The spend has to carry SPHINCS over SHA-256 or BLAKE. Curves, lattices, and isogenies are not added as substitutes.

A recovered key

If someone can compute the private key from a public key, they can produce a normal 64-byte signature. After H0 that signature still does not enter a block under this rule. Coins that were never moved are frozen against ECDSA too. The chain cannot tell the owner from the attacker once the key is public, so it stops accepting ECDSA for both. Moving before H0 is how the owner keeps a hash-based way to spend.